Your agent can spend money. AgentVeins decides how much, where, and proves it.
Corporate card controls, for AI agents. One bad loop can drain a wallet overnight. AgentVeins sets the limit across every wallet your agent holds, and keeps a receipt for every attempt.
npm install @agentveins/coreBeta
$ agent run --policy team-policy.json ✓ pay api.weather.com 0.05 USDC settled (daily: 24.35/25.00) ✓ pay api.weather.com 0.05 USDC settled (daily: 24.40/25.00) ✓ pay data.chainfeed.xyz 0.55 USDC settled (daily: 24.95/25.00) ✗ pay api.weather.com 0.10 USDC BLOCKED budget.daily exceeded → violation logged · audit #a41f9 · owner notified $ veins freeze agent-07 ✓ kill switch active. All wallets
Three payments settle. The fourth breaks the daily cap and is refused before money moves.
Every payment answers these questions before money moves
One policy, every wallet. Cross-rail spend governance, approvals, and audit for AI agents.
| Check | Question it answers |
|---|---|
| Allowlist | Is this a vendor the owner approved, on one list that covers every wallet? |
| Budget | Is it inside the per-payment and daily limits, counting every wallet together? |
| Recipients | Is the money going to an address you approved, not one the vendor named? |
| Kill switch | Is this agent still allowed to spend, across every wallet at once? |
| Approval | Does this payment need a human sign-off first? |
| Velocity | Is this normal behavior, or a runaway loop? |
Payments that pass go through untouched: the agent never notices AgentVeins is there. Payments that fail come back with the reason, over the daily limit or vendor not approved, so the agent can pick a cheaper vendor or ask a human instead of crashing. Every attempt, on every wallet, allowed or refused, lands in one audit log that shows if anyone edits it.
Why now
57.4%of web page requests now come from bots, not peopleCloudflare Radar · June 2026
~160Mx402 payments settled by agents to datex402 · July 2026
~16.7%of planned enterprise AI spending goes to AI and agent security and governanceIDC · January 2026
The rails are here. The seatbelts are not.
What AgentVeins is not
- Not a wallet: it never holds your money
- Not a payment network: x402, Solana and Base move the money
- Not an agent framework: bring whatever agent you already built
Common questions
- Does AgentVeins hold my money?
- No. It never holds your money and it never moves it. x402, Solana and Base do that. AgentVeins sits between your agent and its wallets, and decides whether a payment is allowed, before the money moves.
- Some wallets already have spending caps. Where does AgentVeins fit?
- Wallet providers are shipping their own allowances, allowlists and caps, which is a good sign for the whole category. Those controls work one wallet at a time. A real deployment holds several wallets on several networks, so a total spending limit, one policy for the whole team, and a single record of what happened all have to sit a layer above any individual wallet. Wallets with built-in caps are something AgentVeins governs, not something it competes with. The way a password manager is not competing with each website's login form.
- Which chains and networks does it support?
- Solana first, running on its test network today. Base and Cloudflare Wallets come next. The policy engine knows nothing about any chain, so the same policy applies to each new network as support for it lands.
- What happens to my agent when a payment is blocked?
- It does not crash. The call comes back with the reason, over the daily limit or vendor not approved, so the agent can retry a cheaper vendor or escalate to a human. The attempt lands in the audit log with the reason it was refused.
- How long does integration take?
- The target is under 10 minutes from npm install to your first governed payment. You wrap the one function where your agent spends money, and that is the only integration point.
- Is this ready for production?
- Not yet. AgentVeins is in beta, open source under the MIT license. The policy engine, the tamper-evident audit log, budgets that survive a restart, human approvals, and velocity limits that a restart cannot reset all work today, as do payments on Solana's test network. The x402 path settles real USDC on devnet, through the standard's own reference facilitator rather than a hosted one. Base and Cloudflare support are still planned. Run it against test funds, not a treasury.