A $5 daily cap means $5. Enforced before the API call.
Per-call, session, and per-project ledgers, all written through
state/store.ts with a lockfile so parallel calls
don't race. Hard caps fire pre-call, not after
the charge — the budget guard returns a structured
BUDGET_EXCEEDED with a suggested fix. Identical
repeats hit the cache and return at $0.
estimate_cost ranks every implemented (provider,
tier) combo as a dry-run before you spend. CSV / JSON receipts
export by month. Pricing lives in a versioned JSON with a 30-day
staleness warning surfaced by health_check.
scenario · the demo on the right
A $0.05 daily cap. One image (gemini · flash · $0.0039). One
long TTS via Voicebox ($0.0000). The ledger reveals the running
total. The next image is blocked pre-call — no
provider hit, no spend.