PolicyVault Documentation
Non-custodial delegated-spending vaults on Kaspa L1 — for people and AI agents.
PolicyVault lets a vault owner hand a spending key to an agent — an employee, a service, a bot, or an AI agent — without handing over control of the funds. The spending policy is enforced by Kaspa L1 consensus through a covenant: even an agent who bypasses this entire application and talks directly to a Kaspa node cannot exceed the owner's policy.
AI MAY REQUEST. POLICYVAULT DETERMINISTICALLY DECIDES. THE COVENANT ENFORCES. SIGNERS RETAIN CUSTODY.
New here? Start with PolicyVault in 5 Minutes for the complete mental model, or jump straight to Create your first vault.
Production status (honest labels)
| Surface | Status |
|---|---|
| Web / Agent platform | PRODUCTION — LIVE at https://app.policy-vault.org (you can also fully self-host) |
| Current production source | PUBLIC — https://github.com/zapsoblige-hash/PolicyVault, v1.0.0 |
| Covenant protocol v0.4.1 | Mainnet-operational (real mainnet lifecycle evidence; see Covenant enforcement) |
| Native mobile (iOS/Android) | DEVELOPMENT — NOT YET PRODUCTION-CAPABLE. Source and architecture are published, honestly labeled |
| External professional security audit | Has NOT occurred. Planned. Nothing in this documentation claims otherwise |
PolicyVault does not claim to be "FULL-SCALE POLICYVAULT — COMPLETE." The web/agent platform above is a production release; native mobile is a separate, later, honestly-labeled effort.
Find your way around
- Start Here — what PolicyVault is, what it is not, the 5-minute mental model, connecting a wallet, and your first vault and delegated spend.
- Core Concepts — owner, agent, external approver, vault, spending authority, limits, budgets, allowlists, approvals, pause/revoke, rotation, recovery, fee reserve.
- How-To Guides — task-oriented steps for the operations owners and agents actually perform.
- AI + Developers — the REST/Agent API, MCP server, JavaScript and Python SDKs, x402 and AP2 adapters, machine identities.
- Security — the non-custodial architecture, what the hosted server can and cannot do, covenant enforcement, and the honest external-audit status.
- Reference — states, error codes, supported networks, API versions, terminology.
- FAQ / Troubleshooting — answers to the problems people actually hit.
Product policy (permanent)
PolicyVault is free forever, including commercial use — no subscriptions, no transaction fees, no paid security, no usage caps. No patents on the protocol or its mechanisms. Apache-2.0 license. Voluntary support only, via KAS donations: kaspa:qyppakv5y7kmeynffldl9zshwgkjrl3fy9jjj8wf24v7f64v0gnuragz7ehdqhn (public receiving address; nothing in PolicyVault ever asks for or handles donation-wallet keys).