Skip to content
Everruns Cloud is open in early access. Run agents without operating the platform.

Machine payments: wallets, spend policies and attempts.

CommandWhat it does
payments accounts createCreate a machine-payment wallet account.
payments accounts disableDisable a machine-payment wallet account.
payments accounts getGet a machine-payment wallet account.
payments accounts listList machine-payment wallet accounts.
payments accounts updateUpdate a machine-payment wallet account.
payments attempts listList machine-payment attempts.
payments policies createCreate a machine-payment spend policy.
payments policies disableDisable a machine-payment spend policy.
payments policies getGet a machine-payment spend policy.
payments policies listList machine-payment spend policies.
payments policies updateUpdate a machine-payment spend policy.

Create a machine-payment wallet account.

Terminal window
everruns payments accounts create [OPTIONS] --label <label> --owner-id <owner_id> --owner-type <owner_type> --rail <rail>
FlagDescription
--label <LABEL>Required. Human-readable label.
--metadata <METADATA>Free-form metadata attached to this account (caller-defined; opaque to the platform). Example…
--owner-id <OWNER_ID>Required. Prefixed identifier of the owning principal.
--owner-type <OWNER_TYPE>Required. Principal class that owns the account.
--private-key <PRIVATE_KEY>Private key material for the rail.
--public-address <PUBLIC_ADDRESS>Public address on the rail (chain address, account number, etc.).
--rail <RAIL>Required. Settlement rail this account operates on.

Example:

Terminal window
# Register a wallet an agent can pay from
everruns payments accounts create --owner-type organization --owner-id org_01h9 --rail mpp_tempo --label 'Research wallet' --public-address 0x742d35Cc6634C0532925a3b844Bc454e4438f44e --reason 'Fund paid API calls'

Disable a machine-payment wallet account.

Terminal window
everruns payments accounts disable [OPTIONS] --payment-account-id <payment_account_id>
FlagDescription
--payment-account-id <PAYMENT_ACCOUNT_ID>Required. Payment account’s prefixed public identifier.

Example:

Terminal window
# Stop all spending from a wallet
everruns payments accounts disable --payment-account-id payacct_01h9 --reason 'Wallet compromised'

Get a machine-payment wallet account.

Terminal window
everruns payments accounts get [OPTIONS] --payment-account-id <payment_account_id>
FlagDescription
--payment-account-id <PAYMENT_ACCOUNT_ID>Required. Payment account’s prefixed public identifier.

Example:

Terminal window
# Inspect a wallet's rail, owner and status
everruns payments accounts get --payment-account-id payacct_01h9

List machine-payment wallet accounts.

Terminal window
everruns payments accounts list [OPTIONS]
FlagDescription
--owner-id <OWNER_ID>Only accounts owned by this principal’s prefixed public identifier.
--owner-type <OWNER_TYPE>Only accounts owned by this kind of principal: user, virtual_user, or organization.

Example:

Terminal window
# List the wallets an organization owns
everruns payments accounts list --owner-type organization --owner-id org_01h9

Update a machine-payment wallet account.

Terminal window
everruns payments accounts update [OPTIONS] --payment-account-id <payment_account_id>
FlagDescription
--label <LABEL>New label.
--metadata <METADATA>Free-form metadata attached to this resource.
--payment-account-id <PAYMENT_ACCOUNT_ID>Required. Payment account’s prefixed public identifier.
--private-key <PRIVATE_KEY>New private key to rotate in.
--public-address <PUBLIC_ADDRESS>New public address on the rail.
--status <STATUS>Current lifecycle status.

Example:

Terminal window
# Rotate a wallet's label or deactivate it
everruns payments accounts update --payment-account-id payacct_01h9 --label 'Research wallet (prod)' --reason 'Mark the production wallet'

List machine-payment attempts.

Terminal window
everruns payments attempts list [OPTIONS] --limit <limit>
FlagDescription
--limit <LIMIT>Required. Maximum number of items returned in this page.
--session-id <SESSION_ID>Session’s prefixed public identifier.

Example:

Terminal window
# Audit what a session tried to pay for
everruns payments attempts list --session-id session_01h9 --limit 20

Create a machine-payment spend policy.

