# Saifuro documentation **Start here** - [Introduction](/): What Saifuro is, who it is for, and what it deliberately does not do. Start here. - [Quickstart](/get-started/quickstart): How an evaluation starts and what the first month looks like. - [Use cases](/get-started/use-cases): Where agent spending shows up, and what Saifuro does in each case. **Core concepts** - [Core concepts](/concepts/core-concepts): Mandate, decision, and record: the three objects every Saifuro event is made of. - [How it works](/concepts/how-it-works): The path a single spend request takes, from agent intent to audit record. - [Escrow](/concepts/escrow): Funds held against a condition instead of paid straight through, and who holds them. - [Decision codes](/concepts/decision-codes): Reference table of every verdict Saifuro returns and what happens next. - [Protocols and standards](/concepts/protocols): The five rails a decision can be tagged with, what support means precisely, and what we are not. **Guides** - [Guides](/guides): Five recipes, each one a task somebody actually has to do: first authorization, sandbox, seller-side checks, escrow, and the day you switch on enforcement. - [Your first authorization](/guides/first-authorization): From an issued key to a signed verdict, and back out through deny, review and revoke — all in the sandbox. - [Test in the sandbox](/guides/sandbox): Same API, sandbox keys, nothing settles — and how to force every verdict on purpose. - [Accept a signed approval](/guides/accept-approvals): You sell to agents. Before you deliver, check the buyer's approval yourself — no Saifuro account needed. - [Escrow a deal end to end](/guides/escrow-deal): One agent buys from another: lock the funds, deliver, attest, and watch the contract settle it. - [Before you switch on enforcement](/guides/go-live): The checklist between observe mode and the first blocked payment. **Deploying** - [Getting access](/deployment/getting-access): How to get access to Saifuro, and why there is no public download. - [Observe mode](/deployment/observe-mode): Why every deployment starts by watching, not blocking. - [Pricing](/deployment/pricing): What Saifuro charges, how decisions and settled volume are counted, and what is not charged for. **Check it yourself** - [Verifying a verdict](/reference/verify-a-verdict): How a counterparty checks a signed verdict against the public key at verdicts.saifuro.com/.well-known/jwks.json, without a Saifuro account. - [Signing keys and rotation](/reference/signing-keys): What is in the public key set today, how rotation works, and what your verifier must do when it meets a kid it does not know. - [Limits of a signed verdict](/reference/verdict-limits): The exact boundary of the primitive: what the signature covers, and the two fields it does not. **Security and trust** - [Security](/reference/security): How Saifuro handles data, and how certifications are reported. - [Known gaps](/reference/not-built-yet): Gaps in the product an integrator would otherwise find in the first hour, and where the plan to close each one lives. - [Documentation scope](/reference/portal-gaps): An inventory of the gaps in these docs, with the reason for each. Written by us so you do not have to find them. - [Subprocessors](/reference/subprocessors): Third parties that process data on our behalf, and what each one sees. **Help** - [Glossary](/reference/glossary): Canonical definitions of the terms used across Saifuro documentation. - [FAQ](/reference/faq): Questions that come up on the first technical call. - [Support](/reference/support): Who to contact, and what to expect. ## API reference **Basics** - [Overview](/api/overview): Base URL, what every endpoint shares, and a map of this section. - [Environments](/api/environments): Sandbox and production are the same API on different keys. Where they differ, stated exactly. - [Authentication and keys](/api/authentication): Two classes of key, what each one may do, how they are stored, and what rotation actually does. - [Errors and status codes](/api/errors): The error envelope, the seven codes, and four behaviours that surprise people the first time. - [Pagination](/api/pagination): Cursors, their lifetime, and the one rule that invalidates a cursor mid-walk. - [Rate limits](/api/rate-limits): A sliding window per key, the headers that carry the numbers, and why the numbers are not printed here. - [Versioning and deprecation](/api/versioning): What may change under /v1 without warning, what may not, and the notice period we have never yet had to use. - [Object ids](/api/object-ids): Every prefix the system emits, and what to store. **Endpoints** - [Agents](/api/agents): Register agents, issue and rotate their keys, disable them. - [Mandates](/api/mandates): Create, read, and revoke an agent's authority to spend. - [Authorizations](/api/authorizations): Create a spend authorization, read the decision, and resolve reviews. - [Escrows](/api/escrows): Create a conditional deal, attest delivery, and read its state. Release is the contract's job, not an endpoint. - [Webhooks](/api/webhooks): Event delivery signed with the same key set as verdicts — verify a webhook the way you verify an approval. - [Usage and exports](/api/exports): Aggregated usage for dashboards, and the full decision log for your controller. Every page is also available as Markdown: add .md to its URL, for example https://docs.saifuro.com/api/overview.md