A permission checkpoint for AI agents. One API call before any sensitive action — your rules enforced, every decision logged. Agents don't go rogue on our watch.
Quickstart Start here
1
Create a workflow and write rules
Go to the Rules engine. Name your workflow, write rules in JavaScript, click Deploy.
2
Register your agent's signing key
Go to Agent Identity. Generate an Ed25519 key pair in-browser. Register the public key.
3
Generate an API key
Go to API keys. Select your workflow. Generate a key.
4
Add the check to your agent
Before any sensitive action — call POST /check with your API key, a signed request, and the action details.
StraxisWall is a permission checkpoint — not a proxy. Your agent keeps calling its existing APIs directly. You just add one call to StraxisWall before any sensitive action. If it's allowed, proceed. If it's blocked, stop — with a reason logged forever.
flow — request lifecycle
animated
Your AI Agent
POST /check + signature
StraxisWall Gateway
verify signature
Signature Verified
run your rules
Rules pass?
YES
allowed: true logged permanently
NO
allowed: false reason + logged
StraxisWall never sees your OpenAI keys, Stripe keys, or any sensitive credentials. Your AI model traffic never passes through our servers. We only see what you send in the request body.
Workflows
A workflow is a named set of rules tied to one API key. Each workflow governs one type of agent or process.
refund-pipeline → rules: max refund $500, no refunds after hours
email-automation → rules: approved domains only, no bulk > 50
data-fetcher → rules: no bulk queries > 1000 records, no deletes
POST /check Core
The only endpoint you need. Call this before any sensitive action.
endpointPOST https://www.straxiswall.com/check
Headers
Header
Description
x-api-key
Your StraxisWall API key for this workflow
required
x-agent-id
Name of the agent making this call — e.g. refund-bot
required
x-signature
Ed25519 signature of the request body (hex-encoded). Required if the agent has a registered key.
required*
x-timestamp
Unix timestamp in milliseconds. Must be within 5 minutes of server time.
required*
x-workflow
Override the workflow name. Falls back to the workflow tied to your API key.
optional
Content-Type
application/json
required
* Required when the agent has a registered Ed25519 public key.
Request body
action is the only required field. Add any other fields your rules need.
Always check the HTTP status code. If StraxisWall is unreachable, your agent should block the action by default — fail safe, not fail open.
Agent Identity Signing NEW
Agent signing gives every request a cryptographic proof of origin. It proves the request came from a specific agent — not just anyone who has the API key — and that the request body was not tampered with in transit.
Every verified check is stored with its signature in your logs — creating an audit trail that is admissible as evidence. Banks, healthcare companies and legal firms require this level of proof.
StraxisWall uses Ed25519 — a modern elliptic curve signature scheme. Keys are generated in your browser using the Web Crypto API. Your private key never leaves your device or gets sent to StraxisWall.
How it works
1
Generate a key pair
Go to Agent Identity page. Generate an Ed25519 key pair in your browser. Download and store the private key securely — it never leaves your device.
2
Register the public key
Submit the public key to StraxisWall with an agent ID and label. StraxisWall stores it and uses it to verify future requests from that agent.
3
Sign every request
Before calling /check — sign the request body + timestamp with your private key. Include the signature in x-signature and the timestamp in x-timestamp.
4
StraxisWall verifies
Every request is verified against the registered public key. Replay attacks are blocked — timestamps must be within 5 minutes. Tampered bodies are rejected instantly.
Signing — code example
Python
python
import requests, json, time
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from cryptography.hazmat.primitives.serialization import Encoding, PrivateFormat, NoEncryption
# Load your private key (PEM or raw bytes)with open('agent-private.pem', 'rb') as f:
private_key = Ed25519PrivateKey.from_private_bytes(f.read())
defstraxis_check(action, body={}):
payload = {'action': action, **body}
body_bytes = json.dumps(payload, separators=(',', ':')).encode()
timestamp = str(int(time.time() * 1000))
message = body_bytes + timestamp.encode()
signature = private_key.sign(message).hex()
res = requests.post(
'https://www.straxiswall.com/check',
headers={
'x-api-key': 'sk-your-key',
'x-agent-id': 'refund-bot',
'x-signature': signature,
'x-timestamp': timestamp,
'Content-Type': 'application/json'
},
data=body_bytes
)
return res.json()
# Usage
result = straxis_check('issue_refund', {'amount': 250})
if result['allowed']:
issue_refund()
Rules are JavaScript functions written in the Rules engine. Each function receives a request object. Return { block: true, reason: "..." } to block or { block: false } to allow. Rules run top to bottom — first block wins.
request.action// what the agent wants to do
request.agent// agent ID from x-agent-id header
request.workflow// which workflow
request.body// full request body
request.count// async — count past actions (velocity)
request.sum// async — sum a field from past actions
Velocity rules NEW
Velocity rules let your rules look at history, not just the current request. This catches runaway agent loops that single-action rules miss.
A rule that says "no refund above $500" won't catch an agent issuing 200 refunds of $499 each. Velocity rules catch that on refund number eleven.
javascript// Block if agent issued more than 10 refunds in last 60 minutesasync functionnoRunawayLoop(request) {
const count = await request.count('issue_refund', 60);
if (count > 10) {
return { block: true, reason: `Agent issued ${count} refunds in 60 min — possible loop` };
}
return { block: false };
}
// Block if agent spent more than $5000 in last 24 hoursasync functionspendingCap(request) {
const total = await request.sum('issue_refund', 'amount', 1440);
if (total > 5000) {
return { block: true, reason: `Agent spent $${total} in 24h — cap exceeded` };
}
return { block: false };
}
Helper
Arguments
Returns
request.count()
action, minutes
Number of times that action was called in the last N minutes
request.sum()
action, field, minutes
Sum of a numeric body field across matching logs in the last N minutes