> Call POST /v1/check before a tool that writes. DENY means do not invoke the tool. For clean Markdown of any page, append .md to the page URL. For the complete index, fetch https://docs.withwrit.com/llms.txt.

# README badge

> A dynamic badge that proves your agent's writes are gated by Writ.

A badge you embed in your README that doesn't just *say* your agent's writes
are gated — it shows the live count, straight from your audit log:

```md
[![agent writes gated by Writ](https://api.withwrit.com/v1/badge/writ_badge_....svg)](https://withwrit.com)
```

The badge renders `agent writes gated · 1.2k/30d` — your tenant's gated-write
count over the trailing 30 days. Green when you've gated at least one write in
the window, grey at zero. Counts are cached for an hour.

## Mint a badge

```bash
curl -s https://api.withwrit.com/v1/badge/tokens \
  -H "Authorization: Bearer writ_..." \
  -H "Content-Type: application/json" \
  -d '{"label": "support-agent repo"}'
```

The response includes `badgeUrl` and a ready-to-paste `markdown` snippet. Paste
it into your README. The `badgeToken` is shown exactly once — store it; you
need it to revoke the badge.

## What the badge proves (and doesn't)

**It proves:**

* The embedder controls a real Writ tenant — the token is minted with that
  tenant's API key.
* That tenant actually gates writes: the count is computed live from the
  tenant's audit log. A badge showing `0/30d` is honest about it.

**It doesn't prove:**

* That the *specific repo* embedding the badge is the codebase whose writes
  are gated. The badge binds a token to a tenant, not a repo. Don't embed a
  badge on a repo whose agent doesn't gate through Writ.

**What leaves the gate:** only the aggregate 30-day count. No tenant IDs,
names, API keys, or receipt contents are ever in the badge or its URL.

## Revoke

```bash
curl -s https://api.withwrit.com/v1/badge/tokens/revoke \
  -H "Authorization: Bearer writ_..." \
  -H "Content-Type: application/json" \
  -d '{"badgeToken": "writ_badge_..."}'
```

The badge URL 404s from that moment on — embeds show a broken image rather
than a stale claim. Badge tokens can never be used as API keys, and they never
appear in your key list.

## No dynamic badge? Use the static one

If you'd rather not mint a token, the `pywrit` repo ships a static SVG with
the same design (no live count). See the
[pywrit badge docs](https://github.com/AvenueDAdmin/pywrit/tree/main/badge).