Skip to main content

Terms of Service

Last updated: March 1, 2026 · Effective: April 1, 2026

1. Agreement to Terms

By creating an account or using PayClaw (“the Service”), you agree to these Terms of Service. If you do not agree, do not use the Service. The Service is operated by PayClaw LLC (“PayClaw,” “we,” “us”).

By creating an account, you consent to receive all disclosures, notices, and communications from PayClaw electronically, including via email and your account dashboard. You may withdraw this consent at any time by contacting us, but doing so may limit your ability to use the Service. This consent applies to all communications that we are required or permitted to provide in writing under applicable law, including the Electronic Fund Transfer Act (for Spend users).

2. Description of Service

PayClaw is a technology platform for AI agent identity and payment. The Service includes two products:

Badge — Agent Identity Verification

Badge verifies your AI agent's identity to merchants before it shops. When your agent presents itself to a merchant, Badge provides a cryptographic verification token that confirms the agent is acting on behalf of an authorized user, without revealing your personal identity. Badge is free and involves no financial transactions. Badge includes:

  • API key generation with consent-based disclosure
  • Cryptographic verification token issuance (HMAC-SHA256)
  • Agent identity disclosure to merchants
  • Trip outcome tracking within your consented scope
  • A dashboard showing your agent's trip history and outcomes

Spend — Agent Payment Cards

Spend issues single-use virtual Visa cards for agent purchases. Virtual cards are issued by our sponsor bank through Lithic, Inc., pursuant to a license from Visa. PayClaw is a technology partner and program manager — not the card issuer, a bank, or a money transmitter. Spend is currently available in sandbox mode (test transactions only). Spend includes:

  • A PayClaw wallet with a configurable balance (maximum $500)
  • Virtual card issuance for agent-initiated purchases
  • Intent-based authorization and post-purchase audit
  • A dashboard for managing your account, cards, and transactions

Both products are accessible via the PayClaw dashboard, API, and MCP server (Model Context Protocol) for agent integration.

3. Eligibility

Badge

  • You must be at least 13 years old (as required by Google and GitHub OAuth)
  • You must have a valid Google or GitHub account
  • You must provide an accurate email address

Spend (additional requirements)

  • You must be at least 18 years old
  • You must be a resident of the United States
  • You must provide accurate identity information for KYC verification (collected by Lithic, Inc.)
  • You must enable multi-factor authentication (MFA) on your account

4. Badge: Agent Identity Authorization

When you generate a Badge API key, you authorize your AI agent to present a verified identity disclosure to merchants on your behalf. This section describes how Badge works and what you are consenting to.

Consent and Disclosure

At the time of API key generation, you are shown a disclosure describing exactly what your agent will present to merchants and what data will be recorded. Generating the key after reviewing this disclosure constitutes your consent for the declared scope (currently: [BROWSE] — agent identity declarations and their outcomes).

Future scopes (such as search, cart, and checkout activity) may be offered in later versions. Each additional scope will require separate, explicit opt-in consent. You will never be enrolled in a new scope without your affirmative action.

Verification Tokens

Each time your agent requests identity verification, PayClaw generates a cryptographic verification token. This token is presented to the merchant along with the agent type, authorized scope, and a contact email. The token cannot be reversed to reveal your personal identity without PayClaw's server-side secret. Tokens expire after 24 hours.

What Merchants See

Merchants receive only: the verification token, the agent type, the authorized scope, and a contact email (agent_identity@payclaw.io). Merchants cannot derive your identity from the token alone. If a merchant contacts PayClaw to verify a token, we will confirm only whether the token is valid, expired, or revoked. We will not disclose your identity without your explicit consent.

Revoking Consent

You may revoke any API key at any time via the dashboard. Revoking a key immediately stops all future token generation and event recording for that key. Events already recorded under a valid token are retained per our data retention policy (see our Privacy Policy, Section 10).

What Badge Does NOT Track

Badge does not track your agent's browsing history, cart contents, price data, screenshots, page content, or any data outside the scope you consented to. No data is recorded without a valid verification token.

5. How Funding Works (Spend Only)

Important: Please read carefully.

When you add funds to your PayClaw account, two separate financial transactions occur:

  1. Your payment is processed by Stripe for the deposit amount plus a service fee (currently 1.5% of the deposit amount). For example, a $100 deposit results in a charge of $101.50 to your payment method.
  2. Your card balance is funded by our sponsor bank through Lithic, Inc. for the deposit amount ($100 in this example). The service fee is PayClaw's revenue and is not loaded onto your card balance.

