Give your agent a USDT budget. Not your wallet.
Agents request economic actions. Spenda checks budget, risk, approval and policy on-chain before a single dollar moves.
- 01
AI agent
Wants to pay a vendor
Holds zero funds
- 02
SpendIntent
Amount · target · expiry
Single-use request
- 03
Policy engine
Caps · allowlists · risk
Approve or block
- 04
USDT vault
Executes · emits receipt
You keep custody
The agent asks for a payment it cannot execute itself.
Hand an agent your wallet and one mistake can drain everything.
Prompt injection, a hallucinated action or a runaway loop: an unrestricted agent key exposes the entire balance, instantly and irreversibly.
Today: a raw agent wallet
- The agent holds the private key
- No spend cap, no expiry, no allowlist
- One prompt injection can drain the full balance
- Funds leave before a human can react
With Spenda: a policy vault
- The agent holds nothing and signs nothing
- Per-tx cap, daily cap and expiry enforced on-chain
- Blocked requests emit evidence and move zero funds
- Every decision becomes a public receipt
of the wallet balance is exposed the moment one raw agent key leaks
held by a Spenda agent. Caps, custody and every decision stay with the vault
Authorization fails closed at every layer.
The restricted account constrains what an agent can call. The vault independently decides whether value moves.
It cannot call around the vault
The account binds to one vault and one paymaster. It rejects direct owner execution, arbitrary targets, native value and every selector except the vault’s spend request.
Every payment is independently checked
The vault checks agent status, expiry, token and target allowlists, per-transaction cap, daily cap and action replay before transferring USDT. Blocked requests emit evidence and move nothing.
How Spenda works
Give your agent autonomy.
Keep control of your money.
Spenda gives AI agents programmable identities, budgets, and permissions to act on your behalf while your funds remain secured inside a policy-controlled vault.
Low risk · Within policy
Higher value / elevated risk
Policy violation · Nothing moved
Spenda Vault
The vault holds user funds and enforces the policy boundary before any token moves.
Custody boundary
The agent never gets your wallet.
Your private key stays in the user wallet. The agent has an address and a request path, not custody of your money.
User wallet
Private key
AI agent
Own address · $0
Spenda Vault
Policy-controlled execution
Recipient
Receipt on-chain
Technical layer
From identity to settlement.
Autonomous spending without autonomous custody.
Every transaction is evaluated, authorized, executed, and recorded on-chain. Agents get autonomy. Users keep custody. Spenda controls the boundary.
From economic intent to verifiable receipt.
Agent expresses intent
Purchase compute, renew a service, pay another agent or request an RWA transaction with a fixed amount and expiry.
Spenda decides
Independent budget, allowlists and deterministic risk produce approved, blocked or requires-approval outcomes.
Human signs when needed
High-risk requests bind the owner signature to one agent, token, recipient, amount, nonce and expiry. No blanket permission.
Vault executes and receipts
The restricted UserOperation reaches the vault. USDT moves only if on-chain policy passes, then chain events produce the receipt.
Built for USDT settlement on BOT Chain mainnet.
BOT funds gas and the paymaster. Official bridged USDT stays inside the policy vault. Restricted agents never custody either asset.
Deployment status
Deployed on mainnet · Aug 22, 2026
Spend asset
USDT · 6 decimals
0xaBabc7Ddc03e501d190C676BF3d92ef0e6e87a3C
Gas asset
BOT
Owner wallet + paymaster deposit
Mainnet network
Chain ID 677
rpc.botchain.ai
Policy outcomes you can inspect.
Real BOT Chain mainnet acceptance transactions show an approved restricted-account payment and a blocked policy request. Settlement is official bridged USDT; agents never custody it.
Max 0.50 USDT per tx · 1 per day · active on mainnet
0 unauthorized spends
0 unauthorized moves
Across every deployed agent since the restricted stack went live. Blocked requests moved nothing.
Agents get autonomy. You keep custody.
Inspect intents, agent budgets, approvals, risk decisions and chain-derived receipts from the live restricted deployment.