Solana
Solana agents that check before they sign
An agent with a Solana wallet signs whatever its tools hand it: a swap from a plugin, a token launch, a transfer a prompt talked it into. presign-guard reads every instruction of the transaction and simulates it before the wallet signs. Red is never signed, and what leaves the wallet counts toward limits you set.
What gets caught
- Red, never signed: SetAuthority handing one of your token accounts to someone else, System Assign handing the wallet itself to a program, the same changes hidden inside another program (seen in the simulation).
- Orange, ask a person: an unlimited token delegate, a durable nonce (signable much later), closing a token account to someone else, an owner or delegate change the instructions don't show, a transaction that fails.
- Intent: pass what the agent means to do (“swap 1 SOL for USDC”), and a transaction that does something else is orange.
- Your limits: SOL beyond the network fee counts toward a SOL limit, USDC toward a USDC limit, other tokens and delegates go to you for approval (Telegram or the wallet dashboard).
Pick your framework
| Framework | Package | What it guards |
|---|---|---|
| Solana Agent Kit (SendAI) | presign-guard-solana-agent-kit | The wallet every plugin signs through: transfers, swaps, launches, staking |
| Coinbase AgentKit | presign-guard-agentkit | Solana keypair and CDP wallets: SPL transfers, Jupiter swaps, native transfers, x402 payments |
| ElizaOS | plugin-fizzl | An action that checks a pasted or given Solana transaction before the agent signs it |
| Claude and other MCP agents | presign-guard-wallet-mcp | Paying x402 APIs in USDC on Solana (SOLANA_PRIVATE_KEY), checked and kept to your limits |
| Vercel AI SDK, LangChain, Python | presign-guard-ai-sdk, fizzl-langchain, fizzl | A check_solana_transaction tool the model calls before signing |
| Your own code | presign-guard-wallet | solanaSigner(signer, { any: true }) around any @solana/kit signer |
Solana Agent Kit in a few lines
import { Keypair } from '@solana/web3.js';
import { KeypairWallet, SolanaAgentKit } from 'solana-agent-kit';
import TokenPlugin from '@solana-agent-kit/plugin-token';
import { createKeyPairSignerFromBytes } from '@solana/kit';
import { wrapFetchWithPayment, x402Client } from '@x402/fetch';
import { ExactSvmScheme } from '@x402/svm/exact/client';
import { guardSolanaWallet, GuardPlugin } from 'presign-guard-solana-agent-kit';
const keypair = Keypair.fromSecretKey(secretKey);
// The agent's own Solana account pays the $0.01 checks, capped per payment.
const checkPayer = new x402Client().setSpendControls({ maxAmountPerPayment: '$0.05' });
checkPayer.register('solana:*', new ExactSvmScheme(await createKeyPairSignerFromBytes(keypair.secretKey)));
const wallet = guardSolanaWallet(new KeypairWallet(keypair, rpcUrl), {
pay: wrapFetchWithPayment(fetch, checkPayer),
limits: { tokens: { SOL: { perTx: '0.1', perDay: '0.5' }, USDC: { perDay: '20' } } },
});
const agent = new SolanaAgentKit(wallet, rpcUrl, {}).use(TokenPlugin).use(GuardPlugin);
GuardPlugin lets the agent see its own budget and pause itself when something looks wrong.
Cost
$0.01 per check, paid over x402 in USDC on Solana (or Base, the XRP Ledger, Algorand). Or prepaid: 100 checks for $0.80. The checks are free to try through the AI SDK, LangChain and Python tools: without a payer they answer with the free quick check, the verdict only.
More
- presign-guard: the API behind all of these, with every reason code
- Source on GitHub
- Want limits and approvals managed for you? The Fizzl agent wallet