Back
Cloudflare brings paid access to MCP tools: who controls the agent's spending?
SiTech AI Team3 min read

Cloudflare brings paid access to MCP tools: who controls the agent's spending?

Cloudflare opened a closed beta of its Monetization Gateway, letting sellers charge AI agents for MCP tools, APIs and datasets. The x402 protocol settles payments, but developers still need their own controls over agent spending.

Cloudflare opened a closed beta of its Monetization Gateway: domain owners can now charge AI agents for access to APIs, MCP tools, websites and datasets. The x402 protocol carries payment authorization inside the HTTP request and releases the resource once payment settles in USDC on the Base blockchain.

The beta is limited to sellers and buyers in the United States, and Cloudflare's AI Gateway already charges for inference per request. For developers, a paid tool call adds a decision to the execution loop: the runtime must know whether the agent may spend.

Spending authority belongs in the runtime

Spending authorization should sit outside the model. Cloudflare's planned Virtual Wallets move in that direction: an Account Wallet owner sets an allowance, an allowlist and a maximum transaction size that apply to any tool the agent calls.

On the client side, the Agents SDK's withX402Client wrapper takes a confirmation callback that reviews the payment requirements before money moves; passing null lets the agent pay automatically. Teams can require approval for paid calls, similar to MCP's elicitation feature for pausing tool calls.

Budgets beyond per-call caps

A per-transaction cap only goes so far: an agent limited to $0.10 per call could still spend $10 during one task without breaking the rule. Wallet allowances cap total spending, but without a separate Virtual Wallet per run, they do not limit what one task spends.

Variable pricing and retry risk

Pricing can change between authorization and settlement. Cloudflare supports x402's exact scheme for fixed prices and upto for variable pricing, where the client authorizes a ceiling and the seller reports the actual charge. API2PDF uses upto because each PDF job uses different amounts of compute. Prices run from $0.001 to $100.

The runtime therefore tracks two boundaries: what a call may cost and how much of the task budget remains. Under variable pricing, the safer assumption is that each call consumes its full ceiling until settlement reports the actual amount.

Retries add risk: a paid request can fail before authorization, during settlement, or after payment but before the response arrives, and retrying could then mean paying twice. Cloudflare handles payments inside the gateway, while x402 clients check the HTTP status before retrying. The framework needs its own record of each payment.

Tool choice and tracing spend

The SDK's paidTool lets MCP servers mix free and paid tools; a client without payment gets a 402 and can retry through x402 with proof of payment. Whether it is worth buying stays a client-side decision.

Cloudflare plans to expose logs for Monetization Gateway transactions, but those logs target sellers, so buyers need their own telemetry to link payments to the tool calls that triggered them. A wallet balance can show an agent spent $50, but not that one task burned $3.80 across 27 calls.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.