TWZRD
Don't let your agent sign blind.
Spend control and counterparty trust for agents paying over x402 on Solana (and Base).
Vet the seller before USDC leaves the wallet, cap and ledger every spend, and bind each settled payment to the exact offer it paid for (bind-v1 — verifiable from public chain data). Advisory preflight is free ($0). Signed execution clearance is $0.001 (twzrd.payment_decision.v1 / quickCheck). Not a wallet. Not a payment network. Not Catena's Agent Commerce Kit — the walkthrough lives in docs/COMMERCE-KIT.md.
Canonical skill (always refresh) • https://intel.twzrd.xyz/skill.md (twzrd-trust 1.13.24) · ClawHub twzrd-trust
Spend-control SDK (npm) • twzrd-x402-gate@0.9.12 + seat x402-solana@3.0.0
Live MCP • https://intel.twzrd.xyz/mcp (streamable HTTP — 22 tools)
Agent contract • https://intel.twzrd.xyz/llms.txt · https://intel.twzrd.xyz/.well-known/agent.json
60-second deterministic free demo
Run this one-line command with no wallet, no API key, and no configuration:
curl -fsS https://intel.twzrd.xyz/v1/intel/demo-gate | jq '{verdict: (.steps[] | select(.name == "block_path") | .verdict), approved: (.steps[] | select(.name == "block_path") | .approved), signerInvocations: (.steps[] | select(.name == "block_path") | .signer_invocations), mode, ok}'
Without jq, run: curl -fsS https://intel.twzrd.xyz/v1/intel/demo-gate
Expected output:
{
"verdict": "block",
"approved": false,
"signerInvocations": 0,
"mode": "no_spend",
"ok": true
}
Blocks happen before your signer is invoked (signerInvocations: 0) — zero USDC at risk.
From this repo
This checkout is a public monorepo, not npm install twzrd-x402-gate. CI is
root npm ci then npm run ci (Node 20). Do not npm ci inside
twzrd-x402-gate/ — gate typecheck needs sibling twzrd-log-verifier deps
from the root lockfile.
npm ci
npm run build
npm run typecheck
npm test --workspace=twzrd-x402-gate
npm run gate-eval-refuse --workspace=twzrd-x402-gate
gate-eval-refuse is the hello-world that closes (0 USDC, signer_invocation_count: 0).
It needs egress to https://intel.twzrd.xyz. Artifact dirs (eliza-plugin/,
plugin-trustgate/, twzrd-mcp-server/) are dist/ mirrors — do not try to
build or demo them locally. Hosted MCP: https://intel.twzrd.xyz/mcp.
Quickstart
1. Install
npm install twzrd-x402-gate@0.9.12 x402-solana@3.0.0
2. Wrap paid fetches with spend controls
import { twzrd } from "twzrd-x402-gate";
const result = await twzrd.safeFetch("https://merchant.example/paid-endpoint", {
maxSpend: "0.10", // per-call cap AND cumulative budget in USD
allowNetworks: ["solana"], // allowed settlement networks
requireOfferBinding: true, // demand an on-chain verifiable bind-v1 receipt
pay: async ({ url, paymentRequired, selected }) => {
// Your existing x402 client signs here — e.g. @x402/fetch + your signer
return await myWallet.payX402(url, paymentRequired, selected);
},
});
// On block: result.verdict === "block", result.signerInvocations === 0
3. Or hook an existing client
import { createX402Client } from "x402-solana";
import { createTwzrdBeforePaymentHook } from "twzrd-x402-gate";
const client = createX402Client({
wallet,
network: "solana",
beforePayment: createTwzrdBeforePaymentHook({ refuseWashFlagged: true }),
});
Commerce loop
One path. Install twzrd-x402-gate@0.9.12. Free preflight does not enforce; AutoGate on the pay path does.
- Install the gate —
npm i twzrd-x402-gate@0.9.12theninstallTwzrdAutoGate - Cold-start (optional) —
npx twzrd-cold-startwrites a default-denypolicy.jsonfrom a pinned foreign 402 diet (0 USDC; not a TWZRD bazaar) - Directory —
GET /v1/intel/resources(orlistDirectoryCallables) — bazaars list; TWZRD sits beside - Preflight — free ReadinessCard + merchant_card wash refuse
- Pay only when policy allows — blocks have
signerInvocations === 0 - Clearance ($0.001) —
quickCheck+ portabletwzrd.payment_decision.v1(npx twzrd-payment-decision --verify) - Evidence bundle —
exportEvidenceBundle/npx twzrd-evidence-bundle - Optional Path A — $0.05 V7 intel receipt. Not the primary SKU.
Refuse-first demo (0 USDC): npx tsx twzrd-x402-gate/examples/commerce-kit.ts
Cold-start diet (0 USDC): npx twzrd-cold-start
Walkthrough: docs/COMMERCE-KIT.md
Default Protection Sequence
- Discover —
GET /v1/intel/resources(resource catalog) - Merchant card —
GET /v1/intel/merchant_card/{pay_to}(refuse ifwash_flagged: true) - Preflight —
POST /v1/intel/preflight→ ReadinessCard (allow / warn / block) - Clearance ($0.001) —
GET /v1/intel/quick/{pay_to}+twzrd.payment_decision.v1 - Pay — sign only when preflight & spend policy allow
# Free preflight (no signup, no wallet)
curl -s -X POST https://intel.twzrd.xyz/v1/intel/preflight \
-H 'content-type: application/json' \
-d '{"seller_wallet":"46vMcwuC4sK11sB3gkLhyA7J7GEwfkhn5rFyDtihBwqe","price_usdc":0.01,"agent_intent":"preflight"}'
Packages & References
| Package | Pin | Description |
|---|---|---|
twzrd-x402-gate | @0.9.12 | Spend-control SDK (twzrd.safeFetch) + pre-sign gate hooks |
x402-solana | @3.0.0 | Compatible Solana client seat for the pre-payment gate |
twzrd-receipt-verifier | @^1.4.0 | Standalone offline verifier for Ed25519 V5/V6/V7 receipts |
twzrd-mcp-server | @0.5.4 (this tree) | Local spend-capped auto-pay client (6 tools); prefer hosted MCP |
@wzrd_sol/plugin-trustgate | @^0.3.7 | Eliza / facilitator adapter |
- Commerce loop (don't sign blind): docs/COMMERCE-KIT.md
- Step-by-step Guide: QUICKSTART.md
- Concepts & Architecture: docs/taxonomy.md
- V6/V7 Receipt Specification: docs/receipt-v6-spec.md
- Receipt Transparency Log: docs/transparency-log.md (in-repo
twzrd-log-verifier— not on npm) - Receipt Verification & Ground Truth: REVIEW.md
- Security Policy: SECURITY.md · docs/security-assurance.md