Authorize · Protect · Govern

Autonomy for your agents. Authority for your team.

Where your AI spend is going, who's cleared to spend it, and the calls big enough to need your sign-off — in one place, above whatever gateway your engineers run. Every decision on a signed record, made before the money moves.

Start freeTalk to us →
Agent wallet · MCP · REST · Any rail
SANCTION
Agent Access Key
PXY · •••• · •••• · AGNT
Clearance ◆ 5 · Valid thru ∞
Cardholder
AUTONOMOUS AGENT
The seat above the stack

Your gateway routes the calls. Sanction is where you answer for them.

LiteLLM, Bedrock, Vercel — let them route, cache, and log. Sanction sits above whatever you run: the one place the people accountable for the spend can see it, set the budget, and sign off on the calls that cross the line.

For the CFO

The monthly number

Where AI spend went this month — by team, by provider — and whether you're on budget. The one figure that rolls up across every agent, in every division.

For the CTO

Who can do what

Which agents are cleared for which actions, the line where a human takes over, and a signed record of every call. Set the policy once; it holds across providers.

For the CMO

My team's usage

Your department's agent spend and budget at a glance — no ticket to engineering to find out what your team's AI actually costs this month.

Authorize

Agent Wallet

Budgets and policy on every spend and provisioning action. Auto-approve under threshold, escalate over it, deny what's blocked.

Protect

Credential Vault

AES-256-GCM at rest under a rotating KMS-wrapped key, tenant-isolated at the database. A 15-minute mandate gates every injection; counterparties verify it without a Sanction key.

Govern

Clearance Levels

A 1–5 clearance system. Agents only ever touch what they're explicitly cleared for. Fail-closed by default.

The decision engine

Every call comes back one of three ways.

Approved

Under the threshold, allowed category. The agent proceeds; the spend is logged.

Escalated

Over your line. The request pauses and waits for a human — approval mints a one-use grant.

Denied

Blocked category or over the hard cap. It never reaches the merchant.

The settlement rail is changing

Sanction authorizes the spend; any rail settles it.

Agent payments are moving to stablecoin rails — USDC over x402. On card rails, authorization is one control point among several: disputes, chargebacks, and issuer reversals stand behind it. On stablecoin rails there are no chargebacks. Settlement is irreversible, and the pre-transaction decision is the only control point. That decision is what Sanction makes.

Settlement-aware ledger — live
Send settlement: {rail, asset, network} with any /v1/authorize call — a closed vocabulary, x402 / USDC / Base today — and the rail is recorded in the decision evidence and the audit CSV export.
Every decision point, shipped
The MCP broker intercepts tool calls before they run. The LLM gateway meters model spend per call. Escalations pause for a human; approval mints a one-use grant. All of it replayable, with hash-chained evidence exports.
The x402 spend gate — live
When an agent meets an x402 payment requirement, Sanction prices the quote and runs it through the same ladder as any purchase — before the wallet signs. Through the MCP broker this is interception: a refused challenge is withheld, and an agent that never receives the payment requirements cannot sign them. Quotes priced in USD-pegged stablecoins only; a rate we would have to guess is denied, never estimated.
Non-custodial, veto-only
Sanction never holds funds or keys, and can never initiate a transfer — it can only refuse one. The GENIUS Act made payment stablecoins a regulated instrument; the pending CLARITY Act (Senate vote scheduled September 2026) would codify that non-custodial, non-controlling software is not a money transmitter. Sanction is built deliberately to that shape — and every decision leaves auditable evidence that supports your compliance program.

sanction (v.) — to give official authorization. The older meaning. The one we mean.

For the builders

Three calls. Governed agent.

Register an agent, set a policy, authorize in real time. The agent carries a wallet over MCP; counterparties verify a mandate with no API key. No SDK lock-in.

The agent wallet →
# authorize.sh
curl -X POST /api/v1/authorize \
  -H "x-api-key: pxy_••••" \
  -d '{ "action": "purchase",
      "amount_usd": 12.50 }'

# → { "status": "approved" }
Security posture

Built like the company you're trusting it to be.

SOC 2 Type II
In flight — report available under NDA on completion.
Encrypted + isolated
AES-256-GCM at rest under a rotating key; row-level tenant isolation at the database.
Fail-closed
No policy match, no action. Denial is the default state.
Full audit trail
Every decision attributable, exportable, on the record.
Pricing

The meter is the decision.

Free for individuals. Metered for teams. An agreement for the enterprise.

Individual
Free
No card. Personal, production, and client work.
Start free
Pro · Early access
$20/mo
For teams. 5,000 decisions included, then $5 per 1,000.
Metered in decisions — the one unit of what Sanction does. Approvals, denials, escalations count once; replays never do.
Pay by card — or your agent pays via x402/USDC (pilot).
Join the Pro early access
Enterprise
Agreement
SSO, policy administration, audit export, SLA, deployment control.
Commercial license guide →Talk to us
Stay in the loop

Not ready to wire up an agent?

Get launch updates and early access as we ship — Pro early access included. One email when it matters — no spam.