Three ways to place an order. The same limits on all of them.
Your wallet in the app, x402 agents calling typed MCP tools and paying per call, and enterprise users on the REST API with replay-safe webhooks. Each check is read off your account rather than off the instruction, which is why the surface that asked makes no difference to what is allowed. Sessions are bound to the device that opened them.
