# agentsub > Your agent’s way in. Manage service access, permissions and spending. ## Getting started - [Build with agentsub](https://agentsub.dev/docs): Agent identity, credit access, and human approval in one connected workflow. - [Start with agentsub](https://agentsub.dev/docs/quickstart): Sign in, authorize an agent and request a connected service within your permissions and spending limits. - [Use connected services](https://agentsub.dev/docs/use-flows): Connect an owner account, authorize an agent and use services within explicit permissions and spending limits. ## Owners - [Owner controls](https://agentsub.dev/docs/owners): Manage agent budgets, view receipts and approve runtime payment requests from the owner console. - [Identity and ownership](https://agentsub.dev/docs/identity): How Clerk owner sessions and AgentID agent identity establish separate authority in the gateway. ## Merchants - [Merchant integration](https://agentsub.dev/docs/merchants): Publish service offers, required permissions and accepted payment methods in the separate merchant portal. - [Price, deliver and capture](https://agentsub.dev/docs/merchant-integration): Build a service integration around explicit prices, supported payment methods and idempotent fulfillment. ## Developers - [Gateway API](https://agentsub.dev/docs/api): Read the actual HTTP contract, authentication boundaries, errors and integer amount conventions. - [TypeScript SDK](https://agentsub.dev/docs/sdk): Use the repository SDK to make authenticated gateway requests and build merchant payment challenges. - [MCP connections](https://agentsub.dev/docs/mcp): Choose the public documentation server or the authenticated transaction server for your task. - [Human and agent MCP OAuth](https://agentsub.dev/docs/oauth): Authorize remote MCP through verified human Clerk sessions or AgentID identities with explicit consent and resource-bound tokens. - [Agent CLI](https://agentsub.dev/docs/cli): Run the repository CLI with explicit credentials, structured output and stable keys for retries. ## Payments and credits - [Credit units and eligibility](https://agentsub.dev/docs/credits): Understand dollar face value, integer precision, scoped grants, expiry and held credit amounts. - [Credits and payments](https://agentsub.dev/docs/payments): Start with free credits, then purchase AgentSub service credits when needed. - [Agent Credit Standard](https://agentsub.dev/docs/spec): Identity, amount precision, spending authority, payment challenges and authoritative receipts in the reference protocol. ## Blume capabilities - [Platform capabilities](https://agentsub.dev/docs/capabilities): Every Blume feature, with an honest view of what is enabled and what requires configuration. - [Component gallery](https://agentsub.dev/docs/components): Built-in accessible Blume components and Markdown extensions in action. - [Authoring and configuration](https://agentsub.dev/docs/authoring): Configure navigation, content adapters, islands, themes, and the Blume lifecycle. - [Public documentation discovery](https://agentsub.dev/docs/discovery): Read the complete documentation through Markdown, JSON, skills, catalogs and the public Blume MCP server. ## Reference - [AgentSub Gateway API](https://agentsub.dev/reference): Reviewed live AgentSub gateway contract. Blocked fixture, synthetic-agent and legacy execution routes are omitted. This document is imported directly by GET… - [AgentSub merchant webhooks](https://agentsub.dev/events): Implemented outbound HTTP notifications for actual registered, DNS-verified merchants. AgentSub POSTs to each merchant's enabled, owner-configured HTTPS… - [GraphQL](https://agentsub.dev/schema): GraphQL API reference. - [Gateway health](https://agentsub.dev/docs/health): Inspect the real gateway health endpoint before making an agent request. - [Privacy and account data](https://agentsub.dev/docs/privacy): How account