Skip to content

How it works

Three layers, in order: your rules, the content check, then you.

Your agentreads the page, proposes to pay
proxy URL, SDK, advisory MCP tool, or API
The guard, on your side
Your rulesdecide
Content checkcan block or hold
Allowedseller gets paid
Deniednothing is paid
Reviewwaits for you, 2 minutes by default

A wallet spending limit cannot spot a redirected payee under the limit, or hold a payment for review.

Your rules run first

Your limits and lists, checked in code. One daily cap per agent, across all networks and lanes.

All decision rules
AllowlistFirst-time payee reviewWhat the agent may buyPer-payment limitDaily capPayments an hour, per networkUnsupported contract calls denied
Base Sepoliatest USDC, the defaultSolana Devnettest USDCBase and Solana Mainnetreal USDC, when selected

Test USDC counts toward the same daily cap.

The content check runs second

Scans the page, 402 response or tool text for prompt injection.

Deniedcompleted blockReviewunfinished checkClearyour rules stay in force

Anything unsure is held for review

Answer it from a phone before the review timeout. By default, first-time payee review holds a payment to a payee off your allowlist. If that is the only reason, Approve and always allow this payee ends those holds for that seller.

Proxyholds an EVM payment 35 s, then returns the 402SDKpays if approved in time, else throws unpaidMCP tool (advisory)says pay if approved in time, else do not pay

The SDK waits waitForReviewSeconds and the advisory MCP tool waits wait_seconds. A Solana payment gets its answer at once. Through the proxy URL, a retry signed for the same 402 picks up the open review, unless text in that session was flagged since. Then it opens a new one.

Nothing is paid until you approve. Webhook, email and push alerts arrive while the hold is open.

Four lanes

Two enforce, and two only advise.

Setup guides
LaneChecked beforeA deny meansWorks with
Proxy URLEnforcedforwardingthe payment does not go outAny x402 client, in any language
SDKEnforced on routed paymentssigningnothing is signedA TypeScript agent on an x402 client
MCPAdvisorythe agent asksan agent that skips it can still payClaude Code, Codex, or another MCP client
HTTP APIAdvisory: your code actsyour code asksyour code must not send the paymentYour own code, in any language

Observe and enforce

Every agent starts in enforce. Observe mode logs what enforce would do and lets most payments through. It still blocks the ones below.

observe blocks

  • a wrong network
  • a wrong asset
  • a payee not in the 402
  • a declared unsupported payment method
  • an unsupported contract call

enforce blocks

  • every deny

Limits

It only sees payments you route through it. Use the proxy or SDK and keep the wallet small. A wallet-side lock is not built yet.

Security model
Holds no funds

Your agent keeps its wallet.

Never signs your payments

It holds no key of yours.

Sees what you route

An agent that skips it can still pay.

Guard every payment your agent makes

Change one URL. Every payment is checked and explained before it goes out. Free during beta, no card.