18M+
x402 payments audited on-chain. Payer, payee, amount and timing are public for every one.
Deep First Search ·
AI agents are starting to pay for things, and anyone can talk them into paying the wrong party. We keep every payment inside limits you signed, and expose less of your business.
Live on Base · beta · npx @deepfirstsearch/agent-pay demo
The problem
Your agent reads untrusted content all day, and it can move money. One poisoned page is enough to make it pay the wrong party. And every payment it makes is public: who, how much, when. Attackers read your balance. Competitors read your suppliers.
18M+
x402 payments audited on-chain. Payer, payee, amount and timing are public for every one.
$150K+
drained from one AI agent's wallet by a single prompt injection. The same trick worked again a year later.
77%
of employees paste company data into AI tools that keep logs.
Exposure control
Each merchant sees a fresh payer with no history, and what your agent bought is shared with that merchant only, never with facilitators or the chain. Amounts and payees remain on-chain. Funding payers through a regulated exchange breaks the public link to you, while you can still prove any payment to an auditor.
The product
01
An on-chain vault that assumes your agent will be tricked. You sign a budget per merchant; the agent's key can spend inside it and never widen it. Revoke or pause instantly.
02
An x402 client that treats every payment request as hostile. Payee, asset, network and price must match what you approved before anything is signed. The model proposes; code decides.
03
Expose less of your business. Each merchant sees its own payer, nothing extra leaves your machine, and payers can be funded through a regulated exchange so the public can't trace them back to you.
Built to survive
We never hold funds or run relayers. Immutable contracts with no admin keys, open source.
A tamper-evident payment log lets owners prove any payment to an auditor or tax authority, on their terms. Sanctioned addresses are screened before any payment.
Privacy lives in the app, not in the token. stays exchange-listable after EU AMLR 2027.
No master key, no admin, no upgrade path. Enclaves are defense in depth, never the only lock.
Shipped, not promised
3 / 3
Real x402 payments through an owner-signed budget, reconciled to the cent, no double charge. See the transaction.
Claude
A real Claude session with our MCP server bought a price index, then refused an API that asked to pay a different wallet, and explained why. Watch it.
4 → 0
A swapped payee, a price hike, an injected merchant and a budget overrun: refused before anything is signed. Try it offline: npx @deepfirstsearch/agent-pay demo.
260+
Fuzzing, invariants and a Base mainnet fork with real USDC on the contracts; attack regressions on the SDK. Unaudited beta: small amounts while the independent review runs.
Works with your stack
npx @deepfirstsearch/agent-pay-mcp. Listed in the official MCP registry and on Glama. The model gets paid_fetch, never a payee or a limit.
One tool for generateText, one for LangGraph. Refusals come back as data, so the agent can explain them.
Any viem-compatible signer can pay: a local key, an embedded or server wallet, a KMS. During an attack it isn't even asked to sign.
npx @deepfirstsearch/agent-pay owner budget … signs a per-merchant budget on Base. Pause and revoke are instant.
1,000,000,000
total supply, minted once
Tokenomics
One billion , minted once at genesis. The contract has no mint function at all, so the number can only shrink.
| Allocation | Share | Terms |
|---|
Usage burns supply
Agent Safe
0.1% fee in USDC
Fee jar
50% of fees, immutable
Anyone
burns to claim the jar
Burned
supply goes down
No swaps, no oracle, no admin. The price to claim the jar doubles after every claim and halves every three days. Only Agent Safe, SDK and inference fees feed the jar. No transfer taxes, no reflections, no hidden market-maker deals.
0%
to venture capital
0
new tokens, ever
0%
of fees to the burn jar
0y
founder lock, on-chain
No token until there is revenue to burn.
Roadmap
Phase 0 · Done
Market pain, 30+ launches and failures studied, legal and security assessments, tokenomics.
Phase 1 · Done
x402 client with a policy engine outside the model, Agent Safe vaults, per-merchant payers, an owner CLI, an MCP server (official MCP registry), Vercel AI SDK and LangChain tools. Verified on Base Sepolia.
Phase 2 · Now
Live since October 6, 2026, with the first real payments settled (unaudited, small amounts, verified factory). Next: design partners and wallet integrations, an independent review, then the public launch.
Phase 3
Wallet-only airdrop to real users, one-price public auction, liquidity burned, no mint function at all.
Phase 4
Integration with a compliant, third-party privacy pool. Later: private inference paid through the same rails.
npx @deepfirstsearch/agent-pay demo