What this is for
Guardway can stop spend at three levels: on one API key, on an application (every key bound to it), and on a team (every key that belongs to it). They differ in what they cover, whether they reset, and which alerts they send, so the budget you set has to be the one you meant. A “1,000 monthly budget” on an application refills every month. This page compares the three kinds, shows where each is set in the dashboard and through the Claude connector, and describes thebudget.threshold and budget.exceeded alerts.
All three are hard caps enforced by the gateway. Spend is the cost of each request as priced on Settings → Pricing.
Options
The three kinds at a glance
Per-key budget
A per-key budget is a lifetime spend cap in USD on one key. The gateway adds up everything the key has spent since it was created and refuses the key’s requests once that total reaches the budget. It never resets: to let the key spend again, raise or remove the budget, or issue a new key.Application budget
An application budget is the budget section of an application’s policy: a limit in USD and a period. It covers the combined spend of every key bound to the application, so you can budget an agent or a service rather than one credential. A key is bound to an application with the Application field of the key (see API Keys).- Daily and Monthly windows start when the application first spends under the budget and then roll forward by one day or one month at a time. They do not follow the calendar.
- Total (lifetime) never resets.
- The spend counter starts at $0 when the budget is first used. Spend from before the budget existed is not counted.
- A changed limit applies from the next request once the gateway has the updated policy, usually within a minute. Lowering the limit below current spend blocks the application right away; raising it lets requests through again.
Team budget
A team budget caps the combined spend of the keys that belong to a team in the current calendar month (UTC). It resets at 00:00 UTC on the first day of each month.team_id); the Create API key dialog has no team field.
How to choose
A hard ceiling on one credential, for its whole life
A hard ceiling on one credential, for its whole life
A recurring allowance for an app, an agent, or a service
A recurring allowance for an app, an agent, or a service
A monthly allowance for a group of people
A monthly allowance for a group of people
Both a recurring allowance and a lifetime ceiling
Both a recurring allowance and a lifetime ceiling
Setting budgets with Claude
The Claude connector can set per-key and application budgets. It cannot set a team budget: set that in Configuration → Access → Teams.A lifetime cap on this key only, or a monthly or daily budget for an application, shared by all keys bound to it?Say which one to skip the question:
- “Create a key called
ci-botwith a $20 lifetime budget on the key that alerts at 80%.” - “Create a key called
support-workerfor the support app, and give the support app a $500 monthly budget shared by all of its keys.”
Alerts
Budgets send two events, delivered through Settings → Notifications to webhook endpoints and alert rules.When each event fires
budget.threshold: reaching the budget is reported once, by budget.exceeded, when the next request is refused. With the dialog default 50,80,100, a key sends warnings at 50% and 80% and budget.exceeded when it is blocked.
Alerts are evaluated after each request’s spend is recorded, never on the request path. An alert that cannot be evaluated is retried on the budget’s next recorded spend, and no request is delayed or refused because of it. Several gateway replicas that share one database send each alert once.
Subscribing
Pick these events in a webhook endpoint’s Events list, or use them as an alert rule Condition:Payload
Everybudget.threshold and budget.exceeded payload from a budget carries:
- Per-key
budget.threshold:key_id,key_name,key_prefix, andteam_idwhen the key belongs to a team. - Application events:
application_id,budget_id,period,period_start, andperiod_endfor daily and monthly budgets.budget.exceededalso keeps the fields itsspend.thresholdcarried (current_spend,path,budget_enforced,streaming) and adds the refused client’sip. - Per-key and team
budget.exceeded:key_id,type,used,limit,path, andip; a team refusal addsteam_id. These do not carryscopeorthreshold.
How to configure
Decide which budget you need
Set the budget
- Per key: Configuration → API Keys → Create Key → Limits: set Budget ($) and Budget alert thresholds (%). For an existing key, use FinOps → Budgets.
- Per application: Security → Apps → New application and set Monthly budget (USD), or open the application’s policy in Security → Policy and set Budget (USD) and Period in the Budget section. Bind the application’s keys with the key’s Application field.
- Per team: Configuration → Access → Teams: set Monthly spend limit (USD) when creating or editing the team.
Route the alerts
budget.threshold or budget.exceeded. See Notifications.Check the gateway version
budget.exceeded need gateway v0.6.4 or later. See Alerts.Limits
- Spend comes from pricing. A model with no price on Settings → Pricing costs $0, so it never moves a budget.
- The crossing request completes. Budgets are checked before each request against the spend recorded so far. The request that takes spend past the limit is served, so final spend can end slightly above the cap; the next request is refused.
- Per-key and team budgets fail closed. If the gateway cannot read the spend, it answers HTTP 503
quota_check_failedrather than serve the request. Application budgets fail open: the request is served. - A zero-dollar application budget refuses every request from the application’s keys.
- Each gateway counts its own spend. Budgets are measured against the request history in the gateway’s own database. Gateways that do not share a database each count only the spend they served, so a key used on two such gateways can spend up to its budget on each.
- Request retention shortens a per-key “lifetime”. A per-key budget sums the key’s requests still in the gateway’s local history. With
GUARDWAY_RETENTION_DAYSset (see Environment), requests older than the retention window are deleted and stop counting, so the cap then covers roughly that window instead of the key’s whole life.
FAQ
My key shows a budget but I get no alerts
My key shows a budget but I get no alerts
- Gateway version. Before v0.6.4, per-key thresholds are stored but never sent. The key’s detail panel says “(not sent yet)” next to them.
- Thresholds. A key created without Budget alert thresholds (%) sends no warnings, only
budget.exceededwhen it is blocked. A key created through Claude has thresholds only if you asked for them. - Only below 100%. A threshold of 100 is reported as
budget.exceededwhen the key is blocked, not asbudget.threshold. - Already sent. Each threshold fires once per budget amount. A key already past 80% does not warn again until you change its budget.
- Subscription. The webhook must be subscribed to Spend Threshold or Token Budget Warning. An alert rule on
budget.exceededdoes not fire on warnings.
I set a $1,000 budget on a key and it stopped working after a few months
I set a $1,000 budget on a key and it stopped working after a few months
Why does my team budget never warn me before it blocks?
Why does my team budget never warn me before it blocks?
budget.exceeded when the team’s keys are refused. For warnings, use an application budget, which warns at 50% and 80%.I get a budget.exceeded on every request after my key is blocked
I get a budget.exceeded on every request after my key is blocked
budget.exceeded for every refused request. Use an alert rule with a Cooldown to limit how often you are notified.My application budget doesn't reset on the 1st of the month
My application budget doesn't reset on the 1st of the month
Can Claude set a team budget?
Can Claude set a team budget?
Related
- API Keys — create keys, set a per-key budget, and bind a key to an application.
- Access — teams and their monthly spend limit.
- Notifications — webhook endpoints and alert rules that receive budget alerts.
- Pricing — the per-token prices that budgets are measured in.
- Spend — where spend against budgets is reported.