
An agent that holds real money is an agent that can be robbed. HumanPay puts agentic payments on a leash — real USAT, moved only inside limits a human set once, only after proof-of-human, with every decision on a tamper-evident receipt.
Prompt injection drained ~$150K from an agent wallet in May. Over-permissioned agents amplified a $40M breach in January. The accountability layer doesn't exist yet — HumanPay builds it.

Fund your own Celo wallet, sign each tip in your own app, and settle peer-to-peer over gasless x402. The bot never consolidates funds and never sees a private key.

The same guarantees that stop a breach are what make the agent usable by real people.
Per-tx, daily, and lifetime caps in integer micro-units. A prompt-injected agent simply can't overspend.
The agent never holds the master seed. Every payment needs a signature from you.
Allows and blocks are hash-chained receipts. Recompute the whole audit trail in one call.
A payment is ALLOWED only if every one holds. Otherwise it's blocked — and blocked decisions are still receipted.
Self verifies a person is in control.
You sign each request; agent can't self-authorize.
Per-tx + daily + lifetime integer caps.
Funds only reach declared addresses.
Every settlement carries the on-chain tag.
A hash-chained ledger recomputable in one call.

Connect your wallet to launch your HumanPay lab — peer-to-peer, fee-abstracted, and provably bounded.
Launch the app →