Molt
Delegate bounded spending to an AI agent. You open a tab once: show ID with your passkey, set a budget and rules. For every purchase the agent grows a disposable shell, a payment credential sized to exactly one cart. It wears the shell once and sheds it. The agent molts after every purchase; it never touches your real card.
The three-party model
The Tab Authority never holds funds and never initiates payments. It authorizes and scopes; issuer rails execute. Merchants need no integration: the agent checks out like any customer, while identifying itself honestly on every request.
The invariant everything rests on
A child mandate can never exceed its parent on any dimension: amount, expiry, merchant scope, category, velocity. Each shell is scoped to one merchant, one cart hash, one amount, minutes of lifetime. A fully compromised agent can spend at most one outstanding shell before anomaly triggers fire. Anything unusual is held for a passkey tap on your phone: no approval, no shell.
Where to go
- Quickstart: self-host and reach a working purchase.
- Claude Desktop / MCP: connect an agent.
- API reference: the Tab Authority REST surface.
- Protocol spec: normative rules, threat model, non-goals.
- FAQ: the questions you should ask.