Platform

The parts, and how far along each one is.

What we have built, how it is checked, and where each part stops. Status as of October 2026.

Devnet preview. Test tokens only. No real money.

Watch an agent payRoadmap and status

  • 9payment statuses, one at a time per payment
  • 1,000+automated tests, last counted October 2026
  • 2rails, one ledger: wallet on devnet, card on a mock provider
  • 0payment tokens held by Payzilla

Set the rules

An agent follows rules. Try to break them.

An agent pays only within limits a person set, and a seller chooses when to release. Move the sliders and see what happens.

0.002 test USDC
0.05 test USDC
Who is being paid
5 test USDC

The agent's decision

Pays

    When the seller releases

    At Captured

    Sample rules. The agent's limits live in the demo agent today, and the release threshold is set per seller by us, with a default of 5 test USDC. Neither is self-service yet.

    What we have built

    The platform, layer by layer.

    Every part is tagged with its real maturity. Filter by status, and select a part to see what it does, how it is checked and where it stops.

    Built and tested: it runs on devnet and has tests. In development: being built now. Mock only: tested against a mock. Planned: intended, no dates.

    Where payments enter

    What it does. Answers HTTP 402 with a price, then verifies and settles before it serves.

    How it is checked. Tested end to end, including a replayed payment and a hostile run.

    Limit. Reference code, not a packaged SDK.

    What it does. Starts a card payment and hands the visitor to the provider’s hosted card fields.

    How it is checked. Tested end to end, including refunds and disputes.

    Limit. Mock provider only. No real card provider is connected.

    What it does. Tells your system about each payment event, with a timestamped signature and retries.

    How it is checked. Signature, retry and destination-safety tests.

    Limit. Endpoint registration and secret rotation are not available yet.

    What it does. A read-only view of payments, timelines and ledger entries.

    How it is checked. Tested, and it shows real devnet payments.

    Limit. A prototype. Routing, wallet and onboarding screens are previews.

    The rules

    What it does. A maximum price per call and per run, and an allow-list of recipients.

    How it is checked. Tested, including a tampered listing refused before anything is signed.

    Limit. Lives in the demo agent. A reusable mandate service is planned.

    What it does. Decides when a seller may serve: at Captured up to a threshold, at Final above it.

    How it is checked. Tested on both sides of the threshold.

    Limit. Set per seller by us. Not self-service yet.

    What it does. First-match rules decide which rail handles a payment.

    How it is checked. Unit and property tests.

    Limit. Two fixed rules today. An editor is in development.

    What it does. Decides who pays the network fee. A Payzilla-run account pays on devnet today.

    How it is checked. The resolver is tested.

    Limit. A per-seller choice is in development.

    The money path

    What it does. Checks the exact transaction layout, amount, recipient and memo before anything is signed.

    How it is checked. Property tests: the signer signs only when the payment is exactly right.

    Limit. Solana, exact scheme, only.

    What it does. Signs only validated payments. The network-fee key is held in AWS KMS in staging.

    How it is checked. Tested live on devnet with a KMS key.

    Limit. One shared fee-payer key. A key per seller is planned.

    What it does. Settles payments on devnet and follows each one to finality, including duplicates and faults.

    How it is checked. Tested, with fault injection and a reverted-payment path.

    Limit. Devnet and test tokens only.

    What it does. Authorizes, captures, refunds and handles disputes against a mock provider.

    How it is checked. Reviewed twice, with fixes tested.

    Limit. No real card provider has been chosen.

    The records

    What it does. Append-only, balanced entries for every rail.

    How it is checked. Database guards and tests. A reversal must mirror the original.

    Limit. No external audit yet.

    What it does. Nine statuses, one per payment at a time, including Reverted.

    How it is checked. State-machine and property tests.

    Limit. Names may still change before a hosted release.

    What it does. Row-level security keeps each merchant’s data apart.

    How it is checked. A 73-check role test on managed staging.

    Limit. Staging has one merchant, so cross-merchant checks use an unknown merchant.

    What it does. Flags a mismatch between our records and the network or the provider.

    How it is checked. Built for card settlement files and reverted payments.

    Limit. Most checks run on private staging. A few are still to finish.

    Select a part above to see its details.

    Roadmap and statusSecurity and trust

    For builders

    Put a price on an endpoint.

    Your server answers HTTP 402 with a price. The agent pays and retries, and you release the result when Payzilla confirms the payment.

    • Create an intent and return the challenge
    • Verify and settle before you serve
    • Check each webhook signature

    Read the API reference

    A reference for the devnet preview. There is no public base URL yet.

    HTTP/1.1 402 Payment Required
    PAYMENT-REQUIRED: <base64 of the challenge>
    
    {
      "x402Version": 2,
      "accepts": [{
        "scheme": "exact",
        "network": "solana devnet",
        "amount": "2000",
        "payTo": "<seller wallet>",
        "extra": { "memo": "<payment id>" }
      }]
    }
    Abridged. 2000 is 0.002 test USDC. Test tokens only.

    What we do not claim

    Built to be checked.

    We say what is not here yet. Status as of October 2026.

    1. AUDIT

      Internal reviews only

      Several rounds of adversarial review, each with fixes and tests. There is no external audit yet.

    2. MONEY

      Devnet and test tokens

      No real money and no real card provider. Real money comes only after the money path is reviewed.

    3. ROLE

      Software, not a bank

      Payzilla holds no payment tokens and claims no licences or certifications.

    Security and trustWhat we do not claim