Most AI shopping agents don’t give you a real AI agent spending limit, meaning a per-purchase or monthly cap you set once and the agent can’t exceed. ChatGPT, Google’s agentic checkout and Amazon’s Buy for Me depend on you confirming each order. Hard caps you can set yourself show up in only two places we could document: stablecoin agent wallets, and the card layer, where a merchant-locked virtual card or an issuer’s own controls do the work.
How we checked this
We read the official pages for each layer, from platform help centers to card network announcements, one issuer help page and Coinbase’s developer docs, between September 23 and 24, 2026. For each control we asked: does it exist, who sets it, and can the agent change it? Where no page documented a control, we wrote “no control documented” rather than guessing.
The four layers, in one table
A purchase made by an agent passes through up to four layers. Each one can stop a payment, but only some of them let you set the stopping point. Facts checked on September 24, 2026.
| Layer | Example | Per-purchase cap you set | Monthly/session cap you set | What you actually control |
|---|---|---|---|---|
| Platform | ChatGPT Instant Checkout | No control documented | No control documented | Confirm each order; choice of card |
| Platform | Google agentic checkout (Google Pay) | Price you confirm acts as a ceiling for that one order | No control documented | Confirm total; purchase fails if the price rises |
| Platform | Amazon Buy for Me | No control documented | No control documented | Tap to request each purchase |
| Network | Visa Intelligent Commerce, Mastercard Agent Pay | Described in announcements, not as a consumer setting | Not documented as a consumer setting | Agent-specific tokens, passkey step-up |
| Issuer | Capital One virtual card numbers | No per-number limit documented | No | Merchant lock, lock/unlock, delete |
| Stablecoin | Coinbase Agentic Wallets | Yes: “max per call” | Yes: “max per session” | Caps set in the wallet UI that the agent can’t change |
The pattern is clear. The closer a layer sits to the money, the more concrete the control. Platforms rely on confirmation, networks describe controls that issuers and agent developers build on, and the only user-set numeric caps we found sit in a developer wallet product. For how these layers connect in general, start with our agentic payments explainer.
Platform layer: ChatGPT, Google and Amazon
ChatGPT. OpenAI’s Instant Checkout announcement (September 29, 2025) says users “explicitly confirm each step before any action is taken,” and that “encrypted payment tokens are only authorized for specific amounts and specific merchants with the user’s permission.” You can pay with a card on file or other express options. The page does not describe a spending cap, a monthly budget or a way to require a lower limit than the order total. Settings can change, so check ChatGPT’s own payment settings before you rely on that.
Google. The Google Pay help page on agentic checkout describes the closest thing to a per-purchase cap at the platform layer. You confirm a total price, and the agent is “designed to buy the product if the final price is the same as, or lower than the total price you confirmed.” If the price goes up, “the purchase won’t go through, and you won’t be charged.” That’s a ceiling for one order, not a budget. The page mentions minimum and maximum transaction amounts, but those are set by merchants, not by you. It doesn’t document a monthly limit or explain how to turn the feature off, and for cancellations it tells you to contact the merchant.
Amazon. Amazon’s Buy for Me announcement (beta launched April 3, 2025) says you tap a button to ask Amazon to buy from a brand’s own site, and Amazon passes your “encrypted name, address, and payment details” to that site. Delivery, returns and customer service are handled by the brand. The announcement documents no spending control. Our Buy for Me guide covers the flow in more detail.
The takeaway for this layer: confirmation is the control. It works only if you actually read the total each time.
Network layer: what a “scoped credential” means for you
Visa and Mastercard don’t give you a settings screen. They define how agents get card credentials, and those credentials can carry limits.
Visa’s developer page for Intelligent Commerce lists “agent-specific payment tokens that can be used by agents to make secure transactions on behalf of the user,” “Controls to ensure that the agent’s purchasing actions and the related authorizations align with the user’s authenticated instruction,” and step-up verification with a passkey. It also says the “user’s original instruction and the details of each authorized purchase” are kept as commerce signals to help resolve disputes. Visa’s consumer-facing page names “spending limits, approval workflows, authentication requirements and trusted identity signals” among the controls, without explaining where a cardholder sets them. Checkout.com’s 2026 trends piece (January 27, 2026) notes that Visa “has updated its network token provisioning to grant AI agents context-specific payment credential use.”
Mastercard’s Agent Pay announcement (April 29, 2025) introduced Agentic Tokens built on existing tokenization. It says consumers “will have complete control over what the agent is allowed to purchase on their behalf” and that agents must be “registered and verified.”
