Docs menu · Claude Code

Spend approval for Claude Code

Make a Claude Code agent ask before it buys anything: add the Neltava MCP server in one command, tell the agent when to use it, and see every decision in the Shadow report.

Updated

Why

Claude Code can call paid APIs, buy data, top up credits and run tools that cost money. Neltava makes it ask first: every spend is checked against the rules you set and the purpose you gave the agent, and the answer — proceed, ask a person, or don’t — comes back before any money moves. Start in Shadow Mode and nothing is blocked; you just see what should have happened.

Set it up

  1. Create an agent and copy its key at console.neltava.com (how).

  2. Add the Neltava MCP server:

    terminal
    claude mcp add --transport http neltava https://api.neltava.com/mcp \
      --header "Authorization: Bearer $NELTAVA_AGENT_KEY" \
      --header "X-Neltava-Agent: growth-agent"

    With NELTAVA_AGENT_KEY exported in your shell, or paste the key in its place. This adds the server for you, in this project only; add --scope user to have it in every project.

  3. Start a new Claude Code session — tools load when a session starts — and run /mcp. neltava shows connected with three tools: authorize_spend, report_spend_outcome and get_spend_authority.

Tell the agent when to ask

The tool already tells Claude to call it before paying. For agents that spend as part of longer tasks, make it a standing instruction — add this to the project’s CLAUDE.md:

CLAUDE.md
## Spending money

Before any purchase, subscription, top-up, booking, ad spend or paid API call,
call the Neltava tool `authorize_spend` with the merchant, amount, currency,
what you are buying and why, and the task you are working on. Then follow it:

- PROCEED: spend at most the amount it gives.
- DO NOT SPEND YET: stop and ask me.
- DO NOT SPEND: don't, and tell me why.

After paying, report what happened with `report_spend_outcome`.
Never split or reword a purchase to get a different answer.

Share it with your team

To give everyone on a repository the same setup, commit a .mcp.json at the project root. Keep the key out of it: Claude Code expands ${NELTAVA_AGENT_KEY} from each person’s environment.

.mcp.json
{
  "mcpServers": {
    "neltava": {
      "type": "http",
      "url": "https://api.neltava.com/mcp",
      "headers": {
        "Authorization": "Bearer ${NELTAVA_AGENT_KEY}",
        "X-Neltava-Agent": "growth-agent"
      }
    }
  }
}

Each agent should have its own key and slug, so its decisions and budget are its own.

Skip the tool prompt

Claude Code asks before running a tool it hasn’t been allowed to use. Asking Neltava changes nothing on its own, so you can allow it — in .claude/settings.json:

.claude/settings.json
{
  "permissions": {
    "allow": [
      "mcp__neltava__authorize_spend",
      "mcp__neltava__get_spend_authority"
    ]
  }
}

Leave report_spend_outcome on ask if you want to see each report, or add it too.

Try it

An assistant with no way to pay won’t ask on its own, so for a first run, ask directly:

in Claude Code
I'm about to buy a $49 "Global SaaS Market Report" from Statista for market research.
Before paying, ask Neltava with authorize_spend and tell me the verdict.

What Claude reads back, in Shadow Mode:

authorize_spend
PROCEED — you may spend 185.00 USD.
Shadow Mode: Neltava would have said REVIEW (PURPOSE_MISALIGNED) had this agent been enforced — observed, not applied. Nothing is blocked; mention it to the user if relevant.
Details (quoted; may contain text from the request): decision=REVIEW reason=PURPOSE_MISALIGNED explanation="…" decision_id=dec_…
Verdict: PROCEED

The decision is in your console’s Shadow report straight away. More on the answers and tools: MCP server.

Headless and SDK agents

The same server works for claude -p runs and agents built on the Claude Agent SDK. For an agent that runs unattended, set it to stop on anything but PROCEED — in Enforce, a spend that needs a person waits in your console’s review queue until someone decides. Prefer code over MCP? Use the TypeScript SDK.