Skip to main content

crewai-pqsafe

PyPI License: MIT

Drop post-quantum signed payments into any CrewAI agent in one line — FIPS 204 (ML-DSA-65) enforced.

Part of the PQSafe AgentPay ecosystem. Built on pqsafe-agent-pay.


What it does

crewai-pqsafe provides PQSafePaymentTool, a CrewAI-compatible tool that gives your agents the ability to make payments authorized by a signed SpendEnvelope — a post-quantum (ML-DSA-65, NIST FIPS 204) token issued by the human wallet owner. Add the tool to any CrewAI Agent and every pqsafe_pay call is signature-verified and policy-enforced before any payment is dispatched.

No long-lived API keys in your crew definition. No credentials to rotate. The envelope constrains exactly what the agent can spend, to whom, via which rail, and for how long — and it cannot be forged or exceeded.


Install

pip install crewai-pqsafe

Quickstart

from crewai import Agent, Crew, Task
from crewai_pqsafe import PQSafePaymentTool

payment_tool = PQSafePaymentTool()

finance_agent = Agent(
    role="Finance Agent",
    goal="Process approved supplier payments autonomously",
    backstory="You pay invoices that have been pre-authorized via PQSafe SpendEnvelopes.",
    tools=[payment_tool],
)

That's it. The finance_agent can now call pqsafe_pay on any task that requires a payment.


Full crew example

import json
from crewai import Agent, Crew, Task
from crewai_pqsafe import PQSafePaymentTool

payment_tool = PQSafePaymentTool()

# Agent with payment capability
finance_agent = Agent(
    role="Finance Agent",
    goal="Process approved supplier payments",
    backstory="You pay invoices pre-authorized via PQSafe SpendEnvelopes.",
    tools=[payment_tool],
)

# Task — envelope is injected into the description at runtime
pay_invoice = Task(
    description=(
        "Renew the Perplexity Pro subscription at perplexity.ai — $20 USD. "
        "Use this signed envelope: {envelope_json}"
    ),
    agent=finance_agent,
    expected_output="Payment confirmation with txId, status, and rail",
)

crew = Crew(agents=[finance_agent], tasks=[pay_invoice])

# Kick off — inject the pre-signed envelope issued by the wallet owner
signed_envelope = {
    "envelopeJson": '{"version":1,"issuer":"pq1...","agent":"finance-crew-v1",...}',
    "signature": "deadbeef...",
    "dsaPublicKey": "cafebabe...",
}
result = crew.kickoff(inputs={"envelope_json": json.dumps(signed_envelope)})
print(result)
# Payment successful. txId=airwallex-tx-abc123 status=success rail=airwallex

How it works

  1. A human wallet owner issues a signed SpendEnvelope using pqsafe-agent-pay (or the PQSafe wallet). The envelope encodes: agent ID, max amount, allowed recipients, currency, and validity window — all bound by an ML-DSA-65 post-quantum signature.
  2. The envelope is passed into the crew as an input variable. It travels with the task context, not stored in the tool.
  3. When the agent decides to pay, it calls the pqsafe_pay tool with envelope_json, recipient, amount, and optional memo.
  4. PQSafePaymentTool verifies the post-quantum signature server-side, enforces all policy constraints, and routes the payment to the cheapest available rail (Airwallex, Wise, Stripe, USDC/Base, or x402).
  5. The tool returns a string: Payment successful. txId=<id> status=<status> rail=<rail> — included in the task output.

What you get

  • One-line integration — tools=[PQSafePaymentTool()] on any CrewAI Agent
  • FIPS 204 ML-DSA-65 enforcement — every payment is quantum-resistant by default
  • Policy guardrails — amount ceiling, recipient allowlist, and time window enforced before dispatch; the agent cannot overspend
  • Multi-rail routing — Airwallex (live sandbox), Wise, Stripe, USDC on Base, x402
  • No credentials in crew code — only the short-lived signed envelope is required at runtime
  • Compatible with any CrewAI crew — hierarchical, sequential, or custom process types

Tool parameters

Parameter Type Required Description
envelope_json str Yes SignedEnvelope serialized as JSON
recipient str Yes Recipient address (IBAN, crypto addr, domain, etc.)
amount float Yes Amount in the envelope's currency (> 0)
memo str No Human-readable payment reference

Returns a string: Payment successful. txId=<id> status=<status> rail=<rail>


Part of PQSafe AgentPay


Links


License

MIT

Metadata

Release files for crewai-pqsafe 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for crewai-pqsafe 0.1.1
File Size Uploaded
crewai_pqsafe-0.1.1.tar.gz 6.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for crewai-pqsafe 0.1.1
File Interpreter ABI Platform
crewai_pqsafe-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 11.9 kB

Release files / crewai_pqsafe-0.1.1.tar.gz

Download URL crewai_pqsafe-0.1.1.tar.gz
Size 6.2 kB
Tags Source
SHA-256 checksum
How to use checksums
69cd0482751640b319afce8e936cc7aa44ea9207e07d1910200956db4eb69c52
BLAKE2b-256 checksum
How to use checksums
dbe06fcd9fb21c44457f4c57079970c8f93e990b40eef64e922f39bf16c909a0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / crewai_pqsafe-0.1.1-py3-none-any.whl

Download URL crewai_pqsafe-0.1.1-py3-none-any.whl
Size 5.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0cd0b5facb7dfa6ed47df162deae4518969a16feed8cf90821f720246edbffd6
BLAKE2b-256 checksum
How to use checksums
e2ff984c5a14e86562d42cb040d17d1eda05219f7ce04c0f1444b33f0f9cb00f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page