tool Details
Explore More
Alternatives

About Capri Ai Agentpay
Capri AgentPay is a governed payment layer designed specifically for AI agents operating in production environments. As autonomous agents increasingly call paid APIs, settle transactions, and interact with stateful systems, the traditional approach of handing them a private key introduces severe security vulnerabilities. A single compromised prompt or hallucination can drain a wallet or authorize unauthorized payments. AgentPay solves this by inserting a runtime between the agent and the signing mechanism, creating a policy-enforced boundary that evaluates every payment request before any signature is generated. The product is built for engineering teams shipping agent systems that need real controls around budgets, approvals, and audit trails. When an agent encounters an HTTP 402 Payment Required challenge, AgentPay intercepts the request and evaluates it against a fixed policy order: merchant allowlist verification, per-transaction cap check, daily budget enforcement, and an auto-approve threshold that can trigger human-in-the-loop review. Only when all checks pass does AgentPay settle the payment, retry the original request with cryptographic proof attached, and store a signed receipt that can be verified offline. Agents never hold private keys, and every payment is policy-checked before a signature ever exists. The product ships with six MCP tools instead of raw key access, a VS Code extension for developer workflows, and Base Sepolia sandbox settlement for testing.
Features
x402 Payment Handling
AgentPay natively supports the HTTP 402 Payment Required challenge protocol, enabling agents to automatically handle payment challenges from paid APIs and MCP tools. When an agent makes a request and receives a 402 response, AgentPay intercepts the challenge, evaluates the payment against configured policies, and settles the transaction if approved. The original request is then retried with proof of payment attached, allowing seamless integration with pay-per-use APIs without exposing private keys or requiring manual intervention.
Per-Agent Budgets and Caps
Administrators can assign granular budgets and per-transaction caps to individual agents or agent groups. Each payment request is checked against the agent-specific daily budget and the per-transaction maximum before any settlement occurs. This prevents runaway costs from agent loops, infinite retries, or prompt injection attacks that attempt to authorize large payments. Budgets can be reset, adjusted, or frozen independently for each agent without affecting others in the system.
Merchant Allowlists
AgentPay enforces a merchant allowlist that specifies which API endpoints, contract addresses, or payment recipients an agent is permitted to transact with. Any payment request to a merchant not on the allowlist is automatically denied before reaching the key signer. This provides a foundational security layer that prevents agents from sending payments to unknown or malicious destinations, even if the agent is compromised or misdirected by adversarial prompts.
Human-in-the-Loop Approvals
For payment requests that exceed a configurable auto-approve threshold, AgentPay pauses execution and surfaces the transaction to a human operator for review. The operator sees the exact amount, asset, chain, recipient, and the policy branch that triggered the review. They can approve, deny, or modify the request before it proceeds. This gives security and finance teams a safety valve for high-value transactions while still allowing fully automated processing for low-risk payments.
Verifiable Receipts
Every settled payment generates a signed receipt containing hashes, timestamps, verification fields, and the complete policy evaluation trail. These receipts can be verified offline without needing access to the AgentPay runtime, enabling third-party auditing, compliance reporting, and dispute resolution. The receipt structure is designed to be cryptographically verifiable and includes all context needed to reconstruct the payment decision.
Six MCP Tools Instead of Raw Key Access
AgentPay provides six narrow, typed MCP (Model Context Protocol) tools that replace raw key access for agents. These tools cover payment initiation, budget checking, receipt retrieval, merchant allowlist queries, policy status inspection, and human review status polling. Each tool has a defined surface area and cannot be used to sign arbitrary transactions or access the underlying private keys, significantly reducing the attack surface compared to traditional key management approaches.
Use Cases
Autonomous Research Agents Accessing Paid APIs
Research agents that need to query premium data sources, scientific databases, or market intelligence APIs can use AgentPay to handle pay-per-request billing automatically. The agent requests data, AgentPay intercepts the 402 challenge, checks the research agent budget and merchant allowlist, and settles the micropayment if approved. The signed receipt provides an audit trail for cost allocation across research projects.
