Skip to content
Tenzro
Reference design · Rivier

Agentic payments on Tenzro Network 1.

A reference design for a wallet in which AI agents hold balances, pay for services and settle on behalf of people and organisations, within limits their owners set and the network enforces.
Overview

A wallet for people and the agents that work for them.

Rivier is an illustrative design, not a deployed product. A person opens an account with a passkey, then creates agents that act for them. Each agent has its own identity, its own spending limits and its own keys rooted in hardware. Agents pay over x402, MPP, AP2 and ACP in TNZO or stablecoins, and every payment settles on the Tenzro ledger with a receipt the owner can audit.
Architecture

Network 1 primitives Rivier uses.

  • Passkey accounts

    The owner's account is rooted in a passkey with user verification required. Every passkey operation is a hybrid P-256 plus ML-DSA-65 signature. No key files, no seed phrases.
  • Delegated agent identities

    Each agent gets a did:tenzro:machine identity naming its controller, with a delegation scope: per-transaction and daily limits, allowed operations, protocols, chains and a time bound.
  • Smart account policies

    ERC-7579 session-key and spending-limit modules on each agent's smart account check every operation at signing time, so limits hold even if an off-chain check is skipped.
  • Open payment rails

    x402 and MPP for pay-per-request and streaming APIs, AP2 mandates for pre-authorised purchases, and the ACP buyer side for agent-commerce checkouts.
  • Stablecoin wallets

    Balances in stablecoins through Bridge.xyz wallets, with gas paid in stablecoins through the same rails. TNZO pays network fees and settlement underneath.
  • Recovery without custodians

    The owner links more devices, and recovers with a second passkey or with guardians under a timelock and veto. No one else ever holds the keys.
Flow

How it works, end to end.

  1. 01

    Open an account

    The owner creates a passkey wallet in the browser. Their human DID is derived from the passkey. Optional credentials raise their verification tier.

  2. 02

    Create an agent

    The owner issues an agent identity with a delegation scope: a daily ceiling, allowed merchants and protocols, allowed chains and an expiry.

  3. 03

    Agent pays

    A service answers with HTTP 402. The agent signs a payment bound to its DID over x402 or MPP, or completes a checkout through ACP.

  4. 04

    Network enforces

    The delegation scope, the runtime spending policy and the smart account modules must all pass. The payment carries a signature from the paying account.

  5. 05

    Settles per use

    Metered settlement records exactly what was consumed, in TNZO or stablecoins, and returns a signed receipt.

  6. 06

    Owner audits

    Rivier shows every receipt, mandate and limit in one place, backed by the record on the ledger. The owner can tighten or revoke a scope at any time.