Safety checks for LangChain.js agents that pay
fizzl-langchain gives a LangChain or LangGraph agent in JavaScript five checks to run before it signs or pays, as LangChain tools. The checks only check: they never sign, pay or move anything themselves. The JavaScript twin of fizzl for Python, an official LangChain integration ↗.
Install
npm install fizzl-langchain @langchain/core zod
npm install @x402/fetch @x402/evm viem # to pay for the full checks over x402
Try it without a wallet
With no payment set up, the token, signing and endpoint checks answer with the free quick check: the verdict only, a few per hour, marked "free": true.
import { createAgent } from "langchain";
import { fizzlTools } from "fizzl-langchain";
const agent = createAgent({
model: yourChatModel, // any chat model with tool calling
tools: fizzlTools(),
systemPrompt: "Before you pay any API, call check_endpoint_before_paying. " +
"Before you sign anything, call check_before_signing. Never continue on red or no_go.",
});
const result = await agent.invoke({ messages: [{ role: "user", content:
"Is USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913) on Base safe to buy?" }] });
With LangGraph: createReactAgent({ llm, tools: fizzlTools() }) from @langchain/langgraph/prebuilt. Or call a check directly:
const [checkToken] = fizzlTools({ only: ["check_token"] });
await checkToken.invoke({ chain: "base", address: "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913" });
// '{"verdict":"green","grade":"SAFE","free":true,"note":"Free quick check: ..."}'
The tools
| Tool | What it checks | Full check | Free quick check |
|---|---|---|---|
check_before_signing | A transaction, token approval or signature (permit, Permit2, Seaport) before signing: drainers, unlimited approvals, look-alike tokens. Green / orange / red with reasons. | $0.01 | verdict |
check_xrpl_transaction | An XRP Ledger transaction before signing: account takeover, AccountDelete, fake RLUSD, partial payments, risky issuers. | $0.01 | none |
check_token | A token before buying, holding or accepting it: honeypots, rug-pull signs, look-alikes. Solana, EVM chains and the XRP Ledger. | $0.01 | verdict and grade |
check_wallet_approvals | Every open token approval of an EVM wallet, and which ones to revoke. | $0.02 | none |
check_endpoint_before_paying | An x402 or MPP paid API before paying it: go / caution / no_go, the cheapest option that settles, budget, track record, bait signs. | $0.001 | go / caution / no_go with the problems found |
Pick some with fizzlTools({ only: ["check_endpoint_before_paying"] }). Each tool answers a JSON string; a failed check comes back as {"error": ..., "message": ...} instead of throwing, so the model can tell its user. Bad arguments from the model are refused before anything is called or paid.
The full checks: pay per call over x402
Wrap fetch with the x402 client. The agent pays each check in USDC on Base from its own wallet.
import { wrapFetchWithPayment, x402Client } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
import { fizzlTools } from "fizzl-langchain";
const payer = new x402Client().setSpendControls({ maxAmountPerPayment: "$0.02" });
payer.register("eip155:8453", new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)));
const tools = fizzlTools({ fetch: wrapFetchWithPayment(fetch, payer) });
Or prepaid credits
Buy a pack once (presign-guard: 100 checks for $0.80; x402 Doctor: 1000 preflights for $0.80), then pass the keys:
const tools = fizzlTools({ creditKeys: { presign: process.env.PRESIGN_CREDIT_KEY, doctor: process.env.DOCTOR_CREDIT_KEY } });
Options
| Option | Default | |
|---|---|---|
fetch | global fetch | An x402-paying fetch, or plain fetch with credit keys |
creditKeys | none | { presign, doctor }, sent as x-credit-key |
only | all five | Tool names to include |
free | true | Fall back to the free quick check when a check can't be paid |
timeoutMs | 30000 | Per check |
Works with @langchain/core 0.3.58+ and 1.x, and zod 3.25+ or 4.
More
- npm: fizzl-langchain · source on GitHub
- Python: fizzl · the Vercel AI SDK: presign-guard-ai-sdk
- Want the wallet to stop the agent itself, not just tell the model? The Fizzl agent wallet