KIFF · Cards for AI agents
Your agents act for you. Your Cards decide how far.
A KIFF Card is the authority you give an agent, kept with you instead of inside the agent. Requests within the Card go through. Anything past it stops and waits for you. It works with agents whose code you can change, and with any agent that reaches its tools over MCP.
support agent · refunds
€800 a refund€6,000 a refundNo authority
€2,500 of €3,000 left this month€4,500 of €10,000 left this monthHistory kept on its statement
you
Your support agent wants to refund €5,000 on a cancelled order. Earlier today it refunded €500 on another.
agent prompt and logic changednonesample dataKIFF decides before anything runs
A permission says yes. A Card says how far.
- asks
- May the travel assistant book?
- answers
- Yes
- after a booking
- Still yes
- asks
- How much can it still book?
- answers
- €2,500 left this month
- after a booking
- Remaining authority changes
A Card is authority you can hand over, watch being used, and take back.
what you set on a Card
- The action, such as refunding an order or changing a plan.
- Which records it applies to, such as paid orders only.
- A limit per action, such as €500 per refund.
- A total per day, week or month, as an amount or a count.
- An expiry, if you want one.
- What happens to a request over the limits: it waits for you, or it is refused.
Permissions still decide what an agent may touch. The Card is checked on top of them and decides how far.
why this exists
Any agent can have a limit coded in. That is not the same as yours.
A limit inside an agent belongs to the agent
Whoever builds or runs the agent sets it and can change it. Every agent has its own, written differently, and none of them can see what the others have already done for you.
A KIFF Card belongs to you
It sits outside the agent. Every agent you give it to asks it before acting, and the action runs only if the Card allows it. You can change it, move it to another agent or take it back without touching any of them.
It keeps the record
Each Card shows what it has allowed, what is left and what you approved yourself, with a receipt for every decision. The record stays with the Card, not with whichever agent held it.
- used by
- You
- limits
- Money you spend
- when it is over
- Declined
- used by
- Agents acting for you
- limits
- What they may do: bookings, refunds, deploys, messages
- when it is over
- It waits for your answer
many agents, one owner
Several agents, several Cards. The Card has the final word.
Each agent you use gets the Cards for the jobs you give it. Whatever the agent decides, the request goes to the Card before anything happens.
- support agentRefunds · €500 per refund€200 refund, order #8812allowed
- support agentRefunds · €500 per refund€1,500 refund, order #8831waits for you
- billing agentPlan changes · 40 a day12th plan change todayallowed
- coding agentProduction · 2 deploys a daythird deploy todaywaits for you
- inbox agentMessages · 20 sent a day21st email todaywaits for you
This holds wherever the action has to pass KIFF: in code that asks KIFF first and stops on any answer other than allowed, which is what KIFF Guard does, or through the KIFF gateway, where the agent can reach its tools only through KIFF. The example below shows one of these Cards in full.
the same for a company
A support agent with a refunds Card.
The agent refunds orders on its own within these limits. A refund above them waits for you.
- job
- Refund late or damaged orders
- on what
- Paid EU orders only
- per action
- Up to €500
- in total
- €30,000 a week
- outside the Card
- Comes home to you
- #8812 damaged in transit€200allowed
- #8820 wrong size€350allowed
- #8840 duplicate charge€400allowed
- #8831 never arrived€1,500held for you
The first three were within the Card, so nobody had to approve them. The fourth was over €500, so it waited for the owner.
Move customers to another plan
40 changes a day
This limit is a number of changes, not an amount of money.
Give your agent this Card →Roll back a bad deploy at night
2 rollbacks a day
A third rollback in a day waits for the platform team.
Try this Card with sample agents →Your system asks KIFF before it acts.
Requests within the Card are allowed straight away, and each one is recorded on the Card's statement.
d = kiff.decide("issue_refund", order=order, amount=amount)
if not d.allowed:
return d
payments.refund(order, amount) # your code, unchangedYou add one call before the action. Your system runs the refund only if KIFF allows it. KIFF does not touch payments.
Each allowed refund is subtracted from the Card and listed here, with a signed receipt.
agents you can't change
Or connect the agent to KIFF over MCP.
Connect the agent to KIFF instead of to its tools, and connect the tools to KIFF. KIFF keeps the tools' credentials, so the agent has no other way to reach them. Each call is checked against the agent's Card, then sent to the tool, held for you, or refused.
your agent ──MCP──▶ mcp.kiff.dev ──MCP──▶ your tools
│
└─ checks the agent's Card firstKIFF does not host the agent. The agent still plans the work, and the tool still does it. A tool that is also connected to the agent directly is not covered.