Terminal window
everruns payments policies create [OPTIONS] --payment-account-id <payment_account_id> --subject-id <subject_id> --subject-type <subject_type>
FlagDescription
--allowed-capabilities <ALLOWED_CAPABILITIES>Capability IDs this policy permits paid calls for. Repeatable.
--allowed-hosts <ALLOWED_HOSTS>HTTP host allowlist for paid outbound calls. Repeatable.
--max-amount-usd-per-day <MAX_AMOUNT_USD_PER_DAY>Maximum cumulative amount (USD) per UTC day.
--max-amount-usd-per-request <MAX_AMOUNT_USD_PER_REQUEST>Maximum amount (USD) any single paid request may settle for.
--max-amount-usd-per-turn <MAX_AMOUNT_USD_PER_TURN>Maximum cumulative amount (USD) per agent turn.
--metadata <METADATA>Free-form metadata attached to this policy. Example: `{“owner_team”: “ops”, “ticket”: “OPS-12…
--payment-account-id <PAYMENT_ACCOUNT_ID>Required. Payment account this policy authorizes spending from.
--rail-preference <RAIL_PREFERENCE>Preferred settlement rails in priority order; the authority picks the first available. Repeatable.
--require-approval-above-usd <REQUIRE_APPROVAL_ABOVE_USD>Threshold (USD) above which a request would require explicit human approval.
--subject-id <SUBJECT_ID>Required. Prefixed identifier of the bound subject.
--subject-type <SUBJECT_TYPE>Required. Class of subject this policy binds to.

Example:

Terminal window
# Limit what an agent may spend from a wallet
everruns payments policies create --payment-account-id payacct_01h9 --subject-type agent --subject-id agent_01h9 --allowed-hosts api.shippo.com --max-amount-usd-per-request 5 --reason 'Allow shipping quotes up to 5 USD'

Disable a machine-payment spend policy.

Terminal window
everruns payments policies disable [OPTIONS] --payment-policy-id <payment_policy_id>
FlagDescription
--payment-policy-id <PAYMENT_POLICY_ID>Required. Payment policy’s prefixed public identifier.

Example:

Terminal window
# Revoke an agent's permission to spend
everruns payments policies disable --payment-policy-id paypol_01h9 --reason 'Integration retired'

Get a machine-payment spend policy.

Terminal window
everruns payments policies get [OPTIONS] --payment-policy-id <payment_policy_id>
FlagDescription
--payment-policy-id <PAYMENT_POLICY_ID>Required. Payment policy’s prefixed public identifier.

Example:

Terminal window
# Inspect a spend policy's limits and allowlists
everruns payments policies get --payment-policy-id paypol_01h9

List machine-payment spend policies.

Terminal window
everruns payments policies list [OPTIONS]
FlagDescription
--payment-account-id <PAYMENT_ACCOUNT_ID>Only policies that authorize spending from this payment account.
--subject-id <SUBJECT_ID>Only policies bound to this subject’s prefixed public identifier.
--subject-type <SUBJECT_TYPE>Only policies bound to this kind of subject (user, virtual_user, agent, agent_channel…

Example:

Terminal window
# See which policies authorize spending from a wallet
everruns payments policies list --payment-account-id payacct_01h9

Update a machine-payment spend policy.

Terminal window
everruns payments policies update [OPTIONS] --payment-policy-id <payment_policy_id>
FlagDescription
--allowed-capabilities <ALLOWED_CAPABILITIES>Replacement capability allowlist. Repeatable.
--allowed-hosts <ALLOWED_HOSTS>Replacement host allowlist for paid outbound calls. Repeatable.
--max-amount-usd-per-day <MAX_AMOUNT_USD_PER_DAY>Replacement per-day cap in USD (advisory, not yet enforced).
--max-amount-usd-per-request <MAX_AMOUNT_USD_PER_REQUEST>Replacement per-request cap in USD.
--max-amount-usd-per-turn <MAX_AMOUNT_USD_PER_TURN>Replacement per-turn cap in USD (advisory, not yet enforced).
--metadata <METADATA>Free-form metadata attached to this resource.
--payment-policy-id <PAYMENT_POLICY_ID>Required. Payment policy’s prefixed public identifier.
--rail-preference <RAIL_PREFERENCE>Replacement rail preference, in priority order. Repeatable.
--require-approval-above-usd <REQUIRE_APPROVAL_ABOVE_USD>Replacement approval threshold in USD (advisory, not yet enforced).
--status <STATUS>Current lifecycle status.

Example:

Terminal window
# Tighten the per-request spend cap
everruns payments policies update --payment-policy-id paypol_01h9 --max-amount-usd-per-request 2 --reason 'Cost review'