Back to scoreboard

Metric contract · rolling 30d

How AgentPay calculates safety refusals.

Execution requests that failed closed before AgentPay allowed the purchase.

Current value

observed

13

All fail-closed refusals, including invalid capabilities

last 30d

Formula

COUNT(fail-closed spend decisions in the rolling window)

AgentPay counts the fail-closed decisions returned by the KPI snapshot. The aggregate includes verified unsafe requests and operational refusals, so the scoreboard deliberately calls them refusals rather than attacks.

Source
kpi_snapshot.attacks_blocked
Target
Observed for context; not treated as a success target
Window
Rolling 30 days
Refresh
Every 60 seconds

Included

  • Signed-intent mismatches and replay attempts.
  • Invalid signatures, payment proofs, and capabilities.
  • Policy, configuration, and pre-payment rail refusals.

Not counted

  • Authorized executions.
  • Post-payment outcomes requiring incident reconciliation.
  • An assumption that every refusal was malicious.

How to read the status

Observed

Refusals were measured; use the classified feed to understand why.

Operational warning

Repeated capability or configuration failures may indicate broken integration rather than attack traffic.

Not measured

Telemetry is unavailable or no decision sample exists.

What this number cannot prove

A high refusal count is not automatically good or bad. It may show a control working, malformed requests, retries, or an integration problem; the reason classification supplies the missing context.

Other calculations