Getting started
Quickstart
How it works
Workflows
API Reference
POST /check
Headers
Request body
Responses
Agent Signing NEW
Overview
Setup
Code example
Rules engine
Writing rules
Request object
Velocity rules
Examples
Languages
Python
JavaScript
Go
Documentation
StraxisWall

A permission checkpoint for AI agents. One API call before any sensitive action — your rules enforced, every decision logged. Agents don't go rogue on our watch.

Quickstart Start here

1
Create a workflow and write rules
Go to the Rules engine. Name your workflow, write rules in JavaScript, click Deploy.
2
Register your agent's signing key
Go to Agent Identity. Generate an Ed25519 key pair in-browser. Register the public key.
3
Generate an API key
Go to API keys. Select your workflow. Generate a key.
4
Add the check to your agent
Before any sensitive action — call POST /check with your API key, a signed request, and the action details.
5
Watch your logs
Every check appears in Activity logs in real time.

How it works

StraxisWall is a permission checkpoint — not a proxy. Your agent keeps calling its existing APIs directly. You just add one call to StraxisWall before any sensitive action. If it's allowed, proceed. If it's blocked, stop — with a reason logged forever.

flow — request lifecycle
animated
Your AI Agent
POST /check + signature
StraxisWall Gateway
verify signature
Signature Verified
run your rules
Rules
pass?
YES
allowed: true
logged permanently
NO
allowed: false
reason + logged
StraxisWall never sees your OpenAI keys, Stripe keys, or any sensitive credentials. Your AI model traffic never passes through our servers. We only see what you send in the request body.

Workflows

A workflow is a named set of rules tied to one API key. Each workflow governs one type of agent or process.

refund-pipeline → rules: max refund $500, no refunds after hours email-automation → rules: approved domains only, no bulk > 50 data-fetcher → rules: no bulk queries > 1000 records, no deletes

POST /check Core

The only endpoint you need. Call this before any sensitive action.

endpoint POST https://www.straxiswall.com/check

Headers

HeaderDescription
x-api-keyYour StraxisWall API key for this workflowrequired
x-agent-idName of the agent making this call — e.g. refund-botrequired
x-signatureEd25519 signature of the request body (hex-encoded). Required if the agent has a registered key.required*
x-timestampUnix timestamp in milliseconds. Must be within 5 minutes of server time.required*
x-workflowOverride the workflow name. Falls back to the workflow tied to your API key.optional
Content-Typeapplication/jsonrequired

* Required when the agent has a registered Ed25519 public key.

Request body

action is the only required field. Add any other fields your rules need.

json { "action": "issue_refund", "amount": 250, "customer_id": "cus_123", "destination": "stripe" }

Responses

Allowed — 200

{ "allowed": true, "logged": true, "workflow": "refund-pipeline" }

Blocked — 403

{ "allowed": false, "reason": "Refund of $250 exceeds $100 limit", "logged": true }

Invalid signature — 401

{ "allowed": false, "error": "Signature verification failed" }

Invalid key — 401

{ "allowed": false, "error": "Invalid API key" }
Always check the HTTP status code. If StraxisWall is unreachable, your agent should block the action by default — fail safe, not fail open.

Agent Identity Signing NEW

Agent signing gives every request a cryptographic proof of origin. It proves the request came from a specific agent — not just anyone who has the API key — and that the request body was not tampered with in transit.

Every verified check is stored with its signature in your logs — creating an audit trail that is admissible as evidence. Banks, healthcare companies and legal firms require this level of proof.

StraxisWall uses Ed25519 — a modern elliptic curve signature scheme. Keys are generated in your browser using the Web Crypto API. Your private key never leaves your device or gets sent to StraxisWall.

How it works

1
Generate a key pair
Go to Agent Identity page. Generate an Ed25519 key pair in your browser. Download and store the private key securely — it never leaves your device.
2
Register the public key
Submit the public key to StraxisWall with an agent ID and label. StraxisWall stores it and uses it to verify future requests from that agent.
3
Sign every request
Before calling /check — sign the request body + timestamp with your private key. Include the signature in x-signature and the timestamp in x-timestamp.
4
StraxisWall verifies
Every request is verified against the registered public key. Replay attacks are blocked — timestamps must be within 5 minutes. Tampered bodies are rejected instantly.

