Download Latest Version agentguard_1.3.0_windows_amd64.zip (12.9 MB) Google Add to Preferred Sources
Home / v1.3.0
Name Modified Size InfoDownloads / Week
Parent folder
agentguard_1.3.0_windows_arm64.zip 2026-09-27 11.5 MB
checksums.txt 2026-09-27 767 Bytes
install.ps1 2026-09-27 12.7 kB
install.sh 2026-09-27 10.7 kB
agentguard_1.3.0_darwin_amd64.tar.gz 2026-09-27 12.8 MB
agentguard_1.3.0_darwin_arm64.tar.gz 2026-09-27 11.8 MB
agentguard_1.3.0_linux_amd64.tar.gz 2026-09-27 12.6 MB
agentguard_1.3.0_linux_arm64.tar.gz 2026-09-27 11.4 MB
agentguard_1.3.0_windows_amd64.zip 2026-09-27 12.9 MB
agentguard-v1.3.0.cdx.json 2026-09-27 19.4 kB
agentguard-v1.3.0.spdx.json 2026-09-27 29.8 kB
AgentGuard v1.3.0 source code.tar.gz 2026-09-27 1.3 MB
AgentGuard v1.3.0 source code.zip 2026-09-27 1.6 MB
README.md 2026-09-27 6.2 kB
Totals: 14 Items   75.9 MB 3

AgentGuard 1.3.0 — Release Notes

Released: 2026-09-26 Headline: Install AgentGuard with one command, set it up from a menu, and guard Claude Code.

Using the MCP gateway? 1.3.0 refuses to start when its command line has a stray word. If an MCP client config splits an --upstream command across several args entries, put it back in one string: 1.2.0 started that MCP server without its arguments. See MIGRATION.md (github.com).


Why this release exists

Getting AgentGuard running used to mean a Go toolchain, a policy file in the right folder, and a server command you had to remember. This release makes the first ten minutes work:

  1. Install without Go. Every release has prebuilt binaries for Linux, macOS and Windows (amd64 and arm64), one-line installers that check them against the release's checksums, and a container image.
  2. Set it up from a menu. agentguard setup does the rest and can undo it.
  3. Guard the agent people actually use. Claude Code's tool calls go through your policy.
  4. A command line that forgives. A review found flags silently ignored, arguments silently dropped, and help that exited as an error. They're fixed.

What changed

Install, update, uninstall

:::bash
# Linux / macOS
curl -fsSL https://github.com/Caua-ferraz/AgentGuard/releases/latest/download/install.sh | sh
# Windows (PowerShell)
irm https://github.com/Caua-ferraz/AgentGuard/releases/latest/download/install.ps1 | iex

The installers put all three binaries and a starter policy in place. Rerunning one updates and says what changed (Updated, Reinstalled, Downgraded with a warning); --uninstall / AGENTGUARD_UNINSTALL=1 removes AgentGuard and keeps your policy unless you add --purge. The container image is ghcr.io/caua-ferraz/agentguard, for amd64 and arm64. A smoke test installs the published release on seven platforms after every release.

agentguard setup

A menu — arrow keys and Enter, no flags. The first run asks two questions (start at login? API key?) and then writes the starter policy, creates a data folder for the audit log and database, saves an API key only you can read, and installs a login service that starts the server: a systemd user service, a LaunchAgent or a Task Scheduler task, with no admin rights. Later runs open the dashboard (with the key on your clipboard for its login), update in place, restart the server, show the settings for the SDKs and Claude Desktop, connect Claude Code, and — last on the list, after offering to just stop the server — uninstall.

Claude Code

Connect Claude Code in agentguard setup adds a hook to Claude Code's settings. Before each shell command, file read or edit, web fetch or MCP tool call, Claude Code asks AgentGuard:

AgentGuard Claude Code
ALLOW carries on; its own permission prompts still apply
DENY blocks the call, and Claude sees the reason
REQUIRE_APPROVAL waits up to 5 minutes for an approval in the dashboard or with agentguard approve
server not running carries on, with a warning that the call wasn't checked

The starter policy has rules for Claude Code: your projects are open, credentials and system folders aren't, and destructive commands (sudo, rm -rf, force-push, git reset --hard, curl … | sh) and .env files need approval. See CLAUDE_CODE.md (github.com).

The command line

  • agentguard server is the command's name; serve still works.
  • Flags work before or after arguments. agentguard approve ap_1 --url X used to approve on localhost.
  • agentguard validate policy.yaml validates that file; it used to validate the default and print VALID.
  • Typos get suggestions (--serve → Did you mean 'agentguard server'?), stray words are errors, and help exits 0 with examples on every page.
  • The policy file is found in AGENTGUARD_POLICY or the installer's folder when --policy isn't given; AGENTGUARD_URL works for the CLI, the gateway and the proxy.
  • Errors say what to do, e.g. Cannot connect to AgentGuard at … Is 'agentguard server' running there?

Also

  • agentguard server --api-key-file keeps the key out of command lines and service definitions.
  • The update notice names the command that updates (agentguard setup, docker pull or go install).
  • The MCP gateway applies --reconnect-cap, which it used to ignore.
  • The LLM proxy recognizes Claude Code's tool names.

Breaking changes

None in the public API: no field, route, flag, subcommand or schema version was removed or changed, and policies decide as they did in 1.2.0.

Command lines that used to be half-ignored now act fully:

  • A flag after an argument applies, and a stray argument is an error — also for the MCP gateway and LLM proxy.
  • validate <file> validates that file.
  • Command-line mistakes exit 2; help exits 0.
  • AGENTGUARD_URL and the key agentguard setup saves are used when no flag gives a server or key.

Upgrade notes

  1. Check scripts and MCP client configs for the command-line changes above.
  2. Rerun the one-line installer, or go install github.com/Caua-ferraz/AgentGuard/cmd/...@v1.3.0. Nothing on disk changes format.
  3. Run agentguard setup if you want AgentGuard to start at login or to guard Claude Code.

Details: MIGRATION.md § v1.2.x → v1.3.0 (github.com).


Get started

:::bash
curl -fsSL https://github.com/Caua-ferraz/AgentGuard/releases/latest/download/install.sh | sh
agentguard setup

# or
docker run -d -p 8080:8080 -e AGENTGUARD_API_KEY="$KEY" \
  -v agentguard-audit:/var/lib/agentguard ghcr.io/caua-ferraz/agentguard:1.3.0

pip install --upgrade "agentguardproxy==1.3.0"
npm install @lictorate/agentguard@1.3.0

Full change list: CHANGELOG.md § 1.3.0 (github.com).

Source: README.md, updated 2026-09-27