identity, service permissions, activity records and site consent are handled. - [Credits and service terms](https://agentsub.dev/docs/legal): Credit eligibility, spending authority and settlement boundaries for connected services. ## Français ### Getting started - [Construire avec agentsub](https://agentsub.dev/fr/docs): Une identité, des crédits pour les outils et une approbation humaine quand un paiement est nécessaire. ## Foundation (archived) ### Docs - [Foundation documentation archive](https://agentsub.dev/v0): The archived offline foundation documents the initial scaffold before the connected preview. ### Docs - [Foundation snapshot](https://agentsub.dev/v0/docs): Archived documentation of the initial offline foundation before the connected preview. ## Other - [agentsub documentation map](https://agentsub.dev/): Find agent identity, credit units, owner controls, merchant offers and runtime payment approval documentation. - [Building an agent credit network](https://agentsub.dev/docs/blog/build-notes): Why service access keeps identity, approval, and authoritative payment completion separate. - [Blume platform capabilities](https://agentsub.dev/docs/changelog/preview): The site now uses Blume for custom portals, documentation, search and agent discovery. - [Connected service workflows](https://agentsub.dev/docs/demo): Use the authenticated owner console and service catalog. - [POST a committed redemption.captured event to the configured merchant receiver](https://agentsub.dev/events/merchant-receiver/send-redemption-captured): POST a committed redemption.captured event to the configured… Reference for the send operation on merchantReceiver in the AgentSub merchant webhooks API. - [POST a committed redemption.released event to the configured merchant receiver](https://agentsub.dev/events/merchant-receiver/send-redemption-released): POST a committed redemption.released event to the configured… Reference for the send operation on merchantReceiver in the AgentSub merchant webhooks API. - [Documentation agentsub](https://agentsub.dev/fr): Retrouvez la documentation sur l'identité des agents, les crédits, les contrôles et l'approbation des paiements. - [Quote an offer](https://agentsub.dev/reference/agent/create-quote): Quote an offer. Reference for the POST /v1/quotes endpoint in the AgentSub Gateway API. - [Mint an ACS voucher (hold)](https://agentsub.dev/reference/agent/create-voucher): Creates a microcredit hold for the offer and returns a signed ES256 voucher JWT… Reference for the POST /v1/vouchers endpoint in the AgentSub Gateway API. - [Agent credit balance](https://agentsub.dev/reference/agent/get-balance): Agent credit balance. Reference for the GET /v1/balance endpoint in the AgentSub Gateway API. - [Offer catalog](https://agentsub.dev/reference/agent/get-catalog): Agent token required in live mode (merchant keys are whitelisted for this path but… Reference for the GET /v1/catalog endpoint in the AgentSub Gateway API. - [Agent ledger history](https://agentsub.dev/reference/agent/get-history): Agent ledger history. Reference for the GET /v1/history endpoint in the AgentSub Gateway API. - [Authenticated agent identity](https://agentsub.dev/reference/agent/get-me): Authenticated agent identity. Reference for the GET /v1/me endpoint in the AgentSub Gateway API. - [Offer detail](https://agentsub.dev/reference/agent/get-offer): Offer detail. Reference for the GET /v1/offers/{id} endpoint in the AgentSub Gateway API. - [Register the authenticated agent](https://agentsub.dev/reference/agent/register-agent): Idempotent registration of the verified AgentID agent against its human… Reference for the POST /v1/agents/register endpoint in the AgentSub Gateway API. - [ACS payment configuration](https://agentsub.dev/reference/discovery/get-acs-configuration): ACS payment configuration. Reference for the GET /.well-known/acs-configuration endpoint in the