SENTINEL
Get started
[ 01 · Security for the agent economy ]

Check first. Then sign.

One gateway between an AI agent and its wallet. It checks the token, simulates the transaction and applies the owner's policies before anything gets signed.

Scroll
[ 02 · Problem ]

When agents
sign blind.

01Flow
Scams at scale
Thousands of launches a day. Bundles, snipers and dev dumps are invisible in a DEX interface.
02Injection
Prompt injection
Agents read tweets and token descriptions. One malicious line can make the key sign away the whole wallet.
03Coverage
Piecemeal protection
Even with a token check, an agent can still send money to the wrong place. You need one layer that covers the whole path.
04Signing
Blind signing
Nobody shows the agent or its owner what a transaction will actually do.
[ 03 · Idea ]

Two checks, one gateway.

Scan decides whether a token can be trusted. Bastion decides whether a transaction is safe to sign. Together they cover everything from the agent's decision to the money in the wallet.

The agent calls one function, sentinel.execute(intent), instead of signing directly. Everything else happens inside the gateway.

sentinel.executegateway verdict
Allowed
The buttons show example scenarios. Paste a CA to run a live check.
[ 04 · Flow ]

One transaction, four checks.

01
Intent from the agent
“buy token X for 2 SOL”
02
Scan
Token score, flags, rules version → below threshold = block
03
Simulation & decoder
simulateTransaction: what leaves, what arrives, which programs are called
04
Policy engine
Limits, program allowlist, slippage, new addresses, frequency
Allowunsigned tx, ready to sign
Confirmowner approves first
Blockreason in the response
Freezekill-switch on anomaly

Every decision is logged with its reason and rules version, so the owner can see why the wallet said no.

Who it's for
AMCP · REST
For agents
Connect the MCP server, install clawpump-sentinel from npm, or call POST /api/execute. Every route returns a verdict and an unsigned transaction.
Bpolicy.json
For owners
Your policy travels with every request: limits, program allowlist, slippage, new recipients.
CLive check
For everyone
Paste any token CA on this page for a free live mainnet check.
[ 05 · Modules ]

Scan sees the token. Bastion sees the transaction.

Scan module · score 0–100

Open rules. Every verdict carries its rules version.

Creator
past launches, dead-token rate, dev dump, wallet age
20
Holders
top-10 share, clusters funded from one SOL source
20
Bundles & snipers
buys in the first blocks
15
Authorities
mint / freeze authority, mutable metadata
15
Liquidity
depth, LP lock
15
Trading anomalies
sell test (honeypot), wash trading, spikes, crashes
10
Metadata
impersonation, duplicates, broken links
5
Critical flags (active mint, honeypot) block regardless of the amount.

Measured October 1, 2026: a cold scan takes 1.0 s at the median and under 2.1 s for 90% of tokens; 0 of 18 established tokens were blocked and 6 of 6 already-drained tokens were. Small samples, see how it was measured.

Bastion module
01Decode
Simulation
Every transaction is decoded into plain terms before signing.
02Rules
Policies
Per-trade and daily limits, program allowlist, max slippage, no new recipients without confirmation.
03Drainers
Drainer detection
Token approvals to strangers, owner changes and account takeovers are always blocked, no matter the policy.
04Freeze
Kill-switch
A spike in size or frequency, or an attempt to drain the balance, returns a freeze verdict before anything is signed.
policy.jsonv1
{ "limits": { "per_tx_sol": 2, "per_day_sol": 10 }, "programs": ["pump.fun", "jupiter"], "min_token_score": 60, "max_slippage_bps": 300, "new_recipient": "confirm", "mode": "enforce" // "warn" reports but never blocks }
[ 06 · Guard ]

The agent can't skip the check.

An API can be ignored: a compromised agent could sign on its own. A guarded wallet closes that path. Funds sit in a Squads v4 multisig where nothing executes without a vote, and the agent has no vote.

Multisig members · threshold 1
Owner
approves anything, moves funds, removes the agent at any time
all permissions
Agent
proposes trades and runs the approved ones, cannot approve its own
propose · execute
Sentinel
approves what passes Scan and Bastion, cannot propose or move funds
vote only
01On-chain
Enforced by Squads
The rule lives in the multisig program, not on our server. A transaction the agent pushes without Sentinel's vote is rejected on-chain.
02Freeze
A freeze that holds
After a kill-switch verdict Sentinel stops voting for the wallet until the owner unfreezes it with a signed message.
03Approvals
Owner in the loop
Trades that need the owner arrive in Telegram with a link to an approval page, signed with the owner's wallet.
04Exit
No lock-in
The owner holds every permission and can withdraw or remove the agent without Sentinel's involvement.
[ 07 · API ]

Plug it in with one API call.

Swap your agent's direct signing for one request. Sentinel builds the transaction, checks it and returns either a transaction that is safe to sign or the reason it isn't.

requestPOST /api/execute
curl -X POST https://sentinel-clawpump.vercel.app/api/execute \ -H 'content-type: application/json' \ -d '{ "intent": { "type": "buy", "wallet": "<agent wallet>", "mint": "<token CA>", "sol": 0.5 }, "policy": { "limits": { "per_tx_sol": 2 } } }'
response200
{ "decision": "allow", // allow · confirm · block · freeze "transaction": "AQAAAA…", // unsigned, base64 "reasons": [], "scan": { "score": 84, "verdict": "allow" }, "bastion": { "changes": { "sol": -0.5 }, "slippageBps": 0 } }
Connect over MCP
MCPStreamable HTTP
https://sentinel-clawpump.vercel.app/api/mcp
Add it as a custom connector. Your agent gets eight tools: scan_token, execute_intent, check_transaction, guard_setup, guard_execute, guard_finalize, guard_status and decision_log.
Or use the SDK
npm i clawpump-sentinelTypeScript
import { Sentinel } from 'clawpump-sentinel'; const sentinel = new Sentinel(); const res = await sentinel.executeAndSend( { type: 'buy', wallet, mint, sol: 0.5 }, agentKeypair, connection, ); // signs and sends only when res.decision is "allow"
Endpoints
POST/api/execute
Execute an intent
buy · sell · swap · transfer. Scan, build, simulate, apply policy.
POST/api/bastion/check
Check your own tx
Already building transactions? Send one and get Bastion's verdict before signing.
GET/api/scan/:mint
Score a token
0–100 score, flags and a per-block breakdown for any Solana token.
GET/api/journal
Decision log
Every verdict with its reasons and rules version, filterable by wallet.
[ 08 · Trust ]

What keeps your wallet safe.

01Non-custodial
No access to your keys
Sentinel never sees a private key. It returns unsigned transactions, and your agent signs only the ones that passed.
02Local check
You don't have to trust our server
Before signing, the SDK simulates the transaction on your own RPC and compares it with the intent: amount, token, recipient, no new delegates. A mismatch throws, and nothing is signed.
03Fail closed
If Sentinel is down, nothing is signed
An error or a 30-second timeout means no signature. A guarded wallet cannot move funds without Sentinel's vote, and the owner keeps full control. The API allows 30 requests per minute per IP.
04Explainable
Every verdict is explained
Each verdict lists its reasons and the rules version behind it, and is saved to the decision log.
05Warn mode
Start in warn mode
Set "mode": "warn" to see every verdict without blocking anything. Switch to enforce when you're ready.
[ 09 · Signed ]

Checked.
Signed.

The transaction goes on-chain only after Scan, the simulation and the owner's policies have all passed.

Connect your agent