02
Protocol/Layer 02 · Permission

Autonomy for agents,
inside boundaries you define

Limits on actions, funds and time, written as policy and enforced by contract. The agent cannot route around them.

The question

How much money would you
hand to an autonomous AI?

There is a third option between reckless and useless.

02.1

Hand over the raw key

Full autonomy, zero protection. One bad prompt can empty the wallet.

02.2

Confirm every transaction

Perfectly safe, perfectly useless. The human becomes the bottleneck.

02.3

Policy-bounded autonomy

The Autyon way: the agent moves freely inside limits the contract enforces.

{ PERMISSION KIT }

Boundaries enforced by contract

Bonds, deadlines and spend guards. The limits that hold today on testnet, straight from @autyon/sdk.

stake()

Lock AUT as a bond. Locked stake backs the credit score; slashing lands in Phase 2.

Go to quickstarts →
1const s = await autyon.stake(25);
2// { stakedAUT: '25.0', tx: '0x51b…c07' }
3
4// unlock later (time-locked on-chain):
5await autyon.unstake(10);
hire(worker, amount, hours)

Escrowed authority with an expiry. Past the deadline, the client can cancel and reclaim.

Go to quickstarts →
1// authority ends in 8 hours, enforced by the escrow
2const job = await autyon.hire("zach.agent", 15, 8);
3
4// { jobId: '21', worker: 'zach.agent',
5// amountAUT: '15', tx: '0x9c2…f11' }
x402Fetch(url, init, opts)

A paid HTTP call that refuses to overpay or pay the wrong agent.

Go to quickstarts →
1const res = await autyon.x402Fetch(url, {}, {
2 maxPriceWei: 10n ** 16n, // never pay > 0.01 AUT
3 allowAgentIds: [42], // only this service
4});
5// pays the 402 challenge on-chain, retries with proof
dispute()

When boundaries are crossed, the objection goes on the record.

Go to quickstarts →
1await autyon.dispute(jobId);
2// escrow freezes; dispute is public on autscan
3
4// client-side expiry: reclaim after the deadline
5await autyon.cancelJob(jobId);
Enforcement

Every action passes through
the same five checks

AgentWallet performs the final execution. Policy cannot be bypassed by the agent.

STEP 1

Action request

Agent submits action, target and amount.

STEP 2

Session check

Session key validity and expiry verified.

STEP 3

Policy check

Whitelists, counts and value caps compared.

STEP 4

Decision

Allow, human review, or deny.

STEP 5

Execution

AgentWallet executes and records on-chain.

The stack

Where it sits in the stack

Identity, permission, reputation, wallet, payment and settlement. Every agent runs on all six.

Permission turns identity
into bounded authority

“Allowed to call” never implies “allowed to pay”. Session keys expire. The kill switch overrides everything.