One hosted screen where people say yes to your agent: what it can buy, how much, and at which stores. You get a token that can't spend a cent more.
A per-order cap, a daily cap, and an amount above which they confirm each order themselves. You suggest them; they choose.
Major retailers connect through Harbor for Chrome, so orders land in the user's own account with their saved address and payment.
Look up prices, prepare orders, and place them within the limits. Never see passwords, never exceed a limit, never skip a confirmation.
Your server calls POST /v1/approval_tokens with your user's id and suggested limits.
A popup, a tab or a webview. Hosted by Harbor, so there's nothing to build.
By postMessage or your redirect URL, the moment the user says yes.
Your server swaps it for a user_token that buys within the user's rules.
Harbor checks each rule against the store's final number, with shipping and tax, before anything is placed. Not the price your agent saw ten minutes ago.
curl https://www.useharbor.io/v1/approval_tokens \ -H "Authorization: Bearer $HARBOR_KEY" \ -H "content-type: application/json" \ -d '{ "client_user_id": "user_123", "rules": { "max_per_order": 15000, "max_per_day": 30000, "confirm_above": 7500 }, "merchant_ids": ["target", "allbirds"] }' # → { "hosted_url": "https://www.useharbor.io/approve?token=…" }
Stores are connected in the user's own browser. Payment stays with the store and the user's wallet.
How Harbor handles data for developersStore the user token like any credential. It's scoped to your key's environment and to the rules the user chose.
Read the Approve guide