NEWx402 spend gate is live — authorize the demand before the wallet signs →
Runaway agent spend, stopped

Your agent can run. Your API bill can't.

Set a hard limit before the next model call leaves your stack. Sanction authorizes AI spend, MCP tools, and x402 payment demands before they become irreversible.

Start freeSee the workflows →
AGENT WALLET LIVE
DAILY CAPENFORCED
pxy_•••••••3faMCP · REST
MANDATEVERIFIED
vendor_payment
scopestripe.chargecap$480.00expires14m 32s
SIGNATURE + WALLET STATUS VALID
Policy travels with the agent
Why authorization comes first

Runaway spend is not an observability problem.

The agent kept retrying

It kept reading, checking, and repairing after it passed the number you had in your head. Your provider kept accepting calls. Your card kept paying.

The alert arrived after the spend

Usage dashboards explain what happened. They do not decide whether the next call is allowed to leave your stack.

The action could not be taken back

A destructive tool call or signed machine payment needs authorization before execution, not a report after it clears.

Three governed workflows

Start with the most expensive failure mode.

One decision engine sits in front of three irreversible actions. Sanction authorizes the spend; any rail settles it.

Workflow 01

Govern MCP tools before they run

Put the hosted broker in front of an MCP server. Block destructive tools, escalate sensitive ones, and return a machine-readable refusal before the upstream receives the call.

Workflow 02

Cap AI spend by team

Change the model gateway base URL. Wallet-tree budgets enforce agent, team, and organization caps without instrumenting every call.

Workflow 03

Authorize x402 before the wallet signs

Send the payment challenge to Sanction first. It prices the worst case, applies policy, and withholds a denied demand before the wallet can sign it.

How it works

Put policy in the path, not beside it.

1

Connect one enforcement point

Use the LLM gateway, the hosted MCP broker, or the pre-sign quote endpoint. Your provider, tools, and payment rail stay yours.

2

Set the policy

Define agent and team budgets, allowed or blocked tools, escalation bands, and the hard line that cannot be crossed.

3

Get a deterministic decision

Approved proceeds. Escalated pauses for a human and a one-use grant. Denied stops the provider call, tool call, or wallet action.

4

Export the evidence

Every decision is attributable and exportable in a signed, hash-chained record for engineering, finance, and audit.

The control plane

Policy travels with the agent.

Identity says who the agent is. Payment rails move money. Sanction carries the missing authority: what the agent may spend or invoke, under whose policy, within what budget, and with what proof.

01

Discover

A counterparty finds the issuer and verification surface.

02

Present

The agent carries a signed, scoped, time-bound mandate.

03

Verify

The counterparty checks budget, scope, freeze, and revocation.

04

Prove

Each authorization becomes attributable evidence.

sanction-mcp
$ npx sanction-mcp wallet connected ops_agent_07 10 governance tools available sanction_authorize_toolAUTHORIZED · request dec_8f31
Governed MCP

Put policy in front of every tools/call.

Register an upstream once, then point the MCP host at Sanction's broker. Every tool call is authorized before a byte reaches the upstream, and the upstream credential stays in the vault.

SPENDTOOLSCAPABILITIESCREDENTIALSOUTCOMESAPPROVALS

Brokered traffic is enforced. Calls sent directly to the upstream bypass Sanction and are not governed.

The product boundary

What Sanction does not do.

Sanction does not settle payments. It authorizes the spend; any rail settles it.

Sanction does not replace your model provider or MCP server. It governs whether the next request may reach them.

Sanction does not custody signing keys. In the broker, a denied x402 challenge is withheld before your wallet sees payment instructions.

Sanction cannot govern traffic routed around it. Enforcement applies at the gateway, broker, and authorization endpoints you connect.

Start with one workflow

Put a hard limit in front of the next irreversible action.

Start free