Agent spending controls

Spending controls that agents cannot talk their way past.

Limits live in the ledger and the card authorization path, not in a system prompt. When an agent hits one, a human decides.

AgentWallet is invite-only. Request access and we will follow up.

In short

Agent spending controls combine per-transaction, daily and monthly caps on spend-gated routes with approval policies and provider-specific card rules. Hard-cap failures cannot simply be approved away. Not every route is gated; generic x402.pay_url has only an optional per-call maximum.

How it works

Four layers, checked in order.

  1. Account

    Organisation-wide ceilings and approval policy.

  2. Principal

    Limits for everything a person or service delegates.

  3. Agent

    Per-transaction, daily and monthly USD caps.

  4. Card

    MCC, merchant, geography, channel, AVS and velocity rules at authorization.

  5. Decision

    Pass: money moves. Fail: approval_required, and a person approves or rejects.

Capabilities

Controls available today

Caps

Transaction, day, month

Enforced on gated agent routes: agent_purchase, agent_pay_via_x402, agent spends and agent payout tools. Operator-initiated payouts from the dashboard do not go through the agent approval gate.

Approvals

Human in the loop

Approval queue, summary counts and one-click approval links.

Cascade

Parent bounds

Account ⊃ principal ⊃ agent; children cannot exceed parents.

Card

Authorization rules

Allow or block lists and velocity per card.

Assist

Policy chat

Describe a policy in English and get a draft to review.

Audit

Decisions and ledger

Every approval, decline and ledger entry is recorded.

Use cases

Control patterns that work

Small autonomous, big supervised

Let agents spend up to $50 alone; anything above goes to a manager.

Monthly budgets per agent

Cap each workflow agent monthly so costs never surprise finance.

Category fences

Restrict a card to the categories a task legitimately needs.

Payout approvals

Require approval for every payout to a new recipient.

For developers

Handle approvals in code.

Treat approval_required as a normal state, not an error.

  • GET /api/approvals and GET /api/approvals/summary
  • POST /api/approvals/:id/decide
  • Approval links: GET/POST /api/approval-link/:token
  • Agents: agent_request_purchase_approval, agent_request_payout_approval
# Approve a pending request
POST /api/approvals/$APPROVAL_ID/decide
{ "decision": "approve", "reason": "Within Q2 budget" }

# Agent-side error you will see first
{ "code": "approval_required", "limit": "dailyUsd" }
Security & controls

Why server-side enforcement matters.

Coverage caveat: the generic x402.pay_url tool is not gated by caps, approvals or the ledger; it only honours an optional maxAmountAtomic. Withhold the x402:pay scope from agents that must stay within caps.

Prompt-proof

Model instructions cannot raise a limit.

Fail closed

Unknown or invalid policies are rejected.

Separation of duties

Agents request; humans with the right role decide.

Traceable

Approvals store who decided and when.

FAQ

Questions developers ask

What are agent spending controls?

Rules enforced by the payment platform that limit what an AI agent can spend and when a human must approve.

What happens when an agent exceeds a limit?

On gated routes the spend is not executed; the API returns approval_required and a person can approve or reject it. The generic x402.pay_url tool is an exception and is not cap-gated.

Can card rules and agent caps conflict?

Both apply. A charge must pass the agent caps and the card policy.

Who can use AgentWallet today?

Access is invite-only while we onboard teams. Request access from any page; sign-up is enabled per email or domain once you are approved.

Do you guarantee availability in my country or a specific settlement time?

No. Supported rails, currencies and timing depend on the underlying banking, card and payout partners for your account. We confirm what is available for your account during onboarding rather than promising it upfront.

Set limits your agents respect.

Request access and we will help you design your first policy.