Developer docs
Give an agent a wallet in a few API calls
One key per workspace. Your agent asks before it spends, gets a card scoped to that one purchase, and every answer lands in the audit trail. Use the REST API directly, the MCP server, or the Python and JavaScript packages with tools for the frameworks you already run.
Quick start
Create a wallet and a sandbox key in your workspace panel, then ask for a spend. The answer is authorized, pending_approval or declined, with the rule that decided it.
curl -X POST https://agentspay.ai/api/v1/authorizations \
-H "Authorization: Bearer ap_sandbox_..." \
-H "Content-Type: application/json" \
-d '{"wallet":"research-agent-ab12","merchant":"openai.com","amount_cents":1200,"intent":"top up API credit"}'
An authorized answer carries card (the reference the agent holds) and card_details (merchant lock, ceiling, expiry, issuer, masked digits). A held spend waits for a person; read it again with GET /api/v1/authorizations/{reference}.
Scoped virtual cards
Every card is locked to one merchant, capped at the authorized amount, single use, and expires (60 minutes by default, up to 30 days). Asking for a card is asking to spend, so the same limits and approval gate decide it. What a card does not spend returns to the wallet, when it is charged for less, revoked, or expires.
# issue
curl -X POST https://agentspay.ai/api/v1/cards -H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d '{"wallet":"research-agent-ab12","merchant":"openai.com","amount_cents":1200,"expires_in_minutes":30}'
# charge (your checkout code, or your own issuer asking in real time)
curl -X POST https://agentspay.ai/api/v1/cards/card_.../charges -H "Authorization: Bearer $KEY" \
-d merchant=openai.com -d amount_cents=1150
# read, list, revoke
curl https://agentspay.ai/api/v1/cards/card_... -H "Authorization: Bearer $KEY"
curl "https://agentspay.ai/api/v1/cards?status=active" -H "Authorization: Bearer $KEY"
curl -X POST https://agentspay.ai/api/v1/cards/card_.../revoke -H "Authorization: Bearer $KEY"
# instant revocation of a wallet, and the kill switch for the whole workspace (Plus and Scale)
curl -X POST https://agentspay.ai/api/v1/wallets/research-agent-ab12/revoke -H "Authorization: Bearer $KEY"
curl -X POST https://agentspay.ai/api/v1/kill-switch -H "Authorization: Bearer $KEY"
A charge at another merchant, above the ceiling, after expiry, on a used or revoked card, or on a revoked wallet answers 402 with "approved": false and the reason, and is recorded on the card either way.
MCP server
Any Model Context Protocol client can use AgentsPay over streamable HTTP with your workspace key. Tools: list_wallets, request_spend, get_authorization, get_card, revoke_card, receive_payout.
{
"mcpServers": {
"agentspay": {
"type": "http",
"url": "https://agentspay.ai/api/mcp",
"headers": { "Authorization": "Bearer ap_sandbox_..." }
}
}
}
Python, LangChain, CrewAI, OpenAI Agents SDK
pip install https://agentspay.ai/sdk/agentspay-1.0.0-py3-none-any.whl
from agentspay import AgentsPay
from agentspay.tools import langchain_tools, crewai_tools, openai_agents_tools
pay = AgentsPay("ap_sandbox_...")
# LangChain
tools = langchain_tools(pay, requested_by="[email protected]")
agent = create_react_agent(llm, tools)
# CrewAI
researcher = Agent(role="Researcher", goal="...", backstory="...", tools=crewai_tools(pay))
# OpenAI Agents SDK
agent = Agent(name="Buyer", instructions="Ask before you spend.", tools=openai_agents_tools(pay))
# or directly
answer = pay.authorize("research-agent-ab12", "openai.com", 1200, intent="top up API credit")
The agent gets four tools: list_wallets, request_spend, check_authorization and revoke_card. Each framework is imported only when you call its helper. Source package: agentspay-1.0.0.tar.gz.
JavaScript and Vercel AI SDK
npm install https://agentspay.ai/sdk/agentspay-js-1.0.0.tgz
import { AgentsPay } from 'agentspay';
import { agentspayTools } from 'agentspay/ai';
import { generateText } from 'ai';
const pay = new AgentsPay(process.env.AGENTSPAY_KEY);
const result = await generateText({
model,
tools: agentspayTools(pay, { requestedBy: '[email protected]' }),
prompt: 'Renew the API credit for the research agent, 12 dollars at openai.com.',
});
Node 18 or newer. toolSpecs and toolHandlers are exported too, as JSON Schema tools for any other runtime.
Your own issuer and rail
Connect them in the panel, under Your own issuer and rail. We keep deciding every spend and fix each card's scope; your issuer mints the card and your rail books live payouts. Every call we make is a signed POST with AgentsPay-Signature: t=<unix time>,v1=<HMAC-SHA256 hex of "t.body">, keyed with the signing secret the panel shows once.
// to your issuer endpoint, for every live card
{"type":"card.issue","card":{"reference":"card_...","merchant":"openai.com","amount_limit_cents":1200,
"currency":"usd","expires_at":"2026-10-01T12:30:00+00:00","single_use":true,
"wallet":"research-agent-ab12","authorization":"ev_...","mode":"live"}}
// answer 2xx with {"id":"your-card-id","last4":"4821","brand":"visa"}; anything else declines the spend
{"type":"card.revoke","card":{"reference":"card_...","issuer_card_id":"your-card-id", ...}}
// if card.issue timed out, answered 5xx or came back without an id, card.revoke follows with issuer_card_id null:
// cancel whatever you minted under that reference
// to your rail endpoint, for every live payout; the budget is raised only on 2xx with {"id":"..."}
{"type":"payout.create","payout":{"reference":"ev_...","wallet":"...","payer":"...","amount_cents":25000,"currency":"usd"}}
When your issuer receives a card authorization, it asks us in real time: POST /api/v1/cards/your-card-id/charges with merchant, amount_cents and source=issuer, using a workspace key. Approve on 200, decline on anything else (402 for a no, 404 for a card id we do not know).
import hmac, hashlib, time
def verify(secret, body, header):
parts = dict(p.split("=", 1) for p in header.split(","))
expected = hmac.new(secret.encode(), f"{parts['t']}.{body}".encode(), hashlib.sha256).hexdigest()
return abs(time.time() - int(parts["t"])) < 300 and hmac.compare_digest(expected, parts["v1"])
Audit export
In the panel, on every plan: the whole trail or one period, as CSV or JSON, with what settled on each card. On Scale, the audit export API pages through the same rows.
curl "https://agentspay.ai/api/v1/audit?since=2026-09-01&until=2026-09-30&limit=500" -H "Authorization: Bearer $KEY"
SAML single sign-on
On Scale, add your team with roles (admin, approver, viewer) and connect your identity provider in the panel: its entity ID, single sign-on URL and signing certificate. Your provider needs our ACS URL and entity ID, both shown in the panel, with the work email as name ID. Your people then choose Sign in with SSO on the login page. The provider proves the address; the workspace still decides who gets in.