Approve

Consent your usersactually understand.

One hosted screen where people say yes to your agent: what it can buy, how much, and at which stores. You get a token that can't spend a cent more.

Get API keys Read the guide

What the user decides.Once, in plain language, on their own device.

limits

How much, and when to ask

A per-order cap, a daily cap, and an amount above which they confirm each order themselves. You suggest them; they choose.

stores

Which accounts to connect

Major retailers connect through Harbor for Chrome, so orders land in the user's own account with their saved address and payment.

scope

What your app can do

Look up prices, prepare orders, and place them within the limits. Never see passwords, never exceed a limit, never skip a confirmation.

Four steps, like Plaid Link.If you've integrated Link, you already know this.

Create an approval token

Your server calls POST /v1/approval_tokens with your user's id and suggested limits.

Open Harbor Approve

A popup, a tab or a webview. Hosted by Harbor, so there's nothing to build.

Get a public token

By postMessage or your redirect URL, the moment the user says yes.

Exchange it

Your server swaps it for a user_token that buys within the user's rules.

enforced on every order

Limits that hold against the real total.

Harbor checks each rule against the store's final number, with shipping and tax, before anything is placed. Not the price your agent saw ten minutes ago.

  • Over the per-order cap: the checkout stops with a clear reason.
  • Over the confirm amount, or the price moved: the user confirms it themselves.
  • Over the daily cap: Harbor refuses to place it.
approval_tokens
curl https://www.useharbor.io/v1/approval_tokens \
  -H "Authorization: Bearer $HARBOR_KEY" \
  -H "content-type: application/json" \
  -d '{
    "client_user_id": "user_123",
    "rules": {
      "max_per_order": 15000,
      "max_per_day": 30000,
      "confirm_above": 7500
    },
    "merchant_ids": ["target", "allbirds"]
  }'

# → { "hosted_url": "https://www.useharbor.io/approve?token=…" }

Built for trust on both sides.Your users know what they agreed to. You know what you're allowed to do.

Ask once.Then let your agent shop.