Wrap any LangChain tool so a scoped warrant is checked before it runs — spend caps, rate limits, revocation, and an audit trail included.
Wrap the tool's func so authorization runs first:
import { DynamicStructuredTool } from '@langchain/core/tools';
import { createClient, guardTool } from 'liceat';
const decide = createClient({ gateway: 'https://liceat.com' }).decider();
const charge = guardTool(decide,
{ resource: 'pay:stripe/charge', action: 'pay', amount: a => a.cents, currency: 'USD' },
async (a) => stripe.charges.create({ amount: a.cents, currency: 'usd' }));
new DynamicStructuredTool({ name: 'charge_card', schema,
func: (args) => charge(agentWarrant, args)
.then(JSON.stringify, (e) => 'denied: ' + e.message) }); // model sees the denial
Liceat is permission infrastructure for AI agents. You issue a warrant — a scoped, spend-capped, revocable token — that grants an agent narrow authority; the agent presents it at the point of action; Liceat enforces it (scope, spend, rate, holder-binding, revocation) and records every decision in a tamper-evident log. It is open source with a zero-dependency SDK for TypeScript and Python.
The SDK and self-hosted gateway are free and open source. The hosted gateway at liceat.com gives 10,000 free decisions with no card, then meters at fractions of a cent per decision — payable by card or USDC.
Free to self-host. 10,000 free decisions on the hosted gateway — no card.
Get an API key Read the docs