NullRun is the runtime decision layer for tool-using AI agents. Drop in a one-line decorator, set a budget, and govern cost, tool use, and workflow state before a runaway agent turns into an incident.
Managed runtime control plane. Not a self-hosted deployment.
- Stop runaway costs. Hard budget policies stop a workflow at the cap.
Soft policies can allow a bounded overdraft for an active chain — but
only when the policy uses
enforcement_mode = Soft, an activechain_idexists, and the projected cost stays within the configured overdraft limit. - Action-bound approvals. Approval rules can match against a typed
action payload (a money amount or a tool-call argument bag). Every
approval is bound by a SHA-256 digest of the exact payload — the gate
refuses to honour the grant if a later
/executearrives with a different amount or different arguments. - Control from the dashboard. Pause or kill a workflow through the WebSocket control plane. Signals are applied at the next gate or yield boundary.
- Govern sensitive tools safely. Database writes, shell, file deletes, and external actions can be blocked by ToolBlock policies or routed through human approval, with a full audit trail.
The Python SDK is the only runtime client for the agent hot path. Integration coverage varies by framework:
- End-to-end tested (decorator plus dedicated behaviour tests): LangGraph, CrewAI, AutoGen, LlamaIndex.
- HTTP transport tested: OpenAI.
- Decorator implemented, no dedicated end-to-end test: OpenAI Agents, LangChain, Anthropic.
- Extractor unit-tested, no full transport-to-track integration test: Mistral, Gemini, Cohere, AWS Bedrock.
- nullrun.io — managed control plane and dashboard in one place. Start with the Lite plan, no credit card.
pip install nullrun— Python SDK (0.14.x). Pass yournr_live_...API key toinit()to start tracking and enforcing policy.- docs.nullrun.io — install, quickstart, concepts, and recipes.
NullRun evaluates structured action requests before execution and returns
allow, block, or require_approval. It does not inspect prompts,
tool arguments, or model output semantics. Cost enforcement relies on
SDK-reported estimates and usage — a malicious SDK that controls its
own cost reports is not protected by the gate.
- nullrun-sdk-python —
the Python SDK (
pip install nullrun). - nullrun-docs — the documentation site.
- nullrun-examples — copy-paste-runnable examples for the most common agent frameworks.
- Bug or feature? Open an issue in the relevant repo.
- Security? See SECURITY.md — please don't file public issues.
- General questions: Discord is the fastest channel.
- Email support: support@nullrun.io.
