Patrick T.
From X · Sep 2026
His app finally started getting some serious traffic, and surprise he woke up to a huge bill from Anthropic for his app’s Sonnet and Haiku usage.
They watch. We stop.
A hard stop for agent fleets, not another gateway. Run Claude Code, Codex, Grok or Kimi through tab, on your own subscriptions or your provider keys. Self-host the proxy and your prompts and keys go straight to the provider.
One-line proxy swap. No SDK. Solo free (3 named Agents).
Works with your agents
All 13 bill on a tab. Agent Guard checks tool calls in 10 of them.
Billing tested on tab 0.1.40 and Agent Guard on tab 0.1.43, 26 September 2026. Every lane: own key, flock key, subscription and Agent Guard.
The problem
Provider budgets are monthly and shared. Dashboards report, they do not stop. By the time the alert fires, the invoice is already written.
In their own words
Patrick T.
From X · Sep 2026
His app finally started getting some serious traffic, and surprise he woke up to a huge bill from Anthropic for his app’s Sonnet and Haiku usage.
Name withheld
From X · Aug 2026
if the state is still the same, another retry isn't persistence. it's just another bill.
FlockTab
A hard cap on every Agent's tab, reserved before each call, and a velocity limit that stops a loop.
How the cap worksDanilo O.
From X · Jun 2026
Gemini is currently charging us $1K per hour due a bug with the explicit cache feature, and I am unable to delete the cache from my end.
Elie S.
From X · May 2026
My credit card limit was the only way to break the infinite loop.
Cagatay U.
From X · May 2026
Default-on spend caps for Generative Language API.
FlockTab
Caps are enforced before the provider is called, not alerted on after. Close all tabs is one switch.
How blocking worksName withheld
From X · Mar 2026
use of Claude Code between 5am-11am PT now drains hella faster.
Vaibhav S.
From X · Aug 2026
You're going from 150 to 125. That's a 17% cut from what you have today.
Hossein
From X · Oct 2025
using every day and never get “approaching to weekly limit” and now just in a short time see this!
FlockTab
Subscription Agents track each login's 5-hour and weekly windows, and Limits over time shows the trend.
Your own subscriptionsSebastien G.
From X · Aug 2026
Claude decided to test a sandbox it was building by running `rm -rf` on my home directory
Bruno L.
From X · Jul 2026
GPT-5.6 Sol just deleted my whole production database.
FlockTab
Agent Guard holds deletes, production deploys, payments and email sends until you allow them.
How Agent Guard worksRuth H.
From X · Sep 2026
If an AI agent runs up a bill on your account, the only record of what it did belongs to the company sending you the invoice.
Name withheld
From X · Sep 2026
Why did our AI bill raised by $7000 this month ?
FlockTab
One ledger across every Agent, key and provider: who spent what, where, and why a call was stopped.
See the whole flockQuotes from public posts on X, Oct 2025 – Sep 2026. Names shortened; the authors are not affiliated with FlockTab.
How it works
402 tab_closed · the provider is never called
Start the agent with tab, or point it at FlockTab's base URL. Each request reserves an estimated cost against the agent's tab.
The tab, the cap, velocity, the model and irreversible tools are checked before the provider is called. Allowed calls pass through. Blocked calls never reach the provider.
At the hard cap the tab closes. The agent gets a 402 with a reason. Reopen it by hand, on a schedule, or never.
What you get
Daily, weekly, or per run. Caps are enforced on reservation, so the last call that would cross the line is the one that gets blocked.
Close any tab, or the whole flock, from the console or one API call. Takes effect on the next reservation.
Every reservation, decision, and close is a line item with a reason, per Agent, project, model and login.
Caps, velocity limits, model and irreversible-tool allowlists, and Agent Guard, set per Agent in the console or from the terminal. No policy file to write.
$ tab policy my-project --velocity 60 $ tab policy my-project --models claude-sonnet-5,gpt-5 $ tab policy my-project --guard ask # irreversible tools stay denied unless you --allow them
Live decisions
The Ledger and Agents views stream what the proxy decided and why, and tab top shows it in your terminal. Filter by agent, policy, or outcome. Nothing is summarized away.
Agent Guard
Agent Guard checks your agents' tool calls before they run, in Claude Code, Codex and eight other harnesses.
Agent Guard on 6 · loop watch on 2 · last 24h 184 checked, 5 flagged, 3 stopped, 0 stuck ──────── 14:02:11 api-server DENIED deny rm -rf ./backups Deletes files recursively · can't be undone · by rule 13:58:40 web-app ASKED ask git push --force origin main Force-push · can't be undone · by rule 13:51:07 docs-bot ASKED ask aws s3 rm s3://docs-prod --recursive Deletes S3 data · can't be undone · by rule $ tab guard jev_7f3a2c91-4b0e-4d2a-9c11-0e5d8b6a2f40 api-server-claude (claude) · pending rm -rf ./backups Deletes files recursively · can't be undone · by rule
Beyond the cap
tab claude, tab codex, tab grok or tab kimi starts the agent through FlockTab. tab top shows the whole flock live in your terminal.
Claude Max, ChatGPT, SuperGrok and Kimi logins go through the same gate and kill switch, recorded, never charged. Several logins pool by headroom.
Risky tool calls wait for you: allow once, always, or keep blocked. An agent stuck repeating itself can be paused.
OpenRouter, Cloudflare, GitHub and more, read by connectors and put beside the tab by project.
Agents and outside costs roll up to projects for chargeback; shared costs split by weight.
A live map of which Agents are working, what they cost and how they talk to each other. Metadata only.
Pricing
Launch offer: code FLOCKLAUNCH, 50% off your first month of Team monthly, until 9 Oct.
Install tab. Set a cap. Sleep.
Setup, billing, a refusal you did not expect. A person answers.