There is no floating-point number anywhere in the money path.
Not in the request schema, not in the policy comparison, not in
the daily total, not in the audit row.
The wire format enforces it: amountCents
is validated as a positive integer, and the error string says so
in those words. A request carrying 50.00
is a 400 the builder can see, not a value that silently becomes
fifty cents or 4999.999999.
This is unglamorous and it is the single easiest way to lose
money in software. Currency in floats accumulates error the
moment you divide, and a permission layer that compares a
drifting number against a limit is a permission layer that
eventually lets the wrong thing through — or stops the right
one, which erodes trust faster.
The daily cap is per-currency and never converts. Adeia does not
fetch exchange rates, because a limit that changes with the
market is not a limit you set.
POST /actions
// what a float gets you
{ "amountCents": 50.00 }
400 Bad Request
amountCents must be a positive integer
// the only shape that is accepted
{ "amountCents": 5000,
"currency": "usd" }
201 Created
decision: allow