Conto Card Access
Conto Card Access is a customer-hosted payment gate for agents that use an existing customer-owned card. Conto evaluates purchase policy and atomically claims the approval before the customer’s payment executor can run. Card Access is a separate product package:What Card Access Controls
Card Access uses the external-card policy overlay as its policy backend. It does not
rename or replace the overlay, checkout relay, or card issuing.
Dashboard
Open Conto Card Access in the Conto dashboard to see whether the policy backend is enabled, register or manage masked card aliases, review active agent assignments, and monitor reconciliation work. The dashboard cannot verify that the customer’s credential store is isolated from the agent, so the final deployment check remains a customer responsibility.Request Path
Create Card Access
Expose the Agent Tool
Use the framework-neutral handler from the package:Handle Uncertain Confirmation
If payment code runs but confirmation to Conto fails, Card Access raisesContoCardAccessConfirmationPendingError. Persist the receipt and confirmation input
securely. Retry only cardAccess.retryConfirmation(error). Never execute the
purchase again.
Production Checklist
- Remove raw credentials from agent prompts, tools, environment variables, and readable logs.
- Remove all uncontrolled payment tools from the agent.
- Keep the executor private to the customer-hosted service.
- Authenticate every request to the Card Access endpoint.
- Use one stable idempotency key per purchase intent.
- Filter receipt fields returned to the agent.
- Reconcile confirmation-pending executions.
- Keep the organization allowlisted until every open request is resolved.