Open-source runtime security and governance for AI agents, MCP tools, robotics, industrial automation, and physical AI.
-
Updated
Jun 8, 2026 - TypeScript
Open-source runtime security and governance for AI agents, MCP tools, robotics, industrial automation, and physical AI.
Runtime authorization & audit layer for physical AI — T0–T3 tiers, capability tokens, Ed25519, ROS2/MCP/MAVLink bridges, OWASP ASI coverage
Cryptographic verification for AI agent actions — ECDSA-secp256k1 + RFC 6979 signed Action Receipts (v0.1), multi-dimensional Trust Vector, capability tokens (JWT-shaped + Biscuit-style attenuation), UETA §10(b) undo. 29 MCP tools. A2A v1.0 + ERC-8004 format compatible. Receipt-batch Merkle roots anchored on Base mainnet. Starting with code.
Tokfence is the local security daemon that keeps AI agent API keys in an encrypted vault, injects them at request time, and enforces budgets, rate limits, and adaptive risk controls — so your keys never touch agent config files again.
Agent policy layer for safe tool use across MCP, A2A, and orchestrated agents.
Grantz provides capability token primitives.
Add a description, image, and links to the capability-tokens topic page so that developers can more easily learn about it.
To associate your repository with the capability-tokens topic, visit your repo's landing page and select "manage topics."