trigguard
v0.3.1
Published
TrigGuard public SDK — authorize, verify, receipts, agents, CLI. One install.
Maintainers
Readme
trigguard — canonical product SDK
Execution authorization for AI agents and automated systems.
npm install trigguardimport {
authorize,
verify,
receipt,
explain,
createAgent,
createClient,
} from "trigguard";CLI is the same install:
npx trigguard authorize
npx trigguard verify
npx trigguard policy
npx trigguard demoPublic products
| Install | Role |
|---------|------|
| npm install trigguard | SDK + CLI |
| pip install trigguard | Python SDK |
| pip install authgraph | Execution intelligence |
| npx @trigguard/mcp | MCP |
| pip install trigguard-litellm | LiteLLM callback |
Internals (@trigguard/execution-sdk, agent-sdk, intent-sdk, …) stay in the monorepo. Prefer this package. Subpaths exist for gradual migration: trigguard/execution, trigguard/agent, trigguard/express, trigguard/proxy.
Offline demo: examples/quickstart-node/.
API surface
| Method | Purpose |
|--------|---------|
| authorize | POST /v1/authorize — returns CustomerDecisionResult |
| verify | Offline receipt signature verification |
| explain | Human-readable decision summary |
| attest | Record an attestation via authorize |
| audit | Query workspace audit entries |
| coach | Advisory outcome preview (non-binding) |
Integration helpers:
@trigguard/execution-sdk— shared HTTP client (prefertrigguardfor apps)@trigguard/agent-sdk—npm install @trigguard/agent-sdkfor agents@trigguard/proxy/@trigguard/express-middleware— Express; not included in the flagship install
Architecture freeze: docs/PACKAGE_ARCHITECTURE.md.
First protected call (Evaluate-safe)
For no-payment Evaluate tenants, use a staging/sandbox-safe call for the first authorization path:
import { authorize } from "trigguard";
const decision = await authorize({
gatewayUrl: "https://api.trigguardai.com",
apiKey: process.env.TRIGGUARD_API_KEY,
organizationId: process.env.TRIGGUARD_ORGANIZATION_ID,
surface: "payment.execute",
context: {
environment: "sandbox",
provider: "mock_payout",
liveFunds: false,
amount: 10,
currency: "USD",
},
});- Do not send a synthetic default
actorclaim for API-key calls unless you intentionally bind one. - Non-2xx transport/auth responses throw typed SDK errors (
TrigGuardAuthError,TrigGuardForbiddenError,TrigGuardHttpError) rather than returning syntheticSILENCE.
Policy simulation (advisory, separate install):
npm install @trigguard/simulatorMigrating from legacy packages
| Legacy | Status | Use instead |
|--------|--------|-------------|
| @trigguard/execution-sdk | Supported, deprecated | npm install trigguard |
| sdk/node (@trigguard/decision) | Supported, deprecated (Rail B) | createTrigGuard().authorize() |
| trigguard-js | Legacy | createTrigGuard() |
Guide: docs/adoption/MIGRATE_TO_TRIGGUARD_SDK.md.
Python
HOLD until verb parity with Node — see output/PYTHON_PUBLISH_HOLD.md.
Development: pip install -e sdk/python · examples/quickstart-python/
Monorepo development
npm run build -w trigguard
npm run test -w trigguardSee docs/adoption/FIRST_10_MINUTES.md for onboarding.
