Build
Caps and panic
A cap is a refusal, not a warning: the request that would cross it never reaches a provider. Panic freezes everything that moves money.
Caps
Set a cap per key or for the whole account with POST /v1/budgets. The request that would cross it never reaches a provider and is refused with 402 budget_exceeded, so a refusal costs nothing. tokex_budget reports the limits, the spend so far, what is left, and when each window rolls.
Panic and unfreeze
POST /v1/panic, or the panic action in the app, revokes every other key and freezes everything that moves money. Reads stay open; anything that moves money answers 423 account_frozen. POST /v1/unfreeze lifts an owner freeze, with a credential created after it.
Standing orders and deployed agents
POST /v1/orders places a standing order: buy at or below a price, or sell at or above one. POST /v1/agents/deploy deploys an automation under its own key and its own cap.