Commerce & finance · wired today
Drive Paddle with governed agents
Money data demands the strictest governance of anything agents touch. The Paddle connector is one of 205 executable connectors and gives agents 4 read-only tools, with the credential held in the vault and every call receipted.
What agents can run against Paddle
| Tool | What it does |
|---|---|
list_products | List Paddle catalogue products, optionally filtered by status |
list_prices | List Paddle prices, optionally filtered to one product or by status |
list_transactions | List Paddle transactions, optionally filtered by customer or status |
list_customers | List Paddle customers, optionally filtered by exact email address or status |
Every tool above is read-only. Write surfaces ship only after live testing, and always behind approval gates.
What the Paddle connector needs
You provide API key, environment from your Paddle account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.
Where to get it: Paddle's own API documentation ↗ covers creating and scoping the credential.
How proven is this?
This connector was blind shape-proven against the real Paddle API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.
Paddle integration FAQ
What can Quox agents do with Paddle?
Agents can run 4 read-only tools against Paddle: list products, list prices, list transactions, list customers. Every call is receipted in the evidence trail.
What does the Paddle integration need?
You provide API key, environment from your Paddle account; Quox sends it as a bearer token. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.
Do agents see my Paddle credentials?
No. Credentials live encrypted in the Quox vault and are resolved server-side at call time. Agents invoke tools; they never receive the underlying secret.
How proven is the Paddle connector?
This connector was blind shape-proven against the real Paddle API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.