Identity for every agent. A database that refuses what they try to delete.
a-guard is an authorization server + a resource server that verifies every token, redacts PII from every log, and lets Postgres itself enforce what an agent may and may not touch. No SDK secrets, no audit trails you can't trust.
Three guarantees, three layers of truth
One identity surface for every agent. No SDK secrets. No audit trail you can't verify.
OpenID Connect, audience-bound
The resource server verifies every token against the AS's public JWKS — it holds no signing key. A token minted for /api is refused at /mcp.
PII never leaves the service
Every log record is redacted at creation. Raw identities, money, and tokens stay inside — and never reach the agent's context window.
The database says no
Row-level security + column grants + a separate agent pool mean an agent's delete is refused by Postgres. rows=0, nothing changed.
See it in one command
Both services, a real MCP client, and the audit trail where rows=0 is the agent's refused delete.
_runs both services · paced for recording · leave them up with DEMO_KEEP=1_
rows=0 is the refusal
An agent's delete is swallowed by Postgres. The audit log records the attempt — and nothing changed.