Paybond Kit — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Paybond Kit (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
@paybond/kit<!-- mcp-name: io.github.nonameuserd/paybond -->
Paybond Kit for TypeScript is the npm package for tenant-bound Paybond integrations and delegated agent spend controls. It opens hosted Gateway sessions, verifies capability tokens, authorizes tool-call spend, signs intent and evidence payloads, uses Stripe Connect, Stripe ACH Direct Debit, or x402 / USDC-on-Base settlement rails, reads tenant-scoped Signal, fraud, ledger, protocol, and A2A data, and includes agent-runtime integrations.
Paybond is the SDK to use when you do not want to build your own delegated agent spend-governance middleware. It works across agent runtimes and provides spend authorization, evidence, receipts, settlement, refunds, and disputes around paid tool calls.
npm install @paybond/kit@paybond/kit is an ESM-only package for modern Node.js runtimes. Use import from a Node ESM / NodeNext project or a compatible bundler.
@paybond/kit is distributed as open-source software under the Apache 2.0 license. The published npm package includes the full license text in LICENSE.
paybond_sk_sandbox_... or paybond_sk_live_... service-account API keyCreate a sandbox key for local development:
npx -p @paybond/kit paybond loginpaybond login writes a sandbox PAYBOND_API_KEY to .env.local with file mode 0600, adds the default .env.local target to .gitignore when needed, and refuses to overwrite an existing key unless --force is passed. Custom env-file paths inside a git repo must already be ignored. Live production keys are created by tenant admins in Console and stored in deployment secret managers.
Use this first when you have a paid tool and want Paybond guardrails in the sandbox:
npx -p @paybond/kit paybond-init \
--preset paid-tool-guard \
--framework provider-agnostic \
--out paybond-paid-tool-guard.tsThe generated integration opens Paybond from the environment, loads .env.local when PAYBOND_API_KEY is not already present, bootstraps a sandbox guardrail intent, wraps your paid-tool handler, and submits sandbox evidence. It does not generate a paid-tool implementation. Free Developer is sandbox-only; live settlement rails start on paid production plans.
Every session is bound to the tenant realm echoed by gateway-authenticated service-account introspection.
Paybond session per tenant/service account.import { Paybond } from "@paybond/kit";
function requiredEnv(name: string): string {
const value = process.env[name];
if (!value) {
throw new Error(`missing ${name}`);
}
return value;
}
const paybond = await Paybond.open({
apiKey: requiredEnv("PAYBOND_API_KEY"),
expectedEnvironment: "sandbox",
});
try {
console.log("tenant realm:", paybond.harbor.tenantId);
} finally {
await paybond.aclose();
}Use Paybond Kit when an agent workflow needs delegated spend guardrails, tool-call budget checks, paid API or vendor action approval, evidence, release/refund logic, disputes, or audit-ready receipts.
import { Paybond } from "@paybond/kit";
const paybond = await Paybond.open({
apiKey: process.env.PAYBOND_API_KEY!,
expectedEnvironment: "sandbox",
});
const guardrail = await paybond.guardrails.bootstrapSandbox({
operation: "travel.book_hotel",
requestedSpendCents: 20_000,
currency: "usd",
});
const guard = paybond.spendGuard(guardrail.intent_id, guardrail.capability_token);
const guardedTool = guard.guardTool(
{
operation: guardrail.operation,
requestedSpendCents: guardrail.requested_spend_cents,
},
async (input) => bookHotel(input),
);
const result = await guardedTool({ hotelId: "hotel_123", maxPriceCents: 20_000 });
await paybond.guardrails.submitSandboxEvidence({
intentId: guardrail.intent_id,
payload: { result, sandbox: true },
});The paybond.harbor and paybond.guardrails clients are created by Paybond.open(...) and bound to the tenant resolved from the service-account API key. Production integrations read capability_token from paybond.intents.create(...), or from paybond.intents.fund(...) after an x402_usdc_base payment challenge is satisfied.
Scaffold a guardrail integration:
npx -p @paybond/kit paybond-init \
--preset paid-tool-guard \
--framework provider-agnostic \
--out paybond-paid-tool-guard.tsCore SDK:
Paybond.open(...) for API-key-only, tenant-derived hosted sessionsHarborClient for capability verification, intent creation, x402 funding, evidence submission, and ledger readspaybond.signal and paybond.fraud on Paybond sessions opened from one service-account API keyPaybondIntents helpers for principal-signed intent creation, x402 funding, and payee-signed evidence submissionPaybondSpendGuard, authorizeSpend, and guardTool for spend-named wrappers around capability verificationpaybondAgentToolSpendGuard, paybondRuntimeNeutralToolSpendGuard, paybondLangGraphToolSpendGuard, and paybondMCPToolSpendGuardpaybondRuntimeToolCallAdapter for agent SDKs and custom runtimes that expose a tool-call object plus an application-owned executorGateway and trust helpers:
GatewaySignalClient and ServiceAccountSignalSession for tenant-scoped Signal reads and signed portfolio artifactsGatewayFraudClient and ServiceAccountFraudSession for tenant-scoped fraud assessments, review queues, review events, metrics, and release-gate configpaybond login for sandbox device approval and local .env.local API-key setuppaybond-mcp-server for tenant-bound MCP tool exposure to any MCP-compatible hostpaybond-init for generating a Paybond guardrail integration helperAgent-facing surfaces are model-provider agnostic. Paybond verifies tool operations and tenant scope, not whether a tool call came from OpenAI, Anthropic, Gemini, a local model, or another runtime.
Advanced exports:
allowedTools values are your own tool or operation names, not a Paybond-owned catalog. Harbor enforces string matching against whatever names you chose when creating the intent.
settlementRail on intent creation is a principal-signed rail request. Stripe destinations and x402 receive addresses stay tenant-owned server-side config and are never supplied by the SDK caller.
The protocol-v2 surface is trust-first: signed mandates, recognition proofs, and receipts work across supported settlement adapters instead of treating any single rail as the product boundary.
Gateway-backed protocol helpers throw ProtocolHttpError with parsed errorCode and errorMessage fields when the gateway returns a JSON error envelope. Recognition-gated flows surface unregistered_key, revoked_key, mandate_agent_key_mismatch, and protocol_binding_mismatch explicitly.
paybond.spendGuard(...)For maintainers working from a source checkout, release verification lives in this package directory:
npm run verify:releaseThis runs tests, performs a clean build, inspects the packed tarball for stray files, and compiles a temporary consumer app against the packed package.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.