Molt

Delegate bounded spending to an AI agent. It never touches your real card: for every purchase it grows a disposable shell, wears it once, and sheds it.

Self-host in 10 minutes GitHubDocs Spec

One purchase, one shell

馃悮
Grown

A shell is a disposable payment credential sized to one cart: one store, one amount, minutes of lifetime. It only exists because your signed limits allow it.

馃洅
Worn once

The agent checks out with it, after the checkout total matched the mandate to the cent. One authorization is all a shell can carry.

馃崅
Shed

Used or not, the shell dies. The agent molts after every purchase. What remains is a dual-signed receipt you can verify offline.

How it works

You open a tab once: a passkey ceremony where your fingerprint signs exact limits, such as 400 total, 200 per purchase, one week, office supplies only. Every purchase derives a child mandate from that tab, and a child can never exceed its parent on any dimension. Anything unusual, like an unknown store, is held: you get an email, one tap with your passkey approves it, one tap denies it. No approval, no shell.

Worst case, a fully compromised agent gets one shell: one store, one capped amount, already minutes from death. That is the whole security model, and it is written down.

Merchants need no integration and see a customer that identifies itself honestly: signed requests, a truthful user agent, no stealth. Stores that block agents get a clean failure and you get the link instead.

What Molt deliberately does not do

These are design commitments, not roadmap gaps. The full list with reasoning is in the spec.

Hosted live mode

Today Molt is a test-mode beta: self-host it and everything works with play money. A hosted version with a real issuer relationship is waitlisted, pending exactly the compliance work the docs describe.