Sardis Guard Intelligence Plane — Financial intelligence for AI agent payments via MPP (Tempo Hackathon)
sardis-guard-mpp is an early-stage Python project in the AI payments / x402 ecosystem. It currently has 1 GitHub stars and 0 forks.
Financial intelligence and governance for AI agent payments via MPP.
Built at the Tempo MPP Hackathon (March 19, 2026).
# 1. Make sure you have tempo CLI and a funded wallet
tempo wallet whoami
# 2. Evaluate a payment through the 9-gate intelligence pipeline ($0.001)
tempo request -t -X POST \
--json '{"amount":"1.00","merchant":"perplexity.ai","currency":"USDC","network":"tempo"}' \
https://sardis-guard-482463483786.us-central1.run.app/evaluate
# 3. Full V2 intelligence evaluation with mandate + sanctions ($0.001)
tempo request -t -X POST \
--json '{"amount":"5.00","merchant":"suspicious.com","destination_address":"0x8589427373D6D84E98730D7795D8f6f8731FDA16","service_id":"unknown"}' \
https://sardis-guard-482463483786.us-central1.run.app/evaluate/v2
# Screen any wallet address against 750 OFAC-sanctioned addresses
curl -s -X POST -H "Content-Type: application/json" \
-d '{"address":"0x8589427373D6D84E98730D7795D8f6f8731FDA16"}' \
https://sardis-guard-482463483786.us-central1.run.app/screen/address
# Create spending mandates, check health, activate kill switches
curl -s https://sardis-guard-482463483786.us-central1.run.app/health
Every AI agent in the MPP ecosystem can spend money. But nobody asks: should this agent be allowed to spend?
Sardis Guard is the answer. It sits between any AI agent and any MPP service, enforcing an 8-gate security pipeline before every payment clears:
AI Agent → Sardis Guard ($0.001/eval) → 8 Security Gates → ALLOW / DENY
↓
MPP Service
(Perplexity, Alchemy, etc.)
| Gate | What | How |
|---|---|---|
| 0. Dedup | Replay/double-spend prevention | Idempotency keys, monotonic nonces, request fingerprinting |
| 1. Governance | Mandate chain validation | 10-point check: budget, scope, delegation depth, parent chain |
| 2. Sanctions | OFAC/AML screening | Real Treasury SDN list, address exact match, entity fuzzy match |
| 3. Risk | ML anomaly detection | IsolationForest, Markov transition surprisal, cross-agent correlation |
| 4. Policy | Spending rules | 12-check pipeline: limits, merchants, categories, chains, cooldowns |
| 5. Action | Composite scoring | Thresholds: ALLOW < 0.45 < FLAG < 0.70 < HOLD < 0.85 < FREEZE |
| 6. Spend | Budget enforcement | Hierarchical spend propagation through mandate delegation tree |
| 7. Audit | Evidence trail | SHA-256 hash-chained append-only log, evidence pack generation |
Plus session-hash anti-relay (T3) and in-flight limit anti-shadow-lock (T4) from the Sardis Protocol Spec.
# Install
git clone https://github.com/EfeDurmaz16/sardis-guard-mpp
cd sardis-guard-mpp
uv venv && uv pip install "pympp[tempo,server]" fastapi uvicorn scikit-learn numpy duckdb
# Run
source .venv/bin/activate
uvicorn src.server:app --host 0.0.0.0 --port 8402
# Test (free endpoint)
curl http://localhost:8402/health
# Test (MPP-gated — requires tempo wallet)
tempo request -t -X POST --json '{"amount":"1.50","merchant":"perplexity.ai"}' \
http://localhost:8402/evaluate
Benign swarm (6 real MPP calls):
researcher → StableEnrich/Exa: "AI agent payments market" → ALLOWED
researcher → StableEnrich/Exa: "MPP ecosystem" → ALLOWED
scraper → Browserbase: "Tempo blockchain" → ALLOWED
analyst → Tempo RPC: wallet balance → ALLOWED
analyst → Tempo RPC: block number → ALLOWED
researcher → StableEnrich/Exa: "competitor wallets" → ALLOWED
Attack scenario (8 steps, 3 caught):
burst calls (4x rapid) → 3 allowed, 1 DENIED (budget)
novel service (darkweb) → DENIED (service not in mandate)
sanctions (Tornado Cash) → balance check allowed (not a payment)
budget violation ($5) → DENIED (exceeds $0.10 per-tx limit)
Replay protection:
Call 1: idempotency_key=test123, nonce=1 → ALLOW
Call 2: same key, same nonce → 409 REJECTED (duplicate)
Call 3: nonce=2 → ALLOW
Call 4: nonce=1 (backwards!) → REJECTED (replay attack)
sardis-guard-mpp/
├── src/
│ ├── server.py # FastAPI + MPP server (9 endpoints)
│ ├── routes_v2.py # V2: mandates, screening, dashboard, reports (13 endpoints)
│ ├── types.py # 4 canonical types
│ ├── policy.py # 12-check policy engine
│ ├── mandates/ # Delegation tree, scope narrowing, freeze/resume
│ ├── governance/ # 10-point evaluation, HMAC signatures
│ ├── risk/ # IsolationForest + Markov + cross-agent correlation
│ ├── compliance/ # OFAC sanctions, address risk scoring
│ ├── security/ # Dedup, session binding (T3), in-flight limit (T4)
│ ├── storage/ # SQLite WAL + DuckDB analytics, hash chain
│ ├── services/ # MPP service wrappers (Perplexity, StableEnrich, Browserbase, Tempo RPC)
│ ├── swarm/ # Multi-agent orchestrator with benign + attack scenarios
│ └── intel/ # Merchant + onchain intelligence
├── dashboard/ # React + Vite + Tailwind dashboard
├── docs/ # Protocol summary, MPP research
└── CLAUDE.md # Full context (554 lines)
This hackathon project is a focused demo of the Sardis Protocol — the Internet's Financial Operating System for Machine Commerce. The full protocol spec covers UTXO funding, zero-knowledge proofs, escrow/arbitration, FX bridging, recurring mandate trees, and a 22-state payment lifecycle.
MIT
TypeScript Interface for Machine Payments Protocol
Alephant is an open-source AI Agent Gateway for routing, tracking, and controlling LLM usage across AI agents, members, and workflows, and for publishing agent capabilities as paid endpoints with x402 and MPP payment rails.
Specifications for the Machine Payments Protocol - powered by the "Payment" HTTP authentication scheme
Rust SDK for the Machine Payments Protocol
Website for the Machine Payments Protocol
Building blocks for Agentic payments (x402, MPP, AP2) for TypeScript, Rust, Go, Python, Ruby, PHP, Lua, Kotlin and Swift.