Watch a 30-second walk-through, then run the same flow yourself
against the live API. Every button below mints real Haldir state
in a sandbox tenant — your own scoped session, your own audit
chain, isolated from every other visitor.
Try it live
Four buttons walk the happy path — mint a sandbox key, open a governed
session, check a permission, write a tamper-evident audit entry. Then
three more try to break it: spend past the cap, revoke the
session, and act anyway. Every call hits the live API, and every
response below is the real one — verifiable against the
OpenAPI spec.
STEP 01
Mint a sandbox API key
Each visitor gets their own throwaway tenant. No email, no
billing, no rate-limit hostility. The key works for the rest
of this page.
POST /v1/demo/key
Response—
Click "Mint key" to see the JSON response.
STEP 02
Open a governed session
Create a session for the agent "my-agent"
with a $5 spend cap and read+execute scopes. The session is
the unit of governance — every later call references it.
POST /v1/sessions
{"agent_id": "my-agent",
"scopes": ["read", "execute"],
"spend_limit": 5.00}
Response—
Mint a key first.
STEP 03
Check a permission
Ask whether the agent may use a scope right now. The session above
was granted read
and execute
— pick delete
and it refuses, because a check that only ever answers yes is not a
check.
POST /v1/sessions/:id/check
{"scope": "execute"}
Response—
Open a session first.
STEP 04
Log to the audit chain
Write an audit entry for a hypothetical $0.50 Stripe charge.
Haldir computes a SHA-256 hash binding this entry to the one
before it — once chained, no one can rewrite history without
breaking the verifier.
POST /v1/audit
{"session_id": "ses_...",
"tool": "stripe",
"action": "charge",
"cost_usd": 0.50}
Response—
Check a permission first.
Now try to break it
Governance that only ever says yes is indistinguishable from
nothing. The next three calls are the ones that should fail.
STEP 05 · BREAK IT
Spend past the cap
The session above has a $5 ceiling. Authorize an amount and see
which side of it you land on — it starts at $10 so the first click
shows the refusal, and $2 shows the same call succeeding.
Over the cap the API answers 403 and moves no money. There is no
"log it and continue" mode to fall into.
POST /v1/payments/authorize
{"session_id": "ses_...",
"amount": 10.00}
Response—
Open a session first.
STEP 06 · BREAK IT
Pull the kill switch
Revoke the session while the agent is still holding it. Nothing is
coordinated with the agent and nothing is queued for it — the
session simply stops being valid, on the next call, everywhere.
DELETE /v1/sessions/:id
Response—
Open a session first.
STEP 07 · BREAK IT
Try to act anyway
The agent has not been told it was revoked. Ask for the scope it
held a moment ago, on the same session ID, and watch the call that
returned allowed: true
in step 03 come back false.
Note the status is still 200 — the check worked, and the answer is no.
POST /v1/sessions/:id/check
{"scope": "execute"}
Response—
Revoke the session first.
What just happened
01 · GATE
The agent has an identity now.
Without Haldir, "my-agent" is whatever string the LLM hallucinated
last. With Haldir, it's a session ID with declared scopes, a spend
ceiling, and a TTL. Every later call has to point back at it.
02 · POLICY
Permission checks happen pre-call.
The wrapper asks before the agent fires. A denial returns
instantly — no upstream API consumed, no money moved, no
cleanup later. The model never has to reason about whether
it should have done something.
03 · WATCH
The audit trail is tamper-evident.
Each entry's hash is computed over the entry's contents
plus the previous entry's hash. Edit any historical
entry and every later hash stops verifying. This is what
compliance auditors want to see.
Ship it for real?
Same API, your own key, your own data. SDKs for LangChain, CrewAI,
AutoGen, and Vercel AI SDK. MIT-licensed and self-hostable.