Delegate API billing to AI agents.
You want an AI agent to call external APIs (SaaS, payments, data) without the risk of handing over the API key. Lemma issues a scoped delegation — billing ceiling, allowed APIs, and validity — so that via x402 the agent runs autonomously inside scope and stops before acting outside it, letting you operate safely without ever sharing the key.
Three voices from the front line.
- Developer
“We want to avoid the risk of handing an AI agent the API key — delegate with scope instead”
- IT
“We want real-time control over the billing of the APIs the AI uses”
- Security
“We want to structurally eliminate the risk of API-key leakage”
Hand over the source, or just the facts?
Nothing changes on the floor. Everything changes for the receiver.
① Your team just saves, as always.
- The usual step
- Fill in the record and save
- On save
- A proof is attached (API, behind the scenes)
- The document itself
- never sent
② They just open a link.
- Proven fact
- within scope, the AI may call the API
- the API key and billing authority
- not shown
- Login / keys
- not needed
- The document stays private — the record itself is never sent or disclosed.
- Independent verification — the receiver just opens a link. No account, no keys.
- Edits are detected — even a one-character edit fails verification.
An org or developer issues a signed delegation with a billing ceiling, allowed APIs and validity — without handing the agent the API key itself. x402 middleware checks authority via Trust402 before each call, executing inside scope and stopping before anything outside it. Without disclosing keys or billing authority, the fact "called within scope" can be independently verified.
See the technical details ↗Why the usual methods fall short.
Only work that needs all three at once — pass without exposing, independent verification, tamper-evidence — is Lemma's domain.
| Method | Pass without exposing | Independent verification | Tamper-evident | What happens |
|---|---|---|---|---|
| Access control / permissions | △ | ✗ | ✗ | “Someone inside could have edited it” remains possible |
| Masking / redacted copies | △ | ✗ | ✗ | Redaction work grows; the original is still unproven |
| Encrypt and store / send | ✓ | ✗ | ✗ | To verify, the receiver needs it disclosed after all |
| Lemma (ZK proof)the only one with all 3 | ✓ | ✓ | ✓ | The receiver just opens a link |
How it works — and how to start.
We help design disclosure scope and retention, run the PoC, and support production.
Start with a 30-minute call.
Tell us one workflow where you want the AI to call an API but fear handing over the key, in the first 30 minutes. No disclosure of the API key required.
Related use cases
Find the case that matches your industry and problem
Browse all 36 use cases →TRY LEMMA
Run it yourself.
No sales call needed — start hands-on with Lemma's products.