Algorand agents that check before they sign
On Algorand an account is lost in one field of an ordinary-looking transaction: a rekey hands its signing power to someone else, a close sends everything it holds. presign-guard reads every transaction in the group your agent is about to sign, simulates the group on a public node, and answers green, orange or red. Red is never signed, and what the agent sends counts toward limits you set.
What gets caught
- Red, never signed: a rekey to another key, closing the account (all its ALGO to someone else), closing an asset holding to someone else while it still holds a balance, an asset called USDC or USDt that isn't Circle's
31566704or Tether's312769. - Orange, ask a person: a clawback transfer, opting in to an asset with a clawback address or frozen by default, an app being updated, deleted or cleared, an asset's control addresses handed over or cleared, giving up consensus participation for good, a fee far above normal, one transaction of a group sent without the rest, a group that would fail.
- Simulated: the group runs on a public node first (algod simulate), which also says how much a close would send.
- Intent: pass what the agent means to do (“pay 5 ALGO to the shop”), and a group that does something else is orange.
- Your limits: ALGO paid counts toward an ALGO limit, USDC toward a USDC limit, other assets go to you for approval (Telegram or the wallet dashboard).
Before buying an asset
GET https://presign-guard.fizzl.eu/v1/token?chain=algorand&address=<asset id> ($0.01): fake USDC is red; a clawback, default-frozen holdings, an asset less than a day old, a few accounts holding most of the circulating supply and a thin market are orange. Circle's USDC comes back SAFE: no red flags, Circle's USDC.
Pick your setup
| Setup | Package | What it guards |
|---|---|---|
| Your own code | presign-guard-wallet | algorandSigner(signer, { any: true }) around an x402 AVM signer: ALGO payments, asset transfers, app calls and x402 payments in USDC |
| Claude and other MCP agents | presign-guard-wallet-mcp | Paying x402 APIs in USDC on Algorand (ALGORAND_MNEMONIC), kept to your limits |
| Vercel AI SDK, LangChain, Python | presign-guard-ai-sdk, fizzl-langchain, fizzl | A check_algorand_transaction tool the model calls before signing, and check_token with chain: "algorand" |
| Any agent with HTTP or MCP | presign-guard | POST /v1/check with {"type": "algorand", "transaction": "<base64 msgpack>"}, or a whole group as transactions; the same in the MCP tools |
Your own code in a few lines
import { guardWallet } from 'presign-guard-wallet';
import { toClientAvmSigner } from '@x402/avm';
import { wrapFetchWithPayment, x402Client } from '@x402/fetch';
import { ExactAvmScheme } from '@x402/avm/exact/client';
const signer = toClientAvmSigner(process.env.AVM_PRIVATE_KEY);
// The agent's own Algorand account pays the $0.01 checks, capped per payment.
const checkPayer = new x402Client().setSpendControls({ maxAmountPerPayment: '$0.05' });
checkPayer.register('algorand:*', new ExactAvmScheme(signer));
const guarded = guardWallet(walletClient, {
pay: wrapFetchWithPayment(fetch, checkPayer),
limits: { tokens: { ALGO: { perTx: '10', perDay: '25' }, USDC: { perDay: '20' } } },
});
const algo = guarded.algorandSigner(signer, { any: true });
// Sign through algo instead of the raw signer: red is refused, orange asks, the limits apply.
const signed = await algo.signTransactions(groupBytes);
An x402 payment in USDC still takes the quick local path, without a check. guarded.pause() stops everything at once.
Cost
$0.01 per check, paid over x402 in USDC on Algorand (or Base, Solana, the XRP Ledger). Or prepaid: 100 checks for $0.80. The checks are free to try through the AI SDK, LangChain and Python tools: without a payer they answer with the free quick check, the verdict only.
More
- presign-guard: the API behind all of these, with every reason code
- x402 on Algorand: every Algorand x402 endpoint the Trust Index scans, payable today or not
- Source on GitHub
- Want limits and approvals managed for you? The Fizzl agent wallet (sign in with Pera or Defly)