Give an AI agent a wallet and three attacks immediately become possible:
• Redirect the payment
• Inflate the payment
• Replay the payment
Conduit eliminates all three onchain.
Conduit is a custom x402 facilitator that extends the @MetaMaskDev Delegation Framework with a custom caveat we built: X402ReceiptEnforcer and other enforcers
Instead of granting an agent broad spending authority, every payment authorization is cryptographically bound to a single x402 receipt:
→ token
→ recipient
→ amount
→ intent
When the agent attempts to settle payment through ERC-7710 on a MetaMask Smart Account, the delegation is validated inside "redeemDelegations()" before execution.
If the agent deviates from what was authorized:
→ Redirect payment → recipient mismatch → revert
→ Overspend payment → amount exceeds authorization → revert
→ Replay payment → intent already consumed (IdEnforcer) → revert
The result is a security layer for agentic commerce where permissions are not merely granted, they are constrained.
No app-layer validation.
No trusted facilitator assumptions.
No offchain enforcement.
The rules live inside the delegation itself and are enforced by the EVM.
An agent can only execute the exact payment it was authorized to make or nothing at all
Built for the @MetaMaskDev Cook-Off using @MetaMask Smart Accounts, ERC-7710 Delegation Framework, gas sponsorship through @1shotapi , and @AskVenice AI-powered agents.
#x402#aiagents#erc7710#buildinpublic#metamaskdev#osobotai#hackathon
Final lapse of the @MetaMaskDev × @1shotapi × @AskVenice hackathon- so I took a stroll and put ConduitPay through its paces from my phone.
Signed in with a passkey. Subscribed to DeFi Yield Weekly to know the best venue for my USDC — charged delivered instantly (webhook from @1shotapi, no polling).
Then I deposited: granted a USDC budget and authorized the exact yield venues my money is allowed to touch. The scout agent — powered by @AskVenice — picked the best one and handed off to a trade agent that can deposit only into the venues I authorized, nothing else.
The coordinator assigned the agents, and @MetaMaskDev's Delegation Framework @1shotapi's permissionless relayer settled them all in one tx, one fee — no matter how many agents.
One signature. N agents. My USDC, my rules, enforced on-chain.
This is ConduitPay.
A custom on-chain caveat that bounds exactly what your AI agent can do.
Conduit is a custom x402 facilitator with a family of safety enforcers on @MetaMaskDev Delegation Framework. You authorize from an embedded wallet; the rule lives on-chain.
👆 the SwapAllowlist enforcer.
Authorize a set — yield venues or tokens or whatever. Your coordinator agent discovers and hires the best, paying each through erc7710.
Any agent that strays — wrong token, wrong recipient, over budget — Conduit's enforcer reverts it on-chain. It literally can't.
Token-gated features without a separate auth system.
MetaMask Embedded Wallets v11 ships RBAC out of the box — gate by email, wallet address, domain, or token holdings.
Closed betas, loyalty programs, allowlists. All from the dashboard.
The most interesting part isn't that an agent can pay.
It's that users can safely delegate what an agent is allowed to pay for.
That's the problem we're tackling with Conduit using @MetaMaskDev Smart Accounts, EIP-7710, and x402. 🚀
Join us tomorrow for the May Community Call! 🦊
We'll be discussing:
- The latest MetaMask Embedded Wallet updates
- Upcoming ecosystem integrations
- How teams are building in web3
- Much more 👀
📅 Thursday, June 4
🕐 11AM ET
⤵️ RSVP
Join us tomorrow for the May Community Call! 🦊
We'll be discussing:
- The latest MetaMask Embedded Wallet updates
- Upcoming ecosystem integrations
- How teams are building in web3
- Much more 👀
📅 Thursday, June 4
🕐 11AM ET
⤵️ RSVP
Don't miss the live workshop with @AskVenice - starting in 30 minutes! 📢
You'll leave with a working app where AI prepares the transaction and explains the risks before the user approves. 🤖
Live on X.
Join our workshop with @AskVenice tomorrow to learn how to build a wallet-aware AI assistant that turns natural language into safe, reviewable onchain actions.
📅 Wednesday, June 3
⏰ 2:00 PM ET
Live on X.
14 days left.
Conduit started from the @MetaMaskDev Smart Accounts Kit workshops and evolved into a custom facilitator for agentic payments powered by EIP-7710, x402, and gas abstraction.
Excited to keep pushing the infrastructure for agent-to-agent commerce. 🦊🤖
14 days left to build the future of agentic payments 🤖
The @MetaMask Smart Accounts Kit Cook-Off has $16,000 in prizes across 7 tracks.
Submit your project here ↓
hackquest.io/hackathons/Meta…
14 days left to build the future of agentic payments 🤖
The @MetaMask Smart Accounts Kit Cook-Off has $16,000 in prizes across 7 tracks.
Submit your project here ↓
hackquest.io/hackathons/Meta…