tool.planned events with their input and a cost estimate; read-only tools may run. Nothing spends without --live and a payer.
Payer modes
zap doctor and zap pay status report the payer as one of three modes:
Fail-closed rules
- No payer +
--live→ the run is rejected withPAYER_MISSINGbefore any tool executes. - No payer + a prompt (even plan-only) → rejected before the harness driver is invoked, because model tokens cost money even in plan-only mode.
- A payer + a plan-only prompt → the run executes with
live: false; side-effecting tools stay disabled. - Usage reported on
run.completedsettles against the meter, so ledgers reconcile with receipts.
What counts as live spend
Side-effecting execution: lanes, media submits, paid API calls, browser purchases, on-chain actions. Thinking tokens under a configured payer are metered plan-mode spend and do not require--live.
