# Spendkit > Non-custodial AI Agent Spending Policy Firewall. Coding Agents help developers integrate Spendkit into a Runtime Agent; the Runtime Agent uses OAuth + MCP and its bound Payment Wallet to submit authorized payments. ## Start here - [Open House Judge Brief](/open-house/): problem, architecture, USDG/Arbitrum evidence, and demo walkthrough. - [Demo Companion](/demo/): Payment Wallet -> Router -> Demo Recipient flow with ALLOW/DENY evidence. - [Developer Docs](/docs/): public human-readable documentation. - [First Agent setup](/docs/quickstart/): wallet, Policy, Agent connection, and first payment review. - [How Spendkit works](/docs/concepts/): plain-language roles and payment interaction. - [Dashboard guide](/docs/dashboard/): Agents, wallets, daily spending, and payment records. - [AI Coding Agent Integration](/docs/ai-coding-agents/): integrate through MCP and preserve wallet boundaries. - [Runtime Integration](/docs/runtime/): OAuth Client Credentials + MCP. - [Copyable integration examples](/docs/examples/): JavaScript, Python, Go, and C++ clients; business and wallet extension points. - [HTTP and MCP call examples](/docs/api-quickstart/): token exchange, JSON-RPC envelope, tool call and result parsing. - [Payment Flow](/docs/payment-flow/): preview -> authorize -> Payment Wallet -> Router -> record -> status. - [MCP Tool Reference](/docs/mcp-tools/): every tool's inputs, output fields, scopes, and DENY behavior. - [Security Model](/docs/security/): wallet roles and onchain enforcement. - [Full machine-readable reference](/llms-full.txt). - [Integration JSON](/integration.json). ## Wallet roles - Spendkit Admin + Authorization Signer: Router administration, Policy management, pause control, authorization signing. Shared in the Hackathon Demo. - Agent Payment Wallet: holds USDG, submits Router transactions, pays gas, and provides the token source. - Demo Recipient: receives USDG. ## Canonical endpoints - Production base URL: `https://spendkit-alpha.vercel.app` - Dashboard: `https://spendkit-alpha.vercel.app/app` - MCP: `https://spendkit-alpha.vercel.app/mcp` - OAuth token: `https://spendkit-alpha.vercel.app/oauth/token` ## Integration facts - Runtime authentication uses OAuth 2.0 Client Credentials and short-lived Bearer tokens. - Payment tools do not accept `policyId`; the authenticated Agent binding selects the Policy and Payment Wallet. - `spendkit_authorize_payment` returns a signed authorization and transaction with `from = bound Payment Wallet`. - Router requires `msg.sender == authorization.paymentWallet` and transfers USDG from that same wallet. - Spendkit Server never broadcasts payment transactions or pays gas. - Spendkit Server never receives the Payment Wallet private key. - `lastUsedAt` indicates previous MCP activity; it does not prove the Runtime or Payment Wallet client is online now. ## MCP tools `spendkit_get_connection`, `spendkit_get_policy`, `spendkit_preview_payment`, `spendkit_authorize_payment`, `spendkit_record_payment`, `spendkit_get_payment_status`, `spendkit_list_payments`. ## Current chain deployment status The registered Arbitrum Sepolia Router is signed-authorization-v3 at `0xe388644B4115fbE029FA4acC3b20a47600c4bA16`. Runtime validates the deployed schema and fails closed if validation fails. The published confirmed payment is historical evidence from the earlier Router; a new confirmed payment is still needed to demonstrate the current Payment Wallet sender path.