Hard money limits
Per-call, session, daily, service, and lifetime ceilings bind independently. The tightest limit wins.
walletAgentic payments with hard limits
A remote MCP wallet for paid APIs. The agent can discover, inspect, and estimate freely; your policy decides whether it may sign.
remote MCP · x402 v2 · settles on Flare · no local install
Product preview · example policy
Standing authority
spent today
$2.40 / $10.00
Connection
one MCP URL
Surface
6 tools · 1 spends
Enforcement
before signature
Control
revoke any time
Autonomy should be scoped, observable, and reversible.
policy → signature → receipt
The wallet is the boundary
Prompt instructions are not a security boundary. route402 evaluates every paid call against policy stored outside the agent’s context.
Per-call, session, daily, service, and lifetime ceilings bind independently. The tightest limit wins.
Unknown services can stay blocked until their age, reliability, or allowlist entry clears policy.
Ask for approval above a number you choose. If the client cannot ask, the wallet refuses.
Freeze the wallet or revoke one agent grant without changing prompts or waiting for a session to end.
A deliberately small surface
Five read-only tools help the agent find the right service and understand the cost. Only call_service can move money.
search · describe
Find capabilities, schemas, prices, and trust evidence across the public registry.
estimate · balance · history
Know the exact price and remaining policy budget before committing to a request.
call_service
Evaluate policy, sign the x402 retry, return the API result, and attach the receipt.
Designed for a hostile prompt
Limits live with the signer, not in the prompt. A loop, injection, or tool mistake cannot raise them.
Remote MCP
Paste the connector into an MCP-compatible client. OAuth keeps connection consent separate from spending authority.
route402 agent wallet