Proof and operations

Security

Where trust sits, what Tollex refuses to trust, and what has and has not been reviewed.

Keys

  • Agent keys stay in the agent’s signer. Tollex never receives them, and the MCP server never places them in model context.
  • The signer is wrapped so it only signs what the policy approved.
  • Relayer and receipt keys belong to the operator and can live in a KMS or remote signer.

Untrusted input

The following are treated as data and cannot change a wallet, network, asset, recipient, policy, approval, facilitator or spending ceiling:

  • intent text (need)
  • tool and provider descriptions
  • MCP tool metadata, A2A agent cards and OpenAPI descriptions
  • tool output

Economic limits come only from typed constraints and the signing policy, and eligibility is decided before any ranking. The test suite places injection attempts in each of these locations and checks that nothing economic changes.

Payment safety

  • Authorizations are reserved durably; one authorization executes once.
  • On USDG, a replayed authorization does not revert, so Tollex checks authorizationState on chain instead of relying on a failed simulation.
  • Unknown outcomes are reconciled, never assumed failed, and never retried with a new authorization.
  • Unlimited approvals are off unless a policy explicitly allows them.

Network access

Outbound calls to providers and discovered resources refuse private and internal addresses at validation and at connect time, re-validate every redirect, and limit time and response size. Provider credentials are references, resolved per call and redacted from every error.

Requests to external x402 merchants go through the same guard with stricter rules: https only (plain http only for hosts an operator names explicitly), no redirects at all, and a fixed header policy. Only content-type, accept and the payment header are sent. Cookies, authorization headers and Tollex headers never leave the service, and a payment authorization is only ever sent to the merchant’s verified address.

Review status

Tollex has completed an internal adversarial review: payments, reconciliation, policy, discovery, providers and recovery were attacked deliberately, and every finding was fixed with a permanent regression test. An independent external audit has not started yet. Until it is complete, payments run on testnet only.