Declare the purchase constraints.
Send the declared purchase intent, proposed action, exact payment terms and authorization evidence to /api/value/bind/. HumanMirror returns a signed ALLOW, REVIEW or BLOCK binding before settlement.
HumanMirror Purchase Firewall puts an independent policy boundary around an agent purchase. Before payment, the live Value Firewall checks the declared amount, currency, destination, category and authorization requirement. After the action, Execution Receipt keeps settlement separate from evidence of what actually happened.
Send the declared purchase intent, proposed action, exact payment terms and authorization evidence to /api/value/bind/. HumanMirror returns a signed ALLOW, REVIEW or BLOCK binding before settlement.
Card, wallet, x402, bank rail or another provider remains authoritative for authorization and settlement. HumanMirror does not move or custody the purchase funds.
After execution, call /api/value/close/ with the signed binding plus the observed action/payment. HumanMirror returns signed MATCH or DRIFT evidence, keeping authorization separate from what was actually observed.
The one-call transaction-binding surface is live at /api/value/bind/. It compares declared intent with the proposed payment amount, currency and destination and keeps declared authorization evidence explicitly scoped. For workflows that also need operational-risk analysis of the tool action itself, HumanMirror Safe Preflight remains available at /api/x402/safe-preflight/. Execution Receipt remains the post-action evidence layer.
/api/value/ucp-bind/ maps a caller-supplied UCP checkout into the same signed Purchase Firewall binding while preserving the native payment handler. It deliberately does not claim UCP conformance, signature verification or settlement authority.
Purchase Firewall is for agent wallets, payment rails, merchant platforms and autonomous-commerce systems that need a separate boundary between a declared purchase policy, the payment provider and post-action evidence.
HumanMirror evaluates caller-supplied transaction intent and policy constraints. It does not claim that a user legally authorized a transaction merely because an authorization capability was declared, and it does not replace fraud, KYC, card-network, wallet or merchant controls.
HumanMirror maps one production purchase flow, wires the signed transaction binding before settlement, closes it against observed execution after the action, validates drift handling and documents the scale-out path. No automatic renewal.
Start the Production Pilot · 990 €