Agent payment control plane
Give AI agents a wallet, not your treasury.
DelegaPay turns an AI payment mission into a bounded USDC permission, verified through MetaMask, simulated x402 risk scoring, 1Shot dry run, and Base Sepolia proof.
Automated tests mock relayer broadcasts. In the running app, Broadcast is a real Base Sepolia action.
User wallet
treasury stays outside
Bounded Budget Field
USDC moves only through approved gates.
Permission Gate
MetaMask
Risk Gate
x402 simulated
Relay Gate
1Shot relay
Proof
BaseScan visible
Allowance is a cap, not spent until broadcast.
Boundary model
The agent can act, but the treasury stays outside the field.
The unsafe pattern is a raw key. DelegaPay moves the limit into the payment permission itself, so every valuable action must pass through the same bounded route.
Treasury access stays outside the field. Each control narrows what the agent can do before money moves.
Budget cap
The mission starts with a USDC ceiling.
Plan validation
The AI proposal is structured before permission.
Wallet permission
MetaMask grants allowance, not custody.
Risk gate
x402 simulated scoring clears when required.
Dry run
1Shot estimates before broadcast.
Proof
BaseScan confirms the final transfer.
Protocol sequence
One payment story, four visible checkpoints.
MetaMask defines the boundary, x402 marks the simulated risk purchase, 1Shot estimates and relays, and BaseScan becomes the public endpoint.
MetaMask
bounded user permission
x402
simulated paid risk check
1Shot
dry-run quote and relay
BaseScan
public proof endpoint
Proof moment
A payment demo should end with public proof, not a screenshot.
The guided demo keeps dry run safe until the operator explicitly broadcasts. When a confirmed transaction returns, the proof becomes the final stage.
Verified BaseScan proof
0x5b3d…97ab on BaseScan ↗