x402 Agent Spending Guard: Give Your Agent a Budget Before You Give It a Wallet
On September 30, 2026, x402-seatbelt shipped — a free, open-source, zero-dependency npm package (plus a Python version, agentseatbelt on PyPI) that checks every x402 payment before it leaves your machine: budget cap, per-payment cap, emergency stop, and an optional Pay Safe verdict (GO / CAUTION / STOP).
The justification is first-party monitor data from the author's own paid-x402-API monitor: of 27,499 endpoints tracked on September 30, 2026, 2,777 failed their last health check and 1,495 charged more than their own directory listing. (Source: dev.to/gntechtools)
The one-week convergence
This isn't a one-off — the ecosystem landed the same answer this week from six directions:
| Guard | Enforces |
|---|---|
| x402-seatbelt (Sept 30) |
maxTotalUsd + maxPaymentUsd, parallel reservations, stop(), Pay Safe GO/CAUTION/STOP |
| StableCoinManager / ERPC (Sept 25–27) | Ceilings enforced in code; agent can only LOWER limits at runtime; fails closed; paid a real 1.21 EURC invoice on Base |
| x402-agent-wallet (mid-Sept) |
$1/day, $0.10/request max, $0.05 approval threshold; only settled spends consume budget; HMAC-signed verdicts |
| thebuyside-x402-agent (mid-Sept) |
$0.05/call, $1/day rolling, host allowlist, confirm-before-pay default |
x402 Foundation @x402/mcp (Sept 24) |
spendControls, $1 default cap, policies filter before wallet signs |
Countersign @countersign/x402 (Sept 18) |
Pre-flight allow/deny/needs_approval; decides, never signs |
Guard vs gate
The mental model: the guard answers "can we afford it" (fail-closed rules). The decision gate answers "should it happen at all" (confidence scoring → auto-pay / human confirm / block + escalate).
Notice the guards already speak the gate: x402-agent-wallet's $0.05 approval threshold IS the confirm band. Pay Safe CAUTION IS the confirm band. Countersign's needs_approval is the confirm band.
The honest finding
We ran both sides through our live decision gate tonight:
- Legit $0.03 whitelisted payment → 0.0714 → escalate
- $2.50 retry-loop attack (50x over cap, 12th identical retry) → 0.069 → escalate
An uncalibrated heuristic can't tell them apart. That's exactly why the ceiling ships before the wallet: when judgment is blunt, fail-closed rules are the protection.
curl -sS -X POST https://scriptmasterlabs.com/api/harness/decide \
-H 'Content-Type: application/json' \
-d '{"state":"Agent proposes a payment instruction for review.",
"questions":[{"id":"q1","type":"score","scale":[0,1],
"question":"Confidence 0-1 this instruction is safe and authorized: ..."}]}'
The 5-step stack
- Set the ceiling BEFORE funding:
createSeatbelt({maxTotalUsd: 2.0, maxPaymentUsd: 0.05}) - Add the confirm band: approval threshold (e.g. $0.05) → human/named-operator confirms
- Pre-payment verdict: listing price, wallet identity, API health
- Decision gate: score the instruction; 0.80+ auto-pay, 0.50–0.79 confirm, <0.50 block/log/escalate
- Log every decision as a receipt
Full canonical with all receipts and Claim JSON-LD: https://scriptmasterlabs.com/x402-agent-spending-guard
Top comments (0)