A poisoned page tells your agent to pay $180 for “priority access.” It complies. Nobody notices until the wallet is empty.
The control plane for AI agent payments.
Set the rules. Watch every payment. Score every counterparty. Rein governs your agent's authority to spend, whatever wallet it uses — and it never holds the funds.
$ npm install @reinconsole/sdk
Using Claude Code or Cursor? npx -y @reinconsole/mcp gives your agent a spend-governed fetch — MCP setup.
- 14:02:31 SETTLED $0.02 → api.quotes.example base-sepolia
- 14:02:28 ALLOW $0.02 → api.quotes.example vendor score 87
- 14:02:19 DENY $180.00 → premium-intel.example over per-tx cap
- 14:02:16 REFUSED $0.10 → payer 0x3c11…88d0 reputation 31 < 40
- 14:02:14 FROZEN → agent research-scout kill switch engaged
- 14:02:12 SETTLED $0.05 → api.research.example base-sepolia
- 14:02:11 ALLOW $0.05 → api.research.example within budget
An agent with a wallet is an unattended
terminal with a credit card.
A retry loop hits a paid endpoint 400 times before sunrise. Every call cost $0.25. Every call was authorized — by nobody.
The cheapest vendor in the marketplace has a 12% dispute rate and three burned wallets behind it. Your agent only sees the price.
Rein exists because “the agent will behave” is not a security model.
Three planes. One loop.
Guard the demand side, gate the supply side, and let one reputation graph feed evidence back into enforcement on both.
GUARD
demand side
Wrap your agent's fetch once. Every x402 paywall becomes a
policy decision before a cent moves.
import { createGuard } from '@reinconsole/sdk';
const guard = createGuard({ engineUrl, agentId });
const fetch = guard.wrap();
// vendor answers 402 → intent → policy check →
// signed decision. Deny blocks before payment exists.
const res = await fetch('https://api.vendor.example');
- budgets & tx caps
- allow / deny lists
- kill switch
- signed receipts
GATE
supply sidePrice your routes once. Every payment into your API is screened, settled, and receipted before your handler runs.
import { createGate, gateMiddleware } from '@reinconsole/gate';
const gate = createGate({
routes: [{ path: '/api/answer', price: '0.05' }],
rails, payTo: '0xYourTreasury…',
screen: { check: payerCheck(graph, { denyBelow: 40 }) },
});
app.use(gateMiddleware(gate));
- quote consistency
- replay protection
- velocity caps
- payer screening
GRAPH
reputationEvidence in, scores out. Both sides of the wire feed one graph — and the graph feeds back into enforcement.
import { ReputationGraph, payerCheck } from '@reinconsole/graph';
const graph = new ReputationGraph()
.observe(engine).observe(indexer).observe(gate);
// pushed scores make vendorReputationLt policies fire
await graph.syncVendors(engine.spend);
- never stored, always explainable
- unknown ≠ bad
- survives key rotation
“Live on mainnet” — with links,
not adjectives.
Don't take our word for it.
Every claim here has a link.
Rein never asks for a private key and never sees one. Your agent signs its own payments; Rein signs only the decision to allow them. The getting-started path runs on Base Sepolia testnet. Mainnet is a choice you make.
Every @reinconsole/* package is published by GitHub Actions through npm Trusted Publishing,
with a provenance attestation linking it to the commit it was built from. No npm token exists that could
publish one by hand. Check it yourself with npm audit signatures.
“Installation was easy and every test passed.”
“Everything ran smoothly. The bugs we found during testing were fixed.”
Authority moves through Rein.
Money doesn't.
Put reins on it.
$ npm install @reinconsole/sdk
v0.5 — early open-source infrastructure, live on Base mainnet. APIs may change before 1.0.
No waitlist. No email capture. The code is public.