← All guides

Locus product guide · Updated

Control AI Agent Tool Spending

Control agent tool costs with several independent limits: a funded credit balance, an account spend cap, the right credential scope, permitted tools, and explicit ceilings for live quotes. Alerts help you respond, while hard limits decide whether new spending can proceed. Review committed work as well as completed charges.

Match each control to the risk it addresses

A single budget number does not answer every question. Decide which account may pay, which operations may run, and the maximum you will authorize for an uncertain price.

Match each control to the risk it addresses
ControlPurposeLimit to remember
Prepaid balanceFund eligible usage before executionAuto-reload may replenish it if configured
Account monthly spend capStop new spending at an account thresholdIn-progress or completed work can still be charged
Tool and credential scopeRestrict which operations a caller can useAn allowed operation still has its own inputs and prices
Live-quote ceilingReject a quote above the authorized maximum before dispatchChoose a ceiling appropriate to the task
AlertsNotify a person of spend or low balanceA notification alone does not block spending
Reload limitConstrain automated credit replenishmentIt is separate from a spend cap

Give each runtime the access it needs

Interactive MCP clients use browser OAuth. Unattended enterprise agents can use scoped Agent Connections with supported expiry and spending limits. A tenant secret belongs on a trusted server and should not be the default credential placed in an autonomous agent runtime.

For customer-facing platforms, verify that each call is attributed to the intended end user. Test a disallowed operation as well as an allowed one. A connection that works is not necessarily a connection whose permissions match the intended scope.

Authorize uncertain prices explicitly

Tools can be fixed-price, response-priced, or live-quoted. Inspect the price or charging basis before execution. For supported live-quoted calls, a hard max_charge_credits ceiling prevents dispatch when the quote exceeds the authorized amount.

Do not multiply a sample price by a large batch and treat it as a guarantee. Tokens, pages, generations, and per-result pricing can depend on the input or returned output. Bound task size and inspect receipts from representative requests before scaling a workflow.

Make recovery deliberate

If a call is rejected for insufficient credits or access, correct that condition before retrying. Repeatedly issuing the same rejected request does not create permission or funds. Keep retries bounded and reuse the same idempotency key for the same logical operation.

Investigate the receipt when a streaming client disconnects: accepted upstream streams can remain charged. Stopping the client, revoking access, or lowering a cap is not a promise to cancel work already accepted by the provider.

Frequently asked questions

Is a low-balance email a spending limit?

No. It is an alert. Use the documented hard cap, balance, and authorization controls to govern new spending.

Will a timeout always refund the call?

No. Non-streaming failures before success release reservations, while accepted streams can remain charged after a later timeout or disconnect. Check the operation and receipt.

Implementation references

Use these first-party references for current request contracts and account requirements. Tool availability, prices, and negotiated terms can change.

Related guides