api.trlay.dev

The check at the toll, not the charge.

One pass for every agent that spends.

npx trlay@latest init

Issue it once. Sellers check it at the gate. The record says what went through, and TollRelay never touches the money.

A pass is three calls

Register the organisation, create an identity, set what it may spend. Everything after that is a header on requests you already make.

  1. Register the organisation

    One call, one verification. The org is the thing sellers trust; identities hang off it.

  2. Issue a pass

    One per agent, under the organisation. Each gets a signing key. Name it what your team calls the agent.

  3. Sign a mandate

    Per day, per call, per seller. An approver signs it on a screen no agent can reach. Sellers verify it before they charge.

  4. Attach the pass to every request

    The SDK signs each request. If the seller charges, the pass and mandate ride with the payment.

  5. Read the record

    Every verified call lands in your record: seller, amount, rail, receipt. Export it for finance.

trlay.ts
// 01  register the organisation
const client = new TollRelayClient({ credential: dashboardToken });
const org = await client.createOrg({
  name: "Acme Research", handle: "acme", region: "eu",
  email: "ops@acme.example"
});

// 02  issue a pass
const machine = await client.createMachine({
  org: org.id, label: "procurement-agent"
});
// machine.private_key returned once

// 03  sign a mandate (an approver, on the dashboard or the CLI ceremony)
const mandate = await client.createMandate({
  mid: machine.id, usd_per_day: "50", usd_per_call_max: "1",
  sellers_allow: ["api.exa.ai", "api.firecrawl.dev"]
});

// 04  attach it to every request
const fetch = signedFetch({
  key: { keyid: "did:web:trlay.dev:org:acme:agent:procurement", privateKey: machine.private_key },
  mandate
});
await fetch("https://api.exa.ai/search", { ... });
// RFC 9421 signature on every request, the mandate checked as a courtesy

// 05  read the record
await client.listRecord({ month: "2026-09" });

What it does

Pass

A signed pass on every request an agent makes, under a verified organisation. Sellers check it offline with a public key, or at the gate for the mandate that remains.

Mandates

Spend limits per day, per call and per seller, carried by the identity. Changed in one place, enforced everywhere.

Record

What each agent spent, where, on which rail, with the receipt. One export a month for finance.

Gate

Sellers and gateways call one endpoint and get an answer in under 50 ms. Welila's software layer is the first verifier, named in every gated 402 it serves.

Wallets

Bring the wallet you already use. TollRelay never holds money: the mandate's limits are enforced by the wallet, not by TollRelay.

Who it's for

Pick a side. The component on the right is what that side sees.

Not for consumers, hobby agents, or anyone who wants a wallet. TollRelay does not hold money.

Record · acme · Septemberexport.csv
PassSellerRailAmountApproved
procurement-agentapi.exa.aix402$0.020policy
procurement-agentledgerly.devMPP$0.400an approver
research-agentapi.parallel.aix402$0.120policy
enrich-batchapi.firecrawl.devx402$0.050policy
1,914 calls · 9 sellers · $412.30within mandates

One pass per agent, one mandate each, one export for finance. No wallet balance shown, because TollRelay does not hold one.

Where it's used

Five flows. Each one is a trace of a real call, start to receipt.

00.000agentRFQ → the hire company's gate, pass + mandate attached
00.041gatetrust/evaluate · allow · kyb eu · 31 orders, 0 disputes
00.044sellerquote $3,640 queued for the hire desk
11:02humanhire desk approves · mandate receipt rcpt_eu_…
11:02recordrcpt_9c… · ledger row · ERP webhook · both sides agree

Money moves later, on the seller's terms. TollRelay recorded who asked, who allowed, who agreed.

Pricing

Organisations pay for passes and policy. Gates pay per check. No revenue share, no minimums.

Free

$0

forever

  • 1 pass
  • 1 mandate
  • Record
Start

Team

$49

a month

  • 10 passes
  • Mandates per seller
  • CSV export
Start

Business

$199

a month

  • 50 passes
  • Approvals, four-eyes, alerts
  • SSO
Start

Enterprise

Custom

from $999 a month

  • Unlimited passes
  • Evidence export, policy API
  • SLA
Talk to us

Gates
Sellers and gateways that check passes.

Verifier pricing per month
First 10,000 a monthfree
To 1 million$0.001 per check
To 10 million$0.0005
Beyond$0.0002

Questions

Does TollRelay move money?
No. Identity, mandates and verification never hold, move or custody funds. A seller charges on its own rail; TollRelay verifies the identity and records the settlement reference the seller reports.
How does a seller check a pass?
Offline, against the public keys at https://api.trlay.dev/.well-known/jwks.json, with no call to TollRelay. Or online at POST https://api.trlay.dev/verify for revocation, reputation and the mandate remaining, answered in under 50 ms with a receipt id.
What is in a mandate?
A limit per day, a limit per call, and the sellers allowed or denied, signed by an approver on a screen no agent can reach. A seller verifies it before it charges, and the limits are pushed into the wallet the agent pays from.
Where does an organisation's data live?
In the region chosen at creation, the European Union or the United States, and it never leaves it. The control plane holds no personal data.
What does it cost?
Organisations pay for passes and policy, from a free tier with one pass. Gates pay per check after the first 10,000 a month. No revenue share, no minimums.