Sato Hub
← Back to blogSato Kit: guardrails for agents that move money

Sato Kit: guardrails for agents that move money

Spending rules in one file, a clear reason every time it says no, and a receipt for everything your agent does onchain. Works with the framework and wallet you already use.

2026-10-01 · 4 min read

In one line: Sato Kit is a free, open-source toolkit that sits between your AI agent and the blockchain. Before your agent spends anything, it checks your rules, tests the transaction, and has your wallet sign only what was approved. Then it writes down what happened.

Why it matters

An agent that can move money needs guardrails. Today most teams build them by hand: a spending cap here, a retry guard there, logs somewhere else. They are easy to get subtly wrong, and when an agent gets blocked it usually can't tell you why.

Sato Kit gives you those guardrails in one package, on top of the tools you already use. You keep your framework, your wallet and your code.

What you get

  • ▸Your rules in one file. Spending caps per trade and per day in dollars, which chains, tokens and addresses are allowed, and maximum slippage, all in policy.json. If the kit can't read a price, it says no instead of guessing.
  • ▸A "no" that explains itself. When a rule blocks an action, you get the rule, the limit and what it saw: max_usd_per_trade, limit 500, observed 740.
  • ▸Only what you approved gets signed. Every write is two steps: prepare, then execute. Execute accepts only the ID that prepare returned, so nothing can be swapped in at the last second. Each ID runs once, even if two requests arrive at the same moment.
  • ▸Tested before it's real. Every transaction is simulated first, and the kit starts on a local copy of the chain. Using real funds is a switch you turn on in your policy.
  • ▸A record of everything. Each action adds a receipt to a local, tamper-evident log, including any fee that was charged.
  • ▸Proof it still works. Every night, [Sato Status](https://satohub.ai/status) re-runs the kit's read actions and checks each write action's setup without sending it. You see the date each one last passed.
  • ▸Your keys stay yours. The kit never holds keys or funds. Signing happens in the wallet setup you choose: a local key, Coinbase CDP, Privy, Turnkey, OWS, a Safe multisig, or a person approving each action.
  • ▸Open swap pricing. Swaps work with any venue. Sato Swap is the labelled default and shows its fee on every quote, with a quote that carries no Sato fee right next to it.

What it works with

  • ▸Agent frameworks: Vercel AI SDK, Coinbase AgentKit, Claude Agent SDK, OpenAI Agents SDK, LangChain, ElizaOS and GOAT.
  • ▸Any MCP client, such as Claude Code or Cursor, through a built-in MCP server.
  • ▸Chains: Ethereum, Base, Arbitrum, Optimism and Polygon, plus Solana reads, transfers and swaps. The included Solana signer is devnet-only.
  • ▸Actions: read chain data, quote and prepare swaps and bridges, price x402 payments, look up and register ERC-8004 agent identities, list and revoke token approvals, and propose Safe transactions.

How it works

Every action goes through the same five steps:

1. Prepare. Your agent asks for an action, for example "swap 5 USDC for ETH on Base". The kit builds the transaction, unsigned. 2. Check. The pre-flight compares it with your policy.json. If a rule says no, it stops here and tells you which rule and why. 3. Simulate. The transaction runs against the chain without being sent, so you see what would happen. 4. Execute. Your agent passes back the intent ID, and your signer signs exactly what was prepared, once. 5. Record. A receipt goes into the log.

One detail matters: the kit's check explains, and your wallet enforces. For CDP, Privy and Turnkey, the same policy.json compiles into the wallet's own policy, so the limit holds even if something skips the kit. With other signers, the kit's check is the only one.

What it isn't

It isn't a wallet, an agent framework or a guarantee. A nightly pass is a date, not a promise, and a simulation shows what the chain answered at that moment. For x402, the kit prices and checks the payment, and your x402 client sends it.

Get started

You need Node 20 or later.

See it work in 30 seconds, with nothing signed:

``sh npx -y @satohub/kit@0.1 read swap.quote --input '{"chain":"base","sell_token":"USDC","buy_token":"WETH","sell_amount":"5000000"}' --json ``

You get quotes from Sato Swap and LI.FI side by side, each with its fee. Amounts are in the token's smallest unit, so 5000000 is 5 USDC.

Start a new agent from a template that passed last night:

``sh npx create-sato-agent@0.1 "swap USDC to ETH on Base under a daily cap" ``

You get a runnable repo with the kit, a policy.json and tests. It runs on sample data first (npm start -- --mode fixture).

Add it to an agent you already have:

``sh npm install @satohub/kit viem ``

Then use the adapter for your framework, for example @satohub/kit/ai-sdk. The README has one for each framework.

Use it from Claude Code or any MCP client:

``sh claude mcp add sato-kit -- npx -y @satohub/kit@0.1 mcp ``

Check your setup at any time: npx -y @satohub/kit@0.1 doctor.

Docs are at [satohub.ai/kit](https://satohub.ai/kit), nightly results at [satohub.ai/status](https://satohub.ai/status), and the source is on [GitHub](https://github.com/satohubai/sato-hub-integrations/tree/main/packages/kit) under the MIT licence.

Sources

Join the Sato Hub Briefing

One email a week — the agents, tools, and infrastructure that actually shipped, and why they matter.