Overview
What your agents did in the last 24 hours.
Free tier usage
Audit log
Every decision, hash-chained and tamper-evident.
| Status | Verb | Principal | Receipt | Time |
|---|---|---|---|---|
| Loading… | ||||
Principals
The identities your API keys belong to — teams, services, agents. Disable a principal to pause all of its keys at once, or delete one to retire it for good. Every change is written to the audit log.
| Name | Status | Keys | Created | |
|---|---|---|---|---|
| Loading… | ||||
API keys
Keys your agents use to call Writ. Revoking a key kills it instantly. Writ stores only a hash, so a key is shown once.
| Name | Key | Principal | Created | Last used | Receipts | |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Sponsor token
The human half of your credentials: it approves agent actions (grants) and operates the kill switch. Shown once when issued — Writ stores only a hash. Lost it? Rotate it here.
Security
An authenticator app is required before any new API key can be created or the sponsor token rotated. A session alone isn't enough: anything that can read your email — including your own agents — could otherwise mint credentials.
Team
Invite teammates into this tenant: they sign up with your invite code and share this tenant’s policy and audit log. Each member gets their own API key; the sponsor token is never shared.
Policy
Which verbs require a grant before the write. Changes apply to the next check.
Verb policies
Loading…
Default mode
What happens when a verb has no explicit policy.
require_grant Require grant (fail closed) — needs a live grant, else DENY. This default is fixed and not configurable.Per-principal overrides
The top policy layer: a principal's override beats the environment override, which beats the tenant default. Verbs the principal doesn't set inherit downward — the badge shows where each verb's effective mode comes from. Overrides on disabled or deleted principals are inert.
Revoked principals
A revoked sponsor + agent is DENIED on every check, even under an allow policy.
| Principal | Reason | Revoked | |
|---|---|---|---|
| Loading… | |||
Revoke or reinstate
Read-only when you’re signed in by email. Revoking and reinstating is a sponsor action: it needs your tenant’s sponsor token (writ_sp_…, shown once at signup), so a stolen browser session can’t flip the kill switch. Use writ revoke / POST /v1/revoke, or paste the token below (kept in this tab’s memory only).
Billing
The audit log is the meter. Every receipt counts.
Current plan
Metered billing is $1 per 1,000 receipts over the 10,000/month free allowance, via Stripe. Card details go to Stripe’s hosted checkout and never touch Writ.
How billing works
| Free | 1,000 receipts/month, no card required |
| Metered | $1 per 1,000 receipts over the free allowance, billed monthly |
| Enterprise | Production verbs on customer systems, custom policy. Talk to us |