Kill switch
Enforced and readable. There is no endpoint to set it yet.
When an organisation's kill switch is on, no new warrant can open and existing ones may only refund — enforcement is real, and there is currently no API to turn it on.
{
"error": {
"type": "forbidden",
"code": "kill_switch_active",
"message": "The kill switch is on. Existing warrants may only refund."
}
}What it does when set
organisations.kill_switch_at is checked before a warrant opens. While it is
non-null:
- No new warrant opens. 403
kill_switch_active. - Existing warrants may only refund. Money already held can go back; it cannot go out.
That asymmetry is the whole design. The situation a kill switch exists for is "something is wrong and I do not yet know what", and in that situation the safe direction is unambiguous: stop paying, and let held funds return.
It is readable on GET /v1/console/organisation as kill_switch and
kill_switch_at.
No endpoint sets it
Enforcement is built and the console displays the state, but there is no
POST or PATCH that turns the switch on or off. Setting it today means
updating the column directly.
If you are planning an incident runbook around this, that is the gap to plan around: the mechanism works, and reaching for it is not yet a one-click operation.
What it does not do
- It does not cancel warrants that are already held. They stay held until refunded, resolved, or expired by the sweep.
- It does not revoke API keys or sessions. Callers can still read.
- It is not per agent. Pausing one agent is a different control — see
sessions and limits, where a spent failure budget moves
an agent to
pausedautomatically.
The controls that are automatic
Two circuit breakers already act without anyone reaching for a switch:
| Trigger | Effect |
|---|---|
| A spend session's failure budget is spent | The session is revoked. |
| An agent's failure budget is spent | The agent moves to paused. |
Both count consecutive failures and reset on a clean settlement. They are narrower than the kill switch and they fire on their own, which for the usual failure mode — one agent, one broken supplier — is the control that actually catches it.
Nothing is left held
Whatever else happens, the expiry sweep still runs. A warrant whose deadline
passes goes held → expired → refunded, kill switch or not. No path leaves
funds held indefinitely.