Conto
Back to Learn

x402 and API spend controls for AI agents

Set limits on paid API calls so repeated requests stay within budget.

Published Updated

x402 lets an API request payment before returning a result. Set limits on each call and on the task as a whole so repeated requests stay within budget.

Why API spend needs its own controls

An agent may make many paid API calls during one task. Limits on individual calls need a budget for the task as a whole.

At $0.05 per request, 1,000 paid calls cost $50. Repeating that each hour costs $1,200 a day, without a single large payment.

Paid API calls are one way agents can buy what they need for a task. A service quotes its price, and the agent requests approval to pay. We discuss how these uses may develop in The Timeline for Agentic Payments.

How the x402 payment check works

HTTP 402 Payment Required has long been reserved for payment-required responses. x402 lets an API quote a price and accept payment for a request. The agent submits the payment details with its next request to the API.

The buyer’s payment client sends Conto the amount, recipient, service URL, and payment details before signing. It proceeds only when the request is authorized.

After payment, the client records the result with Conto so later checks use the updated spending total.

Budget checks for paid API calls

x402 controls work best when per-call ceilings, service budgets, and velocity rules are checked before the provider is paid.

Budget at request time

$5.00/ $5.00 session

100% spent · $0.00 left

Per-call cap$0.50
Velocity18 / 60 per min

Per-call decisions

inference.helia.dev$0.012
search.serp.api$0.040
gpu-rent.xyz$1.20
embeddings.io$0.008
render.farm$0.30
over per-call cap session budget spent

Conto prices each call against the per-call cap and the remaining session budget before the provider is paid. The $1.20 GPU call is over the $0.50 cap. The $0.30 render is under it, but the session is spent, so it stops too. Nobody is paged, and nothing is billed past the budget.

Enchant: x402 and MPP in action

Live example

Enchant shows what controlled agentic payments look like in a real product

Enchant is a live example of agentic payments with x402 and the Machine Payment Protocol (MPP). A user asks for a task, Enchant finds the right tool, shows the price before anything runs, and routes the paid step through Conto controls.

The example connects the user’s request, quoted price, payment decision, and result. New accounts receive signup credits.

Prompt

User asks Enchant

A task can require a paid tool, data source, or model call.

Quote

Price appears first

The paid step shows its cost before anything runs.

Control

Conto checks policy

Budgets, per-call caps, and approvals are evaluated before spend.

Payment

x402 or MPP clears

Approved micropayments settle and update the user budget.

Try Enchant free

New users get credits when they sign up.

Conto is the spend foundation

Every paid step can carry budget, approval, and audit context.

Policies that matter for x402

The starter values below are a first policy for a research or data agent. Swap in a provider you've actually paid through.

Service allowlist

Restrict paid calls to approved API domains or providers.Starter: api.example-search.com, api.example-data.com

Per-call ceiling

Set the most an agent can pay for one request.Starter: $0.50 per request

Service budget

Cap total spend for each provider per day.Starter: $50 per service per day

Endpoint budget

Limit spend against a specific API endpoint when one route is higher risk.Starter: $10 per endpoint per day

Velocity limit

Limit calls per minute, hour, or day to catch loops and retry storms.Starter: 5 paid calls per endpoint per minute

Session budget

Cap repeated calls inside one task. Session-heavy workflows may be a better fit for MPP.Starter: $25 per task

With those numbers, routine calls clear and a call over $0.50 or past a budget stops. The full rule list lives in the x402 policy reference.

What can go wrong

Check how the agent handles changed prices, failed calls, and missing payment records.

Test a redirected service URL, a changed price, repeated failures, and a task that tries too many paid providers.

Also test a successful payment whose result is not recorded. The next check must not assume those funds remain available.

x402 versus MPP

x402 is a strong fit when each API request is separately priced and the server returns a 402 Payment Required challenge.

The Machine Payment Protocol (MPP) also supports session payments: repeated paid use of a service under one task budget. Choose the supported payment flow that matches the service and how it charges.

A production checklist

Test an approved call and a call above the hard limit. Check each result and its effect on the budget before using real funds.

Related Conto resources

Test a paid API request

Start with a service allowlist, a per-request limit, and a daily service budget. Then record completed calls so each new decision has an up-to-date spending total.