At 22:11:19 UTC on 22 September, a procurement agent asked a GPU seller for 2,000 GPU-hours at $2.50 each. That's $5,000. Its company had allowed it $500 per order.
The seller asked Delegus before taking payment. The answer came back as a signed no, with the reason AMOUNT_EXCEEDS_AUTHORITY. The seller returned HTTP 403 to the agent and never called Stripe. The count of Stripe calls in the log stayed at 1: the one earlier, allowed payment.
This post walks through the whole run that moment came from, step by step.

The setup#
The run is a recording of a real run in Stripe test mode, with example companies. The Delegus side is the reference engine running in-process with an in-memory store, not the hosted production service. The protocol checks are the same ones; the run shows them working end to end with a real payment processor.
- The company: Northwind Robotics, identified as
did:web:northwind.example. - The agent: Northwind's procurement agent, with its own key.
- The permission: one grant from Northwind: purchases up to $500.00 each, in USD, only for
gpu-hours/**anddatasets/**, valid for 30 days. - Seller one: Acme GPU. It takes cards, through the Machine Payments Protocol and Stripe.
- Seller two: Globex Data. It bills a net-30 invoice, with no payment processor at all.
Neither seller has met the agent before. Both make the same single check.
Step by step#
1. A $250 GPU order, paid by card. The agent asks Acme for 100 GPU-hours. Acme answers 402 Payment Required and names the price. The agent pays. Before charging, Acme checks the agent's permission: allow. Stripe charges the test card. Two receipts come back. Stripe's says what was paid. Delegus's says who authorized it, and under which grant.
seller 22:11:17 Acme GPU purchase gpu-hours $250.00 delegus ALLOW stripe: charged
receipt Payment-Receipt status success, method stripe (what was paid)
receipt Delegus-Receipt drc_01M35JRPFWCHZDDT15RRFT2VZ8 (who authorized it, under which grant)2. A $180 dataset license, on invoice. Same agent, same permission, different seller and a different way to pay. Globex checks: allow. Globex issues a net-30 invoice. No card is involved.
3. The $5,000 order. Over the $500 limit. Acme checks before taking payment: deny, AMOUNT_EXCEEDS_AUTHORITY, check P19. The agent gets a
- Stripe is never called.
seller 22:11:20 Acme GPU purchase gpu-hours $5,000.00 delegus DENY AMOUNT_EXCEEDS_AUTHORITY (P19) stripe: not attempted
stripe seller's Stripe calls 1 → 1 (no charge attempted)4. Something the permission doesn't cover. The agent tries to buy a model license ($120) from Globex. Models aren't in the grant: deny, RESOURCE_NOT_AUTHORIZED, check P20. No invoice is issued.
5. The company revokes the permission, once. At 22:11:22.449 UTC, Northwind revokes the grant. The revoke returns only once every later check will see it.
6 and 7. The same orders again. The agent sends the exact orders that were allowed in steps 1 and 2, each with a fresh proof. Acme checks: deny, AUTHORITY_REVOKED. Globex checks: deny, AUTHORITY_REVOKED. No charge, no invoice. One revoke, and both sellers refuse, on both ways to pay.
8. Anyone can re-check it. The receipt from step 1 is re-verified offline, from the receipt itself, the grant, the proof and the action: signature valid, decision reproduced.
- Step 1Acme GPU · cardALLOWcharged $250.00
- Step 2Globex Data · invoiceALLOWinvoiced $180.00
- Step 3Acme GPU · cardDENY, over the limitno, Stripe not called
- Step 4Globex Data · invoiceDENY, not in the grantno invoice
- Step 5(Northwind)revoked
- Step 6Acme GPU · cardDENY, revokedno, Stripe not called
- Step 7Globex Data · invoiceDENY, revokedno invoice
What the log shows at the end#
One Stripe payment, one invoice, four refusals. None of the refusals moved money. In the Stripe dashboard, the one payment carries the Delegus receipt id and its hash as metadata, so the payment record points to the decision that allowed it.
Why the order matters#
Every refusal here happened before the money. That's the point of checking authority at the seller rather than reviewing spend afterwards. By the time a card statement or an invoice exists, the question "was this allowed?" has become a dispute. Asked before the charge, it's a signed yes or no.
And the check didn't care how the money would move. The card seller and the invoice seller asked the same question, of the same permission, and got answers they can each keep.