AI-Powered Trading and DeFi Bots
Trading agents executing on-chain transactions require strict payment controls to prevent catastrophic losses from bugs or exploits. AgentPay enforces per-transaction caps and daily budgets on trading bots, while the merchant allowlist restricts which protocols and token contracts the agent can interact with. Human-in-the-loop approval provides a review gate for large swaps or unusual trading patterns.
Internal Tool Automation Agents
Enterprise agents that automate workflows involving paid internal tools, cloud API calls, or SaaS subscriptions benefit from AgentPay's policy enforcement. The agent can trigger payments for compute resources, data processing jobs, or API usage without granting it direct access to billing accounts. Budgets and caps prevent cost overruns from automation loops or misconfigured workflows.
Multi-Agent Systems with Shared Budgets
Teams deploying multiple specialized agents that share a common budget pool can use AgentPay to enforce collective spending limits. Each agent operates with its own caps and allowlists, but all payments draw from the same daily or monthly budget. This enables granular control over individual agent behavior while maintaining global cost visibility and enforcement across the entire agent fleet.
Pricing
Capri AgentPay is currently in an access-restricted preview phase. The team is opening access in small waves to teams building agent systems that need payment controls, approval flows, or operator-facing runtime boundaries. Specific pricing plans and tiers have not been publicly disclosed. Interested teams can request access through the Capri AI website, book a demo for a personalized walkthrough, or install the VS Code extension to begin exploring the sandbox environment. Pricing details will be shared directly with qualified teams during the onboarding process.
Frequently Asked Questions
How does AgentPay prevent an agent from draining a wallet through prompt injection?
AgentPay places a policy runtime between the agent and the signing mechanism. The agent never holds private keys and cannot authorize payments directly. Every payment request must pass through four sequential checks: merchant allowlist verification, per-transaction cap, daily budget, and auto-approve threshold evaluation. Even if a prompt injection causes the agent to request a payment to a malicious address, the allowlist check will deny it unless that address is explicitly approved. The runtime ensures that no signature is ever generated unless all policy conditions are met.
What happens when a payment request exceeds the auto-approve threshold?
When a payment request exceeds the configured auto-approve threshold, AgentPay pauses the transaction and creates a review request visible to human operators. The operator sees the exact payment details, including amount, asset, chain, recipient, and the specific policy branch that triggered the review. They can approve the payment, deny it, or modify parameters before proceeding. The agent's execution remains paused until the operator resolves the request, preventing any further action until the decision is made.
Can AgentPay be used for settlement on chains other than Base Sepolia?
AgentPay currently supports Base Sepolia for sandbox settlement and testing. The architecture is designed to be chain-agnostic, and the team is expanding support to additional EVM-compatible chains for production deployments. The x402 protocol handling, policy evaluation, and receipt generation are chain-independent, meaning the core security and control features work regardless of the underlying settlement chain. Check the documentation for the current list of supported production chains.
How are receipts verified offline and what information do they contain?
Receipts are signed cryptographic objects containing the transaction hash, settlement timestamp, amount, asset, chain, recipient address, policy evaluation results, and the complete chain of checks that passed. They can be verified offline using the public key of the AgentPay runtime that signed them, without requiring access to the live system. This enables third-party auditors, compliance teams, or external systems to independently validate that a payment was approved through the proper policy channels and not tampered with after settlement.
Similar to Capri Ai Agentpay
Construction Calculator
Free construction calculators with transparent formulas, steps, assumptions, and metric or imperial units.
JsonTranslate
Translate JSON, Markdown, and TXT files while preserving keys, paths, and project structure.
Build or Skip
Build or Skip helps builders find products already making money before they commit to a new idea.
AI Image combinder
Create professional product images with AI. Upload your product photo and transform it into stunning marketing visuals, lifestyle scenes, and e-commer
Luffy
Luffy is an AI employee in Slack that remembers your workspace and executes tasks across every app.
Wisegrid
Spreadsheet-native work management with AI formulas, dashboards, automation, reporting, and project views for growing teams.