# Cap what an agent can spend

Every API key and AI agent on a Porkbun account works within one **monthly
limit**, set by the account holder at https://porkbun.com/account/api. It bounds
two things separately, each against the same figure:

- **What the API buys** in a calendar month: registrations, renewals, transfers,
  closeouts and paid hosting.
- **How much credit the API adds** in a calendar month: card top-ups
  (`POST /account/topup`), auto top-ups set off by an API purchase, card
  payments from an agent wallet (MPP) and USDC checkouts.

Topping up $50 and spending it counts once against each, not twice against one.
The limit cannot be changed over the API; only the account holder can raise it,
on the website.

## The default

An account that has not set a limit gets **$100 a month** for each. Accounts
that were already buying over the API before 2026-10-03 have no default on
purchases (only on credit added). Setting a limit replaces the default with the
account's own figure.

## Read what is enforced

```
GET /api/json/v3/account/apiSettings
```

```json
{
  "status": "SUCCESS",
  "settings": {"monthlySpendLimit": null, "...": "..."},
  "monthlySpend": 4200,
  "spendLimit": {"limit": 10000, "source": "default", "spent": 4200, "remaining": 5800},
  "topupLimit": {"limit": 10000, "source": "default", "added": 2500}
}
```

`settings.monthlySpendLimit` is what the account holder set (`null` when nothing
is). `spendLimit` and `topupLimit` are what is actually enforced. `source` is
`account` (their own limit), `default` ($100, none set) or, for purchases only,
`none` (no cap). All amounts are integer cents.

Check `spendLimit.remaining` before an expensive operation, or send the order
with `"dryRun": true`: the preview carries `monthlySpendLimit`, `limitSource`,
`monthlySpendSoFar` and `withinMonthlySpendLimit`.

## When an order would go over

The order is refused before anything is charged:

```json
{
  "status": "ERROR",
  "code": "MONTHLY_SPEND_LIMIT_EXCEEDED",
  "message": "This $11.08 order would take this month's API spending past the monthly limit of $100.00 ($95.00 spent so far). Nothing was charged. ...",
  "monthlySpendLimit": 10000,
  "limitSource": "default",
  "monthlySpendSoFar": 9500,
  "cost": 1108
}
```

Retrying will not help before the next month. Tell the account holder the amount
and that they can raise the limit at https://porkbun.com/account/api.

A top-up that would go over the credit limit fails with `TOPUP_LIMIT_EXCEEDED`,
carrying `monthlyCeiling`, `ceilingSource` and `toppedUpThisMonth`. For USDC,
checkouts opened in the last day and not yet paid count as if paid.

## Parallel orders

The check holds each order's amount until the order finishes, so several orders
sent at once cannot each pass against the same total and overshoot the limit
together. One that fails or is refunded stops counting when it ends.

## Other guardrails

- **Low-balance alert:** an email when credit drops below a figure you choose.
- **Card top-ups:** 5 a day and 20 a month, $5 to $500 each, an email for every
  charge, and only a card saved on the website can be charged.
- **Per-key scoping:** limit a key to certain domains or source IPs.


---

## More

- Guides (how-tos): https://porkbun.com/llms/guides
- Topic index: https://porkbun.com/llms
- Full reference (one file): https://porkbun.com/llms-full.txt
- OpenAPI spec (full schemas): https://porkbun.com/api/json/v3/spec
- Short overview: https://porkbun.com/llms.txt
- Official MCP server: https://porkbun.com/mcp (`npx -y @porkbunllc/mcp-server`)
- Create API keys: https://porkbun.com/account/api
