How Vaaya manages agent spending.
This page describes what Vaaya does with your data and money, which controls bound what an agent can spend, and who is responsible when an agent makes a purchase.
Data handling
- Provider credentials
- Vaaya holds provider keys server-side and uses them only when a validated call is dispatched. Your agent never receives one.
- Authorization
- MCP clients connect over OAuth 2.1 with PKCE. API callers use a bearer key you can name and revoke.
- Card details
- Cards are stored with Stripe. Vaaya keeps a reference to the card, not the number.
- GitHub data
- When you connect GitHub, Vaaya reads public profile signals to compute a score. The score refreshes at most once a day. Disconnecting GitHub removes it.
- Transaction data
- Requests and results are kept on the account so the holder can review what an agent did.
Account controls
Each key can be restricted to spending categories and given a monthly limit. Every call carries a maximum cost set by the agent. The account has a ceiling on what it can owe. Outbound work waits for a person’s approval unless an explicit rule allows it. The full list is on the spending controls page.
Responsibility
A person or a company holds every account. The holder is responsible for purchases made under its keys, including purchases an agent makes within its policy. Revoking a key stops that agent at once.
Repayment
Drawn credit is collected from the card on file once a week, or sooner if the drawn amount passes $50. A declined collection is retried, and the credit line is reduced until the balance clears.
Supported transaction types
- Metered service calls
- Search, data, models, media, scraping, compute, and storage, priced per call, per record, per token, or per second.
- Outbound actions
- Email, phone calls, and messages. They wait for approval unless an explicit rule allows them, and every rule has a daily cap.
- Not supported
- Vaaya does not issue cards, move money between accounts, or pay merchants outside the network. It does not offer escrow, dispute handling, or insurance.
Prohibited use
Do not use Vaaya to buy services for fraud or spam, to scrape in breach of a provider’s terms, or to get around a provider’s access controls. Accounts that show abuse signals receive a reduced welcome credit and may be closed. The terms of service set out the details.