One Node-native middleware protects any Express or Connect route with warrant-based authorization.
httpEnforcer is a plain (req, res, next) middleware — it extracts the warrant, checks it, and 403s with reasons on deny.
import { httpEnforcer, createClient } from 'liceat';
const client = createClient({ gateway: 'https://liceat.com' });
const method = { GET: 'read', POST: 'write', PUT: 'write', DELETE: 'write' };
app.use(httpEnforcer({
decide: client.decider(),
map: (req) => ({ resource: 'api:myservice' + req.url.split('?')[0], action: method[req.method] }),
}));
// Denied → 403 {error, reasons}. Allowed → next().
Liceat is permission infrastructure for AI agents. You issue a warrant — a scoped, spend-capped, revocable token — that grants an agent narrow authority; the agent presents it at the point of action; Liceat enforces it (scope, spend, rate, holder-binding, revocation) and records every decision in a tamper-evident log. It is open source with a zero-dependency SDK for TypeScript and Python.
The SDK and self-hosted gateway are free and open source. The hosted gateway at liceat.com gives 10,000 free decisions with no card, then meters at fractions of a cent per decision — payable by card or USDC.
Free to self-host. 10,000 free decisions on the hosted gateway — no card.
Get an API key Read the docs