Live demo — deterministic sequence enforcement for an AI agentTry to make an AI agent skip a step.
Run the clean path first, then try to break it. The gate decides, not the agent.
Each run is an AI agent calling the live gate. Nothing runs until you start it. The gate decides whether each step is permitted before execution — not the agent itself. Green means the step ran in correct compliance order. Red means the gate blocked it: a duplicate request, a skipped approval, or an attempt to reopen a closed file. Every decision produces a cryptographic receipt, issued before any action executes, and every run ends with a one-click link to its signed report — verifiable without relying on the agent's own logs.
demo- sequence without a key, so whatever a run puts in
attestation is public. Demo receipts are also deleted 30 days after
they are written. Both are fine for a demo and wrong for real work —
get your own key for a
private lane whose receipts are kept: US$39 a month, self-serve, and the key is
emailed when the payment clears. Larger deployments are
a conversation.
Try replay attacks, wrong step order, fake sequence IDs, anything.
Run a scenario to see live gate responses.
You just ran that. Here it is in your code.
The same gate, the same public demo key, no account and nothing to sign up for. You declare the order once; the gate refuses anything out of it and signs a receipt for every decision either way.
pip install agenticrail
# No key needed. With no argument the client sends no credential and the # gate answers on its public demo lane, saying so in every decision. from agenticrail import RailClient client = RailClient() seq = client.sequence( sequence_id="my-agent-run-001", step_order=["verify_identity", "assess_risk", "execute_transfer", "audit_ledger"], ) seq.next("verify_identity") # -> ALLOW seq.next("assess_risk") # -> ALLOW seq.next("execute_transfer") # -> ALLOW seq.next("audit_ledger") # -> ALLOW, seals the sequence # Out of order, replayed, or after the seal: raises RailDenied seq.next("verify_identity") # -> RailDenied: SEALED_SEQUENCE
npm install @agenticrail/core
// No key needed. With no options the client sends no credential and the // gate answers on its public demo lane, saying so in every decision. import { RailClient } from "@agenticrail/core"; const client = new RailClient(); const seq = client.sequence("my-agent-run-001", [ "verify_identity", "assess_risk", "execute_transfer", "audit_ledger", ]); await seq.next("verify_identity"); // -> ALLOW await seq.next("assess_risk"); // -> ALLOW await seq.next("execute_transfer"); // -> ALLOW await seq.next("audit_ledger"); // -> ALLOW, seals the sequence // Out of order, replayed, or after the seal: throws RailDenied await seq.next("verify_identity"); // -> RailDenied: SEALED_SEQUENCE
Works under LangGraph, CrewAI, Mastra, Genkit or a plain loop — it is one HTTPS call before each step, so the framework is irrelevant. Full reference in the docs.