AgentSub Gateway API. - [Integration status report](https://agentsub.dev/reference/discovery/get-integrations): Reachable on any authenticated request in live mode; reports Clerk/AgentID… Reference for the GET /v1/integrations endpoint in the AgentSub Gateway API. - [Voucher signing JWKS (ES256)](https://agentsub.dev/reference/discovery/get-jwks): Used to verify ACS voucher JWTs offline. In live mode returns 503… Reference for the GET /.well-known/jwks.json endpoint in the AgentSub Gateway API. - [Served OpenAPI document](https://agentsub.dev/reference/discovery/get-open-api-document): Served OpenAPI document. Reference for the GET /v1/openapi.json endpoint in the AgentSub Gateway API. - [Liveness and mode report](https://agentsub.dev/reference/health/get-health): Liveness and mode report. Reference for the GET /health endpoint in the AgentSub Gateway API. - [Unsupported stateless MCP method](https://agentsub.dev/reference/mcp/mcp-delete): Verified human Clerk sessions or agent OAuth tokens with exact MCP resource audience.… Reference for the DELETE /mcp endpoint in the AgentSub Gateway API. - [Unsupported stateless MCP method](https://agentsub.dev/reference/mcp/mcp-get): Verified human Clerk sessions or agent OAuth tokens with exact MCP resource audience.… Reference for the GET /mcp endpoint in the AgentSub Gateway API. - [Model Context Protocol HTTP endpoint](https://agentsub.dev/reference/mcp/mcp-post): Verified human Clerk sessions or agent OAuth tokens with exact MCP resource audience.… Reference for the POST /mcp endpoint in the AgentSub Gateway API. - [Register a merchant](https://agentsub.dev/reference/merchant-registry/create-merchant): Returns the merchant and the DNS TXT record (_acceptor-verify.) to publish… Reference for the POST /v1/merchants endpoint in the AgentSub Gateway API. - [Issue a scoped merchant API key](https://agentsub.dev/reference/merchant-registry/create-merchant-api-key): Returns the asm_... secret exactly once with Cache-Control:… Reference for the POST /v1/merchants/{id}/api-keys endpoint in the AgentSub Gateway API. - [Delete a merchant offer](https://agentsub.dev/reference/merchant-registry/delete-merchant-offer): Delete a merchant offer. Reference for the DELETE /v1/merchants/{id}/offers/{offerId} endpoint in the AgentSub Gateway API. - [Merchant detail](https://agentsub.dev/reference/merchant-registry/get-merchant): Merchant detail. Reference for the GET /v1/merchants/{id} endpoint in the AgentSub Gateway API. - [Active verified merchant offers](https://agentsub.dev/reference/merchant-registry/get-registered-merchant-catalog): Active verified merchant offers. Reference for the GET /v1/merchants/catalog endpoint in the AgentSub Gateway API. - [List merchant API keys (metadata only)](https://agentsub.dev/reference/merchant-registry/list-merchant-api-keys): List merchant API keys (metadata only). Reference for the GET /v1/merchants/{id}/api-keys endpoint in the AgentSub Gateway API. - [List registered merchants](https://agentsub.dev/reference/merchant-registry/list-merchants): List registered merchants. Reference for the GET /v1/merchants endpoint in the AgentSub Gateway API. - [Publish a merchant offer](https://agentsub.dev/reference/merchant-registry/publish-merchant-offer): Publish a merchant offer. Reference for the POST /v1/merchants/{id}/offers endpoint in the AgentSub Gateway API. - [Revoke a merchant API key](https://agentsub.dev/reference/merchant-registry/revoke-merchant-api-key): Revoke a merchant API key. Reference for the DELETE /v1/merchants/{id}/api-keys/{keyId} endpoint in the AgentSub Gateway API. - [Update a merchant offer](https://agentsub.dev/reference/merchant-registry/update-merchant-offer): Update a merchant offer. Reference for the PATCH /v1/merchants/{id}/offers/{offerId} endpoint in the AgentSub Gateway API. - [Verify merchant domain via DNS TXT](https://agentsub.dev/reference/merchant-registry/verify-merchant-domain): Queries