Skip to content

AI agents

Your agent pays from its own wallet, up to a daily cap you set

Connect the agent you already run, give it a stablecoin wallet with hard ceilings or a card that holds only what you loaded, and keep the signature on the human side.

It proposes. You sign

Not a setting anyone can turn off. A new agent starts observing, and every write waits in the queue until you let it work.

Waiting for you

A payment to Modal for 2,840 USDC came here because it is over the agent's daily cap; a Datadog charge of 410 dollars to file under Software came here because the agent that spotted it is still observing. Accept or reject; nothing in this queue expires on its own, however long it waits.

research-agentTreasurer preset · its own wallet · never signsInside its fence
Daily ceiling150 USDCTermto Oct 31, 2026x402 hostsapi.firecrawl.dev, api.browserbase.comRequest ceiling2 USDCSpent today105.40 USDCWorst casethe deposit

api.firecrawl.dev · crawl02:22 AM · inside its policy1.20 USDC

api.browserbase.com · session02:22 AM · inside its policy0.12 USDC

GPU compute02:24 AM · inside its policy62.40 USDC

Freeze it, narrow it, send it back to observing

The drawer of one agent: what it has done, the spaces it reaches, its card, its wallet and its keys. Freezing stops the card and the wallet in the same click, and the history stays where it is.

research-bot · keysshown once, at creation · revoked on the next callNew key

orla_ak_7f3c…last used 02:22 AM todayActiveDelete

orla_ak_b91e…revoked Sep 2 · 340 calls kept under its nameRevoked

A new key is shown once and never again; the history stays under the agent, not the key

A key shown once, revoked on its own

A key is shown once and never again; revoking it takes effect on the agent's next call, and the agent's history stays under its name.

Its own money, with a fence around it

A wallet whose balance is the budget, a card whose balance is the fence, a ceiling per call; each refusal is logged with its reason.

A budget that cannot overdraw

An EVM address and a Tron address, and the balance on them is the agent's whole budget: nothing stands behind it, so no mistake in any rule can spend more than you put in. Two ceilings sit beside it, one per request and one per day, and until both are set the agent buys nothing.

The cards screen with the agent's card opened: what is left on it out of what was loaded, and every charge it made.
A card that cannot spend more than you loaded

The balance is the fence: what you loaded is all it can spend. A new card has no merchant rules or ceilings, so load only what the agent may spend; over the balance is declined.

Pay per request · todayper request 0.50 USDC · per day 50 USDC · spent 38.4

GET serper.dev/search402 · 0.02 USDC → paid → 20002:22 AM0.02 USDC

GET chainfeed.io/feed402 · 0.05 USDC → paid → 20002:22 AM0.05 USDC

GET chainfeed.io/archive402 · 1.20 USDC · over the per request ceiling02:22 AMrefused

Over the ceiling is refused, not queued: the other side is holding a connection open

It can buy from pages that charge by the call

The page answers 402 with a price, the agent pays in USDC from its own wallet, and the content arrives. Over the per-request ceiling is refused, not queued, because the other side is holding a connection open; every call leaves a receipt behind.

In this chapterConnect+MCP+

Three ways in, one set of rules

Connect it observing, widen it when it earns that. Every call is checked against the grant, so it never does more than you could.

Name it, say what it is for

Read the books and propose, pay by card, or pay in crypto: the choice decides what the drawer shows, not what the agent may do. Every permission still comes from the access you give it afterwards, and no role can sign a payment.

Connect an agentClaude · claude.ai · verified: the request came from claude.ai

Spaces it may reach

  • Elif Kaya
  • Lantern Automation

It reads what you can read and records what waits for you; it cannot settle a payment, and it takes no agent seat in your plan

AllowCancel

Or a client you already have

A Claude connector, Cursor, VS Code, Zed, Windsurf or the terminal reach the same server; the first question sends you to Orla's own consent page to tick which spaces it may reach.

Where an agent can spend it

Services that take a machine's payment without an account or an API key, with the price, the network and the source on every row.

What it refuses without you

Rules in the code, not defaults that someone can change

Never

Signing a payment
It proposes, and a person signs; no role and no setting changes that.
Releasing an approved payment
Not by the agent that proposed it, and not by any other.
Widening its own limits
A change to its grant is a proposal in the same queue as everything else.
Paying an address it read in a document
A send goes only to an address the space already trusts, and only a person ever writes to that book.
Exporting its key
Shown once at creation, to nobody afterwards.

Only you

Trusting a new address
Written into the space's own address book by a person.
Withdrawing the wallet
The balance comes back to you on your signature.
Setting the two ceilings
Per request and per day; unset means closed, not open.
Opening a host
The agent can search the catalogues and ask; only your Allow puts a host on its list.
Changing where a host is paid
The first payment pins the address; a new one counts only after you confirm it by hand.
Freezing it
The card and the wallet stop in the same click, and the history stays.

Questions

Where an agent's limits sit

Can an AI agent sign a payment?

No. It proposes and a person signs, and that is not a setting anyone can turn off, including the person who owns the space. A fresh agent starts in observation, where every write it tries becomes a proposal rather than an entry.

What stops an agent from overspending?

Its wallet is its whole budget: nothing stands behind the balance, so no mistake in any rule can spend more than you put in. Sends go only to addresses the space already trusts, anything over the daily cap waits for you, and freezing it stops the card and the wallet together, in the same single click. A card spends only the balance you loaded onto it, and a payment over that balance is declined.

What stops an agent from paying the wrong service?

It pays only hosts on a list a person keeps, and an empty list is a closed door. The agent can search the catalogues and ask for a host, but only your Allow adds it. The first payment to a host pins the address that host is paid at; a later quote naming another address is refused until you confirm the change yourself, checked against the host's own documentation and never against the request.

How does an agent connect to Orla?

Through a Claude or ChatGPT connector, an MCP server, the CLI, an n8n flow or your own code over the API. It never does more than you could do yourself, recomputed on every call, and every cent it spends carries its name in the books.

See it on your own books

Thirty minutes: we connect an account, drop a real bill in, and close a month together.