Custom x402 facilitator · ERC-7710 · MetaMask Delegation Framework

Pay AI agents you
don't have to trust.

Conduit binds every agent payment to a permission you sign — exact amount, recipient, intent — enforced on-chain. A fully compromised agent still can't overspend, redirect, or pay anyone you didn't approve.

Built onMetaMask·1Shot·Venice AI
Authorization
signed ✓
pay up to2.00 USDC
toyour approved agents
per request≤ the exact quote
proceeds toyour account
expiresin 24h · revocable

The agent physically can't overspend this cap, accept a worse fill, buy a token off your set, or redirect the proceeds — the enforcer rejects it on-chain.

rogue: redirect → blockedrogue: overspend → blocked

1 signature. N agents. 1 transaction.

How it works

Authorize once. The agents do the rest — bounded.

01

Sign one permission

From an embedded wallet or passkey, you sign a bounded permission on MetaMask's Delegation Framework — a set of agents or assets, a cap, an expiry.

02

The coordinator hires

A coordinator agent discovers the best agents on an ERC-8004 registry and pays each through erc7710 — every payment locked to one exact x402 request.

03

Settle in one tx

Conduit's facilitator settles it all through 1Shot's permissionless relayer — one transaction, one fee, gas paid in USDC. An on-chain receipt per payment.

Inside ConduitPay

Four things you can do — each bounded on-chain.

Pay

Hand an agent team a budget and let a coordinator hire + pay each one through erc7710 — every payment locked to one exact request. Or run a bounded swap into a token set you signed.

Subscriptions

Fixed-price, one-merchant, once-per-period charges with on-chain double-charge protection. Every charge delivers a live intelligence report — and hands off into a matching action.

Yield

Deposit USDC into the best APY across a vetted set of lending venues you signed. A scout picks the venue; a hijacked agent still can't supply anywhere you didn't approve.

Portfolio

Every active permission with its decoded on-chain caveat, and a gasless kill switch — revoke any grant, or the whole tree, without holding ETH.

The thesis

Security that doesn't depend on the agent behaving.

Compromise an agent — prompt injection, a poisoned dependency, a breached server. It still can't step outside the permission you signed. You don't detect the cheating; you make it impossible by construction.

  • Bounded, not trusted
    Wrong token, wrong recipient, over budget, bad fill — all reverted by the enforcer on-chain, not in the UI.
  • Revoke anytime
    Kill the root permission and every agent's rights die at once, atomically. Your kill switch is one tx away.
  • A real receipt
    Every settlement is on-chain and tx-linked — the x402 request bound to the payment that fulfilled it.
Conduit delegation chain
// no Solidity. inherit the caveat family.
const req = await fetch402("/services/yield-scout")
const pay = buildPayment({ grant, coordinator, req })
settle(pay) // → 1Shot relayer, gas in USDC
// bounded by SwapAllowlist · X402Receipt · ApproveBounds…
For developers

Make agents safe to pay — without a line of Solidity.

Conduit is a custom x402 facilitator plus a family of safety caveats on MetaMask's Delegation Framework. Integrate it and your agents inherit them all — bounded payments, swap allowlists, approvals, subscriptions. No enforcer to write or audit.

X402ReceiptX402SubscriptionSwapAllowlistYieldAllowlistSwapBoundsApproveBounds
Built on

The best of the agentic stack, composed.

MetaMask Delegation Framework

Advanced Permissions (ERC-7715), redelegation (ERC-7710), and EIP-7702 account upgrades — the rails Conduit extends with a custom caveat family.

1Shot Permissionless Relayer

Settles redeemDelegations with gas paid in stablecoins and EIP-7702 bundled in. N payments share one transaction and one fee.

Venice AI

Permissionless intelligence — the coordinator reasons with Venice, and the paid Yield Scout reasons over your approved set with live market data.

Proof

Every claim is verifiable on-chain.

6 enforcers deployed
Receipt · Subscription · SwapAllowlist · YieldAllowlist · SwapBounds · ApproveBounds
All-or-nothing
N payments settle in one redeemDelegations, or none do
Compromise-proof
Rogue redirect / overspend / off-list all revert on-chain

Pay an agent — and watch it fail to cheat.

Sign in, hand an agent team a bounded budget, and try to make a compromised one misbehave. It can't.