Every endpoint is agent-callable with scoped auth. Limits and policy run server-side, so a prompt injection can't override them. MCP ships first-class, not as an afterthought.
Every identity ships with a scoped Model Context Protocol server at mcp://agent/{slug}. The agent discovers its own tools: wallet, card, inbox, ledger. Every invocation runs through the same policy engine.
Node, Deno, Bun, edge. Full typings for every endpoint and webhook.
3.9+. Sync + async. Works directly with LangChain, LlamaIndex, CrewAI.
Zero dependencies. Built for servers provisioning fleets of agents.
Identity minted, all 8 components.
Any rail, tagged with agent id.
Live with MCC + merchant.
Cap hit, geo blocked — principal notified.
Inbound mail, with parsed attachments.
Old key expired, new key scoped identically.