Skip to main content
Glama

Warden — warden402.xyz

The pre-execution security & trust layer for agents transacting on Base.

Give Warden a token, a pending transaction, or an address → get a single decision: block · review · clear with reasons, a risk score, and a plain-language summary.

Warden uses the x402 Bazaar as its intelligence backend and builds judgment, a provable track record, and (next) a firewall on top.

Why

x402 infrastructure is ahead of demand; the missing layer is trust. The marketplace vertical is crowded (Coinbase Bazaar + dozens of clones), but pre-execution security is wide open. Warden owns that vertical.

Related MCP server: agentiam-mcp

What's in here

Path

What

web/

The website (warden402.xyz) — landing + live demo + track-record. Runs the guard in-process, so it deploys as a single Vercel project.

src/

Standalone Hono Guard API (same logic) — for agents/SDK/MCP and a persistent-ledger host.

sdk/

@warden402/sdk — client + enforce/assertSafe gate + LangChain tools.

mcp/

warden402-mcp — stdio MCP server exposing guard_token / guard_tx / guard_address.

scripts/

smoke.ts (offline decision tests), probe.ts (calibration), recheck.ts (outcome re-checker).

The decision contract (immutable spine)

Every endpoint returns a Verdict (src/schema/verdict.ts). Principles:

  1. The LLM never touches the verdict. decision and riskScore come from deterministic rules; the LLM only writes summary. Auditable.

  2. Fails safe. If a Bazaar signal can't be fetched it becomes unknowndegraded:true → the verdict is review at worst, never a false clear.

  3. Every verdict is snapshotted (verdictId + signal evidence) → the track-record moat.

Decision rules

  • Hard rule: honeypot or sanctions fail → block (regardless of score).

  • Weighted-average risk ≥ 70 → block; degraded → review.

  • Any single fail (e.g. liquidity collapse) floors the decision at review (can't be diluted by the average). 2+ warns → review. Else clear.

Endpoints

Endpoint

What it checks

GET /guard/token?address=

honeypot, taxes, liquidity, holder concentration, OFAC

POST /guard/tx {from,to,calldata}

decodes calldata (unlimited approve / setApprovalForAll), sanctions + contract risk on the counterparty

GET /guard/address?address=

sanctions, contract risk, age/activity

GET /track-record

public trust stats (decision mix, hit-rate, rugs caught/missed)

(The website exposes the same via /api/guard.)

Run locally

# Single-project site (recommended) — runs guard in-process
cd web && npm install
cp .env.example .env.local   # set BAZAAR_INTERNAL_SECRET
npm run dev                  # http://localhost:3000

# Or the standalone Hono API
npm install
cp .env.example .env         # set BAZAAR_INTERNAL_SECRET
npm run smoke                # offline decision tests
npm run dev                  # http://localhost:8787

Production topology

  • web/ is the production API + site. Deployed as a single Vercel project (Root Directory = web). It runs the guard/firewall in-process, so the endpoints agents actually call (/api/guard, /api/firewall) are live here. Hot path is edge-friendly: KV store (no fs) + per-IP rate limiting. Persistence turns on when KV_REST_API_URL / KV_REST_API_TOKEN are set.

  • src/ (Hono API) is an optional Node host — for teams that want a persistent-disk ledger or the x402 payment layer. Not required; not deployed by default. The src/ modules are the canonical logic; a drift-guard test (tests/drift.test.ts) proves the web copy stays identical.

  • Drift is impossible to ship silently: npm test fails if the two diverge.

Deploy

See DEPLOY.md. TL;DR: new Vercel project, Root Directory = web, set BAZAAR_INTERNAL_SECRET (+ optional KV_REST_API_URL/KV_REST_API_TOKEN for persistent track-record), deploy. Done.

Bazaar internal-auth

Warden calls Bazaar without paying x402 (so our own products don't bill themselves) via the X-Warden-Internal header. Bazaar must have a matching WARDEN_INTERNAL_SECRET. Until set, all signals come back unknown and verdicts stay safely at review.

Roadmap

  1. ✅ Guard MVP (/guard/token) + verdict contract

  2. /guard/tx (pre-sign) + /guard/address + track-record + re-checker

  3. ✅ SDK / MCP / website

  4. ⏳ x402 payment layer (free tier → 402) + MCP Registry / Agentic.Market listing

  5. Firewall / policy gateway — sits in front of an agent's x402 + onchain calls: spend caps, allow/deny by trust score, anomaly + injection-drain detection, audit log. B2B, Cloudflare Worker edge. The north star.

F
license - not found
-
quality - not tested
A
maintenance

Maintenance

Maintainers
Response time
Release cycle
1Releases (12mo)
Commit activity

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or HTTP/SSE) and blocks destructive tool calls before they execute, with TOFU catalog pinning against rug pulls and tool-poisoning/result-injection scanning. Single Rust binary, Apache-2.0.
    Last updated
    14
    6
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Solana token risk-scoring MCP server for AI trading agents with insider wallet cluster detection.

  • Reputation oracle for AI agents on Base: SAFE/CAUTION/BLOCK + 0-100 score before you pay. x402+MCP

  • Fail-closed safe-to-pay verdicts on Base: known-bad wallets, look-alike tokens, repeat rug funders.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/sukrutkrdg/warden402.xyz'

If you have feedback or need assistance with the MCP directory API, please join our Discord server