Cloudflare brings paid access to MCP tools — who controls the agent’s spending?
Summary
Cloudflare opened a closed beta of its Monetization Gateway on Wednesday, giving domain owners a way to charge AI agents The post Cloudflare brings paid access to MCP tools — who controls the agent’s spending? appeared first on The New Stack .
Original Text
Cloudflare opened a closed beta of its Monetization Gateway on Wednesday, giving domain owners a way to charge AI agents for access to APIs, MCP tools, websites, and datasets. The gateway carries payment authorization inside the HTTP request using the x402 protocol and releases the resource only after payment settles in USDC on the Base blockchain.
The beta is limited to eligible U.S. sellers and buyers, with Cloudflare’s own AI Gateway already using it to charge for inference per request. For agent developers, a paid tool call adds another decision to the execution loop because the runtime has to determine whether the agent has permission to spend before it can continue.
Spending authority belongs in the runtime
Spending authorization should sit outside the model, and Cloudflare’s planned Virtual Wallets move in that direction by letting the owner of an Account Wallet set an allowance, an allowlist, and a maximum transaction size that apply no matter which tool the agent decides to call.
On the client side, the Agents SDK’s withX402Client wrapper accepts a confirmation callback that receives the payment requirements before any money moves, and passing null in its place lets the agent pay automatically. That’s also where a team can require approval before a paid call goes through, similar to how MCP’s elicitation feature can pause a tool call and ask the user to step in.
Budgets beyond per-call caps
A per-transaction limit only goes so far. An agent capped at $0.10 per call could still spend $10 during a long research or coding task without breaking the rule. Wallet allowances cap total spending, but unless developers create a separate Virtual Wallet for every run, they don’t say how much one task can spend.
Some agent platforms are already moving that control into the gateway. TrueFoundry’s TrueForge routes model calls and MCP interactions through its AI Gateway, where teams can enforce budgets and rate limits across their agents.
Variable pricing complicates budgets
Pricing can also change between authorization and settlement. Cloudflare supports x402’s exact scheme for fixed-price requests and upto for variable pricing, where the client authorizes a ceiling, and the seller’s origin reports the actual charge. Launch customer API2PDF uses upto because each PDF job consumes a different amount of compute and bandwidth, so the agent knows the maximum a request could cost but not the final figure. The gateway currently supports prices from $0.001 to $100.
That leaves the runtime tracking two boundaries — what an individual tool call is allowed to cost and how much of the task budget remains when the next paid call arrives. Under variable pricing, the safer assumption is that each call consumes its full authorized ceiling until settlement reports the actual amount.
If an API request times out, an agent can often retry with little consequence beyond latency and compute. Once a request can trigger settlement, the runtime also has to know what happened to the transaction before deciding whether another attempt is safe.
Under variable pricing, the safer assumption is that each call consumes its full authorized ceiling until settlement reports the actual amount.
When retries become repurchases
A paid request might fail before it’s authorized, during settlement, or after the payment has gone through but before the response reaches the client. If it’s the last one, retrying the request could mean paying twice for the same resource.
Cloudflare handles the payment process inside the gateway, including failed transactions that need another attempt, while x402 clients check the HTTP status and response before retrying. The agent framework still needs its own record of each payment so it can tell whether the purchase failed, the payment went through, but the response was lost, or the next call is a new transaction.
Price becomes part of tool selection
Cloudflare’s Agents SDK lets MCP servers mix free and paid tools through paidTool, with developers setting a per-call price in USD. A client that chooses a paid tool without payment gets a 402 and can retry through x402 with proof of payment, but the SDK doesn’t decide whether that tool is worth buying. That stays with the client, where price joins latency, reliability, and output quality as another factor in tool selection.
Variable pricing complicates that choice because the runtime may know the most a call could cost without knowing the final charge. It can choose a cheaper service when that’s enough for the job or spend more when the task calls for it, as long as the purchase stays within the remaining budget.
Cloudflare also says it will make sellers’ services discoverable to agents, which would allow agents to find paid tools while a workflow is already running. The runtime then decides whether to approve the seller and how much the agent can spend.
A successful tool call in a trace does not indicate what the agent spent along the way, particularly if retries are involved. A simple final response can hide a history of tool calls and retries across several agents, and payments add another record to track. Each call needs to carry its payment history so developers can tell two attempts from two purchases and trace unexpected costs back to the workflow that generated them.
Each call needs to carry its payment history so developers can tell two attempts from two purchases and trace unexpected costs back to the workflow that generated them.
Tracing spend across tool calls
The company says it plans to expose logs for Monetization Gateway transactions, but those logs are aimed at sellers. Developers buying paid tools will still need their own telemetry to connect payments with the model and tool calls that triggered them. Observability vendors have already been reworking their platforms around token usage because inference has a measurable cost; paid tools extend that accounting to the other services an agent uses. A wallet balance can show that an agent spent $50, but not that one task burned $3.80 across 27 calls or that a retry paid twice for the same resource.
Cloudflare’s AI Gateway now accepts x402 payments for inference, so model calls and paid tools can draw from the same wallet. Developers will need to track both against the task that spent the money.
The post Cloudflare brings paid access to MCP tools — who controls the agent’s spending? appeared first on The New Stack.
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.