← Deep First Search

Partners: add safe payments to your agents in minutes

Your users' agents are starting to pay for APIs with x402. Agent Safe makes sure they can't be talked into paying the wrong address, the wrong price or more than the owner allowed, without changing the wallet you already run.

We do the integration work with you, for free. Email [email protected].

Three ways to integrate

Level What you add What your users get Effort
1. Guard Wrap your agent's x402 calls with the SDK, using your existing wallet signer (Privy, Turnkey, Crossmint, Coinbase CDP, any viem account) Merchant allowlist, pinned prices, a spending plan sealed before the agent reads anything untrusted, rate limits, a hash-chained audit log. Your signer is never even asked to sign an attack ~10 lines, nothing on-chain
2. On-chain budgets Users fund an Agent Safe vault they own; your agent key spends inside the budget they sign Per-payment, per-day and per-merchant caps enforced by a contract on Base, a timelock on any new budget, instant pause and revoke, one payer address per merchant. Non-custodial: neither you nor we can move their funds A day, with our help
3. Drop-in Ship our MCP server, Vercel AI SDK tool or LangChain tool All of the above inside Claude, Cursor, generateText or LangGraph Configuration only

Level 1 in practice

import { createAgentPay, MerchantRegistry } from "@deepfirstsearch/agent-pay";

const pay = createAgentPay({
  registry: new MerchantRegistry([{
    origin: "https://api.example.com", payTo: "0x…",
    network: "eip155:8453", maxPerTx: 50_000n, pricePin: 10_000n,
  }]),
  policy: { allowedNetworks: ["eip155:8453"] },
  // Any viem account: your API, KMS or enclave signs.
  payer: () => yourWalletAccount,
  session: { readsUntrustedInput: true, accessesSensitiveData: false, canPay: true },
});

const plan = pay.commitPlan(
  [{ origin: "https://api.example.com", maxSpend: 1_000_000n }],
  60 * 60_000,
);
// Pays only if every check passes.
const res = await pay.fetch("https://api.example.com/data", {}, { plan });

A test in the repository (sdk/test/external-signer.test.ts) runs exactly this with a remote signer: an honest 402 is paid, and a 402 that swaps the payee is refused before the signer is called.

What makes it different

What partners get

Costs, plainly

Level 1 and the drop-in tools are free. On-chain budgets (level 2) carry a 0.1% protocol fee on top of each payment or top-up, paid by the vault. There is no integration fee.

Status

Live on Base mainnet as an unaudited beta (small amounts), and on Base Sepolia for testing. Addresses: DEPLOYMENTS.md. Security reviews: SECURITY.md.