Skip to content

Define and implement optional non-monetary credits and free-tier limits #83

Description

@ctfbruce

Problem

TEST marks intents paid and records local earnings, but it is not a user credit balance or free-tier policy. There is no supported allowance, hosting-credit or per-account spending contract.

Proposed change

Offer an optional non-monetary allowance model for authenticated users with explicit issuance, reservation, consumption and refund rules, without requiring a wallet or implying a transferable monetary balance.

Acceptance criteria

  • Decide whether allowances are fixed, periodically replenished or earned by hosting, and document abuse/Sybil assumptions and operator authority.
  • Store auditable credit grants/reservations/consumption with bounded values and idempotent run/order linkage; expose remaining allowance through a versioned API and SDK/CLI.
  • Test concurrent submissions, exhausted allowance, cancellations, unknown run outcomes, grant renewal and restart without double-spending or automatic refunds of uncertain work.
  • Keep anonymous local TEST mode separately explicit and retain monetary activation as an independent optional feature.

Current evidence

unimplemented product feature; source inspection only, no new runtime reproduction. Backlog classification is based on source inspection; this issue does not claim a new runtime reproduction.

Dependencies

  • #88 — Replace UUID-cookie login with authenticated user sessions
  • #89 — Enforce ownership and role authorization on every HTTP operation
  • #35 — Make repeated submission return the same admitted run identities

Related work

These are integration points, not prerequisites for starting this issue.

  • #77 — Define exact pricing units and reject overflow before persistence
  • #66 — Enforce aggregate user and target-group egress budgets
  • #99 — Enforce per-account request and concurrent-work admission quotas

Priority context

Optional adoption/economic-policy feature after core local usability; not a correctness prerequisite for TEST.

Activation

Optional work, deferred while the local team alpha is the priority. Development and fault injection use owned local fixtures. Production monetary operation, deployment and publication require the applicable release and operator approvals.

Validation must use owned local fixtures on supported Linux environments. Record the implementing merge request and relevant test results before closing this issue.


Imported from GitLab issue 82. Originally opened 2026-09-10. Historical GitLab links may require access to the original project.

Activity

  1. added this to the Optional payments milestone on Sep 24, 2026
  2. added
    DeferredIntentionally deferred; see the issue for its activation condition.
    FeatureA specific missing product behavior.
    OptionalAn optional product expansion, not required for the local team alpha.
    Optional paymentsOptional credits and monetary settlement, outside the supported wallet-free alpha.
    P2Follow-on improvement or optional expansion after core requirements.
    Source reviewedCurrent source evidence checked; no new runtime reproduction claimed by backlog creation.
    on Sep 24, 2026
  3. ctfbruce commented on Oct 7, 2026

    @ctfbruce
    CollaboratorAuthor

    Implemented by #380 and #407, verified on main 7ad50b0b717108459f5c11af74698d4785e3c6ed.

    • Allowances are optional, fixed grants issued by authenticated operators with a recorded reason and idempotency key. There is no automatic refill, hosting reward or cash redemption. The policy explains operator authority and the absence of inherent Sybil resistance.
    • Immutable grants and existing order/settlement records provide auditable granted, reserved, consumed and remaining TEST units. Atomic reservation prevents concurrent overspending; bounded integer totals refuse overflow. API 1.15, the SDK's Allowance method and dbl allowance expose exact amounts, including JSON output. Disabled or unauthorized reads do not invent a balance.
    • The Linux main test job passed the allowance concurrency/exhaustion, expiration-versus-admission, idempotent additional-grant, overflow, unknown-outcome/restart, cancellation/settlement recovery and CLI cases. Settled orders consume TEST allowance even when refunded; uncertain admitted work stays reserved. Only expired intents with no admitted run release their reservation.
    • Anonymous local-development TEST remains explicitly uncapped and separate from authenticated allowance enforcement. Shipped configurations leave allowances disabled. Monetary activation remains an independent optional feature; this change activates no payments or deployment.

    All four acceptance criteria are covered. Main CI passed all 16 jobs: run 37621446527.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    DeferredIntentionally deferred; see the issue for its activation condition.FeatureA specific missing product behavior.In progressImplementation is active.OptionalAn optional product expansion, not required for the local team alpha.Optional paymentsOptional credits and monetary settlement, outside the supported wallet-free alpha.P2Follow-on improvement or optional expansion after core requirements.Source reviewedCurrent source evidence checked; no new runtime reproduction claimed by backlog creation.

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions