AI agents
Your agent pays from its own wallet, up to a daily cap you set
Connect the agent you already run, give it a stablecoin wallet with hard ceilings or a card that holds only what you loaded, and keep the signature on the human side.
It proposes. You sign
Not a setting anyone can turn off. A new agent starts observing, and every write waits in the queue until you let it work.
A payment to Modal for 2,840 USDC came here because it is over the agent's daily cap; a Datadog charge of 410 dollars to file under Software came here because the agent that spotted it is still observing. Accept or reject; nothing in this queue expires on its own, however long it waits.
1.20 USDC
0.12 USDC
62.40 USDC
The drawer of one agent: what it has done, the spaces it reaches, its card, its wallet and its keys. Freezing stops the card and the wallet in the same click, and the history stays where it is.
A key is shown once and never again; revoking it takes effect on the agent's next call, and the agent's history stays under its name.
Its own money, with a fence around it
A wallet whose balance is the budget, a card whose balance is the fence, a ceiling per call; each refusal is logged with its reason.
An EVM address and a Tron address, and the balance on them is the agent's whole budget: nothing stands behind it, so no mistake in any rule can spend more than you put in. Two ceilings sit beside it, one per request and one per day, and until both are set the agent buys nothing.

The balance is the fence: what you loaded is all it can spend. A new card has no merchant rules or ceilings, so load only what the agent may spend; over the balance is declined.
The page answers 402 with a price, the agent pays in USDC from its own wallet, and the content arrives. Over the per-request ceiling is refused, not queued, because the other side is holding a connection open; every call leaves a receipt behind.
Three ways in, one set of rules
Connect it observing, widen it when it earns that. Every call is checked against the grant, so it never does more than you could.
Read the books and propose, pay by card, or pay in crypto: the choice decides what the drawer shows, not what the agent may do. Every permission still comes from the access you give it afterwards, and no role can sign a payment.
A Claude connector, Cursor, VS Code, Zed, Windsurf or the terminal reach the same server; the first question sends you to Orla's own consent page to tick which spaces it may reach.
Where an agent can spend it
Services that take a machine's payment without an account or an API key, with the price, the network and the source on every row.
What it refuses without you
Rules in the code, not defaults that someone can change
Never
- Signing a payment
- It proposes, and a person signs; no role and no setting changes that.
- Releasing an approved payment
- Not by the agent that proposed it, and not by any other.
- Widening its own limits
- A change to its grant is a proposal in the same queue as everything else.
- Paying an address it read in a document
- A send goes only to an address the space already trusts, and only a person ever writes to that book.
- Exporting its key
- Shown once at creation, to nobody afterwards.
Only you
- Trusting a new address
- Written into the space's own address book by a person.
- Withdrawing the wallet
- The balance comes back to you on your signature.
- Setting the two ceilings
- Per request and per day; unset means closed, not open.
- Opening a host
- The agent can search the catalogues and ask; only your Allow puts a host on its list.
- Changing where a host is paid
- The first payment pins the address; a new one counts only after you confirm it by hand.
- Freezing it
- The card and the wallet stop in the same click, and the history stays.
Questions
Where an agent's limits sit
Can an AI agent sign a payment?
No. It proposes and a person signs, and that is not a setting anyone can turn off, including the person who owns the space. A fresh agent starts in observation, where every write it tries becomes a proposal rather than an entry.
What stops an agent from overspending?
Its wallet is its whole budget: nothing stands behind the balance, so no mistake in any rule can spend more than you put in. Sends go only to addresses the space already trusts, anything over the daily cap waits for you, and freezing it stops the card and the wallet together, in the same single click. A card spends only the balance you loaded onto it, and a payment over that balance is declined.
What stops an agent from paying the wrong service?
It pays only hosts on a list a person keeps, and an empty list is a closed door. The agent can search the catalogues and ask for a host, but only your Allow adds it. The first payment to a host pins the address that host is paid at; a later quote naming another address is refused until you confirm the change yourself, checked against the host's own documentation and never against the request.
How does an agent connect to Orla?
Through a Claude or ChatGPT connector, an MCP server, the CLI, an n8n flow or your own code over the API. It never does more than you could do yourself, recomputed on every call, and every cent it spends carries its name in the books.
See it on your own books
Thirty minutes: we connect an account, drop a real bill in, and close a month together.