SQLPermit

active

SQLPermit parses a candidate statement with PostgreSQL's own grammar (libpg-query, PG 18), walks the syntax tree, and reports whether it complies with the policy you supply — read-only, schema and table allowlists, row ceilings, a function allowlist, single-statement enforcement. Detection is structural, so comments, dollar quoting, Unicode escapes, and stacked statements cannot hide a construct…

Transactions · 30d
0
Volume · 30d
$0.00
Unique buyers · 30d
0
Uptime · 30d
100.0%
Latency p50
145ms
Reported calls · 30d
39

Endpoints (1 live)

  • POST /v1/guard/sql — Decide whether an agent-authored PostgreSQL statement complies with an execution policy, using PostgreSQL's own parser rather than pattern matching. Detects statement stacking, data-modifying CTEs, COPY PROGRAM, privilege changes, and dangerous functions that read as ordinary SELECTs. Returns reason codes and an optional short-lived signed permit bound to the exact normalized statement. Never connects to your database. (0.01 USDC on Base)

First seen · last seen