For agents
An account for your agent, on your terms.
A private banker's mandate, enforced by a contract instead of a promise. The agent's key can spend from its own vault, in USDG, inside limits you sign, and nothing else. It pays x402 invoices natively and never goes a cent past the line.
- No funds ever rest under the agent key: a leak is answered by pause or revoke
- Three tiers: supervised, semi-autonomous, fully autonomous
- Rotate the signer and keep vault, policy and history; revoke and the balance comes home in the same transaction
The agent side
// the running agent, with its own signer key (viem) const route = await agents.read.routeFor([id, merchant, amount]); // 0 Settles · 1 Queues · 2 Refused if (route === 0) await agents.write.payInvoice([id, merchant, amount, invoiceId]); if (route === 1) await agents.write.queueInvoice([id, merchant, amount, invoiceId, memoHash]); // 2: ask the owner, do not retry // invoiceId = keccak of the HTTP 402 challenge, so the operator's // webhook can reconcile AgentPaymentExecuted against the invoice
The mandate
Four numbers the chain holds you to.
Per payment
The ceiling on any single settled spend. Above it the payment is refused outright, before it reaches a queue.
Per 24 hours
A rolling window the contract resets itself the first time a payment arrives more than a day after it opened.
Review above
Anything above the threshold queues for you. Nothing moves until you approve; rejecting leaves nothing to reverse.
Allowlist
Up to ten recipients. When it is on, the agent can pay those and nobody else, checked before a queue, not after.
Mandate study
Limits the chain enforces, not a server promises.
An agent signs with its own key. That key can spend from a vault the contract controls, in USDG, inside the mandate, and nothing else: no withdrawals, no re-keying, no widening its own limits. Lose the key and you pause or revoke; you never race it.
- Settles, queues or refuses: the agent asks routeFor before it spends
- x402 invoice ids ride into every settlement event for reconciliation
- Rotate the signer and keep the vault, the policy and the history
Route
Settles
payInvoice: per-payment ✓, window ✓, allowlist ✓, at or under the review threshold
Two paths
payInvoice(agentId, recipient, amount, invoiceId)
per-tx ✓ window ✓ allowlist ✓ amount ≤ review threshold
→ settles now, AgentPaymentExecuted(invoiceId, windowSpent)
queueInvoice(agentId, recipient, amount, invoiceId, memoHash)
per-tx ✓ allowlist ✓ amount > review threshold
→ ApprovalRequired; the daily cap is checked at approval,
because what fit when queued may not fit when read
approvePending / rejectPending / withdrawPendingWhy the key is weak on purpose
The signer can do three things: spend from a vault this contract controls, in one token, inside the policy. It cannot withdraw, cannot re-key itself, cannot widen its own limits. Because funds never rest under the agent's key, a leak is answered by pausing or revoking the agent rather than by racing it to empty an account. Vaults are internal balances, so one agent's funds are unreachable to another by construction, not by check.
The protocol fee comes out of the vault and stays outside the mandate: your limits cover what the agent spends, not what the house charges to carry it.