Raxol Payments + ACP Skill
Agentic commerce layer for Raxol agents. raxol_payments (v0.2) gives an agent a
wallet, a ledger with spend limits, HTTP 402 auto-pay, and the cross-chain settlement
protocols (Xochi/Riddler/MPP/Permit2/x402) plus stealth/privacy. raxol_earn (v0.2)
implements the Agent Commerce Protocol: a per-job state machine, service offerings, and
on-chain writes via ERC-4337 smart accounts or EOAs.
This is the Elixir client layer. It signs and calls; the contracts themselves are out
of scope (see solidity-auditor). Riddler is the payments protocol/module here
(Raxol.Payments.Protocols.Riddler), now delegating to Xochi.
What You Get
- Protocol map: Xochi (default cross-chain), MPP, Permit2, x402, Riddler
- Agent wallets (env key, 1Password, ERC-4337 SCA, EOA nonce server)
- Ledger spend limits, SpendGate authorization, mandates, checkpoint idempotency
- Privacy: stealth (ERC-5564/6538), Glass Cube tiers, ZKSAR trust scores, PXE bridge
- ACP job lifecycle state machine, Offering DSL, HookClient + provider adapters
- Test patterns with the Mock provider adapter (no real chain calls)
Two package split
| Concern | Package | Entry modules |
|---|---|---|
| Pay for a resource / cross-chain move | raxol_payments |
Protocols.Xochi, Ledger, SpendGate |
| Sell/deliver a job on-chain (ACP) | raxol_earn |
JobSession, Offering, HookClient |
See also
raxol-- core agent/TUI framework (agents, directives, MCP, workflow)raxol-symphony-- coding-agent orchestrator (uses ACP for paused-run resume)solidity-auditor-- the on-chain contracts these clients callethskills-- Ethereum tooling, RPC, standards (ERC-4337, ERC-5564, ERC-3009)noir-- ZK circuits behind ZKSAR / shielded settlement
Reading Guide
| Task | File |
|---|---|
| Move funds / pay a 402 (protocols) | payments/protocols.md |
| Stealth, privacy tiers, ZKSAR trust | payments/privacy.md |
| Wallets, ledger, spend gate, checkpoints | payments/wallets-ledger.md |
| Sell a service via ACP (job lifecycle) | acp/job-lifecycle.md |
| Test without real chain calls | testing.md |
Key Conventions
- Amounts are atomic units as strings (
"1000000"= 1 USDC), aggregated asDecimalin the ledger. Never pass floats. - Every spend goes through
SpendGate.authorize/3-> reserve -> sign ->release/release_by_intent. Reservations expire (TTL) and are swept. - Wallets implement
Raxol.Payments.Wallet(address/0,sign_message/1,sign_typed_data/3,sign_hash/1). Pick env/op/SCA/EOA per deployment. - Idempotency: derive a
Checkpointkey from canonical intent fields and check it before re-submitting an in-flight intent.
Common Pitfalls
- Floats for money -- use atomic-unit strings +
Decimal; floats lose precision. - Signing before gating -- authorize/reserve budget first, or a failed send leaks
the reservation. Always pair
authorizewithrelease/release_by_intent. - Re-submitting on retry -- without a
Checkpoint, a retry double-spends; derive the key from intent fields and short-circuit on a hit. - Real RPC in tests -- use
Raxol.Earn.ProviderAdapter.Mock; never a live bundler.