What agent actions cost and how they're secured
What it costs#
Reading, counting, adding, editing, tagging and running quality checks are free. Everything an agent spends comes from the workspace owner's credit balance, the same balance the members of that workspace use. AI column filling is billed by usage, like AI derivations in the app. Credits are also spent when the agent triggers an enrichment type you've allowed (see "API connection: permissions and presets" for the list and exact per-lookup credits) or a paid research tool like Reddit Search or Twitter/X Search. Google Search, Hacker News Search and Website Scrape are always free. See "Price list" for exact per-action amounts, and "Not enough credits" for what an agent gets back if the balance is too low (an HTTP 402 error over REST, a tool error over MCP). Over REST, an agent can check your balance first with the credit_balance action.
Limits on a single request#
Four separate limits, all set on the Permissions tab, cap how much one call — or the connection overall — can do:
- Max records per enrich request — how many rows one enrichment call can touch at once (only shown once you've allowed at least one enrichment type).
- Max rows per query — how many records a single query can return.
- Max total rows — a lifetime cap on how many rows this connection can ever add (0 = unlimited).
- Requests per minute — the connection's overall rate limit; calls above the connection's limit are refused with an error until the minute is over.
Executions log#
Every call a connection handles — success or error — is logged on the Executions tab: the action, a short detail line, credits spent, the time, and how long it took, grouped by day with a running Calls/Errors count and a Download CSV button. If nothing has called the connection yet, the tab just says "No executions yet."
The secret URL#
The connection's URL is the credential: whoever has it can act within that connection's permissions, so treat it like a password — don't paste it somewhere public, and only share it with the AI or tool you intend to use it with. It's shown in full on the Overview tab for as long as the connection exists.
No rotation — delete and recreate#
There's no button to generate a new secret while keeping the same URL. If a URL may have leaked, or you just want a fresh one, delete the connection (Permissions tab → Delete API Endpoint, which immediately stops the old URL from working) and create a new one from the list's Automation panel — it gets its own new URL.
Turning it off without deleting it#
The Active/Inactive switch next to the connection's name turns access off and back on without losing your permissions or execution history — while inactive, every call to that URL is refused. Expires on (Permissions tab) does the same thing automatically on a date you set, after which calls get an HTTP error stating the endpoint has expired.
Related topics: api-connection-overview · api-connection-setup · api-permissions · billing-in-workspaces · not-enough-credits · price-list.
FAQ#
Does it cost credits just to let an agent connect to my list?#
No. Creating the connection and letting an agent query, add, edit, tag or run quality checks is free — credits are only spent on actions that cost credits in the app too, like enrichment, AI column filling or paid research tools, at the same rate. Those credits come from the workspace owner's balance.
How much does an enrichment an agent triggers cost?#
The same as the identical lookup costs in the app — see the price list for exact per-action credits. You also choose which enrichment types a connection may use at all, so an agent can never spend credits on a lookup you haven't explicitly allowed.
What's the maximum an agent can do in one request?#
Four separate caps: max records per enrich request, max rows returned per query, a lifetime max total rows the connection can add, and a requests-per-minute rate limit — calls above the connection's limit are refused with an error until the minute is over.
Where can I see what an agent has done with my list?#
The connection's Executions tab lists every call — action, result, credits spent, time and duration — grouped by day, with a Download CSV button for the full history.
Is the connection's URL secret, and what happens if it leaks?#
Yes — the URL itself is the credential, so anyone who has it can act within that connection's permissions; treat it like a password. If it may have leaked, delete the connection and create a new one to get a fresh URL, which stops the old one from working immediately.
Can I rotate the URL, or just pause access without losing my settings?#
There's no separate "rotate" button — the way to get a new URL is to delete the connection and create a new one, which also means reconfiguring its permissions. To pause access temporarily instead, switch the connection to Inactive next to its name; every call is refused while it's off, and your permissions and past executions stay exactly as they were when you switch it back on.
Can I make a connection expire automatically?#
Yes. Set Expires on (Permissions tab, date picker) and the connection stops accepting calls after that date on its own, without you having to remember to disable or delete it.