Your judgment. Before the action.

Let your AI work. Keep the decisions that matter.

A message to a client. A purchase. A change to a shared system. When an agent asks for permission, review the exact action and decide. Start with one approval; add budgets and policies as your team needs them.

Start freeTalk to us →

Need one human decision? Connect your AI tool and ask for approval →

Connected agents must ask Sanction and honor its answer. Enforcement applies to supported traffic routed through Sanction.

SANCTION
Agent Access Key
PXY · •••• · •••• · AGNT
Clearance ◆ 5 · Valid thru ∞
Cardholder
AUTONOMOUS AGENT
For the people responsible

Know what was allowed. And who said yes.

Keep approval requests, connected usage, and budget limits in one place. Give the people responsible for the work a decision record they can review.

For the CFO

The monthly number

Reported AI spend by team and provider, alongside budgets for connected agents and wallets.

For the CTO

Who can do what

Set policies for governed requests, review escalations, and export hash-chained decision evidence signed at export time.

For the CMO

My team's usage

Your department's agent spend and budget at a glance — no ticket to engineering to find out what your team's AI actually costs this month.

Authorize

Agent Wallet

Budgets and policy on spend and provisioning requests sent to Sanction. Auto-approve under threshold, escalate over it, deny what's blocked.

Protect

Credential Vault

Credentials use AES-256-GCM envelope encryption with per-wallet keys and tenant-scoped access. A short-lived mandate gates credential injection.

Govern

Clearance Levels

Clearance levels constrain governed requests. Tool governance is opt-in: empty tool lists allow tools unless another rule restricts them. Apply a policy pack or request explicit approval.

One request. A clear next step.

Proceed, ask a person, or stop.

Approved

Under the threshold, allowed category. The agent proceeds; the spend is logged.

Escalated

Needs your judgment. A one-off request or policy threshold asks a human to decide; approval creates a one-use grant.

Denied

Blocked category or over the hard cap. The caller must stop; a cooperative decision does not itself block an external payment.

The settlement rail is changing

Check authorization before settlement.

Sanction evaluates supported payment requirements before the caller signs or settles. Its decision records permission, not payment completion. The caller remains responsible for settlement and confirming the outcome.

Settlement-aware ledger — live
Send settlement: {rail, asset, network} with any /v1/authorize call — a closed vocabulary, x402 / USDC / Base today — and the rail is recorded in the decision evidence and the audit CSV export.
Every decision point, shipped
The MCP broker intercepts tool calls routed through it. The LLM gateway meters routed model usage. Escalations can pause for a human; approval mints a one-use grant. Stored decision evidence supports replay and hash-chained audit exports.
The x402 spend gate — live
Sanction evaluates supported x402 quotes before the caller signs. On the governed broker path, a refused payment challenge is withheld. This does not prevent a caller obtaining it through another path. Unpriceable quotes are denied rather than estimated.
Authorization and settlement are separate
The x402 authorization path evaluates the quote; the caller signs and settles. Separately, Sanction stores encrypted credentials. Connected provider keys stay server-side; other vaulted credentials require scoped authorization. An authorization decision is not evidence that a payment occurred.

sanction (v.) — to give official authorization. The older meaning. The one we mean.

For the builders

Three calls. Governed agent.

Register an agent, set a policy, authorize in real time. The agent carries a wallet over MCP; counterparties verify a mandate with no API key. No SDK lock-in.

The agent wallet →
# authorize.sh
curl -X POST /api/v1/authorize \
  -H "x-api-key: pxy_••••" \
  -d '{ "action": "purchase",
      "amount_usd": 12.50 }'

# → { "status": "approved" }
Security posture

Built like the company you're trusting it to be.

Documented security model
Published threat model covering controls, trust boundaries, and enforcement limits.
Encrypted + isolated
AES-256-GCM envelope encryption and tenant-scoped credential access.
Explicit limits
Hard policy denials override approval requests. Tool restrictions must be configured; empty tool lists allow tools.
Decision evidence
Recorded decisions can be exported as a hash-chained snapshot signed at export time.
Pricing

Start as an individual. Govern as a team.

Free for individuals. An agreement for your organization.

Individual
Free
No card. Personal, production, and client work.
Start free
Enterprise
Agreement
Talk with us about your organization’s governance, support, and deployment requirements.
Commercial license guide →Talk to us
Stay in the loop

Not ready to wire up an agent?

Get product updates and new integration announcements. One email when it matters.