SQL execution certificate firewall

$0.004 per call · USDC via x402 · POST /api/sql-guard

Review a SQL statement an agent is about to run against production, and certify it. Send POST /api/sql-guard with the required field sql and pay $0.004 per call over x402 or MPP (there is no free tier). It returns a JSON object with verdict, mutating, statementCount, sha256, risks and 1 more.

Returns a policy verdict (pass / warn / block) with named risks - unbounded UPDATE or DELETE, tautological WHERE, DROP, TRUNCATE, DROP COLUMN, statement stacking, COPY ... FROM PROGRAM, GRANT/role changes, session_replication_role and trigger/constraint bypass, writes to pg_catalog - and, when the verdict is pass, an Ed25519 certificate binding that verdict to the SHA-256 of the exact statement. Your database layer verifies the certificate with sql-cert-verify before executing, so the check cannot be skipped by a confused or compromised agent. Literals and comments are scrubbed before analysis, so a keyword inside a string is never a false alarm. HONEST SCOPE: a lexical guard over a fixed, published risk catalogue - it catches the shapes that destroy production data, it is not a SQL parser and cannot know that a WHERE clause names the wrong tenant.

Category: Validation & parsing · Tags: sql postgres firewall guard safety database certificate ed25519

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
sqlstringyesthe exact statement you are about to execute
allowarraynorisk ids to downgrade from block to warn (see riskCatalogue in the response)
allowMultiStatementbooleannopermit more than one statement in the submission (default false)
ttlSecondsnumbernocertificate lifetime, 30-3600 (default 300)

Example request

curl -i -X POST https://agent402.tools/api/sql-guard \
  -H "Content-Type: application/json" \
  -d '{"sql":"UPDATE users SET plan = '\''pro'\'' WHERE id = 42"}'

Without payment this returns HTTP 402 Payment Required with the exact price for sql-guard; any x402 v2 or MPP client pays it and retries.

Example response

{
  "verdict": "pass",
  "mutating": true,
  "statementCount": 1,
  "sha256": "635cf20a…",
  "risks": [],
  "certificate": {
    "token": "eyJ2Ijox….signature",
    "expiresAt": "2026-07-28T20:05:00Z"
  }
}
FieldTypeAlways presentIn the example
verdictstringyespass
mutatingbooleanyestrue
statementCountnumberyes1
sha256stringyes635cf20a…
risksarrayyes0 items in the example
certificateobjectyes2 fields: token, expiresAt

From an MCP client

catalog.call {
  "slug": "sql-guard",
  "params": {
    "sql": "UPDATE users SET plan = 'pro' WHERE id = 42"
  }
}

The hosted connector at https://agent402.tools/mcp needs a payment for sql-guard; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/api/sql-guard", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "sql": "UPDATE users SET plan = 'pro' WHERE id = 42"
  }),
});

Related tools

SQL execution certificate verify

FREE w/ compute · or $0.001 · POST /api/sql-cert-verify

Verify an Ed25519 execution certificate against the exact SQL statement you are about to run - the gate your database la…

CSV lint

FREE w/ compute · or $0.001 · POST /api/csv-lint

Validate CSV structure: consistent column counts across rows, properly closed quotes, delimiter detection. Returns row/c…

OpenAPI agent-readiness lint

FREE w/ compute · or $0.002 · POST /api/openapi-lint

Score an OpenAPI 3.x or Swagger 2.x spec on agent-readiness - i.e. does an LLM-driven caller have what it needs to call …

OpenAPI payload validator

FREE w/ compute · or $0.001 · POST /api/openapi-validate-payload

Validate a JSON payload against the request or response schema for one operation in an OpenAPI 3.x or Swagger 2.x spec. …

Card number validate

FREE w/ compute · or $0.001 · POST /api/card-validate

Validate a payment card number (Luhn checksum) and detect the brand. Numbers are not stored or logged.

Color convert

FREE w/ compute · or $0.001 · POST /api/color

Convert a color between hex, RGB, and HSL. Accepts "#1a2b3c", "rgb(26,43,60)", or "hsl(210,40%,17%)".