Controls
—
Payment controls
Manage vendor trust, rolling spend limits and emergency freezes before money reaches a facilitator.
How to use this page & what the results mean
How to use this page
- Add vendor registers an external service that your agents are allowed to pay. A vendor can be an API hostname (for example
api.example.com), an endpoint, or a wallet address. - In Vendor key, enter the stable hostname or wallet you see in the payment request. Use only the host, without
https://or a URL path when possible; the value is normalized before it is saved. - Endpoint pattern is optional. Use it when one vendor owns several routes and you want to document or narrow the allowed endpoint (for example
/v1/translate). Leave it blank to allow the vendor key generally. - Set Risk score from 0–100. Use 0–79 for an allowed vendor under observation; a score of 80 or higher blocks new payments for that vendor. Click Allow vendor to save the rule.
- After the first vendor is added, the allowlist becomes active: vendors not listed here are denied before a payment reaches the facilitator. Remove a vendor to turn off that vendor rule; an empty list returns to observe-only mode.
- Freeze a tenant, agent or vendor when an incident needs an immediate stop.
- Use rolling limits to cap spend or call volume over a short window.
What the results mean
- Allowed vendor means the vendor is on the allowlist and can pass vendor checks unless it is frozen or its risk score is 80+.
- Risk score 80+ blocks new payments for that vendor.
- Empty allowlist preserves observe-only compatibility; the first vendor turns enforcement on for the workspace.
- Vendor key is matched against the normalized vendor/hostname extracted from each payment request; it is not an agent ID.
- Rate limits are evaluated against confirmed settlements in the configured rolling window.
Example: To allow a translation provider, enter translate.example.com as the Vendor key, optionally enter /v1/translate as the Endpoint pattern, keep Risk score at 0, then click Allow vendor.
Add vendor
Allow a trusted payment destination
Use the hostname or wallet that appears in payment requests. Add an endpoint pattern only when you need to narrow the rule; risk score 80+ blocks new payments.
Freeze scope
fail closed immediately
Choose what to stop, enter its ID, and click Freeze. Use an agent ID, normalized vendor hostname, or leave the scope as Tenant to stop the whole workspace.
Rolling rate limit
amount is smallest token unit
Set a scope and time window, then provide at least one limit: maximum amount, maximum calls, or both. The window is in seconds (3600 = 1 hour).
Vendors
Loading…
Frozen scopes
Loading…
Rate limits
Loading…