AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Agent Security Guides (22) Market & Frameworks (9) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
Free · Apache 2.0 · runs on your machine

Let your AI agent read the web. Stop it before it logs in, signs up or posts.

Agent Egress Guard checks every request an agent is about to send. Reads pass. Login and sign-up forms, cloud metadata addresses and every write it does not recognise are denied, before the request leaves.

Python 3.8+no dependencies no network callsv0.2.0
agent-egress-guard
$ agent-egress-guard check https://example.com/login -X POST
DENY  POST https://example.com/login
      layer: rules  rule: login

$ agent-egress-guard check http://2852039166/latest/meta-data/
DENY  GET  http://2852039166/latest/meta-data/
      layer: host list  rule: 169.254.169.254 (same address, written as a number)

$ agent-egress-guard check https://docs.python.org/3/
ALLOW GET  https://docs.python.org/3/

$ agent-egress-guard replay
15 of the 18 steps that the full policy denies are denied here.
0 differenceswith the production service, on 726,018 real URL checks
15 of 18incident steps stopped by the free edition (18 of 18 with the full rules)
4 layershost list, page-type database, URL rules, default deny for writes
29 testsshipped with the source, including URL-encoding and IP-notation tricks
How it decides

Four checks, in a fixed order

The same order the AI Agent Allowlist service uses. Every verdict names the layer and the rule that decided it, so you can log it, audit it and explain it.

Free: 2 hosts

1 · Host list

Hosts denied whatever the page. The free edition blocks the cloud metadata addresses, where agents in sandboxes look for credentials.

Full edition

2 · Page types

The domain's verified login, sign-up, checkout and upload pages, from a database of 40.8 million domains. Added with an API key.

Free: 3 rules

3 · URL rules

Patterns that recognise risky endpoints on any site. Free: login, sign-up and password reset. Full: 40 rules.

Free

4 · Default

GET and HEAD pass. POST, PUT, PATCH, DELETE and every other method to an unrecognised URL are denied.

Before any check, URLs are read the way servers read them: /%6Cogin is /login, /login;jsessionid=1 is /login, and 2852039166, 0xA9FEA9FE and [::ffff:a9fe:a9fe] are all 169.254.169.254.

Install and try

From nothing to a working check in four steps

Works on Windows, macOS and Linux with Python 3.8 or newer. Nothing else is installed.

Make a folder and a virtual environment

Keeps the tool separate from the rest of your Python.

terminal
mkdir egress-guard-test && cd egress-guard-test
python3 -m venv .venv
. .venv/bin/activate        # Windows: .venv\Scripts\activate

Install the package

Straight from this page. The file's SHA-256 is listed under Download.

terminal
pip install https://www.aiagentallowlist.com/egress-guard/agent_egress_guard-0.2.0-py3-none-any.whl

Check a few requests

Exit code 2 means denied, so you can use it in scripts.

terminal
agent-egress-guard check https://example.com/login -X POST
agent-egress-guard check https://example.com/docs
agent-egress-guard check http://169.254.169.254/latest/meta-data/

Replay the 2026 incidents

24 representative requests reconstructed from public AI-agent incident disclosures. The output lists each step, its verdict and what the free edition lets through.

terminal
agent-egress-guard replay
Put it in front of your agent

One line for the client your agent already uses

Denied requests raise EgressDenied (HTTP clients) or are aborted (browsers and proxy). Every verdict carries the layer, rule and a note for your logs.

python
from agent_egress_guard import Guard

guard = Guard()
v = guard.check("https://example.com/wp-login.php", "POST")
print(v.decision, v.layer, v.rule)      # deny rules login
Free and full edition

The free edition stops most writes. The full edition knows the pages.

Same code, same verdict format. Loading the full rule files and an API key is one line: Guard(rules_path=..., hosts_path=..., api_key=...).

URL rules

Free: login, sign-up, password reset. Full: 40 rules, including checkout, payment, uploads, repository writes, package publishing, wiki edits sent as GET, admin panels and CI/CD.

free3
full40

Host list

Free: the cloud metadata addresses. Full: 62 hosts, such as cloud consoles, package registries, paste sites, deployment APIs and webhook sinks.

free2
full62

Page-type database

URL patterns recognise fewer than half of real login pages; many sit on paths like /account or /mon-compte. The database lists each domain's verified login, sign-up and checkout URLs.

domains40.8M
Why you can trust it

Nothing hidden, nothing sent home

A security tool has to be checkable. Here is what you can verify yourself.

Open source, Apache 2.0

Free for commercial use. Read every line: browse the source or download the source archive below.

Runs on your machine

Standard library only, no telemetry. The free edition makes no network calls at all; only the optional page-type database contacts our API, and only when you give it a key.

Same verdicts as production

With the full rule files loaded, the engine matched the AI Agent Allowlist service on all 726,018 real URL and method pairs we compared.

Tested, tests included

29 unit tests ship with the source, including URL-encoding, path-parameter and IP-notation tricks. Run them with python -m unittest.

Checksums on every file

Compare the SHA-256 below with sha256sum (macOS: shasum -a 256) before you install.

Who is behind it

Alpha Quantum, enterprise software since 2007. AI Agent Allowlist publishes open data on page types across 40.8 million domains.

Download

Version 0.2.0

The package (wheel) installs with pip; the source archive contains the same code plus the tests.

agent_egress_guard-0.2.0-py3-none-any.whlPython package · 23 KB · SHA-256 82402e070177f8ba804dd6b3cdcaeb19d79e9fb032686bc70647705800553e2c
Download
agent_egress_guard-0.2.0.tar.gzSource and tests · 25 KB · SHA-256 178127bbd96cfcb70be29a60b76668b894a385528eb0cc4587473baba57cfd69
Download

Licence: Apache License 2.0 · README · Copyright 2026 Alpha Quantum

Questions

Before you install

Does it replace a firewall or a secure web gateway?

No. It decides at the level of pages and methods (may this agent submit this login form?), which network firewalls do not see. Use it next to your existing controls, inside the agent (Python hooks) or in front of it (mitmproxy).

What happens with sites the rules do not know?

Reads (GET, HEAD) pass and every other method is denied. That default alone stops most of the harmful steps in the incident replay, because they were writes.

Will it block legitimate reading?

Only pages whose URL matches a rule (login, sign-up, password reset) and the metadata addresses. Measured on real verified URLs, the full rule set matches about 0.2% of read pages, and most of those turn out to be sign-up or login pages filed under another label.

Where do the incident steps come from?

They are representative requests reconstructed from public disclosures of 2026 AI-agent incidents, grouped by scenario. See the incidents report for the sources.

Can I use it in a commercial product?

Yes. The Apache License 2.0 allows commercial use, modification and redistribution, with the licence and notice files kept.

Your agents need the whole map

40 rules, 62 hosts and verified page URLs for 40.8 million domains, in the same engine you just installed.