AXIGATE FINOPSDocs
Start free
Use cases ›

Put a daily limit on every key

A misused provider key can run up a bill fast. Give every key a daily limit on what it spends through the gateway: a key that reaches it is refused until midnight UTC, whatever runs it starts.

You will learn

  • How to give every key a daily limit, or a total
  • How to give scheduled jobs one daily limit across runs
  • How AxiGate tells keys apart without keeping them
  • How to let a paused key back in

Where this works

You don't need a plan to read on.
Free editionyour own machinesHosted FreehostedTeamhostedBusinesshosted
Give every key a daily limit
Give scheduled jobs one daily limit
Give every key a total limit
Resume a paused key

Give every key a daily limit

The limit goes on the gateway, so it covers every key that calls through it. Add it to the command that starts the gateway, then start it again.

The $50 below is an example: pick a little more than a key's busiest normal day.

Terminal
AXIGATE_INGEST_KEY=<the key from Connect a gateway> axigate-finops gateway --ingest-url https://<your workspace>/api/ingest --max-spend-per-key-day 50

One daily limit for scheduled jobs

A scheduled job that starts a fresh run each time it fires gets a fresh --max-spend each time, so nothing limits its day. In one reported case, claude -p scripts on a schedule sent dozens of requests an hour and billed about $858 one day and $960 the next.

Give run a daily limit per key. Every run on this computer that writes the same ledger counts toward it, and it resets at midnight UTC.

crontab
*/20 * * * * axigate-finops run --max-spend 2 --max-spend-per-key-day 20 -- claude -p "<your prompt>"

Once the key reaches the limit, each run's next call on it is refused until midnight UTC, and so is the first call of a run that starts later. Each receipt says what the key spent today across runs, for example: today on key …7f2c: $20.1400 of the $20.00 daily limit, across every run on this computer · paused until midnight UTC.

With --stop-alert-url, a stop message goes from each run that was using the key when it reached the limit. A run that starts after that is refused without sending another, so a job that fires every few minutes does not send one per firing; its receipt says why none went. Give every job that uses the key the same --stop-alert-url, so a message goes whichever run reaches the limit.

Or a total for each key

For a key that should only ever spend so much, set a total instead of, or as well as, a daily amount. A key that reaches its total stays paused until someone resumes it, so start the gateway with an admin token too.

Terminal
AXIGATE_INGEST_KEY=<the key from Connect a gateway> axigate-finops gateway --ingest-url https://<your workspace>/api/ingest --max-spend-per-key 200 --admin-token <token>

When a key is paused

The gateway refuses that key's calls and says why in each refusal, and Needs a look lists the key. Where the dashboard runs beside a gateway that keeps its own count (serve on your own machines, without a shared count), the Keys page shows each key's spend against its limit and can resume a paused key; anywhere else, a key is resumed on its gateway.

On a shared server, Resume from another computer asks for a code first: the admin token the gateway was started with (--admin-token), or the dashboard code printed when it started.

A key at its daily limit works again at midnight UTC on its own. One at its total stays paused until it is resumed.

Resuming gives the key a fresh start: today's count begins again, and so does its total if the total paused it.

With run's daily limit (--max-spend-per-key-day on run), Resume on a run's Keys page lets only that run's calls through. Other runs, and runs that start later, still count the whole day, so the key stays paused for them until midnight UTC, or until they start with a higher --max-spend-per-key-day.

How a key is recognised

AxiGate never keeps a key. It recognises each one by a fingerprint and shows only its last four characters, like …a3f9.

The limit binds to the key itself, not to a name, so renaming a key can't get it around its limit.

Recap

  • A daily limit caps what each key spends through the gateway; it resets at midnight UTC. A key used directly with the provider needs the provider's own limit.
  • With run, the daily limit counts every run on the computer, so a scheduled job has one limit a day, not one per run.
  • A total limit holds until someone resumes the key.
  • Keys are told apart by a fingerprint and never kept, so a new name can't dodge a limit.