Overview

B
Bloom & Bean Coffee
Coffee shop · 2 locations
▾
Demo workspaces · pick a company size

Good morning

Live · no agent activity yet today

Agent payment requests

Today

Agents and budgets

Vaults

Vaults

Money is split into vaults with a purpose. An AI agent can only spend from the vault it is attached to, in the currencies that vault holds.

AI Agents

Every agent is a sub-account with its own key, vault, owner, monthly budget and single-payment cap. It never sees a card number or bank login. It asks; the policy answers.

Policies

Rules are checked top to bottom. The first rule that matches decides: allow, ask a person, or block. Anything no rule covers is blocked.

v1 · published

Payment rules

Approvals

Only what the policy could not decide on its own lands here. Each request carries the rule that stopped it and the agent's own reason.

0 waiting
Select a request.

Transactions

Every decision the policy made, with the rule that made it and the credential used. Exportable for your accountant.

Payees

Suppliers, platforms and contractors your agents may pay. A payee that is not on this list makes an agent's request stop and ask, every time.

Team & Roles

The people agents answer to. Roles say what a person may see and do; approval groups say how many of them a payment needs.

Mobile app

The phone app has one job: show you the payments that need you, and let you approve or decline. Nothing else lives here. Balances, rules and agents stay in the console.

What arrives on the phone

  • Only requests where you are named as an approver. Other people's requests never show up.
  • Each card carries the amount, the payee, the rule that stopped it, and the agent's own reason. Enough to decide in five seconds.
  • Approve issues the credential immediately. Decline tells the agent to stop and logs your name.
  • If you do not answer within the timeout set in the rule, the request is declined, never silently approved.

Deliberately missing

No balances, no transfers, no rule editing, no agent settings. A stolen phone can approve or decline what was already asked; it cannot move money on its own.

Sign-in

Face ID or fingerprint on every approval above the amount you choose. Push notifications carry no amounts until the phone is unlocked.

Developers

Any agent framework connects through our MCP server or plain REST. It never touches the money; it asks for a decision and, if allowed, receives a credential scoped to that one payment.

MCP tools your agent gets

pink.check_policy(intent)

Before doing work, the agent asks whether a payment like this would clear. Returns allow / would_ask / block plus the reason, so it can plan inside its limits.

pink.request_payment(payment)

The real call: payee, amount, currency, line items, purpose, evidence links. Returns a decision immediately, or a hold id while a person is asked.

pink.get_credential(hold_id)

Once allowed: a single-use virtual card locked to the payee and amount, or a bank transfer instruction already submitted. Expires in 15 minutes.

pink.report_receipt(payment_id, receipt)

The agent files the invoice or receipt. We reconcile it against the credential and update the agent's trust score.

Connect in one line