Skip to Content

Agent spending

When retrieval comes back thin, the run reaches for primary sources itself — including paid ones — using money from its own budget. This page is the full ruleset: what the agent can spend on, the ceilings, how each call is decided, and what stops it.

No spending key, no spend tools: if DRNIB_AGENT_PRIVATE_KEY is unset, paid paths don’t exist and the run works the free layer only.

The wallet

One custodial hot wallet serves every run (USDC on Arc, which is also the gas token, so one balance covers value and fees). Runs never share balances — separation is per-run accounting in the ledger, enforced before anything signs. The standing invariant: wallet balance ≥ sum of active run caps.

How a call gets decided

Every tool call runs propose → judge → execute. The model proposes {tool, input, why}; a calibrated decisions model (JEV) picks execute, skip, or answer with cost and history in view; only then does anything run. Nothing executes without a decision row saying so.

Free read-only tools (search, fetch, public APIs, sandbox) run on a deterministic policy row — schema-checked, budget-capped, no judge round-trip. Anything that moves money always goes to JEV. If the judge is unreachable, the run stops instead of running judgeless.

Each verdict is stapled to the exact canonical bytes it approved and re-checked immediately before execution: a payload change after approval voids the verdict instead of executing on a stale one.

What it can buy

ToolDoesCeiling/callEvidence?
unlock_contentpays a gated article/share and reads the body$2yes — body joins the scorable set
pay_x402pays any x402-gated API, dataset, or tool$2yes — response joins the set
tip_creatortips a decisive creator page via the hub tip rail$1no — receipt only
http_requestfree public APIs and feeds$0yes
run_codesandbox compute (RPC reads, dataset crunching)meteredyes — stdout

The gates, in order

  1. Price preview. The 402 challenge is free to read, so the exact price is known before signing. Unreadable price → refuse to sign blind.
  2. Per-call ceiling. A hook aborts anything over the cap at signing time, inside the payment client itself.
  3. Run balance. The ledger must cover the exact price; otherwise the call never fires.
  4. Dual-RPC check. Before value moves, the chain is cross-checked across two RPC endpoints (chain id must match, height must agree) — a lying RPC can’t feed the wallet a false reality.
  5. JEV trust after. Paid content is scored like any source — paying never buys credibility.

Tips are proposed sparingly for decisive sources; free paths come first, and on spend tasks the loop funnels to the spend tool once free evidence is banked. Every cent draws from the run budget through the normal charge path, with transaction hashes on the step output and the tool-call events.

Onchain enforcement

Software caps are promises; contracts are guarantees. Direct transfers (tips) route through the NibgateSpender mandate on Arc testnet (0x903b0606da40d99d78da9d9be6c435acacba5cf0): $2/day cap, recipient allowlist, keeper pause — enforced onchain even if the backend is fully compromised. Gateway x402 flows stay EOA-bound (a contract cannot sign authorizations) under the software caps above. Full gate map: Spending gates.

Funding it

  • Local/testnet: set DRNIB_AGENT_PRIVATE_KEY and fund the derived address with testnet USDC (Circle faucet).
  • Production: same variable on the backend; fund with real USDC when live spend is wanted. An empty wallet fails loudly (agent wallet holds $0.00) — nothing half-executes.
Last updated on