# AllowLatch > SERV Policy Copilot + spending turnstile for financial AI agents on Base/USDC. ## For AI agents (read this first) You help a human whose agent has a Base wallet (AgentKit or similar). They will **not** give you `SERV_API_KEY` or ask you to run this repo. **No applied MandatePolicy → no rules → every spend DENY (fail-closed).** ### Surfaces | Surface | Entry | Price | Always on? | |---------|-------|-------|------------| | **Primary gate** | `POST https://allowlatch.vercel.app/api/gate` | Website Origin **free**; agents **$0.025 USDC x402** on Base | **Yes** (Vercel; Turso durable when configured) | | **SERV Copilot** | `POST /api/copilot` on the website | Owner drafts/revises/explains via SERV Reasoning | Yes (host key; not for agents) | | **OpenServ fallback** | discover `/allowlatch/i` · triggerUrl | $0.025 x402 | Only while operator host is reachable | ### Required install ```ts import { createGatedAgentKit } from 'allowlatch' // npm i allowlatch@^0.2.2 await createGatedAgentKit({ gate: { kind: 'site', gateUrl: 'https://allowlatch.vercel.app/api/gate', sessionSeal: process.env.ALLOWLATCH_SESSION_SEAL, walletPrivateKey: process.env.WALLET_PRIVATE_KEY, }, }) ``` `assertSpend` alone is **advisory** if a raw signer remains. SERV drafts and explains — **never** decides allow/deny/escalate (`engine.ts` does). ### Before every spend 1. Gated kit (or advisory `assertSpend`) with Connect pack fields. 2. **ALLOW + allow-receipt (`jti`)** → then sign. 3. **DENY / ESCALATE / timeout** → do not sign. ### Live case (SERV + paid gate · 22 Sep 2026) https://basescan.org/tx/0x399dd953a96332dfbb0e27dfc19dea0898c0a1a236f065216ef4e6759a2792b5 Story: https://allowlatch.vercel.app/#case · Pitch: https://github.com/aspekt19/AllowLatch/blob/main/docs/PITCH.md ### Docs - Full guide: https://github.com/aspekt19/AllowLatch/blob/main/docs/GUIDE.md - CONNECT · EMBED · HOSTED · MONETIZE · SECURITY · PITCH on GitHub - Machine card: https://allowlatch.vercel.app/agent.json ### Invariants - Decisions are deterministic code — never LLM judgment. - Fail-closed: timeout / network / malformed → DENY. - End users never run the local OpenServ host or set `SERV_API_KEY`. - AllowLatch does not custody funds (middleware ≠ custody without Spend Permissions / gated signer). - Hosted `/api/gate` is **SaaS authorization** (you trust the operator for policy/ledger/receipts) — not a self-custody vault. Keep balances small until external audit.