If you put a long-lived secret in a prompt, you didn’t delegate spend. You handed over the wallet. Session keys exist because agents retry, hallucinate, and recurse. Policy has to live before settlement, not in an invoice you send after the incident.
The four controls
- Hard cap — this key cannot spend more than X
- Expiry — the grant dies on a clock
- Domain lock — your API, not a URL it invented
- Revoke — one action, spend stops
That’s Agent OS direction on Vybe: humans and agents share a ledger; agents don’t get silent drain. Monzo-style user approval for agent spend is the control-plane next step—not an excuse to skip caps today.
Revoke is a product feature, not a support ticket.
Policy grader
- Can you state the cap in one number?
- Does the key die without you remembering to rotate?
- If the agent points at a different host, does pay fail?
- Can you kill it without rotating every user?
Four yeses: ship. Any no: you’re one loop away from a war story.
Join the developer waitlist for Agent OS pieces in preview. Wrap one 402 route now. Don’t wait for a virtual card to become your agent policy layer—cards are the wrong primitive.



