# Basis Theory Agent Skills

Customer-facing markdown guidance for coding agents working on Basis Theory integrations.

## How to use

The links in this file are root-relative. Resolve them against the origin that served this file so production docs and PR previews both point to the matching hosted skill files.

1. Start with [`bt-start`](/agent-skills/skills/bt-start/SKILL.md) unless you already know the exact skill you need.
2. Read the selected `SKILL.md` before changing code; every skill is self-contained and carries the shared safety rules.
3. Treat Basis Theory public docs as the source of truth for product behavior.
4. Keep customer ownership clear: PSP accounts, credentials, compliance decisions, production rollout, and application code remain customer-owned.
5. Never request, echo, store, or commit real credentials. Use placeholders and sandbox data.
6. If live-looking credentials, live cardholder data, or production secrets appear, stop mutation work and require rotation/revocation before continuing.
7. Default to test tenants and PSP sandboxes; do not run production charges, refunds, card reveals, migrations, or data moves unless the user explicitly asks and the plan names safeguards, rollback, and customer approval.

## Skills

- [`bt-start`](/agent-skills/skills/bt-start/SKILL.md) — route a vague Basis Theory request to the right skill and mode.
- [`bt-plan`](/agent-skills/skills/bt-plan/SKILL.md) — plan vague, architectural, repo-wide, or PCI-scope-changing work.
- [`bt-integration-design`](/agent-skills/skills/bt-integration-design/SKILL.md) — draft customer-facing, sign-off-ready integration designs from agreed goals and decisions.
- [`bt-collect`](/agent-skills/skills/bt-collect/SKILL.md) — collect cards, bank accounts, or sensitive data into tokens or token intents.
- [`bt-payments`](/agent-skills/skills/bt-payments/SKILL.md) — process card payments through PSPs using Basis Theory tokens or Proxy.
- [`bt-proxy`](/agent-skills/skills/bt-proxy/SKILL.md) — use Proxy for outbound detokenization or inbound sensitive-data capture.
- [`bt-tokens`](/agent-skills/skills/bt-tokens/SKILL.md) — model token schemas, aliases, masks, fingerprints, and opaque references.
- [`bt-architecture`](/agent-skills/skills/bt-architecture/SKILL.md) — decide tenants, applications, keys, permissions, and primitive boundaries.
- [`bt-migrate`](/agent-skills/skills/bt-migrate/SKILL.md) — plan card and vault migrations with customer-owned execution, rollback, and proof gates.
- [`bt-production`](/agent-skills/skills/bt-production/SKILL.md) — prepare test-to-production readiness, keys, webhooks, allowlists, and monitoring.
- [`bt-test-debug`](/agent-skills/skills/bt-test-debug/SKILL.md) — debug by proving the failure boundary with request, response, and environment evidence.
- [`bt-3ds`](/agent-skills/skills/bt-3ds/SKILL.md) — implement 3DS/SCA challenge, redirect, MIT, and SDK flows.
- [`bt-wallets`](/agent-skills/skills/bt-wallets/SKILL.md) — collect and process Apple Pay, Google Pay, and other wallet flows.
- [`bt-card-lifecycle`](/agent-skills/skills/bt-card-lifecycle/SKILL.md) — design stored-card lifecycle, recurring-payment health, refresh, and retry strategy.
- [`bt-network-tokens`](/agent-skills/skills/bt-network-tokens/SKILL.md) — enroll, store, and use network tokens for recurring card programs.
- [`bt-account-updater`](/agent-skills/skills/bt-account-updater/SKILL.md) — handle account updater enrollment and updated-card lifecycle.
- [`bt-reactors`](/agent-skills/skills/bt-reactors/SKILL.md) — use Reactors for secure programmable logic when Proxy is not enough.
- [`bt-pii`](/agent-skills/skills/bt-pii/SKILL.md) — vault and govern PII, documents, reveal, masked display, and access controls.
- [`bt-issuing`](/agent-skills/skills/bt-issuing/SKILL.md) — display issued cards, reveal PAN/CVC safely, and design cardholder access.
- [`bt-agentic`](/agent-skills/skills/bt-agentic/SKILL.md) — build Agentic Commerce API flows and AI-agent payment experiences.
- [`bt-psp-orchestration`](/agent-skills/skills/bt-psp-orchestration/SKILL.md) — build customer-owned PSP adapters and portability plans.

## Shared references

Some skills link to supporting markdown under `/agent-skills/skills/_shared/` or their own `references/` folder. Read only the references that the selected skill calls out for the current task.
