Check first. Then sign.
One gateway between an AI agent and its wallet. It checks the token, simulates the transaction and applies the owner's policies before anything gets signed.
When agents
sign blind.
Two checks, one gateway.
Scan decides whether a token can be trusted. Bastion decides whether a transaction is safe to sign. Together they cover everything from the agent's decision to the money in the wallet.
The agent calls one function, sentinel.execute(intent), instead of signing directly. Everything else happens inside the gateway.
One transaction, four checks.
simulateTransaction: what leaves, what arrives, which programs are calledEvery decision is logged with its reason and rules version, so the owner can see why the wallet said no.
clawpump-sentinel from npm, or call POST /api/execute. Every route returns a verdict and an unsigned transaction.Scan sees the token. Bastion sees the transaction.
Open rules. Every verdict carries its rules version.
Measured October 1, 2026: a cold scan takes 1.0 s at the median and under 2.1 s for 90% of tokens; 0 of 18 established tokens were blocked and 6 of 6 already-drained tokens were. Small samples, see how it was measured.
policy.jsonv1{ "limits": { "per_tx_sol": 2, "per_day_sol": 10 }, "programs": ["pump.fun", "jupiter"], "min_token_score": 60, "max_slippage_bps": 300, "new_recipient": "confirm", "mode": "enforce" // "warn" reports but never blocks }
The agent can't skip the check.
An API can be ignored: a compromised agent could sign on its own. A guarded wallet closes that path. Funds sit in a Squads v4 multisig where nothing executes without a vote, and the agent has no vote.
Plug it in with one API call.
Swap your agent's direct signing for one request. Sentinel builds the transaction, checks it and returns either a transaction that is safe to sign or the reason it isn't.
requestPOST /api/executecurl -X POST https://sentinel-clawpump.vercel.app/api/execute \ -H 'content-type: application/json' \ -d '{ "intent": { "type": "buy", "wallet": "<agent wallet>", "mint": "<token CA>", "sol": 0.5 }, "policy": { "limits": { "per_tx_sol": 2 } } }'
response200{ "decision": "allow", // allow · confirm · block · freeze "transaction": "AQAAAA…", // unsigned, base64 "reasons": [], "scan": { "score": 84, "verdict": "allow" }, "bastion": { "changes": { "sol": -0.5 }, "slippageBps": 0 } }
scan_token, execute_intent, check_transaction, guard_setup, guard_execute, guard_finalize, guard_status and decision_log.npm i clawpump-sentinelTypeScriptimport { Sentinel } from 'clawpump-sentinel'; const sentinel = new Sentinel(); const res = await sentinel.executeAndSend( { type: 'buy', wallet, mint, sol: 0.5 }, agentKeypair, connection, ); // signs and sends only when res.decision is "allow"
What keeps your wallet safe.
"mode": "warn" to see every verdict without blocking anything. Switch to enforce when you're ready.Checked.
Signed.
The transaction goes on-chain only after Scan, the simulation and the owner's policies have all passed.
Connect your agent