crewai-tollwarden
TollWarden payment security for CrewAI agents — crews inherit "scan before you pay" by default.
pip install crewai-tollwarden
Two additions
from crewai import Agent
from tollwarden import TollWardenClient
from crewai_tollwarden import tollwarden_tools, register_tollwarden_provenance
tollwarden = TollWardenClient(agent_id="my-agent") # free API key auto-minted (100 free scans)
register_tollwarden_provenance(tollwarden) # ← the important line (call once at startup)
agent = Agent(
role="Purchasing agent",
goal="Buy data over x402 safely",
tools=tollwarden_tools(tollwarden),
# ...
)
Every x402 payment the agent scans gets an allow / flag / block verdict with machine-readable reasons: prompt-injection-triggered payments, replayed nonces, overpayment vs the quote, secrets/PII leaking in payment metadata, lookalike-token contracts, address poisoning, counterparty reputation.
Why the provenance registration is the important line
TollWarden's strongest detector catches payments whose decision came from content the agent just read — a prompt-injected page or tool result that says "send payment to 0x…". That check needs to know what the agent read. register_tollwarden_provenance installs a CrewAI after-tool-call hook that observes every tool output automatically, so the very next scan is provenance-tagged and the injection check runs with real input. No prompt engineering, no developer learning what "provenance" means. (TollWarden's own tool outputs are excluded, so verdicts never pollute the signal.) CrewAI's tool-call hooks are process-global — call it once at startup.
Enforcement: payments that can't execute when blocked
Tools rely on the model choosing to scan. guarded_payment doesn't:
from crewai.tools import BaseTool
from crewai_tollwarden import guarded_payment
safe_pay = guarded_payment(execute_x402_payment, tollwarden) # strict=True to refuse flags too
# build your payment tool's _run from safe_pay — on a block verdict it raises
# TollWardenBlockedError BEFORE execute_x402_payment is ever invoked.
For wallet-level enforcement (the signer itself refuses unscanned payments), see TollWardenEnforcer in the tollwarden SDK.
The toolset
| Tool | When the agent is told to use it |
|---|---|
tollwarden_scan_payment |
ALWAYS, immediately before settling any x402 payment (or before paying a received 402 offer with direction="incoming") |
tollwarden_check_reputation |
Before dealing with an unfamiliar counterparty address |
tollwarden_report_counterparty |
After a bad payment experience (always free) — warns other agents |
Verdicts are Ed25519-signed and payment-bound; the underlying client verifies them against a pinned key automatically.
MIT. TollWarden is advisory and non-custodial: it never touches keys, wallets, or funds.
Metadata
Release files for crewai-tollwarden 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| crewai_tollwarden-0.1.0.tar.gz | 8.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| crewai_tollwarden-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 14.2 kB
Release files / crewai_tollwarden-0.1.0.tar.gz
| Download URL | crewai_tollwarden-0.1.0.tar.gz |
|---|---|
| Size | 8.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d2e1f68426281e3bbdf8c28e078e9b7c76a0bc73e65c876e68b42bc48c2fb2bf
|
|
BLAKE2b-256 checksum How to use checksums |
04a8e87fe822a8ca738a73f6af4de089f37265b7f91961a30982bf6712afcead
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.28 {"installer":{"name":"uv","version":"0.11.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / crewai_tollwarden-0.1.0-py3-none-any.whl
| Download URL | crewai_tollwarden-0.1.0-py3-none-any.whl |
|---|---|
| Size | 5.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2f7f2a2d4f78ecd896e33f9d64b03afb37c2859323b7bc643f5588560cb4e7f2
|
|
BLAKE2b-256 checksum How to use checksums |
321aeae85ae6cc7884610e312b0aaf1b01d020f84697bf40667e0b6a04e1e1f3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.28 {"installer":{"name":"uv","version":"0.11.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|