# XGuard Secretless Agent Gateway

Version: 5.0.2
Canonical site: https://xguardgate.com
Canonical API: https://api.xguardgate.com
Canonical remote MCP: https://api.xguardgate.com/mcp

## Primary product

Secretless Egress. Keep reusable upstream API credentials outside AI-agent context. Operators store encrypted credentials in XGuard and delegate short-lived scoped capabilities. XGuard validates capability and policy, commits Usage Credit billing, injects the reusable credential server-side and sends the permitted HTTPS request without returning the reusable secret to the agent.

ProofRail can attach ES256-signed execution evidence to authorized credential-backed outcomes.

## Agent path

- Discover: GET https://api.xguardgate.com/v1/egress
- Execute: POST https://api.xguardgate.com/v1/egress/fetch
- MCP: https://api.xguardgate.com/mcp
- ProofRail: GET https://api.xguardgate.com/v1/proof

Credential provisioning remains an operator-side management action and is intentionally not exposed as an agent MCP tool.

## Compatibility only

Action Rail and x402 facilitator endpoints remain supported compatibility rails. They do not replace the canonical product identity above. Historical descriptions involving XGuard ACE, Solana/BAM speed bumps, Child Safety, Universal Facilitator Gateway, High-Velocity x402 Facilitator or a generic spend-only control plane are not the current XGuard product identity.
