Your AI agents pay.You stay in control.
A dataset to buy, a tool to call: the agent stops, with no account and no card.Keyban gives it one: it buys within the limits you set, under your CFO’s control.
Pull the latest market prices and pay the service per call.
keyban.payx402 · api.exa.ai€0.02- IDENTITY
- Agent “market-watch”, mandated by Finance
- POLICY
- €0.02 under the €5.00 daily cap · payee approved
- RISK
- Score 12 / 100 · signed automatically
Paid €0.02x402 · USDC · settled in 1.4 s
Here are the latest quotes —
Three minutes, and your agent can pay.
The Keyban MCP server plugs into your client — Claude, Cursor, n8n — and exposes approved tools only. Your runtime doesn’t change.
- Create the walletThe console provisions it and hands you its keys.
- Set its limitsCap per purchase, per day, approved payees.
- Install the serverOne command, or the ready-made bundle.
claude mcp add agent-wallet \
-e KEYBAN_API_KEY=… \
-e KEYBAN_APP_ID=… \
-e KEYBAN_INVITE_KEY=0x… \
-e KEYBAN_WALLET_ADDRESS=0x… \
-e KEYBAN_NETWORK=base \
-- npx -y @keyban/agent-wallet-mcpThe five values come from the console.
Rules checked. Two shares sign. Funds never held.
The agent only submits an intent: rules, score and keys stay out of its reach. One key share alone never signs, not even Keyban’s.
- AI AGENTIt asksMCP tool
keyban.pay€0.02x402 · api.exa.aiout of the agent’s reach
No key, no rule, no score is accessible to it.
- POLICY ENGINEKeyban checks
- CAP€0.02 under €5.00 / day
- PAYEEon your allowlist
- RISKscore 12 / 100
Outside the rules: refused, or sent to a human.
- SIGNATURETwo signaturesKeyban sharereleased by the checksClient sharenever leaves the device
Signed · settled in 1.4 s
Neither share signs alone. The client’s never leaves their device.
Funds stay yours
They never leave the client’s wallet. No licence to wait for.
2-of-2 signature
Keyban holds one share, never both. The client’s stays on their device.
MiCA / DORA
EU-native by design. Procurement and the CISO pass instead of stalling.
Where agents already consume paid services.
Six purchases at the prices x402 services charge today, paid per call.
Competitive research
A live web search at €0.01. The quarter’s funding rounds, dated and de-duplicated.
No provider account, no contract.Lead enrichment
400 conference contacts enriched at €0.01 each: industry, headcount, directors.
400 records paid for, not an annual seat.Page collection
120 pricing pages browser-rendered for €1.20.
Real volume, not an annual plan.Supplier check
A European company verified for €0.10: registry, VAT, sanctions.
Ten cents on demand, not a subscription.After a meeting
An hour of call transcribed for €0.03, objections isolated.
An hour of human work for three cents.When it goes over
A report at €0.55, cap at €0.25: nothing is spent, the request reaches you.
Never a charge discovered on the invoice.One vault funds every agent. And no one can drain it.
Account and execution in one place, without anyone holding your funds.
Human multisignature
Sensitive moves require several signers.
Funds agents on demand
Isolated wallets, their own budget, revocable in one click.
One consolidated balance
All rails, all currencies, rebalanced on its own.
Fiat on/off-ramp via Stripe
From your bank account, both ways.
One console for agents, wallets and treasury.
Finance defines the framework, technical teams connect the agents.
Each team sees what its role needs.

Wallets, identities and AI-agent payments.
What is an Agent Wallet?+
An Agent Wallet is a dedicated payment account for an AI agent. It carries its own budget and rules: maximum amount, approved suppliers, approval thresholds and available payment methods.
Why not give an agent a corporate card?+
A shared card or key does not clearly isolate the spending, permissions and accountability of each agent. Keyban separates wallets and applies controls before every payment is signed.
How do you stop an agent from exceeding its budget?+
The Policy Engine verifies limits at infrastructure level, outside the agent's prompt. A non-compliant request is rejected or sent for human approval. The agent cannot change the rule that governs it.
Do we need to rewrite our agents?+
No. Existing agents connect through the MCP Server or SDKs and keep their runtime. Payment requests pass through Keyban before being routed to the appropriate rail.
Can the agent get paid too?+
Yes. An Agent Wallet is an account, not just a payment method: it pays, it gets paid and it holds a balance. Incoming payments feed the same balance Finance follows in the console.
Who holds the funds?+
You do. Funds stay in the client’s wallet and Keyban never holds them. Signing requires two shares: Keyban’s, released only if policy and the risk score allow it, and the client’s, which never leaves their device. One share alone signs nothing, Keyban included.
How do you measure an agent’s error rate?+
Every transaction gets a risk score and stays attached to its agent. The console aggregates those decisions per agent: you read an error rate instead of approving every payment or seeing nothing.
What is the Treasury Wallet for?+
It is the vault that funds every agent. It holds one consolidated balance across rails, tops up from your bank account through Stripe, and its sensitive moves go through a human multisignature.
What is an Agent Passport?+
It links the agent to your organisation, technical identity, scope and status. Signed by your brand, it lets third-party services verify who is acting and with which permissions.
Give your agents autonomy.
Open a wallet, set its cap, paste the configuration the console hands you. Two wallets free for three months on the Free plan, with no commitment and no payment card.
