Docs

Outside spend and connectors

Bills from the services your agents use that never went through a tab: AI vendors, clouds, hosting, CI. Connect them read-only and see what escaped the caps, next to what the tabs settled. Tab caps do not hold these bills; they show what to put on a tab next.

What outside spend is

FlockTab can only stop a call that goes through a tab. Everything else your agents cause (a model called with a key FlockTab never saw, a deploy, a database, CI minutes) is billed by the vendor directly. Outside spend reads those bills so the number that escaped the caps is visible. When it is large, the fix is to put more agents on tabs.

Connect a source

  1. Open Spend, Outside spend and choose Connect on the vendor's card.
  2. Where the vendor has a consent screen (OpenRouter today), you approve on your own account and FlockTab stores the grant. Everywhere else you paste a read-only billing token: the card shows the steps, a prompt you can give a browser agent to create the token, and the vendor's command-line way where one exists.
  3. FlockTab syncs once at once, then about every hour. Sync on the card reads it again now.

Tokens are stored encrypted and only ever read billing. A sync that fails never touches the tabs: the caps keep working.

Sources you can connect

GroupSources
AIOpenRouter, OpenAI, Anthropic, ElevenLabs
InfrastructureDepot, Cloudflare, Vercel, Railway, DigitalOcean, AWS, Google Cloud, Azure, Semaphore, Supabase, Render, Expo (EAS)
SaaSVantage, Datadog, GitHub

Coming: Higgsfield, TypeSafe AI.

Railway's usage comes in for the whole window at once, not day by day, so a Today or 7-day view or alert leaves Railway out until that changes.

Several accounts

Connect the same vendor more than once (two OpenAI organizations, a personal and a company Cloudflare) with Add account on its card. Each account has its own label, Sync and Disconnect, and its own totals.

Bills with no connector

Add by hand on the Outside spend page records a bill FlockTab cannot read: the vendor, the amount in dollars, the date and its category. It counts everywhere a synced bill does. Missing one? at the end of the sources asks us to add a connector.

A bill does not say which agent caused it, so bills are linked to projects by what each line names: a zone, a project, a repo, a model, an API key. Under Projects on the Outside spend page, choose a project for each of them once, and every later line of it follows.

  • A resource several projects use can be shared: by weights you set, or by activity, split each day by what their Agents did.
  • FlockTab suggests a project from names (a repo, a domain, a project's aliases); nothing is applied until you accept it.
  • Lines no rule covers stay visible as Unattributed. Nothing is guessed.

Projects then shows each project's outside spend beside what its tabs spent.

Reading the page

ViewWhat it shows
TotalsWhat the tabs settled, what was billed outside, and how many sources are connected
CausedWhat an agent could have caused (models, compute, messaging) apart from platform lines a person signed for
ProjectsEach resource and the project it goes to, and the rules
AI providers, Infrastructure, SaaSThe connector cards, by kind
OpenRouterSpend by key and by Agent, and linking a key to an Agent
EventsEvery line, newest first, with a search

The page opens on the last 30 days. The range menu and the source, project and resource filters narrow every view; Export downloads them.

Alerts

On Control, Alerts an alert can watch outside spend: every source, one source, a resource, a project or the unattributed lines, over today, 7 or 30 days, this month or this year. It posts to Slack, Discord, Teams, Google Chat or a webhook once a day while spend stays over the amount.

Who can see it

Outside spend is on Team and Fleet. On Fleet, a role needs outside spend access to see these bills anywhere in the console (the Outside spend page, the Overview's outside card, Observability), and outside spend changes to connect or attribute. outside:read and outside:write are the permissions behind them.