DEV Community

Omar Baró
Omar Baró

Posted on

BOLT PayFlow Guard: Open AI That Cannot Spend Without You

Hacktoberfest Weekend Challenge: Build for a Friend Submission 🤝

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend.

What I Built

I built BOLT PayFlow Guard, a governed AI payment workflow designed around one rule: AI can propose, but a person must authorize the consequential action.

I built it for a close friend, who uses AI tools but does not want an AI agent to have silent authority over money. The problem is not whether AI can understand a payment request; it is whether that recommendation can become an irreversible action without explicit human control.

A user can write a natural-language request such as:

Pay 1 EUR for a test purchase.

The local AI turns that into structured JSON with whether a payment is recommended, the proposed amount, and the reason.

But nothing is paid. A separate approval gate blocks the payment path until explicit human authorization exists.

Demo

The demo shows the complete decision flow: intent, AI recommendation, blocked state, human approval, and the PayPal Sandbox path.

Code

GitHub logo ondmindmanagement-hub / bolt-payflow-guard

Governed AI payment workflow prototype using PayPal Orders API

BOLT Payflow Guard

BOLT Payflow Guard is a governed AI-to-payment workflow prototype for the PayPal AI Hackathon.

Flow

  1. A local AI model running in Ollama analyzes a natural-language payment request and returns a structured recommendation. The AI is advisory only and cannot execute payments.
  2. A separate BOLT approval gate blocks the payment step unless explicit human approval is present.
  3. After approval, the PayPal module authenticates with OAuth 2.0 and creates a PayPal Orders v2 Sandbox order.

AI integration

The demo uses Ollama with qwen2.5:7b by default, so the AI part can run locally without cloud credentials.

Run:

npm run ai -- "Pay 1 EUR for a test purchase"

The model returns JSON with should_pay, amount_eur, and reason.

PayPal integration

Requires PayPal Sandbox credentials. Keep them in environment variables only:

  • PAYPAL_CLIENT_ID
  • PAYPAL_CLIENT_SECRET
  • optional PAYPAL_BASE_URL (defaults to the Sandbox API)

Then explicitly approve the sandbox transaction with BOLT_APPROVED=1 and…

https://github.com/ondmindmanagement-hub/bolt-payflow-guard

How I Built It

The open-source AI core is Ollama running Qwen 2.5 7B locally.

The Node.js AI module sends the natural-language request to a local Ollama endpoint and asks the model to return structured JSON containing should_pay, amount_eur, and reason.

The model is advisory only. It never receives PayPal credentials and it cannot execute a transaction.

A separate BOLT approval layer evaluates whether explicit authorization exists. Without approval, the workflow stops before contacting PayPal. With approval, the payment module can authenticate with PayPal OAuth 2.0 and create an order using the PayPal Orders v2 Sandbox API.

The architecture is intentionally simple:

natural-language intent → local open model → structured proposal → human approval gate → PayPal Sandbox

That separation keeps AI reasoning independent from financial authority.

Why Does Open Innovation Matter?

Running Qwen locally through Ollama changes the trust model.

The payment request can be interpreted without sending the user's prompt to a closed hosted model. The model can be swapped, inspected, run offline, or replaced with another open-weight model without changing the governance layer.

With local inference:

  • prompts can remain on the user's machine,
  • there is no AI API key to manage,
  • inference can keep working without a cloud model provider,
  • the model can be changed without redesigning the workflow,
  • and payment credentials remain completely separate from the AI process.

Open AI makes the reasoning layer portable. Human approval keeps the authority layer explicit.

What I Learned

The useful boundary is not “AI versus no AI.” It is recommendation versus authority.

An AI system can automate interpretation and planning while still requiring a person to approve the final consequential step. That pattern can extend to spending limits, role-based approvals, risk checks, multi-step authorization, and other high-impact workflows.

Built With

  • Ollama
  • Qwen 2.5 7B
  • Node.js
  • PayPal Orders v2 Sandbox API
  • PayPal OAuth 2.0
  • Human-in-the-loop approval gating

Top comments (0)