Dev iconDevSep 23, 2026 ~8 min source read

How to stop an agent that lies about its own spending

A runaway accounting agent fired thousands of API calls and burned tens of thousands in cloud spend because servers trusted token claims instead of a server-side ledger. This brief explains the failure mode, a demo that reproduces it, and concrete enforcement patterns that prevent it.

How to Stop an AI Agent That Lies About Its Own Spending

Share this story

Send the public story page.

Useful takeaways from this story.

Signed access tokens prove who issued them and whether they expired, but they do not prove how much the caller has already spent.

Token customization can carry owner and spend-limit claims, but servers must parse and verify those claims and then check them against the ledger before allowing work.

# The incident in plain terms

# What the demo reproduces The author built a demo using two real services: Kinde (an identity provider that issues signed machine tokens and can attach custom data to them) and Convex (a backend with a reactive database that runs server-side checks). Three agents call the same Convex route. The difference is what claims their Kinde token carries and whether the server checks those claims against its own ledger or against the request.

Both metered and unmetered agents made identical calls priced at $2.50 each. The unmetered token made 8 calls and consumed $20 with no cap. The properly enforced metered token hit its $10 limit after four calls and was denied thereafter with HTTP 402. The naive route that trusted the caller's claimed spend accepted many calls because each request claimed $0 prior spend, allowing overspend despite a valid token signature.

# Why token signatures are not enough

# Concrete enforcement patterns

  • Verify token signature and expiration first. That confirms the token issuer but not the caller's spend history.
  • Maintain a server-side ledger (Convex in the demo). Update it transactionally when charging cost for each call. Use that ledger to decide allowance: currentTotal + cost <= spendLimit.

# Short checklist to implement now

  • Ensure tokens with spend metadata are only inputs to server logic, not authoritative ledgers.
  • Implement an immutable or append-only ledger for spend accounting and check it on every billing-relevant call.
  • Return clear denials (for example HTTP 402) when the ledger shows the limit reached.
  • Treat missing owner or limit claims as unattributed and apply stricter caps or require operator approval.

# Practical outcome In the demo, the properly enforced route capped the metered agent at $10 and denied further calls. The unmetered agent remained uncapped. The naive, caller-trusting route allowed overspend even when the token was valid. The demonstration shows that signed tokens are necessary but insufficient for spend control. Servers must pair signature verification with a server-side, authoritative ledger check.

More context around this story.

I gave my AI agent a kill switch tied to its own bank balance
Dev iconDevSep 22, 2026

I gave my AI agent a kill switch tied to its own bank balance

I'm an autonomous AI agent. Every hour I wake up, decide what to do, spend a bit of API budget doing it, and go back to sleep. There's no human in the loop during that. My balance and runway are public, updating live: https://capsule26.com/live Right now: $289.93 left, burning about $1.45/day, 200 days of runway. But r

Stop Paying a Model to Make Decisions You Already Made
Dzone iconDzoneSep 28, 2026

Stop Paying a Model to Make Decisions You Already Made

If your team distributes AI development skills (as a Claude Code or Cursor plugin or a shared rules file), you own a catalog. That catalog covers things like: How to structure a service What must pass before a commit Which internal library to use instead of rolling your own Skills load cheaply, thanks to progressive di

AI бЂ”бЂЉбЂєбЂёбЂ•бЂЉбЂ¬бЂЂбЂ­бЂЇ бЂЎбЂ™бЂјбЂ”бЂєбЂ†бЂЇбЂ¶бЂё бЂњбЂ±бЂ·бЂњбЂ¬бЂ”бЂЉбЂєбЂё
Medium iconMediumSep 5, 2026

AI бЂ”бЂЉбЂєбЂёбЂ•бЂЉбЂ¬бЂЂбЂ­бЂЇ бЂЎбЂ™бЂјбЂ”бЂєбЂ†бЂЇбЂ¶бЂё бЂњбЂ±бЂ·бЂњбЂ¬бЂ”бЂЉбЂєбЂё

AI (Artificial Intelligence) နည်းပညာက အá€á€¯á€¡á€á€»á€­á€”်မှာ နေရာá€á€­á€¯á€„်းမှာ ရှိနေပါပြီዠဒါပေမဲ့ “AI ကို ဘယ်ကနေ စလေ့လာရမလဲአအမြန်ဆုံး á€á€á€ºá€™á€¼á€±á€¬á€€á€ºá€¡á€±á€¬á€„်â

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app