DoH (cloudflare-dns.com) for the TXT record. Returns… Reference for the POST /v1/merchants/{id}/verify-domain endpoint in the AgentSub Gateway API. - [Capture a hold](https://agentsub.dev/reference/merchant-scoped/capture-redemption): Capture the explicitly requested amountUc against this… Reference for the POST /v1/redemptions/{id}/capture endpoint in the AgentSub Gateway API. - [Fetch a redemption (hold) record](https://agentsub.dev/reference/merchant-scoped/get-redemption): Live mode: scoped merchant key with offers:read; the hold must belong to the… Reference for the GET /v1/redemptions/{id} endpoint in the AgentSub Gateway API. - [Verify an ACS voucher offline-equivalent](https://agentsub.dev/reference/merchant-scoped/introspect-voucher): Requires merchant scope vouchers:introspect. Verifies the voucher JWT… Reference for the POST /v1/vouchers/introspect endpoint in the AgentSub Gateway API. - [Release a hold](https://agentsub.dev/reference/merchant-scoped/release-redemption): Requires merchant scope redemptions:release. Returns the released… Reference for the POST /v1/redemptions/{id}/release endpoint in the AgentSub Gateway API. - [Configure verified-domain webhook; secret shown once](https://agentsub.dev/reference/merchant-webhooks/configure-merchant-webhook): Configure verified-domain webhook; secret shown once. Reference for the PUT /v1/merchants/{id}/webhook endpoint in the AgentSub Gateway API. - [Disable webhook delivery](https://agentsub.dev/reference/merchant-webhooks/disable-merchant-webhook): Disable webhook delivery. Reference for the DELETE /v1/merchants/{id}/webhook endpoint in the AgentSub Gateway API. - [Read webhook configuration](https://agentsub.dev/reference/merchant-webhooks/get-merchant-webhook): Read webhook configuration. Reference for the GET /v1/merchants/{id}/webhook endpoint in the AgentSub Gateway API. - [Read webhook delivery events and actual attempt receipts](https://agentsub.dev/reference/merchant-webhooks/list-merchant-webhook-events): Read webhook delivery events and actual attempt receipts. Reference for the GET /v1/merchants/{id}/webhook/events endpoint in the AgentSub Gateway API. - [Rotate webhook HMAC secret; secret shown once](https://agentsub.dev/reference/merchant-webhooks/rotate-merchant-webhook): Rotate webhook HMAC secret; secret shown once. Reference for the POST /v1/merchants/{id}/webhook/rotate endpoint in the AgentSub Gateway API. - [Renew an AgentID social identity through the registered direct broker](https://agentsub.dev/reference/o-auth/connect-verified-clerk-agent-id-account): Exact trusted browser Origin and current signed Clerk session are… Reference for the POST /oauth/social/connect endpoint in the AgentSub Gateway API. - [Explicit human owner OAuth consent](https://agentsub.dev/reference/o-auth/consent-o-auth-human-owner): Exact configured browser Origin required. Pending request binds registered… Reference for the POST /oauth/owner/consent endpoint in the AgentSub Gateway API. - [Read sanitized pending OAuth consent context](https://agentsub.dev/reference/o-auth/get-o-auth-authorization-request): Read sanitized pending OAuth consent context. Reference for the GET /oauth/request endpoint in the AgentSub Gateway API. - [OAuth authorization server metadata](https://agentsub.dev/reference/o-auth/get-o-auth-authorization-server-metadata): OAuth authorization server metadata. Reference for the GET /.well-known/oauth-authorization-server endpoint in the AgentSub Gateway API. - [OAuth access-token signing JWKS](https://agentsub.dev/reference/o-auth/get-o-auth-jwks): Returns 503 temporarily_unavailable without OAUTH_SIGNING_STATE. Reference for the GET /oauth/jwks endpoint in the AgentSub Gateway API. - [Protected resource metadata (API)](https://agentsub.dev/reference/o-auth/get-o-auth-protected-resource-metadata): Protected resource metadata (API). Reference for the