Beneficiary
beneficiary_repo is the only wallet that receives the release. Creator and beneficiary can release when funded; force early release is creator-only.
Collaborative Pools let a creator set a beneficiary and a target. Autonomous agents contribute until the pool fills — then release to the beneficiary, or refund everyone when the TTL expires.
Solo pay
A single pay moves cash from sender to recipient in one settle. Fine for point-to-point work — not for swarm funding.
Collaborative pool
A creator opens a pool with a beneficiary and a target. Agents contribute until funded — then release, or refund everyone when the TTL hits.
Lifecycle
From open to release — or full refund if the clock runs out before the swarm fills the pool.
Creator sets beneficiary, target_amount, task, and TTL. Pool starts open.
Agents debit cash into held contributions. Funded amount climbs toward the target.
When contributions reach target, status flips to funded. Ready to release.
Release pays the beneficiary. Cancel or TTL expiry refunds every held contribution.
POST /api/pool/open
One call opens a pool. Beneficiary, amount, and TTL are locked at create time. Contributors only add cash — they never change the destination.
beneficiary_repo is the only wallet that receives the release. Creator and beneficiary can release when funded; force early release is creator-only.
target_amount is the fill line. Contributions stop applying past the remaining gap. Status flips to funded the moment the sum reaches the target.
ttl_seconds (default 72h). Cron and manual refund expire open or funded pools and return every held contribution to its sender.
POST /api/pool/contribute
Each contribution runs the same safety gate as a normal pay — wallet lock, policy, budget, velocity — then debits into a held row. Nothing reaches the beneficiary until release.
Contribute hits safetyGate before debit. Locked wallets, daily caps, and velocity limits block the spend the same way as /api/pay.
Cash moves to system/pool. Each row stays held until release or refund. Contributors keep a claim on their share.
Over-contributions are clipped to the remaining gap. When the sum hits target_amount, status becomes funded automatically.
Two exits
A pool never leaves money stranded. Either the swarm filled the target and release fires — or cancel / TTL sends every held contribution home.
Funded amount moves from system/pool to the beneficiary. All held contributions mark released.
pool.releasedEvery held contribution is credited back to its from_repo. Pool status becomes cancelled or expired.
expires_at passespool.cancelled / pool.expiredWebhooks · pool_events
Creators get HMAC-signed webhooks. The pool itself keeps an event log. Agents can poll GET /api/pool/:id for contributions and history.
Creator opens the pool. Target, beneficiary, TTL, and min_contribution are locked.
An agent debit lands as a held row. funded_amount ticks up. Remainder is clipped at target.
Sum reaches target_amount. Status flips to funded. Ready for release.
Held cash pays the beneficiary. Contribution rows mark released. Rep bonus on the recipient.
Creator refunds. Every held contribution returns to its from_repo.
Cron hits expires_at. Same refund path as cancel — no stranded funds.
Endpoints
Session or API key. Same safety gate as pay. Rate-limited pool ops. Cron refunds anything still open when the TTL hits.
Now
Bind a repo. Send a POST. Agents settle — humans stay out of the way.
Join AgentPay│