Editor's note: In a jurisdiction that licenses payment institutions, the distinction in this founder essay matters: a verify-only rail that never holds funds is not a payment service provider, and the author says so.
The agent economy is solving spending faster than it is solving work.
An agent can pay for an API call in seconds. Hiring another agent for a result is harder. What was promised? What counts as done? And what makes payment move without bringing a person back into the loop?
Voidly has proved the first half of that lifecycle on Base mainnet. On August 26, one program accepted another's signed terms for an observatory query, sealed the brief, paid 0.05 USDC directly to the provider and received the result encrypted. The work stayed off-chain. The payment stayed publicly inspectable.
Both participants were operated by Voidly. That makes the first Session controlled product proof rather than customer traction. It does not diminish the technical result: real value moved on mainnet inside the same authenticated flow that carried the signed hire, the private work and the sealed delivery.
The transaction is public, and Voidly published the run record. The chain independently proves the transfer, the addresses, the amount and the one-time authorization. Voidly's record connects that payment to the private Session and reports delivery.
THREE LAYERS EXIST. A FOURTH IS MISSING.
An April IMF paper describes the tension between probabilistic agents and the deterministic controls that payment infrastructure requires. Its framework separates intent, authorization and settlement. Google's AP2 addresses user intent and purchasing authority. x402 standardizes internet-native payment requests, verification and settlement, and its foundation now has 40 members under Linux Foundation governance.
Agent-controlled spending is no longer hypothetical. Base currently reports more than 75 million agent transactions, $24 million in payment volume, more than 12,000 active agents and over 22,000 x402 APIs. In its July 29 earnings release, Robinhood reported that nearly 100,000 customers had opened Agentic Trading accounts, with more than $100 million in assets under custody. Software has transaction rails and capital.
Those systems make agent spending legible. They can prove who acted, what an agent was allowed to spend and whether money moved. When the product is another agent's work, a fourth question appears: did the job satisfy the rule agreed before it began?
A settled payment cannot answer that. Paying a fixed price to unlock an API response is one thing. Commissioning a fresh dataset, a code change, a signed network measurement or a reconciliation job is another. The buyer needs more than a record showing money moved. It needs a definition of done. x402's optional offer and receipt extension adds a server-signed delivery record, a useful building block that still represents the server's attestation rather than an independent test of the work.
x402 provides the payment handshake. voidpay is building the accountability around the job. Together, they can move agent commerce from paying for access to paying for a verified outcome. That points beyond an agent that can trade or spend from its owner's account, toward a machine labor market: software with capital hiring other software for research, measurements, reconciliation, data collection and other bounded outcomes. For Base, it expands what internet-native payments can buy beyond access. Agents can buy work.
WHAT IS LIVE
The deployed Session protocol handles signed provider terms, sealed task delivery, payment bound to the authenticated Session, chain-receipt verification and encrypted results. Its public SDK, signed provider manifest and machine-readable provider index are available today. The task and the result stay off-chain while the transfer remains public.
The first Session did not ask a general-purpose verifier to judge arbitrary work. It proved the lower layer an outcome market needs: authenticated hiring, private delivery, payment bound to the Session, receipt verification and a sealed result.
WHAT COMES NEXT
voidpay's next layer ties payment to completion. The rule is fixed before work starts. Evidence is checked by machine. When the rule passes, a payment the buyer already authorized moves from the buyer's wallet to the enrolled recipient, with no one returning at the end to click approve. The output can stay sealed. Voidly does not hold the money.
The chain cannot judge the work. USDC can enforce who pays whom, how much, and that an authorization is used once. It does not know what that authorization represents. voidpay's job is to bind the payment to the work that was agreed and to check the agreed condition before the payment moves. Keeping those two functions separate is the core of the design.
The initial scope is deliberately narrow: digital work judged against explicit, machine-readable evidence. Subjective work belongs elsewhere. "Make the best logo" requires a chosen evaluator or an appeal process. So does "choose the best long-term investment strategy."
WHY VOIDLY
Voidly came to this problem through its open observatory of global internet censorship. Some of the most useful agent jobs involve sensitive targets, networks and results that should never be posted to a public marketplace. Imagine an agent that needs a fresh measurement from a particular network during a narrow window. Publishing the target and the result could expose the work. voidpay is built so the measurement can return sealed while a narrow proof of completion is still checkable.
Several projects make different choices around the same problem. Virtuals ACP coordinates jobs through escrow and an evaluator. TessPay describes proof of execution, validators and escrow. Draft ERC-8183 defines an escrowed job standard with an evaluator. Experimental BountyBook combines Base, x402, USDC escrow and an AI oracle. RAILS, a research specification, describes verification-native agentic clearing.
voidpay's position is different on one point that matters: the buyer's funds are never deposited into job escrow. Work is sealed, the rule is fixed first, and settlement goes wallet to wallet. The same completion decision could serve wallets, marketplaces, payment protocols and enterprise agent systems rather than becoming another closed destination.
WHERE IT STANDS
Voidly has deployed a public bounty board with four automatic rungs as its next proving ground. Payouts are not armed. The board's own readiness check reports that the only enrolled payee is a Voidly address, and the path stays blocked until an outside address is enrolled and authorized. The payout ledger shows 12.95 USDC funded across all rungs and nothing paid.
The next public milestone is a payout to an address Voidly does not control, after it passes a fixed verifier under the published policy. The chain can show that such an address is not ours. It cannot show whose it is, and Voidly's board says so. Outside buyers and repeat use will then test demand.
The first run also showed why payment state matters. Its initial settlement observation was inconclusive. A retry moments later confirmed the transaction before Voidly's run record marked delivery complete. The system did not treat the hash alone as payment. A transaction hash records submission, not success.
The question for every agent payment is no longer only who approved it or whether money moved. What, exactly, did the payment prove?
More on voidpay, including the machine-readable product card and the first-settlement receipt, is published at voidly.ai/pay.
Disclosure: Dillon Parkes is cofounder and CEO of Voidly, which builds voidpay.






