Agent, Buy me a chain.Agent, Buy me a chain.
Four words, one agent, and your card. AchPay is the layer in between — it decides what the agent may spend, refuses everything else, and writes down why.
Every amount below is an integer number of paise. No floating-point number touches money anywhere in this system.
Example intent
quote_id- Masala chai, 250ml
- 4000 paise
- Priced by
- catalog, not the agent
- Mandate headroom
- 50000 paise
- Rule
- allow.under_cap
Allowed, charged once, and written to the chain.
The problem
An agent with a card is a stranger with your card.
The moment a model can spend, every sentence it reads becomes a possible instruction. A product description can ask for a discount. A retry can become a second charge. A helpful assistant, asked politely enough, will find the cheapest way to say yes.
The usual answer is to make the model more careful. That is a hope, not a control. AchPay takes the decision away from the model entirely: the agent never names a price, never names an amount, and never gets to argue with the rule that stopped it.
The only handle an agent has on money is a quote_id it did not write.
How it works
Six layers, in the order a purchase moves through them.
Signed quotes
Prices come from the catalog and are sealed with an HMAC. No endpoint and no tool accepts an amount — the only handle an agent has on money is a quote_id.
Ingest sanitiser
Product prose is untrusted input. It is flagged at ingest, absent from the route agents actually call, and never read by the code that decides anything.
Policy engine
A pure function over structured fields — no database, no network, no free text. Every decision names the rule that made it, including allow.
Idempotency constraint
One intent, one charge. Enforced by a unique index inside the charge transaction, so a retry or a race loses to the database rather than to a check that ran first.
Human approval
A gated purchase stops and waits for a person. The token is consumed on use, and one approval authorises exactly one purchase.
Hash-chained ledger
Insert-only, and every row commits to the hash of the row before it. Tampering does not just get noticed — verifyChain names the seq it happened at.
Give the agent a wallet it cannot misuse.
Every decision names the rule that made it, including the ones that said yes. Start with the attacks, then read the rows they wrote.