So what does “scoped credential” mean for you? The agent doesn’t hold your real card number. It holds a token issued for that agent, and the token can be tied to your instruction, such as a merchant, an amount, or the thing you asked for. If the agent tries to use it outside that scope, the network or issuer can decline. The limitation: you set the scope indirectly, through what you tell the agent and confirm, not through a dial you control. For more on cardholder impact, see Visa Trusted Agent and Mastercard Agent Pay: what changes for cardholders.
Issuer layer: virtual cards and merchant locks
This is the layer you can use today with no new product, as long as your issuer supports it. Capital One’s help page on virtual cards says you can “create virtual card numbers good for use at one merchant only,” hold several at once, and “lock or unlock your virtual cards at any time without affecting your ability to make other purchases with your actual card number.” You can also delete a merchant-specific number. Not every card or user is eligible: the page says some retail partnership cards and authorized users may not be.
What the page does not document is a spending limit per virtual number. So a Capital One virtual card limits where an agent can spend, not how much. Other issuers and virtual-card services may offer per-card amount limits. Check your own issuer’s help pages rather than assuming.
Do virtual cards work with agent checkout? It depends on how the agent pays. When the agent uses a card saved in a wallet or account, like Google Wallet or a card on file in ChatGPT, you can usually save a virtual number there instead of your main card. A merchant-locked number, though, only works at the one merchant it first gets used with. That fits a recurring purchase from a single store, but not open-ended shopping. When the payment runs through a network token, the token stands in for the card number anyway, and your issuer’s controls on the underlying account still apply.
Stablecoin layer: agent wallets with hard caps
The clearest user-set caps we found are in Coinbase’s Agentic Wallets, announced on February 11, 2026. The launch page lists session caps (“Set maximum amounts agents can spend per session”), transaction limits, private keys kept “in secure Coinbase infrastructure, never exposed to the agent’s prompt or LLM,” and built-in KYT (Know Your Transaction) screening that “automatically blocks high-risk interactions.”
The developer FAQ is more concrete. It lists “Max per call” (its example is $0.05) and “Max per session” (example: $5.00), which you set “manually in the wallet UI.” It also states: “Agents respect these limits but can’t change them.” That last point is what makes it a real limit. The agent can’t raise its own ceiling.
Two caveats. First, these wallets pay in stablecoins over x402, a protocol for per-request payments, mostly to APIs and data services, not to retail checkouts. Our x402 explainer covers how that works. Second, it’s a developer product. It’s not a consumer shopping setting, and stablecoin balances don’t carry the dispute rights of a credit card. This is an explanation of the controls, not a suggestion to hold crypto.
A layered setup, without buying anything new
No single layer covers everything, so we suggest stacking whatever you already have:
- Pay with a separate card number. If your issuer offers virtual or merchant-locked numbers, save one of those in the agent’s wallet instead of your main card. If something goes wrong, lock it or delete it without touching your main card.
- Use your issuer’s alerts and limits. Check what your bank’s app offers for the card your agent uses. If it supports transaction alerts or limits, turn them on for that card.
- Treat the confirmation screen as your cap. On ChatGPT and Google, the total you confirm is the only per-order ceiling documented. Read it every time.
- For per-request agent payments, fund only what you’d accept losing. Where you can set a per-call and per-session cap, set both low and fund the wallet with a small amount.
- If a product documents no control at all, don’t connect it to a card you can’t lock. Use a locked or low-balance payment method, or skip it until controls appear.
If a purchase does go wrong, our guide to refunds, chargebacks and liability walks through your options. For disputes involving significant amounts, consider talking to your card issuer first and a consumer-protection professional if needed.
What to watch out for
- Confirmation fatigue. A confirm step only protects you if you read it. Once you’ve approved ten orders in a row, it’s easy to tap through the eleventh.
- Merchant locks aren’t amount limits. A merchant-specific virtual card stops spending elsewhere, but it won’t stop a large order at the merchant it’s locked to.
- “Control” in announcements isn’t a settings page. Network press releases describe what the system supports. Whether you see a limit depends on your issuer and the agent’s app.
- Price protection only covers one order. Google’s “won’t go through if the price rises” rule caps a single purchase, not your total spending.
- Returns move to the merchant. With Buy for Me and Google’s agentic checkout, cancellations and returns go through the brand or merchant, not the AI platform.
Go deeper
- Agentic payments, explained: how AI agents pay and who is behind it (hub)
- An AI agent bought the wrong thing. Who pays? Refunds, chargebacks and liability
- Agentic commerce protocol tracker: ACP, UCP, AP2, TAP, Agent Pay, x402 — who supports what
- Amazon “Buy for Me”: how it works, what it can spend, how to cancel
- All guides in Agentic payments




