How to Give an AI Agent a Spending Limit (and the Tools That Do It)
An agent that can pay for things is useful right up to the moment it pays for the wrong thing. Here are the four ways teams cap agent spending, and what each tool actually enforces.
Quick answer
There are four ways to cap what an AI agent can spend: give it a virtual card with network-enforced limits (Stripe Issuing for agents); give it a wallet with per-transaction and per-session caps (Coinbase Agentic Wallets, Natural); put a policy layer or approval gate in front of its payment tool (SpendNod, Veyra); or use x402 pay-per-call, which needs a capped wallet behind it because x402 sets no limit itself. Most teams combine a hard cap with a human approval step above a threshold.
How we compared them
Disclosure: Zapx Labs makes Veyra. Facts below come from each vendor's own documentation as of 1 October 2026, linked at the end. We left out products whose sites are parked or that have moved to a different market.
The four approaches
- Virtual cards: the card network enforces limits per authorisation or per period, and your server can approve or decline each charge in real time.
- Capped wallets: the wallet, or an on-chain allowance, caps how much can move per transaction or per session.
- Policy layers and approval gates: every payment request is checked against rules before it runs, and anything above a threshold waits for a human.
- x402 pay-per-call: payments ride on HTTP 402 responses. It is a payment protocol, not a limit, so it needs a capped wallet behind it.
Six tools and what they enforce
- Stripe Issuing for agents: virtual or single-use cards and shared payment tokens, with spend limits per authorisation or period, merchant-category controls, and real-time webhook approval (two-second timeout, then your default rules apply). Requires a Stripe Issuing account.
- Coinbase Agentic Wallets with x402: configurable caps per session and per transaction; Coinbase holds the keys. USDC on Base, Polygon and Solana. x402 facilitator fees are free for the first 1,000 transactions a month, then $0.001 each.
- Natural: agent wallets and payments with limits per transaction, per day and per month; payments over a limit are held for review. Funds sit in FDIC-insured accounts through Column N.A. Wallets free; business payments 0.1%.
- SpendNod: an open-source, self-hosted MCP authorisation gateway with per-transaction, daily and monthly caps, vendor and category blocks, velocity limits and phone approval. It approves or denies but never moves money. Free.
- Skyfire: pre-funded pay tokens where the token amount is the most a seller can charge. Wallets fund by card, USDC on Base, or bank transfer.
- Veyra: a non-custodial permission layer with one MCP endpoint per agent. Per-transaction and daily caps, auto / ask / block bands and a recipient allowlist; payments in the ask band wait for a one-tap approval in your own wallet, and approvals lapse after 24 hours. USDC on Base. Free, Pro £19 a month, Team £79 a month. One caveat its own docs state plainly: auto-pay uses a capped allowance to a relayer Veyra operates, so the cap limits how much can move but not where — the destination within that cap relies on Veyra's policy engine.
What to look for
- Who holds the keys or funds: you, the vendor, or a bank.
- Whether limits are enforced by the network or contract, or only by the vendor's software.
- Whether there is a human approval step above a threshold, and how long a pending approval lives.
- An audit log tied to the specific agent, not just the account.
Key takeaways
- Four patterns: virtual cards, capped wallets, policy layers, and x402 with a capped wallet behind it.
- Combine a hard cap with human approval above a threshold.
- Check who holds funds and what actually enforces each limit.
- Facts come from each vendor's own docs on 1 October 2026.
FAQ
Sources
Developer Infrastructure
Explore Veyra
Spending authority for AI agents — without handing over the keys. Connect wallets once, set policy, then ship one MCP endpoint.