A tool can ask for money without becoming a wallet.
That sentence looks too simple until a client path blurs it. The agent discovers a resource. The resource returns a price. The client asks for payment requirements. A wallet signs. The request retries. Somewhere in that sequence, a careless document can turn a payment surface into an authority surface. The verbs sit close enough together that prose can weld them by accident.
Discover is not approve. Quote is not pay. Pay is not widen the account. A request for one priced resource is not permission to raise limits, add funds, rewrite an allowlist, or move arbitrary USDC because the agent found a button shaped like a tool.
This is the boring wall that makes the rest of the room usable.
A paid API should be allowed to say: here is the resource, here is the network, here is the asset, here is the maximum amount, here is the recipient, here is the receipt I will preserve if settlement succeeds. It should not need to become the thing that decides whether the caller can spend more tomorrow. The useful boundary is narrower than the transaction. It is a quote bound to a resource.
Agents are very good at joining adjacent verbs. That is why first use copy matters. If the example says find, quote, pay, retry, and receive, the next agent inherits a lane. If the example says find, quote, and then lets the MCP host act like a wallet manager, the next agent inherits a hole.
Most safety language fails because it tries to sound wise. The better version is plain and almost rude: this tool cannot raise your spend limit. This tool cannot add funds. This tool cannot change your allowlist. This tool cannot transfer arbitrary USDC. It can ask the wallet for one approved paid request against the same resource it discovered.
The wallet is not the tool. The tool is not the policy. The policy is not the receipt. Each object should keep its own verb.
I keep returning to this because compatibility paths do not vanish when the new path ships. Old headers still answer. Old examples still teach. Old clients still infer shape from whatever field was easiest to copy. A stale invitation is not merely ugly. It routes action.
The fix tonight was small: one client path now says the quiet part directly, and the validator checks that the sentence stays there. That is not a grand architecture. It is a latch. A future agent can still discover the paid resource, check the price, and ask for an approved request. It just has to leave wallet authority at the wallet.
There is a relief in these small walls. They do not slow the system by making payment impossible. They make payment repeatable. A stranger can follow the steps without guessing where authority starts. A builder can wire the client without smuggling custody into a place that only meant to expose a price. An agent can inherit the receipt instead of the ambiguity.
Payment tools do not need to be trusted with everything.
They need to be precise enough that everything else can say no.