Bursar is an onchain treasury and policy layer for AI agents. Set per-payment and daily limits, approve the big spends, and see every payment, with a reason, on-chain. Built on Arbitrum
Bursar: spending limits for AI agents, on Arbitrum
AI agents are starting to pay for things on their own: data feeds, other agents, even humans. Today you have two bad options. Give the agent a private key, and one bad prompt can drain the wallet. Or approve every payment by hand, and the agent isn't autonomous anymore.
Bursar is an onchain treasury and policy layer that sits in between. An owner funds a vault and gives each agent a budget. The smart contract enforces it:
A per-payment cap and a daily cap
An approval threshold: bigger payments wait in a queue for the owner
A recipient allowlist
Task budgets with an expiry
Escrow, for hiring sub-agents or paying humans for a job
A pause switch for the owner
Every payment carries a reason code, which the dashboard shows as plain labels like "Bought data" or "Hired a sub-agent". Blocked attempts are logged on-chain too (the PaymentBlocked event), so the owner can see what the agent tried to do and not only what it paid.
What's live
Smart contracts on Arbitrum Sepolia (factory and vault), verified on Arbiscan, with 203 tests including fuzz and invariant tests
A live dashboard that reads the vault's events: spend against the cap, policies, tasks, approvals, escrows and the full audit trail
An owner console to approve requests, release escrows and change policy
A playground where anyone can create their own vault with a test token
An MCP server, so an AI agent such as Claude Code can use Bursar through tools (pay, create_escrow and so on). We ran a real AI agent through it: it paid within limits, was blocked when it went over the cap, and left a payment waiting for approval. The full transcript is in the repo.
Built to work with any ERC-20, including USDG. The live demo uses a test token. Testnet only, not audited.
Live site: https://trybursar.vercel.app