SLOTH
WebMCP/Connecting

Payment operations / controlled autonomy

Clean up today’s
payment problems.

Delegate outcomes, not unlimited access. Sloth equips autonomous agents with narrow baseline tools, surfacing temporary financial capabilities only through verified, human-approved grants.

Open console

Autonomous simulation mode active for standard browsers.

Runtime Authority Boundary

Dynamic Capability Lifecycle · Zero Standing Financial Privileges

Interactive Operations Console

Delegated Outcome Workbench

Watch the agent investigate payment anomalies, execute pre-authorized recoveries, and request scoped human authority when encountering hard boundaries.

Delegated run

Waiting for intent

Idle
↳

Operator Intent

“Clean up today’s payment problems. Only bother me when you actually need my authority.”

—

payment issues reviewed

—

duplicate charges confirmed

—

retries resolved safely

Awaiting capability grant: no financial mutation capability is registered. Approve a request above to activate boundary testing, the TTL countdown, and execution controls.

  1. Run is waiting for your intent.

Dynamic Capability Architecture

Authority that scales with trust.

Narrow by default, temporary when escalated, and enforced inside the tool handler — not only in the UI.

Phase 01 / Least Privilege

Narrow Baseline Discovery

The agent begins with read-only inspection tools and pre-authorized idempotent retries. Financial mutations do not exist in the browser context.

inspect_issuesread-only
inspect_transactionread-only
retry_paymentpre-auth policy
request_capabilityboundary hook
refund_scoped_transactionsUNREGISTERED
● 04 Tools in WebMCP Registry
Phase 02 / Hard Boundary

Just-in-Time Authority Request

When duplicate charges are confirmed, the agent halts at the boundary and calls request_capability. The operator approves or limits an immutable grant.

request_capability({
  capability: "refund_scoped_transactions",
  scope: {
    transactions: ["TX-48", "TX-72", "TX-184"],
    maxAmount: 184,
    maxTotalAmount: 304
  },
  reason: "Confirmed duplicate charges"
})
● Human Governed · Scope Locked
Phase 03 / Deterministic Safety

In-Tool Enforcement & Expiry

Scope constraints are checked inside the tool handler, returning structured violations. The capability disappears when consumed, denied, or expired.

01Tool dynamically registered
02TX-999 ($220) → SCOPE_VIOLATION
03TX-48, TX-72 refunded within grant
04Consumed or expired → unregistered
● 4 → 5 → 4 Lifecycle

Standardizing Agent Authority

Ready to delegate outcomes with scoped authority?

Inspect live WebMCP tools in Chrome DevTools or Google’s Model Context Tool Inspector, test autonomous runtime adaptation, and explore how just-in-time capability grants replace permanent API keys.