Waiting for the owner's approval: this call is outside the agent's Card. Nothing has been sent to the tool.
The message links to the place where you answer. When the agent retries the same call, it gets your answer, and the call is sent at most once.
Works with agents that use remote MCP over HTTP; tested with Claude Code and Codex. Tools are remote MCP servers at a public HTTPS address. You connect them, and each agent, from KIFF Cloud.
When a request goes past the Card.
KIFF holds it and emails you. Nothing runs until you answer, and if nobody answers in time it is refused.
support-agent wants to refund €1,500 on order #8831.
The Card allows up to €500 per refund. This one is €1,000 over.
- Approve once
- This authorizes the request. When your agent asks again, it is allowed: your system runs the refund, or, through the gateway, KIFF sends the call to the tool once. The Card does not change, and the refund is listed separately on its statement.
- Change the Card
- The limit is raised enough to allow this refund, and it stays raised. The change is recorded on the Card.
- Reject
- Nothing happens.
- No answer
- A held request waits as long as the Card says, 10 minutes unless you choose otherwise, then it is refused and nothing happens. An approval given later cannot let a stale request run.
What authority have we put into the world, and how much is left?
KIFF Cloud
Your Cards, in one place.
KIFF Cloud lists every Card by the agent that holds it. Each Card shows what remains and keeps its revision history. You can change a limit, move a Card to another agent, or revoke it.
tap a Card to revoke it
Revoking a card withdraws only the authority that card granted. The others keep working.
revisions
- rev 314:20limit €5,000 → €8,000anna@retailer.example
- rev 2Monlimit €20,000 → €5,000anna@retailer.example
- rev 1Frilimit €5,000 → €20,000marc@retailer.example
not a mockup · the real app, sample data
busy weekend · refunds limit €5,000 → €20,000
Same change. Two ways.
- Open a ticket
- Edit the prompt or config
- Review and test
- Deploy
- Monday: do it all again
2 releases
- Owner sets €20,000
- Monday: owner sets €5,000
0 releases
Both changes saved, with who made them.
how teams adopt KIFF
Free to build. Paid when it runs your business.
Framework + Guard
Open source. Put KIFF in front of any agent action, on any stack. No contract, no procurement.
Start building →For the company
- Company workspace
- Owner controls for every card
- Dashboard and statements
- Full history and evidence
- Grows with your agents
Production Launch
We connect your first real action, issue the first cards, test the controls and hand it over.
Get it live with us →Questions teams ask first.
Do I have to rewrite my agent?
No. If you can change its code, you add one call before the action, and if KIFF says no, your code stops. It works with Agno, LangGraph, OpenAI, Google ADK, Strands, n8n or your own code. If you can't change it, connect it to KIFF over MCP instead of to its tools.
d = kiff.decide("issue_refund", order=order, amount=amount)
if not d.allowed:
return d
payments.refund(order, amount) # your code, unchangedCan the agent raise its own limit?
No. The agent’s key can only ask for a decision. Only an owner or admin of your KIFF account can issue, change or revoke a card.
Does every action need a Card?
No. You choose which actions require one. Permissions and the state of the record are checked first; a Card can narrow and cap what they allow, never widen it.
What does the agent see while an action waits for me?
A held answer, not an allowed one, so it does not act. Guard SDKs only run an action on allowed. Through the gateway, the agent is told the call is waiting for you, with the link where you answer, and nothing is sent to the tool. Either way, the same request asked again gets your decision, and if nobody answers before the hold expires, it is refused.
What if KIFF cannot read the balance?
The answer is no. An unknown balance is never treated as zero, and a retried request is only counted once.
Does KIFF run the action or touch payments?
With Guard, no: KIFF only answers whether the action is allowed, and your system runs it as it does today. Through the gateway, KIFF sends an allowed call to the tool you connected, at most once, using the tool's credential, which KIFF stores encrypted. The tool does what it always does; KIFF never moves money itself.
Is it only for money?
No. A card can limit amounts, or how many times something happens: three account deletions an hour, two deploys a day.
Can a new model start small?
Yes. Give it its own card with a low limit, and raise it when its statement looks right. The other agents never change.
We build agents for clients. Does it fit?
Yes. Ship the same agent to every client. Each client holds its agents’ cards in its own KIFF account and changes them without calling you.
Start with one Card.
Open your assistant with a prompt to read llms-full.txt and answer from it.