The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the M2M Sentinel listing page.
Official multi-language client library, Model Context Protocol (MCP) server, and Coinbase AgentKit ActionProvider for M2M Sentinel — deterministic EVM bytecode capability observations and common-proxy resolution for autonomous applications operating on Base. Callers own transaction policy.
This export labels npm 1.2.8 as a local release candidate, not a verified published artifact. This candidate version does not establish registry publication or installability. The install commands below use the last-verified npm release 1.2.7.
This quickstart uses Base USDC, a published allowlisted sample at
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913. The response contains factual
capability evidence and limitations, not a safety guarantee or transaction
advice. The live demo can be rate limited (HTTP 429 with Retry-After) or
unavailable when upstream evidence sources fail (HTTP 503).
Other addresses receive only the public preview. Full /v1/audit/:address
analysis remains protected by an API key or an explicitly authorized x402
payment; the demo never pays silently. The client does not automatically retry
or fall back to a protected route after a demo error. The source SDK export includes a
runnable no-credential JavaScript example at examples/try_public_demo.js;
it is not included in the last-verified npm 1.2.7 artifact.
Connect M2M Sentinel directly to Claude Desktop, Cursor, Windsurf, or any MCP-compliant LLM agent.
claude_desktop_config.json)https://api.m2msentinel.com/mcphttps://api.m2msentinel.com/sse with messages at https://api.m2msentinel.com/messageswallet_sendCalls GuardThe public SDK includes guardWalletSendCalls, a customer-side execution-identity
boundary for Base Account / EIP-5792 batches. It preflights the anchor call and
evaluates its caller policy before scheduling any remaining call, then pins
remaining calls to the first trusted block identity in waves of at most four.
Each settled wave is validated and policy-checked in ascending request-index
order before a later wave starts; a failure or rejection stops later scheduling.
The original detached request is forwarded only after all checks pass. It does
not sign, broadcast, custody funds, infer inner UserOperation semantics, or
make a safety claim. See examples/base_account_paymaster_guard.js for a no-network fixture.
The public repository includes a standalone, mock-only transaction boundary
example at examples/transaction_preflight.js.
From this repository root, run:
It observes one caller-supplied Base transaction, passes the observation to a caller-owned policy, and reaches only a mock signing/send callback. It refuses to continue on unverified evidence, unresolved execution, an observation mismatch, or a missing Diamond selector mapping. It never signs or sends a transaction; optional live mode uses only a caller-supplied API-key header and remains the caller's responsibility.
MIT License. Copyright (c) 2026 M2M Sentinel.