Your AI agents pay.You stay in control.
One account per agent: it pays, it gets paid and holds a balance.Caps, approved payees and human approval apply at signature — under your CFO’s control.
Pull the latest market prices and pay the service per call.
keyban.payx402 · api.exa.ai€0.02- IDENTITY
- Agent “market-watch”, mandated by Finance
- POLICY
- €0.02 under the €5.00 daily cap · payee approved
- RISK
- Score 12 / 100 · signed automatically
Paid €0.02x402 · USDC · settled in 1.4 s
Here are the latest quotes —
Connect your agents to one governance engine.
Each agent receives a signed passport, a scope and an MCP connection exposing only approved tools. Runtimes and frameworks stay in place.
- Your agent
- Keyban MCP
- Policy Engine
- Approved rail
- Custom GPT, Claude, Gemini, Cursor or business bot
- Native MCP and NPM / PIP SDKs
- Scopes, vendors and resolvable endpoint
- Suspension, credential rotation and audit

Policy checks. Risk scores. Two shares sign.
The agent submits an intent, nothing more: policy, score and keys live on Keyban servers, out of its reach. One share alone signs nothing, Keyban included.
Requests
The agent submits a payment intent. No key, no policy, no score: none of it is accessible to it.
Checked
Mandate, caps and approved payees, set by Finance. Outside policy, a transaction is unsignable.
Scored
Every transaction gets a score. Low risk clears automatically. High risk goes to a human.
Two shares
Keyban’s share is released only if policy and risk said yes. The client’s share never leaves their device.
Traceable
The payment settles on-chain and shows up immediately in the CFO dashboard.
Where agents already consume paid services.
APIs & data
Enrichment, scoring, translation, authorised scraping, models and datasets.
Paid media
Campaign budgets, approved platforms and approval above a threshold.
Procurement
Software purchases, service bookings and governed recurring spend.
Machine micropayments
Pay-per-use services and endpoints with real-time decisions.
One vault funds every agent. And no one can drain it.
Account and execution in one place, without anyone holding your funds.
Human multisignature
Sensitive moves require several signers.
Funds agents on demand
Isolated wallets, their own budget, revocable in one click.
One consolidated balance
Across rails and currencies, auto-rebalanced.
Fiat on/off-ramp via Stripe
Top up the vault from your bank account, cash out to it anytime.
Compliance becomes the accelerator.
Holding a client’s funds is regulated custody under MiCA. We do not hold them: the biggest friction to agent payments at scale is removed.
Funds stay yours
They never leave the client’s wallet. A lighter compliance path, no licence to wait for.
2-of-2 signature
Keyban holds one share and can never sign alone. The client’s share never leaves their device.
MiCA / DORA
EU-native by design. Procurement and the CISO pass instead of stalling.
One console for agents, wallets and treasury.
Finance defines the framework.
Technical teams connect agents.
Each team gets the view it needs.

Wallets, identities and AI-agent payments.
What is an Agent Wallet?+
An Agent Wallet is a dedicated payment account for an AI agent. It carries its own budget and rules: maximum amount, approved suppliers, approval thresholds and available payment methods.
Why not give an agent a corporate card?+
A shared card or key does not clearly isolate the spending, permissions and accountability of each agent. Keyban separates wallets and applies controls before every payment is signed.
How do you stop an agent from exceeding its budget?+
The Policy Engine verifies limits at infrastructure level, outside the agent's prompt. A non-compliant request is rejected or sent for human approval. The agent cannot change the rule that governs it.
Do we need to rewrite our agents?+
No. Existing agents connect through the MCP Server or SDKs and keep their runtime. Payment requests pass through Keyban before being routed to the appropriate rail.
Can the agent get paid too?+
Yes. An Agent Wallet is an account, not just a payment method: it pays, it gets paid and it holds a balance. Incoming payments feed the same balance Finance follows in the console.
Who holds the funds?+
You do. Funds stay in the client’s wallet and Keyban never holds them. Signing requires two shares: Keyban’s, released only if policy and the risk score allow it, and the client’s, which never leaves their device. One share alone signs nothing, Keyban included.
How do you measure an agent’s error rate?+
Every transaction gets a risk score and stays attached to its agent. The console aggregates those decisions per agent: you read an error rate instead of approving every payment or seeing nothing.
What is the Treasury Wallet for?+
It is the vault that funds every agent. It holds one consolidated balance across rails, tops up from your bank account through Stripe, and its sensitive moves go through a human multisignature.
What is an Agent Passport?+
It links the agent to your organisation, technical identity, scope and status. Signed by your brand, it lets third-party services verify who is acting and with which permissions.
Give your agents autonomy.
Two wallets free for three months on the Free Trial plan, with no commitment and no payment card. Long enough to connect a first agent and watch it pay under your rules.