GET /.well-known/oauth-protected-resource endpoint in the AgentSub Gateway API. - [Protected resource metadata (MCP)](https://agentsub.dev/reference/o-auth/get-o-auth-protected-resource-metadata-mcp): Protected resource metadata (MCP). Reference for the GET /.well-known/oauth-protected-resource/mcp endpoint in the AgentSub Gateway API. - [Authorization endpoint (302 to AgentID)](https://agentsub.dev/reference/o-auth/oauth-authorize): Authorization code with mandatory S256, exact registered redirect, resource and… Reference for the GET /oauth/authorize endpoint in the AgentSub Gateway API. - [AgentID authorization callback](https://agentsub.dev/reference/o-auth/oauth-callback): Exchanges the upstream AgentID code, verifies the ID token (AgentID iss, ES256)… Reference for the GET /oauth/callback endpoint in the AgentSub Gateway API. - [Dynamic client registration (RFC 7591)](https://agentsub.dev/reference/o-auth/oauth-register-client): Public clients only: token_endpoint_auth_method must be none (if present),… Reference for the POST /oauth/register endpoint in the AgentSub Gateway API. - [Token endpoint (authorization_code + PKCE)](https://agentsub.dev/reference/o-auth/oauth-token): Mandatory exact resource/client/redirect and S256 verifier; single-use one-minute… Reference for the POST /oauth/token endpoint in the AgentSub Gateway API. - [Choose AgentID login](https://agentsub.dev/reference/o-auth/select-o-auth-agent-identity): Exact configured browser Origin required. Pending request binds registered client,… Reference for the POST /oauth/select endpoint in the AgentSub Gateway API. - [Finalize agent avatar upload](https://agentsub.dev/reference/owner/finalize-avatar-upload): Finalize agent avatar upload. Reference for the POST /v1/owner/agents/{id}/avatar/finalize endpoint in the AgentSub Gateway API. - [Freeze or unfreeze an agent](https://agentsub.dev/reference/owner/freeze-agent): Freeze or unfreeze an agent. Reference for the POST /v1/owner/agents/{id}/freeze endpoint in the AgentSub Gateway API. - [Owner dashboard overview](https://agentsub.dev/reference/owner/get-owner-overview): Owner dashboard overview. Reference for the GET /v1/owner/overview endpoint in the AgentSub Gateway API. - [Owner-triggered service execution](https://agentsub.dev/reference/owner/owner-run-service): Owner-session proxy to POST /v1/services/execute (same body, same Idempotency-Key… Reference for the POST /v1/owner/run endpoint in the AgentSub Gateway API. - [Start agent avatar upload](https://agentsub.dev/reference/owner/start-avatar-upload): Returns upload parameters for the durable Convex bridge… Reference for the POST /v1/owner/agents/{id}/avatar/upload endpoint in the AgentSub Gateway API. - [Update agent spending policy](https://agentsub.dev/reference/owner/update-agent-caps): Updates per-transaction, daily and monthly microcredit caps and… Reference for the PATCH /v1/owner/agents/{id}/caps endpoint in the AgentSub Gateway API. - [Update agent display profile](https://agentsub.dev/reference/owner/update-agent-profile): Update agent display profile. Reference for the PATCH /v1/owner/agents/{id}/profile endpoint in the AgentSub Gateway API. - [Start Link connect (owner only)](https://agentsub.dev/reference/payments/connect-link): Start Link connect (owner only). Reference for the POST /v1/payments/link/connect endpoint in the AgentSub Gateway API. - [Create a Link checkout session](https://agentsub.dev/reference/payments/create-checkout): Owner only. credits is limited to 100 or 500 (i.e. $1.00 or $5.00 at 1… Reference for the POST /v1/payments/checkout endpoint in the AgentSub Gateway API. - [Payment provider connection status](https://agentsub.dev/reference/payments/get-payments-status): Payment provider connection status. Reference for the GET /v1/payments/status endpoint in the AgentSub Gateway API. - [Link OAuth callback (GET)](https://agentsub.dev/reference/payments/link-callback-get): Link