Spend7

Spend7 blog

Keeping agent payments inside the leash

Guides and analysis on agent payment fraud detection, x402 and AP2 spend limits, and keeping an autonomous agent's spending inside what you actually authorised.

Academy8News3Reviews4
A hand holding a card payment terminal, illustrating agent payment fraud detection at the moment of authorisation
Academy8 min read

Agent payment fraud detection: what actually goes wrong

Agent payment fraud detection needs different signals to card fraud. Here are the failure modes that matter, and how to score them before money moves.

Read the article →
Network switch with patch cables, representing the untrusted inputs that carry a prompt injection attack into an agent
News

When a prompt injection attack ends in a payment

A prompt injection attack used to leak data. Now agents hold payment credentials. Here is how the attack reaches your money, and where to stop it.

7 min read
A robotic arm moving at speed on a production line, the tempo at which ai agent spending can run away
News

AI agent spending goes wrong in four minutes, not four weeks

AI agent spending rarely fails slowly. A minute-by-minute anatomy of a runaway, the four points it could have been stopped, and what to set.

6 min read
Bundled fibre optic cables, representing the machine-speed traffic that x402 spend limits have to bound
Academy

How to set x402 spend limits your agent cannot argue with

A step-by-step guide to x402 spend limits: per-agent caps, rolling windows, quote checks and the deny path. Wire it in about ten minutes.

6 min read
Rack-mounted network hardware, the infrastructure layer where an HTTP 402 payment exchange takes place
Academy

HTTP 402 Payment Required: reserved for 25 years, now in use

HTTP 402 sat unused since 1997. Agents and x402 gave it a job. What the status code does, how the flow works, and where it goes wrong.

6 min read
Data centre racks in low light, the kind of infrastructure a payment MCP server runs against
Academy

How to add a payment MCP server without handing over the keys

A payment MCP server lets an agent check spend limits natively. Here's how to wire one in, and why tool descriptions are untrusted input.

6 min read
Parallel rows of network cabling, illustrating the competing agent commerce protocol options available to builders
Reviews

Which agent commerce protocol should you build on?

An agent commerce protocol comparison: x402, AP2 and ACP side by side. What each one solves, what it ignores, and how to pick without regretting it.

6 min read
A customer tapping a card on a payment terminal, the human authorisation step AP2 payment safety encodes as a mandate
Academy

AP2 payment safety starts with checking the mandate

AP2 payment safety depends on mandates you actually verify. What intent and cart mandates prove, what they don't, and the five checks that matter.

6 min read
Rows of illuminated network equipment, the always-on infrastructure autonomous agent payment monitoring runs against
Academy

Autonomous agent payment monitoring: what to watch, and when

Autonomous agent payment monitoring done properly: the six signals worth alerting on, why post-settlement logs are too late, and how to tune.

6 min read
A card payment being completed at a counter, the transaction a liability backstop for AI agents would have to cover
News

Why Spend7 does not offer a liability backstop for AI agents

A liability backstop for AI agents sounds reassuring. Here's why we don't sell one, what we ship instead, and how to judge anyone who does.

6 min read
Neatly patched network racks, the disciplined infrastructure that good ai agent security resembles
Academy

AI agent security: 12 checks before you give an agent a credential

An AI agent security checklist for agents that spend money. Twelve checks, ordered by what actually bounds the loss, with the reasoning for each.

6 min read
Dense network cabling converging on a switch, the fan-in shape that merchant risk scoring is built to detect
Reviews

Merchant risk scoring: the patterns one customer can never see

Merchant risk scoring works better across accounts than within one. The four cross-merchant patterns worth detecting, and why your own logs miss them.

6 min read
Industrial robots working unattended on an assembly line, the autonomy that makes ai agent governance necessary
Academy

AI agent governance stops being theoretical when agents can pay

AI agent governance needs teeth once agents hold payment credentials. Mandates, spend authority, evidence and the four questions auditors ask.

6 min read
Server racks bathed in blue light, the compute behind modern ai fraud detection systems
Reviews

AI fraud detection has an inversion problem

AI fraud detection was built to score human buyers. When the buyer is an agent, the training data inverts. Why rules beat models in this niche.

6 min read
A payment terminal on a shop counter, the traditional setting payment fraud prevention was designed around
Reviews

Payment fraud prevention for agents: three approaches compared

Payment fraud prevention for agent buyers: extend your card vendor, build in-house, or use an agent-native layer. Honest trade-offs for each.

6 min read

Put a leash on it

Every article here describes something the API actually does. Score a payment intent in the browser on the home page, or take a key and wire the check into your agent in about ten minutes.