NewRun PyxGrant's real engine in your browser →

Delegated authority. Sealed as evidence.

A grant can only narrow. Revoking the parent ends every child, and each end is a signed record. Each call is checked against who the agent acts for, what it was granted, and what it could break, then allowed, redacted, held, or refused before it lands.

  • A grant can only narrow
  • Revoke the parent, the tree ends
  • Receipts anyone can verify offline
In plain terms
  1. A grant can only narrow.A partner can re-delegate without a shared secret, never widen it. Revoking the parent ends every child, and each end is signed.
  2. Checked against who it acts for.The person, the grant, and the session travel with the call. An identity export is checked against who actually acted.
  3. Data stays where it belongs.Keys, card numbers, and personal data are redacted or held before they reach a model or leave through a tool.
  4. Anyone can check the record.Every decision comes with a signed receipt your auditor can verify without trusting us.
Try the real engine

Make an agent misbehave. Watch PyxGrant decide.

Every answer below comes from PyxGrant's own decision engine under its hardened policy. Switch to live and the engine itself runs in this tab, compiled to WebAssembly. Edit the request, then check the signed receipt with PyxGrant's own verifier. Nothing is sent to us.

Loading…
What the agent tries
Edit the request switch to live to run it
Signed decision receipt
…

Loading…

Tool call
Why
Decided
Receipt
This record
Previous
Signature
Full engine output

In the product, a held call waits up to ten minutes for a signed approval. Controls that need the real machine, such as Linux kernel confinement, aren't part of this demo. The live engine is about 4 MB to download and loads once.

Where it sits

Start with grants, tools, and coding agents. The rest of the map is labeled.

Each plane is tagged shipped, decision-only, or preview. A pilot starts with coding agents and the MCP tools they load. Pick a plane to watch what PyxGrant does there. Each animation replays a check from the walkthrough and tests, or behaviour read from the code.

Start here

Also in the binary

Not fully shipped

Authority passes down as grants that can only narrow. A partner can re-delegate your grant without a shared secret but never widen it, sensitive methods can wait for a person, and revoking the parent ends every child.

Shippedpyxgrant a2apyxgrant grantProof: pyxgrant demo sections 14 and 15 pass
Where to start

One team, observe first, then enforce.

Coding agents and their MCP tools are the first place agents touch source and secrets. The same binary also decides model calls, agent hops, browsers, and payments.

What reaches PyxGrant, and what doesn't →

Deployment

Runs on your machine. A held call that nobody answers is refused.

The four questions every security review asks first, answered before the demo.

01

How does it deploy?

One Go binary on each machine that runs agents, with a Windows service option. Agents reach it four ways, and you can mix them.

  • MCP proxy. In front of each server, over stdio or HTTP.
  • Coding-agent hook. Claude Code and Cursor ask before each tool call.
  • Decision service. Your own agents ask over loopback.
  • Model proxy. Meters and budgets model API calls.
02

What does it do to speed?

Decisions run inside the binary, from your policy file. No vendor cloud sits in the path, and the optional data classifier runs locally.

  • pyxgrant perf measures decision time on your hardware. We don't quote a number from ours.
03

What if nobody answers?

The call is refused, not waved through.

  • A held call waits for a signed approval, ten minutes by default, then it is refused.
  • Approvals are refused until approver signing is set up.
The product's own list of limits →
04

What does it work with?

It sits in front of agent actions and leaves the rest of your stack in place.

  • Identity. Okta, Entra, and SCIM exports, checked against who actually acted.
  • Policy. Open Policy Agent, through a bridge.
  • Secrets. The OS vault: DPAPI, Keychain, or secret-tool.
  • EDR. Keeps the host. PyxGrant decides agent actions and does not replace it.
Evidence

Proof you can rerun, not a logo wall.

We don't have public customer results yet. The numbers below are from a full Windows run on 26 September 2026. Reproduce them with the same commands on the binary you have.

Hostile server walkthrough 90 of 90

checks pass in pyxgrant demo, which starts a hostile MCP server behind the gateway. All 26 sections pass: tool poisoning, rug pulls, poisoned results, confused deputy, blast radius, self-protection, memory poisoning, grant revocation, browsers, payments, and the audit chain among them. No planted secret reached the client or the audit log.

Open benchmark 0 of 45

attacks missed, with no false alarms on 22 benign calls. A miss means the attack was allowed. An attack that was only flagged, not blocked, still counts as caught; pyxgrant benchmark prints that count as under_enforced and does not fail the run on it. It is our own corpus and small; the 95% range on the miss rate is 0 to 8%.

Test suite 133

Go packages passed go test on that run, and none failed.

Reproduce it: pyxgrant demo · pyxgrant benchmark · More output, condensed →

Boundary

What it does, and what we don't claim.

Enforced today

  • Tools whose descriptions change after approval are quarantined
  • Secrets and personal data are kept out of tool results and the audit log
  • Under the hardened profile, an agent can't rewrite its own MCP config or PyxGrant's policy
  • Under the hardened profile, high blast-radius actions are held or refused before they run
  • A restricted or irreversible tool result on SSE is held until the verdict; a deny releases no bytes
  • Revoking a grant ends every child grant, with a signed record

Not claimed

  • Prompt injection is not solved. Scoring is pattern-based, so novel phrasing can pass; pinning, taint, the blast-radius gate, and a human hold sit behind it.
  • A call that never reaches PyxGrant can't be stopped. Reconciliation names it afterwards.
  • Kernel confinement is Linux only, and doesn't cover UDP or DNS.
  • If the signing key sits beside the audit log, a local admin could shorten and re-sign it. Keep the key elsewhere.
  • Signing is software Ed25519, not a FIPS 140-3 validated module. ML-DSA-65 is an opt-in build.

Start with one team's coding agents.

PyxGrant is built by Omantiv. A pilot covers one team, its laptops and CI runners, and the MCP servers they use. Start in observe mode, read the record, then enforce. Company · Book a demo