A chat widget wired to a language model, built around the assumption that an anonymous endpoint spending money will eventually be pointed at.
A retrieval-augmented agent that answers questions about this site from a curated knowledge base. Entries are embedded and stored as pgvector columns in PostgreSQL; a run retrieves the top matches, composes a layered prompt, calls the provider, and can invoke exactly one tool — creating a contact request — when the conversation calls for it. Widget conversations carry a six-turn window, because every turn resends everything before it and an unbounded history has no ceiling on cost.
A public chat box attached to a paid API is an open invoice. The interesting failure is not a wrong answer, it is a bill nobody capped and a month later nobody can reconstruct.
Budget is reserved from the period's balance before the provider is called and reconciled against the reported usage afterwards, so the cap holds in both directions. Every run is persisted, including the ones rejected for lack of balance, because a rejection that leaves no row is a rejection nobody can explain later. The three points where money is at stake all fail closed: no configuration, no priced model, or no balance means no run.
"I do not know what this costs" is not permission to spend, so a model missing from the price catalog has to be rejected rather than estimated. And the rejected run is the most valuable row in the table: it is the only evidence of the ceiling doing its job.