fizzl
Safety checks for Python AI agents that pay: LangChain, LangGraph, CrewAI or your own loop.
| Check | What the agent checks | Service | Price |
|---|---|---|---|
check_before_signing |
a transaction, token approval or signature before signing it: green / orange / red with reason codes (drainers, unlimited approvals to unknown spenders, look-alike tokens, Permit/Permit2/Seaport signatures that hand over tokens) | presign-guard | $0.01 |
check_token |
a token before buying or accepting it: honeypot, rug-pull signs, look-alikes (Solana and EVM) | presign-guard | $0.01 |
check_wallet_approvals |
every open approval of a wallet and which to revoke | presign-guard | $0.02 |
check_endpoint_before_paying |
an x402 or MPP paid API before paying it: go / caution / no_go, the cheapest option that settles, budget, track record, bait signs (fake brands, airdrop lures, output that doesn't match) | x402 Doctor | $0.001 |
The checks only check. They never sign, pay or move anything themselves. A failed check comes back as
{"error": ..., "message": ...} instead of raising, so the agent can tell its user.
Install
pip install "fizzl[x402]" # with the x402 client, to pay per check
pip install "fizzl[langchain,x402]" # plus LangChain tools
Use
import requests
from eth_account import Account
from x402 import x402ClientSync
from x402.http.clients import wrapRequestsWithPayment
from x402.mechanisms.evm.exact import ExactEvmScheme
from fizzl import Fizzl
payer = x402ClientSync().register("eip155:8453", ExactEvmScheme(Account.from_key(AGENT_KEY))) # USDC on Base
session = wrapRequestsWithPayment(requests.Session(), payer)
fizzl = Fizzl(session=session)
fizzl.check_endpoint_before_paying("https://api.example.com/funding", max_usd=0.05)
# {'verdict': 'go', 'summary': 'OK to pay: $0.02 on Base.', 'options': [...], 'reasons': [], ...}
fizzl.check_token("base", "0x...")
fizzl.check_before_signing(type="approval", chainId=8453, token="0x...", spender="0x...", amount="115792089237316195423570985008687907853269984665640564039457584007913129639935")
Prepaid credits instead of a payment per check: buy a pack once (presign-guard: 100 checks for $0.80; x402 Doctor: 1000 preflights for $0.80), then use a plain session:
fizzl = Fizzl(credit_keys={"presign": PRESIGN_CREDIT_KEY, "doctor": DOCTOR_CREDIT_KEY})
LangChain / LangGraph
from langgraph.prebuilt import create_react_agent
from fizzl.langchain import fizzl_tools
tools = fizzl_tools(session=session) # or credit_keys={...}; only=[...] for some of them
agent = create_react_agent(model, tools + your_tools,
prompt="Before you pay any API, call check_endpoint_before_paying. Before you sign anything, call check_before_signing. Never continue on red or no_go.")
The tools are plain StructuredTools with typed arguments, so CrewAI and other frameworks that take LangChain tools can use them too.
Want the wallet to enforce it, not just inform the model?
Tools inform the model; a model can still ignore them. To make red and over-budget payments impossible, guard the wallet itself: presign-guard-wallet (Node) checks every signature with presign-guard and your spending limits, with Telegram approval above them.
License
MIT
Metadata
Release files for fizzl 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fizzl-0.1.0.tar.gz | 7.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fizzl-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 15.4 kB
Release files / fizzl-0.1.0.tar.gz
| Download URL | fizzl-0.1.0.tar.gz |
|---|---|
| Size | 7.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0547640d1f079b7c061cc10a0530b996f81982a606d797fd590ea00962e2ccec
|
|
BLAKE2b-256 checksum How to use checksums |
f773b98db4e760bb7d4927b58f3a4034d4e1115d78b067b7cb8ef7ec448dd096
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency logRelease files / fizzl-0.1.0-py3-none-any.whl
| Download URL | fizzl-0.1.0-py3-none-any.whl |
|---|---|
| Size | 7.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f65c20b50f136c1402a4ae6c80f40a76e893eab092acd312fe7401c3242dd0be
|
|
BLAKE2b-256 checksum How to use checksums |
c51a97d8bd52357b2ca31f3bd26eca1a46875433a798bddd67d8560d29fe185c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency log