Skip to content
Story

Shared Agent Wallet: Spend Limits for Family and Team

Shared Agent Wallet: Spend Limits for Family and Team

Why Your Current Setup Is One Leaked API Key Away From Disaster

Most developers think their AI agents are cheap. Then they check the billing dashboard and find a five-figure overage they didn't authorize.

Here's the uncomfortable truth: if you gave an agent your card details or an API key six months ago, you probably can't answer three basic questions today. How much could be drained before you noticed? Which other people share that same key? And what's the actual monthly ceiling? Stick with me, because there's one architectural pattern that solves all three at once, and it's not what most tutorials recommend.

Map where agents touch money right now. Subscriptions, API credits, marketplace purchases, cloud overages, per-tool billing dashboards you open once a month. Every one of those is a separate blast radius with a separate failure mode.

Now run the blast radius test on your own setup. If a single key leaked this second, how much damage happens before an alert fires? Per-seat billing and shared logins collapse the moment two people and three agents use the same account. The account has one identity, but five spenders.

The goal isn't fewer agents. It's one identity, one budget, per-person and per-agent ceilings, and a full audit trail.

The Identity Layer Comes First: Who Is Actually Spending?

People conflate two questions constantly. Authentication asks who this agent is. Authorization asks what it's allowed to spend. Mixing them is why your logs show "API key used" instead of a name.

Give every human and every agent a distinct identity. No shared logins, ever. When a transaction has a name attached, accountability stops being a group project.

For the practical baseline, OAuth 2.0 scopes with short-lived tokens work on nearly every platform you already use. For self-hosted agents, workload identity standards like SPIFFE/SPIRE are production-ready and handle the machine-to-machine case cleanly.

But that's only half the picture. Plan revocation on day one. One command, one click, one agent's access dies without touching anyone else's. If revocation requires a support ticket, you don't have a control, you have a hope.

Design the Wallet: Budgets, Ceilings, and the Rules That Actually Hold

Structure the wallet in tiers. A master balance at the top, per-person sub-budgets beneath it, and per-agent hard caps underneath those. Money flows down; authority flows down too.

Now separate your limits by type:

  • Soft limits alert and log. Good for exploratory agents and new workflows.
  • Hard limits reject the transaction outright. Non-negotiable for anything touching a live card.

Here's where it gets interesting: totals are the wrong metric. A monthly cap of $500 sounds safe until a runaway loop burns it in forty minutes. Velocity rules catch what totals miss. A daily cap stops the loop while the monthly cap is still asleep.

Then define approval thresholds. Under a set amount, auto-approve. Above it, route to a human in the family or team. Autonomy without a ceiling is just an unmonitored card on file.

Wire It Up: A Step-by-Step Setup You Can Finish Today

Let me show you exactly how, in five moves.

  • Create the shared wallet or agent account. Fund it with a fixed amount. Keep it completely separate from your primary personal or company card.
  • Provision identities for each member and each agent. Attach scopes matching what that agent actually does, nothing broader.
  • Configure the limits from the previous section. Screenshot the config so you have a written record of intent.
  • Connect your existing tools so agents transact through the wallet instead of individual keys. All spend flows through one governed pipe.
  • Test with a small real transaction per agent. Confirm it lands in the ledger with the correct identity attached.
  • That last step matters more than it sounds. An untested limit is a limit you'll discover is misconfigured during an incident, not before one.

    The Monitoring Loop That Catches Problems Before the Statement Does

    Set alerts on three triggers: any transaction above threshold, any agent hitting 80% of its cap, and any new payee appearing for the first time. That third one catches the attacks your spend limits won't.

    Review the ledger weekly for the first month, then monthly. Look for patterns, not individual charges. A $12 charge is noise. Twelve $12 charges from one agent is a signal.

    Write a one-page incident playbook. Who to call, which key to revoke, how to reconcile what was already spent. You'll never write it calmly during an actual incident.

    Revisit limits quarterly. Agent workloads grow quietly, and yesterday's generous cap becomes today's bottleneck.

    Where This Is Heading: Agents That Carry Their Own Credentials

    As of today, there is no single ratified AI agent identity standard. The industry is converging on a layered approach: the IETF's WIMSE working group and OAuth 2.0 family for workload identity, the A2A protocol's agent-card discovery URI, and W3C Verifiable Credentials for cross-organizational trust. The ITU's Focus Group on Trusted Identity is working toward a common identity stack for humans and agents.

    Interoperability for continuity, meaning identity that persists across sessions and contexts, remains unsolved. That's exactly why clean identity hygiene today compounds. When discovery and verifiable credentials make agent-to-agent payments automatic, the teams with governed wallets will just switch standards on. Everyone else starts over.

    Start with the wallet you built today. Let the standards catch up to it, not the other way around.

    The core takeaway: one identity, one funded wallet, per-agent ceilings, and a ledger you actually read beats any amount of trust you place in a shared key.

    Your next ten minutes: open your billing dashboard and calculate your current blast radius. That number is your baseline.

    Which approach are you running right now, shared keys or per-agent identities? The tradeoffs are real, and I'd genuinely like to hear where your setup breaks. Drop your experience below.

    Written byBoris Zarinski/u/borcezarinskiAll posts →