PayClaw does not hold or custody your funds. Deposited funds are held by our sponsor bank through our card issuing partner Lithic, Inc. PayClaw is a technology platform that facilitates the funding process on behalf of the card issuer.

6. Account Security

You are responsible for:

  • Maintaining the security of your account credentials and MFA device (Spend users)
  • Safeguarding your API keys (treat them as passwords)
  • All activity that occurs under your account and API keys, subject to Section 9 (Unauthorized Transactions)
  • Immediately revoking compromised API keys via the dashboard
  • Notifying us immediately of any unauthorized access

7. Spend: Agent Purchase Authorization & Shared Security

When you provide a Spend-enabled API key to an AI agent (directly or via MCP configuration), you authorize that agent to:

  • Declare purchase intents on your behalf
  • Retrieve virtual card credentials for approved intents
  • Complete purchases at merchants using your funded card balance

Shared Security Responsibility. PayClaw and our users share responsibility for transaction security. PayClaw is responsible for providing secure infrastructure, intent-based authorization, and audit capabilities. You are responsible for configuring appropriate spending controls, safeguarding your API keys, and promptly reporting suspicious activity. Neither party bears sole responsibility for losses resulting from AI agent errors or compromises, and both parties will cooperate in good faith to investigate and resolve disputes.

Risk of AI Agent Errors

AI agents, including those powered by large language models, may be susceptible to adversarial manipulation (such as prompt injection) that could cause them to take unintended actions, including unauthorized purchases. While PayClaw provides intent-based authorization, merchant whitelists, and spending limits as risk-reduction tools, no safeguard is absolute. We strongly recommend:

  • Enabling merchant whitelist restrictions for all API keys
  • Setting per-intent spending limits below your total card balance
  • Regularly reviewing your transaction audit trail
  • Promptly revoking API keys if you suspect compromise

8. Spending Limits & Controls (Spend Only)

  • Maximum account balance: $500
  • Per-transaction limits enforced by our sponsor bank through Lithic, Inc.
  • Merchant whitelist controls (configurable by you)
  • Balance holds placed at time of intent approval, captured on purchase completion
  • Intent auto-audit flags transactions that deviate from declared intent by more than 20%

9. Unauthorized Transactions & Error Resolution (Spend Only)

Your Rights Under Federal Law

If you believe a transaction on your account is unauthorized or incorrect — including transactions resulting from AI agent compromise — contact us at support@payclaw.io as soon as possible.

  • Report within 2 business days of learning of the unauthorized transaction, and your liability is limited to $50.
  • Report after 2 business days but within 60 calendar days of your statement being sent, and your liability is limited to $500.
  • Report after 60 calendar days, and you may be liable for the full amount of unauthorized transactions that occurred after the 60-day period.

When you report an unauthorized transaction, we will investigate within 10 business days (20 business days for new accounts open less than 30 days). If we need more time, we may take up to 45 calendar days to complete our investigation, but we will provisionally credit your account within 10 business days while we investigate.

10. Fees

  • Badge: Free. No fees for identity verification.
  • Spend service fee: 1.5% of each account deposit (charged at time of deposit)
  • No per-transaction fees — PayClaw does not charge per purchase
  • No monthly subscription (current plan; subject to change with notice per Section 19)

Payment processing fees charged by Stripe are separate from PayClaw's service fee and are borne by PayClaw, not the user.

11. Transaction Disputes (Spend Only)

Unauthorized or incorrect transactions: If you believe a transaction is unauthorized or incorrect, report it under Section 9 above.

Merchant disputes: For disputes regarding the quality, delivery, or description of goods or services purchased by your agent, you may work directly with the merchant or contact us for assistance. PayClaw will cooperate with card network dispute processes as required by our sponsor bank and the applicable card network.

Abuse of the dispute process — including filing disputes for transactions you authorized or repeatedly filing frivolous disputes — may result in account suspension or termination.

12. Prohibited Uses

You may not use the Service to:

  • Purchase illegal goods or services
  • Engage in fraud, money laundering, or terrorist financing
  • Circumvent spending controls, authorization policies, or consent boundaries
  • Impersonate another user or present false identity information via Badge
  • Use verification tokens for purposes other than legitimate agent-merchant interactions
  • Resell or redistribute API access without authorization
  • Reverse-engineer the Service or attempt to extract source code
  • Overwhelm the Service with automated requests beyond normal agent usage
  • Use the Service if you are under economic sanctions or on a restricted persons list

13. Intellectual Property

The Service, including its software, design, documentation, APIs, and MCP server, is owned by PayClaw LLC and protected by intellectual property laws. “PayClaw,” “Badge,” “Spend,” “KYA,” and “Know Your Agent” are trademarks or service marks of PayClaw LLC.

