SpendPreflightdocs
SDKs / developer guide

JavaScript guard

Enforce a decision in the client that creates the payment authorization.

Operator-maintained documentation
Live features and staging previews are distinguished. Index coverage is not yet available.

Local policy first

The published package is spendpreflight 0.2.0, released through GitHub Actions with provenance. The guard provides atomic budgets, network-bound assets and strict recursion protection on Node 20+. Import guard from the package, configure your normal x402 client, then pass both to this factory. No key is embedded in the sample.

npm.mjs
// Pass guard imported from spendpreflight and your configured x402 client.
// This example is local-only: it makes no screening HTTP request.
export function installLocalGuard(client, guard) {
  return guard(client, {
    remote: false,
    rules: { maxPerPaymentUsd: 0.10, holdAboveUsd: 0.05, dailyCapUsd: 1,
      allowedNetworks: ["eip155:8453"], usdcOnly: true },
    onHold: () => false, // route to an explicit human/policy approval in your app
  });
}
Download tested source

Budget reservations

Version 0.2.0 reserves approved atomic amounts before signing, serializes concurrent decisions and retains reservations if signing fails or the payment is abandoned. The budget resets only as the UTC day advances. It is per guard/process, not a chain settlement ledger or a fleet-wide budget.

Optional remote checks

Enable remote screening explicitly. Trial uses plain fetch and never falls back to payment. Paid remote screening needs a separate locally guarded client with an exact payTo/network/asset policy and its own budget. Never reuse the merchant guard recursively. Only the selected offer is screened. Unknown/failed remote results hold by default; the legacy explicit onError:allow disables that protection.