# Agent spending

> Let the agent pay for outside services it needs, from a wallet of its own, inside limits you set. Experimental.

Source: https://graspable.dev/docs/agent-spending

Some requests need something that costs money: a web search, a dataset, a model, compute. With agent spending on, the agent can find services that are paid per call and buy from them, inside limits you set. It is **experimental** and off until you switch it on.

Three things to know first:

- **The agent pays the service directly**, from a wallet of its own. Graspable takes nothing from these payments, is not told what was bought, and keeps no record of it.
- **The limits are enforced by Graspable, not by the AI model**, before anything is signed.
- **Everything is written down for you**, on your computer only: what was bought or refused, for which request, and how it was decided.

## Switch it on

Open **Settings → Agent spending**.

1. **Make the wallet.** Graspable makes a new wallet on this computer and keeps its key in your keychain. It is not your own wallet, and Graspable never asks for that one.
2. **Send it USDC on the Base network** (**Copy address**). Other coins and other networks will not arrive. The wallet can spend only what you send it, so keep in it what you would keep in an app.
3. **Set the limits**: for one purchase, one request, and one day.
4. Choose **how readily it pays**, and tick **Let the agent pay for outside services**.

The wallet stays on your computer. Agent spending does not work in [Cloud Agents](https://graspable.dev/docs/cloud-agents.md).

## What the agent can do

It gets two tools. One searches a public catalogue of services that are paid per call and shows each one's price and how many different payers used it in the last 30 days. The other calls a service: the agent says what it needs and why, and Graspable decides.

The agent never holds the wallet's key and never builds a payment itself.

## How a purchase is decided

In this order:

1. **Limits.** A request or a day that has used its budget buys nothing more. A service that asks more than its listed price is refused. Only exact amounts of USDC on Base are paid, only to services from the catalogue or ones already paid before.
2. **The judge.** [System One](https://graspable.dev/docs/approvals-and-safety.md) answers four questions: does your request need this, would a free tool the agent already has do, is the price in line with the alternatives, and does the reason come from your request or only from text the agent read on the way. It can make the agent stricter than the limits, never looser.
3. **You**, whenever the setting, the service or the judge says so.

| How readily it pays | What happens |
|---|---|
| **Ask me every time** | Nothing is paid without your click |
| **Save money** | Pays only when the judge is very sure the request needs it and no free way exists. Asks above a small amount and for a service it has not paid before |
| **Balanced** | Pays for what the request needs within the budget. Asks for a service it has not paid before |
| **Finish fast** | Pays without asking inside the budget. Still refuses what the request does not need |

You are always asked when:

- the amount is above your limit for one purchase;
- the reason to buy seems to come from text the agent read, not from your request;
- fewer than three others have paid the service in the last 30 days;
- no judge with measured confidence is available;
- your [approval setting](https://graspable.dev/docs/approvals-and-safety.md) is Strict.

When nobody can be asked (the request runs without asking, or the agent is the Codex CLI, which cannot put a question to you), a purchase that needs your yes is refused.

## Spending on its own (experimental, unsafe)

**Let the agent spend on its own, without asking** removes the questions. The setting above decides instead: **Finish fast** pays even through doubt, **Balanced** pays when the judge agrees or when there is no judge, **Save money** pays only when the judge is sure.

An AI model can be wrong, and text it reads on the web can try to talk it into buying. With this on, the limits are the only thing between the agent and the wallet. Assume that everything inside them can be spent, and keep in the wallet only what you accept losing.

Three things hold even then: nothing above the limit for one purchase is bought, a purchase the judge traces to text the agent read is refused, and the agent buys only from services that at least three others have paid in the last 30 days.

## The record

**Settings → Agent spending → What the agent bought** lists every purchase and every refusal, with totals. Open one to see:

- the request it was for, and the agent's own reason;
- what else it considered;
- who decided (a limit, the judge, your setting, or you), and why;
- the judge's answers with their scores, and which judge it was;
- the budget at that moment, the service, and the payment itself.

**CSV** and **JSON** save the record as a file. Each purchase also appears in the request's transcript as it happens.

The record is a file on your computer (`~/.graspable/payments`). It is not sent to Graspable, and neither is anything else about a purchase: not the amount, not the service, not that one happened.

## What the judge is shown

Your request, the agent's reason, what the service says of itself, and its price. Never the wallet, its balance, the receiver or a transaction.

Under **Who judges whether a purchase is worth it** you choose: System One as you set it up, only your own System One providers, or nobody (you are then asked whenever a judge would be needed). With the first choice and no provider of your own, the judgement passes through Graspable's System One like its other judgements. Choose the second or third to keep purchases entirely away from Graspable.

## Limits of this first version

- It pays in USDC on Base only, to services that speak the x402 protocol.
- Prices must be fixed per call. Services with open-ended prices are not used.
- It has been tried against real services up to the point of payment. Treat it as new.