Signing — code example

Python

python
import requests, json, time from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey from cryptography.hazmat.primitives.serialization import Encoding, PrivateFormat, NoEncryption # Load your private key (PEM or raw bytes) with open('agent-private.pem', 'rb') as f: private_key = Ed25519PrivateKey.from_private_bytes(f.read()) def straxis_check(action, body={}): payload = {'action': action, **body} body_bytes = json.dumps(payload, separators=(',', ':')).encode() timestamp = str(int(time.time() * 1000)) message = body_bytes + timestamp.encode() signature = private_key.sign(message).hex() res = requests.post( 'https://www.straxiswall.com/check', headers={ 'x-api-key': 'sk-your-key', 'x-agent-id': 'refund-bot', 'x-signature': signature, 'x-timestamp': timestamp, 'Content-Type': 'application/json' }, data=body_bytes ) return res.json() # Usage result = straxis_check('issue_refund', {'amount': 250}) if result['allowed']: issue_refund()

JavaScript / Node.js

javascript
const { createPrivateKey, sign } = require('crypto'); const fs = require('fs'); const privateKey = createPrivateKey(fs.readFileSync('agent-private.pem')); async function straxisCheck(action, body = {}) { const payload = { action, ...body }; const bodyStr = JSON.stringify(payload); const timestamp = Date.now().toString(); const message = Buffer.concat([Buffer.from(bodyStr), Buffer.from(timestamp)]); const signature = sign(null, message, privateKey).toString('hex'); const res = await fetch('https://www.straxiswall.com/check', { method: 'POST', headers: { 'x-api-key': 'sk-your-key', 'x-agent-id': 'refund-bot', 'x-signature': signature, 'x-timestamp': timestamp, 'Content-Type': 'application/json' }, body: bodyStr }); return res.json(); }

Writing rules

Rules are JavaScript functions written in the Rules engine. Each function receives a request object. Return { block: true, reason: "..." } to block or { block: false } to allow. Rules run top to bottom — first block wins.

javascript const rules = [ function myRule(request) { if (someCondition) { return { block: true, reason: 'Why blocked' }; } return { block: false }; } ]; module.exports = rules;

Request object

request.action // what the agent wants to do request.agent // agent ID from x-agent-id header request.workflow // which workflow request.body // full request body request.count // async — count past actions (velocity) request.sum // async — sum a field from past actions

Velocity rules NEW

Velocity rules let your rules look at history, not just the current request. This catches runaway agent loops that single-action rules miss.

A rule that says "no refund above $500" won't catch an agent issuing 200 refunds of $499 each. Velocity rules catch that on refund number eleven.
javascript // Block if agent issued more than 10 refunds in last 60 minutes async function noRunawayLoop(request) { const count = await request.count('issue_refund', 60); if (count > 10) { return { block: true, reason: `Agent issued ${count} refunds in 60 min — possible loop` }; } return { block: false }; } // Block if agent spent more than $5000 in last 24 hours async function spendingCap(request) { const total = await request.sum('issue_refund', 'amount', 1440); if (total > 5000) { return { block: true, reason: `Agent spent $${total} in 24h — cap exceeded` }; } return { block: false }; }
HelperArgumentsReturns
request.count()action, minutesNumber of times that action was called in the last N minutes
request.sum()action, field, minutesSum of a numeric body field across matching logs in the last N minutes

Rule examples

Block large refunds

javascript function blockLargeRefunds(request) { const amount = request.body?.amount || 0; if (request.action === 'issue_refund' && amount > 500) { return { block: true, reason: `Refund of $${amount} exceeds $500 limit` }; } return { block: false }; }

Off hours lockdown

javascript function offHours(request) { const hour = new Date().getHours(); if (hour < 6 || hour >= 23) { return { block: true, reason: 'Blocked outside 6am–11pm' }; } return { block: false }; }

Python — without signing

python import requests result = requests.post( 'https://www.straxiswall.com/check', headers={ 'x-api-key': 'sk-your-key', 'x-agent-id': 'refund-bot', 'Content-Type': 'application/json' }, json={'action': 'issue_refund', 'amount': 250} ) if result.json()['allowed']: issue_refund() else: print(result.json()['reason'])

JavaScript — without signing

javascript const res = await fetch('https://www.straxiswall.com/check', { method: 'POST', headers: { 'x-api-key': 'sk-your-key', 'x-agent-id': 'refund-bot', 'Content-Type': 'application/json' }, body: JSON.stringify({ action: 'issue_refund', amount: 250 }) }); const data = await res.json(); if (data.allowed) issueRefund();

Go — without signing

go func straxisCheck(action string, body map[string]interface{}) (bool, string) { body["action"] = action data, _ := json.Marshal(body) req, _ := http.NewRequest("POST", "https://www.straxiswall.com/check", bytes.NewBuffer(data)) req.Header.Set("x-api-key", "sk-your-key") req.Header.Set("x-agent-id", "refund-bot") req.Header.Set("Content-Type", "application/json") resp, _ := http.DefaultClient.Do(req) defer resp.Body.Close() var result map[string]interface{} json.NewDecoder(resp.Body).Decode(&result) allowed := result["allowed"].(bool) reason, _ := result["reason"].(string) return allowed, reason }