Recipe · Python (any function)
Python (any function): guard http requests with CAIN
Step by step, for an agent that fetches URLs: install, wrap the tool, see the live decision, write and test a rule, handle approvals.
Last reviewed 2026-10-02
1 Get a key
No key yet? Create a free account (every new account starts with a 7-day trial), then copy the key from the console. Requests go from your browser straight to this site.
Give each agent its own key in production (console → Agent keys): decisions, trust history and revocation are then per agent.
2 Install
pip install "cainstudio @ https://cainstudio.online/cainstudio-0.4.1-py3-none-any.whl#sha256=1bea5cf49aeeb2775acec58933fc39b008a1c84bfd7c9690c54723ed707af689"
export CAIN_API_KEY=...cainstudio 0.4.1, pinned by URL and SHA-256 so pip installs exactly the published wheel (the package is not on PyPI yet). Framework dependencies come from PyPI as usual.
3 Put CAIN in front of the function that acts
@cainstudio.guard() sends the function's name and arguments to CAIN before the body runs. Async functions work the same way.
import cainstudio
@cainstudio.guard(agent_id="http-agent")
def http_get(url: str) -> str:
"""HTTP requests: an agent that fetches URLs."""
... # your existing code, unchanged
try:
http_get(url='http://169.254.169.254/latest/meta-data/')
except cainstudio.ApprovalRequired as e:
print("held for a human:", e.approval_id)
except cainstudio.ActionBlocked as e:
print("refused:", e.decision.reasons)
except cainstudio.CainUnavailable:
print("CAIN unreachable: not run") # fail-closedOn a refusal the agent gets an exception: ActionBlocked, ApprovalRequired (with the approval id) or CainUnavailable. The tool body never runs: not on a refusal, not on a hold, not when CAIN cannot be reached.
4 See what CAIN decides for this exact call
This is the request the integration sends when the model calls http_get with these arguments. record: false evaluates it without writing an evidence record. A new agent has no trust history, so expect REQUIRE_APPROVAL at first; destinations outside your egress allowlist are refused by the egress stage.
5 Write the rule, and test it before you save it
The cloud metadata address, the classic server-side request forgery target, is refused. For everything else, an egress allowlist of the hosts the agent may reach is the stronger control.
The panel sends the draft rule to the rule tester: it says which rule would decide the call and saves nothing. Swap in the safe arguments below to see it pass through. matches is a case-insensitive glob (*, ?), not a regular expression; conditions on one rule must all hold; the first matching rule by priority wins.
Safe arguments: {"url": "https://api.github.com/repos/acme/app"}
When it does what you want, save it from the console or with POST /fabric/tool-rules:
curl -sS -X POST https://cainstudio.online/fabric/tool-rules \
-H "X-API-Key: $CAIN_API_KEY" -H 'Content-Type: application/json' \
-d '{"name": "http-guard", "effect": "deny", "priority": 10, "match_path": "/tools/http_get", "conditions": [{"field": "url", "op": "contains", "value": "169.254.169.254"}]}'6 Handle the calls that wait for a person
A held call is not executed. It appears in the approval queue with its exact arguments; an approval lets that one call run once. Adapters can wait instead of returning: wait_for_approval=120.
GET /fabric/approvals
7 Check it before you ship
cainstudio redteam --agent http-agent # dry-runs dangerous calls; exit 2 if any would run
cainstudio decisions # what was decided, and why
cainstudio explain <decision_id>Every recorded decision is signed; Cain().verify(decision) checks its quorum certificate on your machine (Python SDK).
More
Python (any function), other tool types
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem