A spending box for your AI agent
Put USDC in a box that only you control. Your agent pays for things by itself, but only inside your rules: at most so much per payment, so many payments a day, only to the services you pick, until a date you choose. Stop it or take your money back at any time.
Create a box
Open a box by its address
Why a box and not a wallet
Giving an agent its own wallet means trusting it with everything in it. Limits written in an agent's software or on someone's server hold only as long as that software and that server do. Here the limits are checked by the contract on Arc on every payment, so a buggy agent, a leaked agent key or a bad prompt can never move more than your rules allow: at most the per-payment limit, at most so many times a day, only to your list, and never after the end date.
For agents and developers
The agent pays in one of two ways, both checked against the same rules and the same daily count:
Standard x402. The agent signs a normal EIP-3009 USDC authorization with the box as the payer. Arc's USDC asks the box whether to allow it (EIP-1271), and the box says yes only when the agent signed exactly that payment and it fits the rules. The seller's x402 checkout must check the payer with EIP-1271 and settle with the bytes-signature version of the transfer; ours does. A checkout that only checks plain wallet signatures turns a box payment away.
Direct. The agent calls pay(to, amount, slot, ref) and the box sends the USDC. Any seller that accepts a plain Arc USDC transfer can take it.
import { x402Fetch } from './sdk/mandate.mjs';
// pays a 402 on Arc from the box, inside the owner's rules
const res = await x402Fetch('https://apexfaucet.xyz/api/x402/arc-gold',
{ pub, account: agentKey, box: '0xYourBox', maxUsd: 0.01 });
Proof: our own agent uses one
Our demo agent spends from our own box (our money, at most 0.01 USDC per payment, 20 payments a day, only to our shop). On 7 October 2026 it bought gold data twice and was refused once, all on Arc mainnet:
- standard x402, signed by the agent, approved by the box: 0.003 USDC paid
- direct payment through the box: 0.003 USDC paid
- 0.010001 USDC, one millionth over its limit: refused by the box (Refused: over the per-payment limit)
Contracts on Arc mainnet: factory 0x69e444f7…6b26, box code 0xb380369c…ef9b. No admin, no fee, no upgrade. Code, tests and agent SDK: github.com/apexfaucet-hub/arc-mandate. Reviewed by its own tests (36, plus 18 planted faults) and an independent AI review; not audited by a security firm, so put in what you would give the agent anyway.
Each payment uses one of today's numbered slots, and a slot is a USDC authorization nonce. Arc's USDC records the slots spent by x402, the box records the ones spent by a direct payment, and each path checks both, so no slot is used twice. Days are UTC days: an authorization signed for today is refused after midnight UTC. A box holds USDC; any other token sent to it can be taken out by the owner.