AUTHORITY GATEWAY · IN-PROCESS REFERENCE

A prompt can be ignored.
The protected handoff cannot self-approve.

The agent-facing surface never exposes the payment tool. It can only request a bounded authorization and present the resulting single-use capability to the gateway. Human confirmation remains mandatory.

SEPARATION OF AUTHORITY

The agent proposes.
The owner’s boundary decides.

01POLICY

Owner policy exists outside the agent request

02CAPABILITY

Only the gateway can mint the in-process handoff object

03BUDGET

Eligible requests reserve shared budget before handoff

04REPLAY

Every nonce and handoff capability is single use

EXECUTABLE REFERENCE VECTORS

Attack the boundary,
not the prompt.

AG01eligible request reaches only the protected handoffsingle_use_handoffPASS
AG02direct call without a capability is blockedinvalid_capabilityPASS
AG03a consumed capability cannot be replayedcapability_replayPASS
AG04agent-side policy mutation cannot raise the real limitper_request_limitPASS
AG05wrong agent cannot self-authorizeagent_mismatchPASS
AG06unapproved scope is blockedscope_deniedPASS
AG07blocked vendor is rejectedblocked_vendorPASS
AG08unknown vendor requires human reviewunverified_vendorPASS
AG09missing evidence requires human reviewmissing_evidencePASS
AG10reserved spend is included in the daily limitdaily_limitPASS
AG11authorization nonce cannot be reusednonce_replayPASS
AG12malformed request fails closedinvalid_requestPASS

WHAT THIS PROVES

A reference agent cannot reach the protected handoff without passing the gateway model.

WHAT IT DOES NOT PROVE

No production process isolation, persistent ledger, real identity, cryptographic mandate, wallet integration, security audit, customer demand or payment execution exists. Those remain external gates.

NEXT PROOF

Put the gateway in front of one real sandbox payment tool.

Open x402 pilotDownload evidence ↗
No payment execution · Human confirmation required · Zero production integrations