Valiron Payment Interceptor
Add a trust gate in front of outgoing agent payments.
Workflow
- Extract counterparty identity from the payment request.
- Prefer
counterpartyAgentId. - Support wallet fallback with
getWalletProfile(wallet).
- Prefer
- Evaluate trust with Valiron.
- Fast path:
checkAgent(agentId). - Full path:
getAgentProfile(agentId)when you need reasons/signals, pricing, or audit details.
- Fast path:
- Apply deterministic decision policy from
references/decision-policy.md. - Enforce spend controls from
references/spend-controls.md. - If allowed, continue to payment initiation (x402 challenge creation or equivalent flow).
- If blocked/restricted, return explicit denial/degrade reason.
- Log outcome using
references/audit-events.md.
Decision model
Map route decisions to payment actions:
prod: allow payment under normal limits.prod_throttled: allow with reduced caps/rate limits.sandbox: allow only test/sandbox payment rail (or deny prod transfer).sandbox_only: deny outgoing payment.
Never authorize payment using free-form model output alone.
x402-specific sequencing
For x402-protected purchases or settlement-like flows:
- Trust-check counterparty identity.
- Evaluate route + spend policy.
- If denied, abort before creating payment commitment.
- If allowed, generate/send x402 payment payload.
- Record authorization decision + amount + result.
Outage and fallback
Use endpoint-class fallback from references/fallback-modes.md:
- High-risk payment actions:
fail-closed. - Low-risk/test actions: optional
fail-open-guardedwith strict caps.
Keep fallback mode explicit and versioned.
Use bundled resources
- Decision matrix:
references/decision-policy.md - Spend/risk controls:
references/spend-controls.md - Fallback guidance:
references/fallback-modes.md - Audit schema:
references/audit-events.md - Error handling:
references/error-handling.md - Interceptor template:
assets/payment-interceptor.ts - Policy validator:
scripts/validate-payment-policy.mjs