api.trlay.dev
The check at the toll, not the charge.
One pass for every agent that spends.
npx trlay@latest initIssue it once. Sellers check it at the gate. The record says what went through, and TollRelay never touches the money.
GET api.trlay.dev/agents.md for the three calls. Present X-Trlay-Identity on every request. Sellers verify at api.trlay.dev/verify. Your mandate is in the token; do not exceed it.
A pass is three calls
Register the organisation, create an identity, set what it may spend. Everything after that is a header on requests you already make.
Register the organisation
One call, one verification. The org is the thing sellers trust; identities hang off it.
Issue a pass
One per agent, under the organisation. Each gets a signing key. Name it what your team calls the agent.
Sign a mandate
Per day, per call, per seller. An approver signs it on a screen no agent can reach. Sellers verify it before they charge.
Attach the pass to every request
The SDK signs each request. If the seller charges, the pass and mandate ride with the payment.
Read the record
Every verified call lands in your record: seller, amount, rail, receipt. Export it for finance.
// 01 register the organisation
const client = new TollRelayClient({ credential: dashboardToken });
const org = await client.createOrg({
name: "Acme Research", handle: "acme", region: "eu",
email: "ops@acme.example"
});
// 02 issue a pass
const machine = await client.createMachine({
org: org.id, label: "procurement-agent"
});
// machine.private_key returned once
// 03 sign a mandate (an approver, on the dashboard or the CLI ceremony)
const mandate = await client.createMandate({
mid: machine.id, usd_per_day: "50", usd_per_call_max: "1",
sellers_allow: ["api.exa.ai", "api.firecrawl.dev"]
});
// 04 attach it to every request
const fetch = signedFetch({
key: { keyid: "did:web:trlay.dev:org:acme:agent:procurement", privateKey: machine.private_key },
mandate
});
await fetch("https://api.exa.ai/search", { ... });
// RFC 9421 signature on every request, the mandate checked as a courtesy
// 05 read the record
await client.listRecord({ month: "2026-09" });What it does
A signed pass on every request an agent makes, under a verified organisation. Sellers check it offline with a public key, or at the gate for the mandate that remains.
Spend limits per day, per call and per seller, carried by the identity. Changed in one place, enforced everywhere.
What each agent spent, where, on which rail, with the receipt. One export a month for finance.
Sellers and gateways call one endpoint and get an answer in under 50 ms. Welila's software layer is the first verifier, named in every gated 402 it serves.
Bring the wallet you already use. TollRelay never holds money: the mandate's limits are enforced by the wallet, not by TollRelay.
Who it's for
Pick a side. The component on the right is what that side sees.
Not for consumers, hobby agents, or anyone who wants a wallet. TollRelay does not hold money.
| Pass | Seller | Rail | Amount | Approved |
|---|---|---|---|---|
| procurement-agent | api.exa.ai | x402 | $0.020 | policy |
| procurement-agent | ledgerly.dev | MPP | $0.400 | an approver |
| research-agent | api.parallel.ai | x402 | $0.120 | policy |
| enrich-batch | api.firecrawl.dev | x402 | $0.050 | policy |
One pass per agent, one mandate each, one export for finance. No wallet balance shown, because TollRelay does not hold one.
// the seller's 402 declares the identity extension
extensions["tollrelay-identity"] { header: "X-Trlay-Identity", verify, jwks }
// the agent's retry: the pass alongside the payment
X-Trlay-Identity org acme · agent procurement · kyb verified · eu
payload.authorization $0.020 USDC · base
// one call to the gate, 38 ms
POST api.trlay.dev/trust/evaluate
→ { decision: "allow", evidence: […], receipt_id: "rcpt_8a1f…" }No account, no key. The seller learns which organisation paid and that it may, then serves.
The trade counter answers phones; the portal answers logins. This answers an agent, with the seller still deciding.
Approval gates the mandate, not the money. The organisation credential verifies against the trust list, offline, with no TollRelay account.
Where it's used
Five flows. Each one is a trace of a real call, start to receipt.
Money moves later, on the seller's terms. TollRelay recorded who asked, who allowed, who agreed.
Two seconds, no account. The delivered flag comes from the seller's layer, not a probe.
Over the cap, a person changes the mandate. Both on record.
The export is the product for finance. The dashboards are for everyone else.
Every verified call is one row, with its receipt.
Pricing
Organisations pay for passes and policy. Gates pay per check. No revenue share, no minimums.
Gates
Sellers and gateways that check passes.
| First 10,000 a month | free |
| To 1 million | $0.001 per check |
| To 10 million | $0.0005 |
| Beyond | $0.0002 |
Questions
- Does TollRelay move money?
- No. Identity, mandates and verification never hold, move or custody funds. A seller charges on its own rail; TollRelay verifies the identity and records the settlement reference the seller reports.
- How does a seller check a pass?
- Offline, against the public keys at https://api.trlay.dev/.well-known/jwks.json, with no call to TollRelay. Or online at POST https://api.trlay.dev/verify for revocation, reputation and the mandate remaining, answered in under 50 ms with a receipt id.
- What is in a mandate?
- A limit per day, a limit per call, and the sellers allowed or denied, signed by an approver on a screen no agent can reach. A seller verifies it before it charges, and the limits are pushed into the wallet the agent pays from.
- Where does an organisation's data live?
- In the region chosen at creation, the European Union or the United States, and it never leaves it. The control plane holds no personal data.
- What does it cost?
- Organisations pay for passes and policy, from a free tier with one pass. Gates pay per check after the first 10,000 a month. No revenue share, no minimums.