Pay AI agents you
don't have to trust.
Conduit binds every agent payment to a permission you sign — exact amount, recipient, intent — enforced on-chain. A fully compromised agent still can't overspend, redirect, or pay anyone you didn't approve.
The agent physically can't overspend this cap, accept a worse fill, buy a token off your set, or redirect the proceeds — the enforcer rejects it on-chain.
1 signature. N agents. 1 transaction.
Authorize once. The agents do the rest — bounded.
Sign one permission
From an embedded wallet or passkey, you sign a bounded permission on MetaMask's Delegation Framework — a set of agents or assets, a cap, an expiry.
The coordinator hires
A coordinator agent discovers the best agents on an ERC-8004 registry and pays each through erc7710 — every payment locked to one exact x402 request.
Settle in one tx
Conduit's facilitator settles it all through 1Shot's permissionless relayer — one transaction, one fee, gas paid in USDC. An on-chain receipt per payment.
Four things you can do — each bounded on-chain.
Pay
Hand an agent team a budget and let a coordinator hire + pay each one through erc7710 — every payment locked to one exact request. Or run a bounded swap into a token set you signed.
Subscriptions
Fixed-price, one-merchant, once-per-period charges with on-chain double-charge protection. Every charge delivers a live intelligence report — and hands off into a matching action.
Yield
Deposit USDC into the best APY across a vetted set of lending venues you signed. A scout picks the venue; a hijacked agent still can't supply anywhere you didn't approve.
Portfolio
Every active permission with its decoded on-chain caveat, and a gasless kill switch — revoke any grant, or the whole tree, without holding ETH.
Security that doesn't depend on the agent behaving.
Compromise an agent — prompt injection, a poisoned dependency, a breached server. It still can't step outside the permission you signed. You don't detect the cheating; you make it impossible by construction.
- Bounded, not trustedWrong token, wrong recipient, over budget, bad fill — all reverted by the enforcer on-chain, not in the UI.
- Revoke anytimeKill the root permission and every agent's rights die at once, atomically. Your kill switch is one tx away.
- A real receiptEvery settlement is on-chain and tx-linked — the x402 request bound to the payment that fulfilled it.

Make agents safe to pay — without a line of Solidity.
Conduit is a custom x402 facilitator plus a family of safety caveats on MetaMask's Delegation Framework. Integrate it and your agents inherit them all — bounded payments, swap allowlists, approvals, subscriptions. No enforcer to write or audit.
The best of the agentic stack, composed.
MetaMask Delegation Framework
Advanced Permissions (ERC-7715), redelegation (ERC-7710), and EIP-7702 account upgrades — the rails Conduit extends with a custom caveat family.
1Shot Permissionless Relayer
Settles redeemDelegations with gas paid in stablecoins and EIP-7702 bundled in. N payments share one transaction and one fee.
Venice AI
Permissionless intelligence — the coordinator reasons with Venice, and the paid Yield Scout reasons over your approved set with live market data.
Every claim is verifiable on-chain.
Pay an agent — and watch it fail to cheat.
Sign in, hand an agent team a bounded budget, and try to make a compromised one misbehave. It can't.