Fund and constrain agent spending
An owner supplies capital and policy; an agent receives only delegated spending authority. The exact transaction builder and console labels depend on the deployment, but the control sequence is stable.
Create and fund a spend account
Choose the Sui network and asset, create one spend account for that owner/asset, and deposit the intended balance. The account remains the buyer's even though it is a shared on-chain object. Keep enough owner-side SUI for setup and administrative transaction gas.
Define policy
Create policy targets from exact registered services. Review the service ID, method, path, target hash, recipient, and authorization epoch. Then set:
- a total cap in integer atomic units;
- a maximum for one payment (policy-level);
- an optional expiry (
0on chain means no wall-clock expiry); and - the set of allowed service targets.
Avoid floating-point conversions for money. A policy cap constrains aggregate spend against that policy; it does not reserve a separate balance from the spend account.
Authorize agents
Two provisioning methods mint scoped grants on the same spend account:
- MCP OAuth (hosted agents): owner completes consent; the agent holds the delegate key. See Pay with MCP.
- Bring-your-own key (SDK/REST): agent shares only its public Sui address;
owner calls
POST /v1/delegated-signersand signscreate_grant. See Authorize an agent.
On a BYO grant, also set the per-signer maxPerPaymentAtomic (in
addition to policy max per payment), total budget, asset, and expiry.
Do not treat an existing dashboard login as payment consent. Review changed terms before signing a replacement grant. A verified owner session never creates or revokes on-chain authority by itself.
Revoke at the narrowest level
- Revoke a grant / delegated signer to disconnect one agent.
- Revoke a policy to stop spending against its targets.
- Revoke the spend account to stop all spending from that account.
Revocation is enforced on chain. Pausing or revoking a seller service separately controls whether the gateway mints new challenges; it does not rewrite the owner's historical receipts.
Pause a BYO signer from the console or
POST /v1/delegated-signers/:id/pause/prepare (owner-signed). Resume restores
pay. Use revoke for a terminal stop.