Skip to main content

fizzl

Safety checks for Python AI agents that pay: LangChain, LangGraph, the OpenAI Agents SDK, CrewAI or your own loop.

Check What the agent checks Service Price
check_before_signing a transaction, token approval or signature before signing it: green / orange / red with reason codes (drainers, unlimited approvals to unknown spenders, look-alike tokens, Permit/Permit2/Seaport signatures that hand over tokens) presign-guard $0.01
check_token a token before buying or accepting it: honeypot, rug-pull signs, look-alikes (Solana and EVM) presign-guard $0.01
check_wallet_approvals every open approval of a wallet and which to revoke presign-guard $0.02
check_endpoint_before_paying an x402 or MPP paid API before paying it: go / caution / no_go, the cheapest option that settles, budget, track record, bait signs (fake brands, airdrop lures, output that doesn't match) x402 Doctor $0.001

The checks only check. They never sign, pay or move anything themselves. A failed check comes back as {"error": ..., "message": ...} instead of raising, so the agent can tell its user.

Install

pip install "fizzl[x402]"              # with the x402 client, to pay per check
pip install "fizzl[langchain,x402]"    # plus LangChain tools
pip install "fizzl[openai-agents]"     # OpenAI Agents SDK tools (Python 3.10+)

Use

import requests
from eth_account import Account
from x402 import x402ClientSync
from x402.http.clients import wrapRequestsWithPayment
from x402.mechanisms.evm.exact import ExactEvmScheme
from fizzl import Fizzl

payer = x402ClientSync().register("eip155:8453", ExactEvmScheme(Account.from_key(AGENT_KEY)))  # USDC on Base
session = wrapRequestsWithPayment(requests.Session(), payer)

fizzl = Fizzl(session=session)
fizzl.check_endpoint_before_paying("https://api.example.com/funding", max_usd=0.05)
# {'verdict': 'go', 'summary': 'OK to pay: $0.02 on Base.', 'options': [...], 'reasons': [], ...}
fizzl.check_token("base", "0x...")
fizzl.check_before_signing(type="approval", chainId=8453, token="0x...", spender="0x...", amount="115792089237316195423570985008687907853269984665640564039457584007913129639935")

Try it without a wallet: Fizzl() with no paying session and no credit keys falls back to the free quick checks for check_token, check_before_signing and check_endpoint_before_paying: the verdict only, a few per hour, marked "free": True with a note on what the full check costs. check_wallet_approvals has no free version. Fizzl(free=False) returns payment_required instead.

Prepaid credits instead of a payment per check: buy a pack once (presign-guard: 100 checks for $0.80; x402 Doctor: 1000 preflights for $0.80), then use a plain session:

fizzl = Fizzl(credit_keys={"presign": PRESIGN_CREDIT_KEY, "doctor": DOCTOR_CREDIT_KEY})

LangChain / LangGraph

from langgraph.prebuilt import create_react_agent
from fizzl.langchain import fizzl_tools

tools = fizzl_tools(session=session)          # or credit_keys={...}; only=[...] for some of them
agent = create_react_agent(model, tools + your_tools,
    prompt="Before you pay any API, call check_endpoint_before_paying. Before you sign anything, call check_before_signing. Never continue on red or no_go.")

The tools are plain StructuredTools with typed arguments, so CrewAI and other frameworks that take LangChain tools can use them too.

OpenAI Agents SDK

from agents import Agent, Runner
from fizzl.openai_agents import fizzl_tools

agent = Agent(name="buyer", tools=fizzl_tools(session=session),   # or credit_keys={...}, or nothing for the free checks
    instructions="Before you pay any API, call check_endpoint_before_paying. Before you sign anything, call check_before_signing. Never continue on red or no_go.")
print(Runner.run_sync(agent, "Is https://api.example.com/funding safe to pay, at most $0.05?").final_output)

The checks run in a worker thread, so a blocking requests session doesn't stall the agent's event loop. Bad arguments from the model come back as {"error": "bad_input", ...} without calling (or paying for) the check.

Want the wallet to enforce it, not just inform the model?

Tools inform the model; a model can still ignore them. To make red and over-budget payments impossible, guard the wallet itself: presign-guard-wallet (Node) checks every signature with presign-guard and your spending limits, with Telegram approval above them.

License

MIT

Metadata

Release files for fizzl 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for fizzl 0.3.0
File Size Uploaded
fizzl-0.3.0.tar.gz 10.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for fizzl 0.3.0
File Interpreter ABI Platform
fizzl-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 20.7 kB

Release files / fizzl-0.3.0.tar.gz

Download URL fizzl-0.3.0.tar.gz
Size 10.0 kB
Tags Source
SHA-256 checksum
How to use checksums
f52335fff494b9738775e832ef39bb47dcd2d10d8c6dbb0257a62b61ad2e494b
BLAKE2b-256 checksum
How to use checksums
4f3f1e49865af954c7cf28f0cdca0e9073ee0d594df59381f771cf965ea1cf8d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release files / fizzl-0.3.0-py3-none-any.whl

Download URL fizzl-0.3.0-py3-none-any.whl
Size 10.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
83f6873b1795807f4c2b3ffec9e4901f983989b871d8fd49fb8dac4568db0b7d
BLAKE2b-256 checksum
How to use checksums
daa9b9d1b6002be69f03f0b4e5215f3cdf2e9496e49499bf454f721d81d537a8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release history Release notifications | RSS feed

0.4.0

2 release files

This release

0.3.0 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page