Technical docs · Devnet
Agent requests, human decisions.
An agent can propose agreement drafts and request a fixed test-USDC payment under a team policy. The owner submits the draft, recipients accept one version, and a person signs in a wallet. Pix and real money are unavailable.
Payment request example
A team owner creates the credential and policy. The agent uses the published agreement ID and a stable idempotency key. The IDs below are fictional; no credential is included.
POST /api/agent
Authorization: Bearer [team credential]
Content-Type: application/json
{"action":"request_payment","team":"11111111-1111-4111-8111-111111111111","agreementId":"22222222-2222-4222-8222-222222222222","idempotencyKey":"campaign-42"}{"request":{"id":"33333333-3333-4333-8333-333333333333","state":"pending_approval","expiresAt":"2026-10-11T12:00:00Z"},"paymentUrl":null}Retrying with the same key and agreement returns the existing request. A key reused for another agreement is denied. The agent reads later state with get_payment_request; a signing URL appears only when the policy permits it and required human review is complete.
Controls and limits
- The policy checks budget, per-payment limit, recipient allowlist, and expiry. Updating the policy or revoking the credential expires open requests.
- The agent cannot approve for a recipient, approve its own payment request, or sign a transaction.
- An invalid or expired request cannot start from its agent payment link. A confirmed Devnet receipt must match the agreement, request memo, and USDC transfers before the owner can record it.
- Invalid credentials return 401. Invalid input returns 400. A denied or unavailable request returns 403. The policy applies to agent requests; existing public payment links remain reusable under their original terms.
Published links can be paid more than once. The browser keeps an agent payment attempt locally for recovery, but simultaneous tabs and other devices are not globally serialized. This workflow still needs proof with a funded Devnet wallet.
For the complete local MCP adapter and API contract, see the Allot source repository.