Documentation Protocol v1.0

Integrate pre-execution governance: API contract, signed receipts, offline verification, and CI enforcement. Verification is live today; the execution gateway is in private beta.

Authorization before execution

Every irreversible action passes through TrigGuard. Policy is evaluated, risk is assessed, and a signed receipt is produced before anything executes.

Current state

AI decides
AI executes

Risk: no authorization layer

With TrigGuard

AI decides
TrigGuard authorizes
Permit Deny Escalate
AI executes
  • Policy evaluated before side effects
  • Risk assessed on every surface
  • Signed receipt independently verifiable
  • Verification Live
  • Gateway Private beta
  • CLI PyPI 0.2.0 · npm trigguard

Installation

Two surfaces: Protocol Verification is live and requires no API key. The Execution Gateway (POST /execute) is in private beta - request access.

npm install trigguard
pip install trigguard==0.2.0

How it works

Architecture and decision semantics live on dedicated pages - this hub links into them.

Quickstart

End-to-end integration path: install, verify offline, then request gateway access when ready.

Protocol reference

Runtime integration

Trust & verification

Deterministic authorization boundary - every request yields PERMIT, DENY, or SILENCE. Report vulnerabilities to security@trigguardai.com.

FAQ

Protocol Verification vs Execution Gateway?
Offline verification is live: Ed25519 over receipt JSON using /.well-known/trigguard-keys.json. The Execution Gateway (private beta) issues PERMIT/DENY/SILENCE for irreversible actions - see TG-EXECUTION-AUTH-01.
API keys for verification?
No. Use published keys with the CLI or /verify.
Canonical quickstart?
/docs/quickstart - offline-first verification path.
SILENCE vs DENY?
DENY is an explicit refusal. SILENCE withholds authorization without leaking policy signals.