One small contract: COLVO sends the customer, context and conversation; your agent answers with JSON and proposes actions back with a per-test key.
{ "reply": "…" } — or any shape, with a reply path like data.answer.colvo.operations_url with colvo.agent_key.POST {colvo.operations_url}
Authorization: Bearer {colvo.agent_key}
Idempotency-Key: {colvo.source_request_id}:refund
Content-Type: application/json
{ "mandate_id": "{colvo.mandate_id}",
"source_request_id": "{colvo.source_request_id}",
"action": "refund.create",
"parameters": { "payment_id": "pi_01", "amount_minor": 5000, "currency": "eur" } }The agent never holds your payment keys — it proposes, COLVO decides and executes.
Node, Python, Go — and our SDKs for Node and Python do the propose call for you.
Set a reply path or let COLVO auto-detect common shapes.
In Guard your backend builds the same request with a real mandate.
No — COLVO only calls public HTTPS hosts; private and metadata addresses are blocked. Use a tunnel for local testing.
30 seconds per call; aim for a few seconds.
Reference: Connect your agent · Guard API
Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.