soroban-guard

Paste a contract,
run sixteen checks

The same suite the CLI runs, signed by your own wallet. There is no soroban-guard server: this page talks to Soroban RPC directly, and your secret key never leaves the extension.

Start a run

How a run works

  1. Connect a wallet

    Freighter signs every write. Your secret key stays in the extension — this page never sees it, and never asks for it.

  2. Name a contract

    Any deployed SEP-41 token on testnet — or the demo token, whose faucet gives any wallet the five units a full run spends, and for which the page creates the second account itself.

  3. Approve each write

    Five members are read, eleven are exercised. Each write is a real transaction you approve in Freighter, and burn and burn_from each destroy one unit for good.

  4. Read the verdicts

    Sixteen rows, each with the clause it asserts and the numbers behind it. Copy the whole thing as CHECKS.md or JSON.

Before you run this

  • It signs real transactions. Each write is one approval prompt in Freighter, and burn and burn_from destroy a unit for good.
  • Your wallet needs testnet XLM and a balance of the token. A classic Stellar asset also needs a trustline. On the demo token, the faucet button supplies the balance. A row of UNVERIFIABLE usually means an unfunded wallet rather than a faulty contract.

56 characters, starting with C. No token of your own? — the vulnerable fixture, with a faucet so any wallet can run all sixteen.

A second account to receive transfers and hold allowances. Leave it empty on the demo token and the page creates and funds one for the run; on any other token, the checks that need a real counterparty say so rather than guess.

Not connected.

Or run it from a terminal

For your own token, the command line takes both keys at once, so the checks that must sign as the spender get a verdict there too — and it drops into a CI pipeline with an exit code to gate on.

See the CLI