The spend account
A spend account is Sui Agent Payments' escrow and buyer control plane. One owner funds one account per asset and reuses that balance across multiple service policies and multiple delegated signers. Funds are not copied into every policy; each successful payment draws from the common account while incrementing the applicable policy and grant counters.
The spend account was historically called a shared pool. The rail tag on the
wire is delegate (renamed from shared_pool as a fresh package lineage, see
docs/decisions/ADR-0035-rename-escrow-rail-to-delegate.md); the Move module is
spend_account.
Objects and roles
| Object | Role |
|---|---|
| Account | Funded balance for one owner + coin type |
| Spend policy | Service targets, total and per-payment ceilings, expiry |
| Grant | Scoped signer: delegate address, policy snapshot, budgets, expiry |
A policy target maps a stable target hash (from service identity) to the
recipient stored on chain. The delegate cannot replace the recipient at
payment time. Policies provide aggregate and per-payment ceilings. Grants
narrow those policies for one delegate and session, adding session budget,
per-signer max_per_payment, expiry, and lifecycle flags.
Payment path
- Agent hits a paid gateway URL and receives a spend-account 402 (rail tag
shared_pool). - Agent (or SDK) builds
spend_account::settle_policy_paymentwith the delegate as sender. - Agent signs; transaction executes on Sui.
- Agent retries the HTTP request with an MPP proof (finalized digest + offer).
- Facilitator matches the on-chain payment event to the offer; gateway delivers only after verification.
Replay protection is account-scoped: a payment_id_hash is single-use
per spend account across all grants on that account.
Control levers
| Lever | Effect |
|---|---|
| Revoke / pause a grant | Stops one agent (one delegate) |
| Revoke / pause a policy | Stops authority for its service targets |
| Pause / revoke the account | Stops spending from that spend account as a whole |
The owner, not the delegate, controls those levers. Seller service pause/revoke controls whether the gateway mints new challenges; it does not rewrite the owner's historical receipts.
Dialects
Current spend-account resources advertise MPP self-settled only. x402 transaction-submit for this rail remains behind an explicit flag and is not the default agent path. See Rails and dialects.