Reference / developer guide
Rules reference
Defaults are conservative starting points. Your caller owns the actual spend ledger.
Operator-maintained documentation
Live features and staging previews are distinguished. Index coverage is not yet available.
Live features and staging previews are distinguished. Index coverage is not yet available.
HTTP and MCP defaults
HTTP rules use snake_case; the JS SDK uses camelCase. New Index settings apply only to remote SDK mode. Cart totals are already USD; no network/asset constraint is invented for card checkout. Sanctions and spending blocks outrank holds. All returned reasons should remain visible to the approver.
| Rule | Default | Behavior |
|---|---|---|
| max_per_payment_usd | 1 | Block when the selected amount exceeds this USD cap. |
| hold_above_usd | 0.25 | Hold above this amount when the maximum has not already blocked it. |
| daily_cap_usd | 25 | Block when context.spent_today_usd plus the quote exceeds this. HTTP callers supply their own ledger. |
| allowed_networks | ["eip155:8453","base"] | Allowed network identifiers. Supply the exact challenge network; default accepts both Base forms. |
| usdc_only | true | Require a recognized USDC contract on that network. Other tokens are not assumed to equal USD. |
| strict_allowlist | false | HTTP preflight holds a merchant domain outside domain_allowlist. A nonempty payto_allowlist also requires that payee. The local SDK accepts either allowlist, so configure deliberately. |
| new_domain_days | 30 | Hold a known registration age below this many days unless the domain is allowlisted. Unknown age is reported, not invented. |
| screen_sanctions | true | Screen public OFAC wallet/name matches. Disabling this removes that protection. |
| max_price_multiple | 5 | hold above this multiple of the public category median; null disables. |
| require_live | true | hold after three usable failed unpaid probes. Missing observations are unknown. |
| hold_on_payto_change | true | hold for seven-day observed payee changes or a quote differing from the latest observation. |
| domain_allowlist | [] | Domain plus subdomains; no wildcard syntax. Treat allowlists as policy, not proof of ownership. |
| domain_blocklist | [] | Block listed domains and subdomains. |
| payto_allowlist | [] | Wallet identifiers. EVM addresses ignore letter case; non-EVM identifiers preserve case. |
| payto_blocklist | [] | Block listed payees. Block takes precedence over approval. |
Missing data
No domain age, missing Index evidence, or an unpriced asset is not positive evidence. Inspect data_as_of and index_evidence. The current gate does not automatically block every unknown/stale component; add stricter policy in your caller if required. A 7-day index is a record of unpaid probes, not proof an endpoint delivers after payment.