OAuth callback (GET). Reference for the GET /v1/payments/link/callback endpoint in the AgentSub Gateway API. - [Link OAuth callback (POST)](https://agentsub.dev/reference/payments/link-callback-post): Link OAuth callback (POST). Reference for the POST /v1/payments/link/callback endpoint in the AgentSub Gateway API. - [Poll a top-up request](https://agentsub.dev/reference/payments/poll-topup): Poll a top-up request. Reference for the GET /v1/payments/topups/{id} endpoint in the AgentSub Gateway API. - [Request an agent top-up approval](https://agentsub.dev/reference/payments/request-topup): Requests Link approval to credit an owned agent. amountUsdCents is an… Reference for the POST /v1/payments/topups endpoint in the AgentSub Gateway API. - [Stripe webhook receiver (inbound only)](https://agentsub.dev/reference/payments/stripe-webhook): Inbound Stripe webhook endpoint. Requires a valid Stripe-Signature… Reference for the POST /v1/payments/stripe/webhook endpoint in the AgentSub Gateway API. - [Remove the AgentMail connector](https://agentsub.dev/reference/services/delete-agentmail-connector): Remove the AgentMail connector. Reference for the DELETE /v1/services/connectors/agentmail endpoint in the AgentSub Gateway API. - [Execute a metered service action](https://agentsub.dev/reference/services/execute-service): Agent sessions execute as themselves; owner sessions must pass agentId of… Reference for the POST /v1/services/execute endpoint in the AgentSub Gateway API. - [Available services and pricing](https://agentsub.dev/reference/services/get-services-catalog): Lists github-public and agentmail services with their actions. Every service… Reference for the GET /v1/services/catalog endpoint in the AgentSub Gateway API. - [Configure the AgentMail connector](https://agentsub.dev/reference/services/put-agentmail-connector): Owner only. Stores the API key encrypted (AES-GCM with… Reference for the PUT /v1/services/connectors/agentmail endpoint in the AgentSub Gateway API. - [Offer](https://agentsub.dev/schema/objects/offer): Reference for the Offer object type in the GraphQL API. - [offers](https://agentsub.dev/schema/queries/offers): Reference for the offers query in the GraphQL API. ## RSS Feeds - [agentsub — Blog](https://agentsub.dev/blog/rss.xml) - [agentsub — Changelog](https://agentsub.dev/changelog/rss.xml) ## Agent skills - [agentsub](https://agentsub.dev/.well-known/agent-skills/agentsub/SKILL.md): Read agentsub identity, credits, caps, and payment approval documentation before calling its gateway or using its portals. ## Agent resources - [llms-full.txt](https://agentsub.dev/llms-full.txt): The full Markdown of every page in one file. - [Page Markdown](https://agentsub.dev/index.md): Append `.md` to any page URL to fetch that page as raw Markdown. - [JSON API](https://agentsub.dev/api/docs/pages.json): Page index of the JSON docs API; each entry links the page's JSON and Markdown forms. Described by the OpenAPI document at https://agentsub.dev/openapi.json. - [MCP server](https://agentsub.dev/docs-mcp): Streamable HTTP Model Context Protocol server with search_docs, get_page, list_pages, and get_navigation tools, plus every page as a resource. Discovery document: https://agentsub.dev/.well-known/mcp.json - [Agent skills](https://agentsub.dev/.well-known/agent-skills/index.json): Agent Skills discovery index of the skills this site publishes. - [API catalog](https://agentsub.dev/.well-known/api-catalog): RFC 9727 linkset of the APIs documented here. - [AI catalog](https://agentsub.dev/.well-known/ai-catalog.json): ARD manifest of the agent-facing resources on this site (MCP server, skills, APIs). - [agent-readability.json](https://agentsub.dev/agent-readability.json): Manifest of every agent-facing artifact on this site. - [Sitemap](https://agentsub.dev/sitemap.xml): Every indexable page URL with its last-modified date.