Connect
Owner issues a restricted key. The agent checks its identity and capabilities.
DEVELOPERS / AGENT QUICKSTART
Add spending policies, exact review, and a connected record to the agent you already use. Start with a restricted connection and a bounded proposal.
Current release: proposal controls + Stripe test refunds. General payment execution is disabled.
BROWSER FIRST
Use the browser workspace to request policies, submit exact proposals, read outcomes and attach authorized tool reports. The forms use the same restricted permissions as the API. No SDK installation required.
Open browser agent workspace →The browser console sends its restricted key without owner cookies. It does not isolate the rest of your computer: an agent in your owner’s logged-in session still has owner access. Keep approval in a separate environment the agent cannot reach.
Read the browser workflow and limits →Owner issues a restricted key. The agent checks its identity and capabilities.
Agent prepares exact policy terms. Owner reviews and activates the allowance.
Agent submits a deal with a stable request key. The owner reviews exact terms.
Inspect decisions and authorized tool reports. Permission and payment evidence stay distinct.
START HERE
Use the JavaScript SDK, a local MCP server, or direct HTTPS. All three use the same restricted, agent-bound key and server-side controls.
npm install --global https://dealgo-portal.vercel.app/downloads/dealgo-middleware-0.5.0.tgz
# Set DEALGO_URL and DEALGO_API_KEY in your secret environment.
dealgo-middleware doctor-commerce
dealgo-middleware config-commerceThe CLI prints an MCP configuration with a placeholder, never your secret. Merge it into your host and supply the key using its secret settings. The MCP transport is local stdio; no hosted MCP URL is provided.
Environment setup and full walkthrough →EXACT TERMS
const connection = await dealgo.capabilities();
// Confirm connection.agentId and workspaceId with the owner.
const { mandates } = await dealgo.listMandates();
// Select the owner's intended mandate by ID.
const result = await dealgo.propose({
mandateId: process.env.DEALGO_MANDATE_ID,
action: "purchase", counterpartyId: "vendor_acme",
amountMinor: 2500, currency: "usd",
description: "Supplies for order PO-1042",
requestKey: "purchase-order-1042",
});
// Give the owner result.proposal.id and result.approvalUrl.
// APPROVED is permission; it does not execute payment.2500 means $25.00 for USD. Use currency minor units, persist the request key before submission, and preserve it on retry. A timeout is not evidence of success.
AGENT TO OWNER
Call requestPolicy with exact terms and a persisted requestKey. The owner opens the returned reviewUrl, reviews the agent, counterparties, limits, and expiry, then activates or rejects those terms.
The agent reads getPolicyRequest for the result. ACTIVATED returns a mandateId for proposals. It never enables payment execution.
ONE CONNECTED EXECUTION PATH
Include the original decision, payment and reason in a refund proposal. After approval, the agent prepares the same terms for the owner’s final submission. No amount or payment retyping.
Read the test refund contract →Policy, connection, expiry and pause are checked again before execution starts. Once started, the allowance stays reserved. An interrupted submission is reconciled against the existing operation, never replaced with another refund.
Stripe test mode only. Requires an eligible payment decision already recorded for the same workspace and agent. Live payments and other execution types remain disabled.
THE OWNER’S SEAT
The workspace brings together review requests, spending policies, searchable activity, and test refund reconciliation. Agent tools cannot issue credentials, approve their own requests, activate policies, or change billing.
Open setup & assistant →Keep direct payment credentials outside the agent. DeAlgo cannot control tools that bypass it. It does not hold funds, provide payment accounts, or prove that an external agent report is true.
Security and current limits →