Skip to content

docs: add bounded spending checklist for AI agents - #1986

Open
osr21 wants to merge 1 commit into
base:masterfrom
osr21:agent-spending-safety-checklist
Open

osr21 wants to merge 1 commit into
base:masterfrom
osr21:agent-spending-safety-checklist

Conversation

@osr21

@osr21 osr21 commented Sep 18, 2026

Copy link
Copy Markdown

Summary

Adds a focused safety checklist to the AI-agent resources page for builders giving agents transaction or token-spending authority.

Why

The existing Base Account Spend Permissions and Session Keys material explains the APIs. This adds the operational safeguards that are easy to miss when adapting those examples to autonomous agents:

  • Authentication is not authorization.
  • Permissions should bind token, recipient, amount, period, and expiry.
  • Wallet-substituted account and permission-hash values must be preserved.
  • Prepared call arrays can have one or two calls depending on first use.
  • Expiry, revocation, allowance, and repeat-use behavior need explicit tests.

The change is documentation-only and complements the open Session Keys work without changing the API guidance.

Validation

  • Markdown/MDX content only
  • Existing page and navigation path preserved
  • No new dependencies

@cb-heimdall

Copy link
Copy Markdown
Collaborator

🟡 Heimdall Review Status

Requirement Status More Info
Reviews 🟡 0/2
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 1
Sum 2

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants