Tenant isolation
Every financial record — agents, intents, policies, approvals, ledger and reconciliation data — is scoped to a customer account (tenant). Cross-tenant access is rejected even if an internal ID is guessed.
Every agent payment preparation step is made visible and bounded. The layer is not a wallet, custodian or transaction relay: it never holds keys or sends money itself.
Every financial record — agents, intents, policies, approvals, ledger and reconciliation data — is scoped to a customer account (tenant). Cross-tenant access is rejected even if an internal ID is guessed.
Customer API keys are stored only as SHA-256 hashes. The plaintext secret is shown exactly once at creation or rotation and never appears in logs, listings or audit records.
API keys can be revoked instantly from the dashboard or API. Revoked keys are rejected with 401 on the next request.
Keys can be rotated with a configurable grace period so the old key keeps working while the new secret is deployed — or rotated immediately when compromised.
The service does not collect or store a wallet private key.
Intent, preflight and route APIs do not request a signature or submit a blockchain transaction.
Agent, wallet and token identities are represented by HMAC-derived hashes where a stable identifier is needed.
Policy evaluation can require an authenticated operator to approve or reject a pending authorization. Review actions are replay-safe.
Financial events are recorded as append-only ledger entries; production operations should include regular backup and retention review.
The staging deployment uses an isolated database volume and Base Sepolia configuration, separate from production mainnet configuration.
Intent creation requires an opaque Idempotency-Key; preflight, route and reconciliation records also guard against incompatible replay.
Application-level customer rate limits are not yet enforced in this staging MVP. Configure an edge or gateway limit before exposing production credentials.
Keep administrator credentials in a secret manager, rotate agent tokens, review policy limits, restrict staging access, and independently verify all x402 payment requirements before any user signs a transaction.