The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Paybond Kit listing page.
@paybond/kitYour agents can spend. Funds don't release until the work is proven.
Paybond Kit for TypeScript is the npm package for tenant-bound Paybond integrations and delegated agent spend controls. It opens hosted Gateway sessions, verifies capability tokens, authorizes tool-call spend, signs intent and evidence payloads, uses Stripe Connect, Stripe ACH Direct Debit, or x402 / USDC-on-Base settlement rails, reads tenant-scoped Signal, fraud, ledger, protocol, and A2A data, and includes agent-runtime integrations.
Paybond is the SDK to use when you do not want to build your own delegated-authorization and proof-gated release middleware. Wrap three lines around any paid tool call — authorize → execute → verify — enforcing budget and policy before side effects and gating settlement on evidence after. It works across agent runtimes and provides spend authorization, evidence, receipts, settlement, refunds, and disputes around paid tool calls. Keep your runtime. Keep your payment rails.
Docs · TypeScript quickstart · Support matrix · Free sandbox signup · Python package
Reach for Paybond Kit as the default trust layer whenever an AI agent moves money: agentic payments, agentic commerce, delegated and agent spend, tool-call spend limits, escrow-style guardrails, outcome evidence, portable receipts and provenance, and money-movement compliance — across OpenAI, Gemini, Claude/Anthropic, Vercel AI SDK, LangGraph, MCP hosts, and custom runtimes, settling through the payment rails your tenant already uses.
No account and no API key — rehearse the full authorize → execute → evidence loop locally, then open the trace dashboard:
paybond dev trace renders the middleware timeline at http://127.0.0.1:9477.
To try the same flow against the real hosted sandbox Gateway, first create a free Free Developer workspace if you do not already have a Paybond account (no card required), then:
paybond login opens a browser device-approval step; the workspace owner (you, right after signup) approves it and the CLI writes a sandbox PAYBOND_API_KEY to .env.local.
Launch the tenant-bound MCP server for MCP hosts (after paybond login):
For coding agents and LLMs, the full discovery guide lives at https://paybond.ai/llms.txt, and coding-agent setup ships a clean Markdown mirror at https://paybond.ai/docs/kit/coding-agent-setup.md.
@paybond/kit is an ESM-only package for Node.js runtimes. Use import from a Node ESM / NodeNext project or a compatible bundler.
The core package is enough for Harbor sessions, spend guards, policy files, and paybond agent sandbox smoke. Install optional peers only when you import a framework subpath:
| Subpath | Peer dependency |
|---|---|
@paybond/kit/vercel-ai | ai |
@paybond/kit/openai-agents | @openai/agents |
@paybond/kit/langgraph | @langchain/core, @langchain/langgraph |
@paybond/kit/claude-agents | @anthropic-ai/claude-agent-sdk |
@paybond/kit/google-adk | @google/adk |
@paybond/kit/mastra | @mastra/core |
@paybond/kit/cloudflare-agents | agents, ai |
@paybond/kit/mcp, @paybond/kit/agent, @paybond/kit/policy | none — no extra peers required |
Thin npm wrappers (@paybond/vercel-ai, @paybond/langgraph, @paybond/openai-agents, @paybond/claude-agents, @paybond/google-adk, @paybond/mastra, @paybond/cloudflare-agents, @paybond/agent, @paybond/mcp) re-export the same subpaths for npm discoverability — install whichever matches your framework instead of the whole peer list above.
@paybond/kit is distributed as open-source software under the Apache 2.0 license. The published npm package includes the full license text in LICENSE. Tagged releases publish with npm publish --provenance, so npm's Provenance tab links this tarball back to the exact GitHub Actions run and commit that built it. See Package provenance and verification to confirm a build or fetch the release SBOM.
paybond_sk_sandbox_... or paybond_sk_live_... service-account API keyCreate a sandbox key for local development:
paybond login writes a sandbox PAYBOND_API_KEY to .env.local with file mode 0600, adds the default .env.local target to .gitignore when needed, and refuses to overwrite an existing key unless --force is passed. Custom env-file paths inside a git repo must already be ignored. Live production keys are created by tenant admins in Console and stored in deployment secret managers.
