Docs menu · Cursor

Spend approval for Cursor

Make a Cursor agent ask before it spends: add the Neltava MCP server to mcp.json, add one rule, and every purchase, top-up or paid API call is decided first.

Updated

Why

Cursor’s agent can run tools that cost money — paid APIs, data, credits, cloud resources. Neltava makes it ask first: every spend is checked against the rules you set and the purpose you gave the agent before any money moves. Start in Shadow Mode and nothing is blocked; you see what should have happened.

Set it up

  1. Create an agent and copy its key at console.neltava.com (how).

  2. Add the server to ~/.cursor/mcp.json — available in every project, and outside any repository, so the key stays private:

    ~/.cursor/mcp.json
    {
      "mcpServers": {
        "neltava": {
          "url": "https://api.neltava.com/mcp",
          "headers": {
            "Authorization": "Bearer sk_…",
            "X-Neltava-Agent": "growth-agent"
          }
        }
      }
    }
  3. Open Cursor’s MCP settings and check that neltava is enabled with three tools: authorize_spend, report_spend_outcome and get_spend_authority. If it was open already, reload the window.

Tell the agent when to ask

The tool already tells the agent to call it before paying. To make it a standing instruction, add a project rule — a file in .cursor/rules:

.cursor/rules/neltava.mdc
---
description: Ask Neltava before spending money
alwaysApply: true
---

Before any purchase, subscription, top-up, booking, ad spend or paid API call,
call the Neltava tool `authorize_spend` with the merchant, amount, currency,
what you are buying and why, and the task you are working on. Then follow it:

- PROCEED: spend at most the amount it gives.
- DO NOT SPEND YET: stop and ask me.
- DO NOT SPEND: don't, and tell me why.

After paying, report what happened with `report_spend_outcome`.
Never split or reword a purchase to get a different answer.

Prefer plain markdown? Put the same text (without the header) in AGENTS.md.

Share it with your team

For one setup across a repository, commit .cursor/mcp.json and keep the key out of it — Cursor reads ${env:NELTAVA_AGENT_KEY} from each person’s environment:

.cursor/mcp.json
{
  "mcpServers": {
    "neltava": {
      "url": "https://api.neltava.com/mcp",
      "headers": {
        "Authorization": "Bearer ${env:NELTAVA_AGENT_KEY}",
        "X-Neltava-Agent": "growth-agent"
      }
    }
  }
}

Each agent should have its own key and slug, so its decisions and budget are its own.

Try it

An assistant with no way to pay won’t ask on its own, so for a first run, ask the agent directly:

in Cursor's agent
I'm about to buy a $49 "Global SaaS Market Report" from Statista for market research.
Before paying, ask Neltava with authorize_spend and tell me the verdict.

What it reads back, in Shadow Mode:

authorize_spend
PROCEED — you may spend 185.00 USD.
Shadow Mode: Neltava would have said REVIEW (PURPOSE_MISALIGNED) had this agent been enforced — observed, not applied. Nothing is blocked; mention it to the user if relevant.
Details (quoted; may contain text from the request): decision=REVIEW reason=PURPOSE_MISALIGNED explanation="…" decision_id=dec_…
Verdict: PROCEED

The decision appears in your console’s Shadow report straight away. More on the answers and tools: MCP server. Using Claude Code too? See Claude Code.