a-guard

Identity for every agent. A database that refuses what they try to delete.

a-guard is an authorization server + a resource server that verifies every token, redacts PII from every log, and lets Postgres itself enforce what an agent may and may not touch. No SDK secrets, no audit trails you can't trust.

e-mail
alice@example.com
REDACTED
card
4111 1111 1111 1111
REDACTED
phone
+1 (555) 019-2021
REDACTED
audit: pii email → redacted (log sink)
audit: card number → redacted (log sink)
audit: phone → redacted (log sink)

Three guarantees, three layers of truth

One identity surface for every agent. No SDK secrets. No audit trail you can't verify.

01 · AUTH

OpenID Connect, audience-bound

The resource server verifies every token against the AS's public JWKS — it holds no signing key. A token minted for /api is refused at /mcp.

02 · REDACTION

PII never leaves the service

Every log record is redacted at creation. Raw identities, money, and tokens stay inside — and never reach the agent's context window.

03 · DATABASE

The database says no

Row-level security + column grants + a separate agent pool mean an agent's delete is refused by Postgres. rows=0, nothing changed.

See it in one command

Both services, a real MCP client, and the audit trail where rows=0 is the agent's refused delete.

bash scripts/demo.sh

_runs both services · paced for recording · leave them up with DEMO_KEEP=1_

04 · AUDIT

rows=0 is the refusal

An agent's delete is swallowed by Postgres. The audit log records the attempt — and nothing changed.