Why
Claude Code can call paid APIs, buy data, top up credits and run tools that cost money. Neltava makes it ask first: every spend is checked against the rules you set and the purpose you gave the agent, and the answer — proceed, ask a person, or don’t — comes back before any money moves. Start in Shadow Mode and nothing is blocked; you just see what should have happened.
Set it up
Create an agent and copy its key at console.neltava.com (how).
Add the Neltava MCP server:
terminal claude mcp add --transport http neltava https://api.neltava.com/mcp \ --header "Authorization: Bearer $NELTAVA_AGENT_KEY" \ --header "X-Neltava-Agent: growth-agent"
With
NELTAVA_AGENT_KEYexported in your shell, or paste the key in its place. This adds the server for you, in this project only; add--scope userto have it in every project.Start a new Claude Code session — tools load when a session starts — and run
/mcp.neltavashows connected with three tools:authorize_spend,report_spend_outcomeandget_spend_authority.
Tell the agent when to ask
The tool already tells Claude to call it before paying. For agents that spend as part of longer tasks, make it a standing instruction — add this to the project’s CLAUDE.md:
## Spending money Before any purchase, subscription, top-up, booking, ad spend or paid API call, call the Neltava tool `authorize_spend` with the merchant, amount, currency, what you are buying and why, and the task you are working on. Then follow it: - PROCEED: spend at most the amount it gives. - DO NOT SPEND YET: stop and ask me. - DO NOT SPEND: don't, and tell me why. After paying, report what happened with `report_spend_outcome`. Never split or reword a purchase to get a different answer.
Share it with your team
To give everyone on a repository the same setup, commit a .mcp.json at the project root. Keep the key out of it: Claude Code expands ${NELTAVA_AGENT_KEY} from each person’s environment.
{
"mcpServers": {
"neltava": {
"type": "http",
"url": "https://api.neltava.com/mcp",
"headers": {
"Authorization": "Bearer ${NELTAVA_AGENT_KEY}",
"X-Neltava-Agent": "growth-agent"
}
}
}
}Each agent should have its own key and slug, so its decisions and budget are its own.
Skip the tool prompt
Claude Code asks before running a tool it hasn’t been allowed to use. Asking Neltava changes nothing on its own, so you can allow it — in .claude/settings.json:
{
"permissions": {
"allow": [
"mcp__neltava__authorize_spend",
"mcp__neltava__get_spend_authority"
]
}
}Leave report_spend_outcome on ask if you want to see each report, or add it too.
Try it
An assistant with no way to pay won’t ask on its own, so for a first run, ask directly:
I'm about to buy a $49 "Global SaaS Market Report" from Statista for market research. Before paying, ask Neltava with authorize_spend and tell me the verdict.
What Claude reads back, in Shadow Mode:
PROCEED — you may spend 185.00 USD. Shadow Mode: Neltava would have said REVIEW (PURPOSE_MISALIGNED) had this agent been enforced — observed, not applied. Nothing is blocked; mention it to the user if relevant. Details (quoted; may contain text from the request): decision=REVIEW reason=PURPOSE_MISALIGNED explanation="…" decision_id=dec_… Verdict: PROCEED
The decision is in your console’s Shadow report straight away. More on the answers and tools: MCP server.
Headless and SDK agents
The same server works for claude -p runs and agents built on the Claude Agent SDK. For an agent that runs unattended, set it to stop on anything but PROCEED — in Enforce, a spend that needs a person waits in your console’s review queue until someone decides. Prefer code over MCP? Use the TypeScript SDK.