agentsub Gateway API
agentsub account and merchant-access API. AgentID identifies agents; Clerk authenticates human owners. Registered merchants own their application delivery and payment terms.
Agents of one verified owner share eligible credit lots while retaining separate clearance, caps and spending history. 1 credit = $0.01 = 1,000,000 integer microcredits. JSON money amounts use exact decimal strings.
Free application access checks create no hold, debit or payment. Paid checks return a requirement, never an entitlement or receipt. Link payment directly to merchants is the primary paid-service integration; credits are optional when accepted by the merchant. Direct seller settlement is not currently enabled. Optional account-credit Checkout requires its own configuration and authoritative successful Stripe receipt.
Human configuration/payment controls reject agents. Merchant keys are hashed, scoped and revocable. OAuth uses PKCE S256 and exact resource audiences. Mutations document their idempotency requirements. Secret issuance replays omit plaintext. Historical grants and journal entries remain intact; retired provider connectors and key imports are unavailable.
Merchant vouchers are agent-, offer-, audience- and amount-bound. Capture records canonical ledger payables, not completed fiat payouts. Signed webhooks are delivered at least once and receivers deduplicate event IDs. Trading, cash-out, x402, inference offers and subscription billing are not available.
https://api.agentsub.devHealth
Discovery
- GETServed OpenAPI document
/v1/openapi.json - GETVoucher signing JWKS (ES256)
/.well-known/jwks.json - GETACS payment configuration
/.well-known/acs-configuration - GETIntegration status report
/v1/integrations
OAuth
- GETOAuth authorization server metadata
/.well-known/oauth-authorization-server - GETProtected resource metadata (API)
/.well-known/oauth-protected-resource - GETProtected resource metadata (MCP)
/.well-known/oauth-protected-resource/mcp - GETOAuth access-token signing JWKS
/oauth/jwks - POSTDynamic client registration (RFC 7591)
/oauth/register - GETAuthorization endpoint (302 to AgentID)
/oauth/authorize - GETAgentID authorization callback
/oauth/callback - POSTToken endpoint (authorization_code + PKCE)
/oauth/token - GETRead sanitized pending OAuth consent context
/oauth/request - POSTChoose AgentID login
/oauth/select - POSTExplicit human owner OAuth consent
/oauth/owner/consent - POSTRenew an AgentID social identity through the registered direct broker
/oauth/social/connect
Owner
- GETOwner dashboard overview
/v1/owner/overview - PATCHUpdate agent spending policy
/v1/owner/agents/{id}/caps - POSTFreeze or unfreeze an agent
/v1/owner/agents/{id}/freeze - POSTStart agent avatar upload
/v1/owner/agents/{id}/avatar/upload - POSTFinalize agent avatar upload
/v1/owner/agents/{id}/avatar/finalize - PATCHUpdate agent display profile
/v1/owner/agents/{id}/profile
Agent
- GETAuthenticated agent identity
/v1/me - GETAgent credit balance
/v1/balance - GETAgent ledger history
/v1/history - POSTRegister the authenticated agent
/v1/agents/register - GETOffer catalog
/v1/catalog - GETOffer detail
/v1/offers/{id} - POSTQuote an offer
/v1/quotes - POSTMint an ACS voucher (hold)
/v1/vouchers
Services
Payments
- GETPayment provider connection status
/v1/payments/status - POSTCreate a Link checkout session
/v1/payments/checkout - POSTStart Link connect (owner only)
/v1/payments/link/connect - GETLink OAuth callback (GET)
/v1/payments/link/callback - POSTLink OAuth callback (POST)
/v1/payments/link/callback - POSTRequest an agent top-up approval
/v1/payments/topups - GETPoll a top-up request
/v1/payments/topups/{id} - POSTStripe webhook receiver (inbound only)
/v1/payments/stripe/webhook
Merchant Registry
- GETList registered merchants
/v1/merchants - POSTRegister a merchant
/v1/merchants - GETMerchant detail
/v1/merchants/{id} - POSTVerify merchant domain via DNS TXT
/v1/merchants/{id}/verify-domain - POSTPublish a merchant offer
/v1/merchants/{id}/offers - PATCHUpdate a merchant offer
/v1/merchants/{id}/offers/{offerId} - DELETEDelete a merchant offer
/v1/merchants/{id}/offers/{offerId} - GETList merchant API keys (metadata only)
/v1/merchants/{id}/api-keys - POSTIssue a scoped merchant API key
/v1/merchants/{id}/api-keys - DELETERevoke a merchant API key
/v1/merchants/{id}/api-keys/{keyId} - GETActive verified merchant offers
/v1/merchants/catalog
Merchant Scoped
- GETFetch a redemption (hold) record
/v1/redemptions/{id} - POSTCapture a hold
/v1/redemptions/{id}/capture - POSTRelease a hold
/v1/redemptions/{id}/release - POSTVerify an ACS voucher offline-equivalent
/v1/vouchers/introspect
MCP
- POSTModel Context Protocol HTTP endpoint
/mcp - GETUnsupported stateless MCP method
/mcp - DELETEUnsupported stateless MCP method
/mcp
Merchant Webhooks
- GETRead webhook configuration
/v1/merchants/{id}/webhook - PUTConfigure verified-domain webhook; secret shown once
/v1/merchants/{id}/webhook - DELETEDisable webhook delivery
/v1/merchants/{id}/webhook - POSTRotate webhook HMAC secret; secret shown once
/v1/merchants/{id}/webhook/rotate - GETRead webhook delivery events and actual attempt receipts
/v1/merchants/{id}/webhook/events
