XGuard / operating contract
An explicit trust boundary
The operator, XGuard runtime and upstream provider remain trusted. The agent and provider response are untrusted. An agent receives a bearer capability scoped to an origin, path, method, expiration, call budget and optional operation/resource allowlist. Possession authorizes only those operations.
The gateway checks scope and reserves idempotency before billing; a committed debit precedes upstream credential decryption. Private destinations, redirects, method changes, reflected credentials and oversized results are rejected. Ambiguous writes are not retried.
XGuard cannot prevent an operator from sharing a provider key elsewhere, remove secrets from a malicious provider's own logs, or promise correctness of provider content. Gateway credit budgets do not cap a provider's invoice; bounded model requests also require provider-side project budgets.