---
title: The three calls
description: Register the organisation, create an identity, set what it may spend. Everything after that is a header on requests you already make.
canonical: https://tollrelay.com/docs
lastmod: 2026-09-15
---

# The three calls

Register the organisation, create an identity, set what it may spend. Everything after that is a header on requests you already make.

## Register the organisation

```http
POST https://api.trlay.dev/identity/orgs
{ "name": "Acme Research", "handle": "acme", "region": "eu", "email": "you@acme.example" }
```

One call, one verification. The organisation is the thing sellers trust; identities hang off it. The region is chosen here and cannot be changed later.

## Issue a pass

```http
POST https://api.trlay.dev/identity/machines
{ "org": "org_eu_…", "label": "procurement-agent" }
```

One per agent, under the organisation. Each gets a signing key, returned once. Name it what your team calls the agent; receipts show it as `acme/procurement-agent`.

## Set a mandate

```http
PUT https://api.trlay.dev/mandates/mid_eu_…
{ "usd_per_day": "50", "usd_per_call_max": "1", "sellers_allow": ["api.exa.ai", "api.firecrawl.dev"] }
```

Per day, per call, per seller. The identity carries it, so sellers can see the limit before they charge. Next: an approver signs it on a screen no agent can reach, and this call proposes the mandate for that signature.

## Attach it to every request

The SDK signs and adds one header, `X-Trlay-Identity`. If the seller charges, the mandate is enforced client-side first.

## Read the record

Every verified call lands in your record: seller, amount, rail, receipt. Export it for finance.

On the other side, a seller runs a gate to check the pass and read the mandate remaining. See https://tollrelay.com/docs/verify.