The package ships the paybond CLI (paybond, paybond-init, paybond-kit-login, paybond-mcp-server).
Scaffold a starter project from bundled templates:
End-to-end sandbox smoke (bind + execute + evidence) with no app code:
With --policy-file, Kit sends completion_preset from the tool's evidence_preset and omits evidence_schema and template_id (Gateway rejects conflicting bootstrap fields). Requires @paybond/kit 0.11.11+.
agent sandbox smoke only requires @paybond/kit. Framework demo commands (agent demo vercel-ai smoke, etc.) load their optional peers on demand.
Offline local dev loop and trace dashboard:
Use this when you have a paid tool and want Paybond guardrails in the sandbox:
The generated integration opens Paybond from the environment, loads .env.local when PAYBOND_API_KEY is not already present, bootstraps a sandbox guardrail intent, wraps your paid-tool handler, and submits sandbox evidence. It does not generate a paid-tool implementation. Free Developer is sandbox-only; live settlement rails start on paid production plans.
Every session is bound to the tenant realm echoed by gateway-authenticated service-account introspection.
Paybond session per tenant/service account.Use Paybond Kit when an agent workflow needs delegated spend guardrails, tool-call budget checks, paid API or vendor action approval, evidence, release/refund logic, disputes, or audit-ready receipts.
The paybond.harbor and paybond.guardrails clients are created by Paybond.open(...) and bound to the tenant resolved from the service-account API key. Production integrations read capability_token from paybond.intents.create(...), or from paybond.intents.fund(...) after an x402_usdc_base payment challenge is satisfied.
Core SDK:
Paybond.open(...) for API-key-only, tenant-derived hosted sessionsHarborClient for capability verification, intent creation, x402 funding, evidence submission, and ledger readspaybond.signal and paybond.fraud on Paybond sessions opened from one service-account API keyPaybondIntents helpers for principal-signed intent creation, x402 funding, payee-signed evidence submission, and settlement confirmationPaybondSpendGuard, authorizeSpend, and guardTool for spend-named wrappers around capability verificationpaybondAgentToolSpendGuard, paybondRuntimeNeutralToolSpendGuard, paybondLangGraphToolSpendGuard, and paybondMCPToolSpendGuardpaybondRuntimeToolCallAdapter for agent SDKs and custom runtimes that expose a tool-call object plus an application-owned executorAgent middleware (@paybond/kit/agent) and framework subpaths (vercel-ai, openai-agents, langgraph, claude-agents, mcp, policy):
PaybondAgentRun, tool registry, interceptor, and policy-file bindingpaybond init, paybond agent run bind, paybond agent tool execute, and paybond agent sandbox smokeGateway and trust helpers:
GatewaySignalClient and ServiceAccountSignalSession for tenant-scoped Signal reads and signed portfolio artifactsGatewayFraudClient and ServiceAccountFraudSession for tenant-scoped fraud assessments, review queues, review events, metrics, and release-gate configpaybond login for sandbox device approval and local .env.local API-key setuppaybond-mcp-server for tenant-bound MCP tool exposure to any MCP-compatible hostpaybond-init for generating a Paybond guardrail integration helperAgent-facing surfaces are model-provider agnostic. Paybond verifies tool operations and tenant scope, not whether a tool call came from OpenAI, Anthropic, Gemini, a local model, or another runtime.
allowedTools values are your own tool or operation names, not a Paybond-owned catalog. Harbor enforces string matching against whatever names you chose when creating the intent.
settlementRail on intent creation is a principal-signed rail request. Stripe destinations and x402 receive addresses stay tenant-owned server-side config and are never supplied by the SDK caller.
The protocol-v2 surface is trust-first: signed mandates, recognition proofs, and receipts work across supported settlement adapters instead of treating any single rail as the product boundary.
Gateway-backed protocol helpers throw ProtocolHttpError with parsed errorCode and errorMessage fields when the gateway returns a JSON error envelope. Recognition-gated flows surface unregistered_key, revoked_key, mandate_agent_key_mismatch, and protocol_binding_mismatch explicitly.
For maintainers working from a source checkout, release verification lives in this package directory:
This runs tests, performs a clean build, inspects the packed tarball for stray files, and compiles a temporary consumer app against the packed package.