Tollary

Protect an AWS KMS agent-wallet signing boundary

Scan the project locally without sending source or credentials. Then inspect the offer and lint an exact signed mandate.

npx tollary fit-check --project .
npx tollary inspect --source guide-aws-kms
npx tollary lint --input ./guard-request.json --source guide-aws-kms

The KMS role should be unable to bypass your gateway. Tollary never receives AWS credentials or KMS signing permission.

A fit-check is advisory and incomplete. Review IAM and key policies yourself; public beta is Base Sepolia only.

Full quickstart · IAM templates · Limitations