You are granted a limited, non-exclusive, non-transferable license to use the Service in accordance with these Terms. You may not copy, modify, distribute, sell, or lease any part of the Service or its content, nor may you reverse-engineer or attempt to extract the source code, except where such restrictions are prohibited by law.

Your use of Badge verification tokens and the PayClaw API does not grant you any rights to PayClaw's trademarks, logos, or branding. Merchants and third parties may not use PayClaw's marks without written authorization.

14. Early Access Program

The Service is currently offered as an early access release. Features, pricing, and availability may change. Spend account balances are limited to $500 during the early access period. Early access status does not modify PayClaw's obligations under applicable law, including consumer financial protection statutes.

15. Service Availability

We strive for high availability but do not guarantee uninterrupted service. The Service is provided “as is” and “as available.” We may suspend or modify the Service with reasonable notice, except in emergencies (security incidents, compliance requirements).

Force Majeure. PayClaw is not liable for delays or failures in performance resulting from circumstances beyond our reasonable control, including but not limited to: outages of third-party service providers (including Lithic, Inc., Stripe, or hosting providers), natural disasters, government actions, or network or infrastructure failures.

16. Limitation of Liability

To the maximum extent permitted by applicable law, PayClaw's total aggregate liability for any claims arising from your use of the Service shall not exceed the greater of (a) the amount of funds in your PayClaw account at the time of the incident, or (b) the total service fees paid by you to PayClaw in the twelve (12) months preceding the incident, or (c) $100 (for Badge-only users who have not paid any fees).

This limitation does not apply to: (i) PayClaw's obligations under applicable consumer protection laws, including the Electronic Fund Transfer Act; (ii) claims arising from PayClaw's gross negligence or willful misconduct; or (iii) PayClaw's indemnification obligations, if any.

PayClaw is not liable for indirect, incidental, consequential, or punitive damages, except where prohibited by law.

17. Termination

You may close your account at any time. If you have a Spend balance, any remaining card balance will be returned to your original payment method, minus any pending transactions. All API keys will be revoked and all verification tokens will be invalidated upon account closure. We may suspend or terminate your account for violation of these Terms, with notice where practicable.

18. Dispute Resolution & Arbitration

Binding Arbitration. Any dispute arising from these Terms or your use of the Service shall be resolved by binding arbitration administered by JAMS under its Streamlined Arbitration Rules. Arbitration shall be conducted in English, by a single arbitrator, remotely (by videoconference) unless both parties agree to in-person proceedings. The arbitrator's award is final and enforceable in any court of competent jurisdiction.

Class Action Waiver. You agree to resolve disputes with PayClaw on an individual basis only. You waive any right to participate in a class action, class arbitration, or representative proceeding.

Small Claims Exception. Either party may bring an individual action in small claims court in Travis County, Texas (or your county of residence) if the claim qualifies.

30-Day Opt-Out. You may opt out of this arbitration agreement by sending written notice to legal@payclaw.io within 30 days of creating your account. If you opt out, disputes will be resolved under Section 20 (Governing Law).

19. Changes to Terms

We may update these Terms from time to time. Material changes will be communicated via email or dashboard notice at least 30 days before taking effect. For changes affecting fees, liability, or your rights under applicable consumer protection laws, we will provide at least 45 days' advance notice. Continued use after changes take effect constitutes acceptance.

20. Governing Law

These Terms are governed by the laws of the State of Texas, without regard to conflict of law principles. Where arbitration does not apply (see Section 18), any disputes will be resolved in the courts located in Travis County, Texas.

21. General Provisions

Severability. If any provision of these Terms is held unenforceable, the remaining provisions remain in full force and effect.

Entire Agreement. These Terms, together with our Privacy Policy and any applicable cardholder agreement provided by our sponsor bank (for Spend users), constitute the entire agreement between you and PayClaw regarding the Service.

Assignment. You may not assign or transfer your rights under these Terms. PayClaw may assign these Terms in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets, provided the assignee agrees to be bound by these Terms.

No Waiver. Our failure to enforce any provision of these Terms is not a waiver of our right to enforce it later.

22. Contact

Questions about these Terms: legal@payclaw.io

Report unauthorized transactions or errors: support@payclaw.io

Agent identity verification inquiries (merchants): agent_identity@payclaw.io