Skip to content
LogoLogo

The spend account

A spend account is Sui Agent Payments' escrow and buyer control plane. One owner funds one account per asset and reuses that balance across multiple service policies and multiple delegated signers. Funds are not copied into every policy; each successful payment draws from the common account while incrementing the applicable policy and grant counters.

The spend account was historically called a shared pool. The rail tag on the wire is delegate (renamed from shared_pool as a fresh package lineage, see docs/decisions/ADR-0035-rename-escrow-rail-to-delegate.md); the Move module is spend_account.

Objects and roles

ObjectRole
AccountFunded balance for one owner + coin type
Spend policyService targets, total and per-payment ceilings, expiry
GrantScoped signer: delegate address, policy snapshot, budgets, expiry

A policy target maps a stable target hash (from service identity) to the recipient stored on chain. The delegate cannot replace the recipient at payment time. Policies provide aggregate and per-payment ceilings. Grants narrow those policies for one delegate and session, adding session budget, per-signer max_per_payment, expiry, and lifecycle flags.

Payment path

  1. Agent hits a paid gateway URL and receives a spend-account 402 (rail tag shared_pool).
  2. Agent (or SDK) builds spend_account::settle_policy_payment with the delegate as sender.
  3. Agent signs; transaction executes on Sui.
  4. Agent retries the HTTP request with an MPP proof (finalized digest + offer).
  5. Facilitator matches the on-chain payment event to the offer; gateway delivers only after verification.

Replay protection is account-scoped: a payment_id_hash is single-use per spend account across all grants on that account.

Control levers

LeverEffect
Revoke / pause a grantStops one agent (one delegate)
Revoke / pause a policyStops authority for its service targets
Pause / revoke the accountStops spending from that spend account as a whole

The owner, not the delegate, controls those levers. Seller service pause/revoke controls whether the gateway mints new challenges; it does not rewrite the owner's historical receipts.

Dialects

Current spend-account resources advertise MPP self-settled only. x402 transaction-submit for this rail remains behind an explicit flag and is not the default agent path. See Rails and dialects.