Docs

Docs

leashcash.com · Docs · Runner desk

Cash for agents, on a leash. A Claude Code plugin that lets your agent pay real people on PayPal, Zelle, Venmo, Cash App, Revolut, Wise and more, only the people you allow and only as much as you allow.

Your agent has the money. Your repo has the rules. Leash has neither.

Install

claude plugin marketplace add michelelandini36-beep/leash
claude plugin install leash@leash

Then, in your project:

/leash:setup

That creates leash.config from a template, adds deny rules to .claude/settings.json so the agent's file tools can't touch it, and prints one command to run in your own terminal to approve (pin) the rules. Until you pin, every payment asks you first.

Requires Node 18+.

leash.config

[limits]
per_job_usd = 1000     # network cap 1000
per_day_usd = 1500     # network cap 5000
max_fee_bps = 200      # runner fee cap, 200 = 2% (network cap 5%)

[[allow]]
name    = "landlord"
to      = "@landlord"
rail    = "zelle"
max_usd = 800
every   = "month"      # job (default), day, week or month

[[allow]]
name    = "designer"
to      = "maya@studio.design"
rail    = "paypal"
max_usd = 300

[default]
unknown_recipient = "ask"     # no rule for them: ask | block
from_untrusted    = "block"   # you never typed the recipient: ask | block
over_limit        = "block"   # known, but too much: ask | block

How a payment is decided, in order:

  1. Valid app, recipient and amount; under per_job_usd, per_day_usd and max_fee_bps. Otherwise deny.
  2. Provenance. The hook reads the session transcript: if you never typed the recipient yourself (it only appears in an issue, PR, web page, file or other tool output), from_untrusted applies.
  3. A matching [[allow]] rule (same recipient, same app) within its max_usd for its period: allow. Over it: over_limit. No rule: unknown_recipient.
  4. If leash.config changed since you last pinned it, an allow becomes ask.

None of the defaults can be allow. The agent is only ever told "allowed", "needs the owner's approval" or "blocked", never the rules.

Commands

Command What it does
/leash:setup Create leash.config, lock it away from the agent, show the pin command
/leash:status Mode, spend in the last 24 h, recent jobs
/leash:dry-run <rail> <to> <amount> What the rules would answer, without paying
/leash:run Break my leash: 10 prompt-injection attacks against your rules
/leash:bounty <pr> <amount> <rail> <to> Pay a contributor once their PR is merged
/leash:split <total> <rail> <a,b,c> Split an amount and pay each share
/leash:recurring <rail> <to> <amount> <period> A rule block to paste, plus how to schedule it

Plus a treasurer subagent for payment work, and MCP tools leash_pay, leash_status, leash_release, leash_dispute, leash_cancel, leash_balance.

Dry run and live

Leash starts in dry-run: jobs are simulated (open → assigned → funded → paid → released), nothing is paid, and dry-run spending is kept apart from live budgets.

To pay for real, give the agent a wallet on Robinhood Chain with some USDG and a little ETH for gas, then:

export LEASH_MODE=live
export LEASH_AGENT_PRIVATE_KEY=0x...     # the agent wallet

No extra install: the network client ships inside the plugin. It only ever funds the mainnet LeashEscrow pinned in the plugin, 0x62ed93d484724aD30D1Db63C78F6F2a9131ae876 (source verified on Sourcify); if the network's API ever points elsewhere, it refuses.

What happens on a leash_pay that your rules allow:

  1. The job goes on the Leash job board with the amount, the app and a hint of the recipient (@l…d). Never the full details.
  2. A runner who pays on that app accepts and signs the exact terms (amount, fee, deadline).
  3. The plugin checks the signature and fee itself, seals the recipient's details to that runner only, approves exactly what the job costs and funds the escrow.
  4. The runner pays from their own app, seals a proof to you (and to the arbiter) and marks the job paid on-chain.
  5. After 24 h the escrow pays the runner. Use leash_release to settle early, or leash_dispute within 24 h if nothing arrived.

If no runner takes the job within 30 minutes, it's withdrawn. If a runner doesn't mark it paid by the deadline, anyone can expire it and you get everything back.

Fees: the runner's fee (capped by you, never above 5%) and a 1% platform fee, only on payments that go through. Limits (in the contract, forever): $1,000 per job, $5,000 per agent per day.

Runners: the runner desk at leashcash.com/runner. Disputes: decided by the job's arbiter on the sealed proof; if the arbiter doesn't act in 30 days, the agent is refunded.

What it guarantees, and what it doesn't

Develop

cd plugins/leash && npm test            # rules, hook, server end to end, Break my leash
claude --plugin-dir ./plugins/leash      # try it in a session

Leash is not a bank. Runners are independent people paying from their own accounts. The escrow contract has been tested and reviewed but not audited by a third party: see Risks. Nothing here is financial advice.