Docs Start here
Held calls and approvals
When an agent asks for something outside its Card, and the Card says to hold such calls, KIFF holds the call and asks the owner. Nothing runs until the owner answers. If nobody answers in time, the call is refused.
Where the owner hears about it
A held call reaches the owner in three places. All three lead to the same page, and the answer is given there.
- Needs you, in KIFF Cloud, and the bell. Every held call is listed with the agent, the action, the Card and how far over it is.
- Email. One email per held call, to the account owner, with what the agent wanted, which Card, how far over, and when the hold expires. Each button opens the call’s Needs you page.
- The agent’s chat, for clients KIFF has verified (Claude Code 2.1.287 or later). The chat shows a prompt to open the Needs you link. This is on by default for a personal account and off for a company’s, where the person running the agent is usually not the owner. Change it in Settings → Account → Held calls.
Who can answer
Only the owner, or an admin, signed in to KIFF Cloud.
- The email and the chat only carry a link to the Needs you page. Neither can approve anything, so a forwarded email or a copied link answers nothing without the owner’s session.
- The agent’s key cannot answer, and a “yes” typed in the chat is not an approval.
- KIFF approval links always go to
app.kiff.dev. A link to answer from anywhere else is not from KIFF.
The three answers
- Approve once: this call only. The Card stays as it is, and its balance does not move.
- Change the card to allow it: raises the Card’s limits just enough for this call, and for everything after it. The change is recorded on the Card’s statement.
- Reject: the call is refused, and the agent is told not to retry it.
What the agent does
The agent gets a result that says the call is waiting for the owner, with the link and when the hold expires. Nothing has been sent to the tool.
To get the answer, the agent retries the same call: the same tool,
the same arguments, and the same kiff_operation_id if it used one.
Through the MCP gateway, an approved call is then
forwarded once; a rejected or expired one is refused. A program can read
the same facts in the result’s _meta (state, retry,
retry_after_s, hold_expires_at).
How long a call waits
Each Card sets how long a held call waits: 10 minutes by default, from 1 minute to 7 days. A held call never runs on silence:
- if nobody answers in time, the call is refused and nothing is sent;
- a late answer is not accepted;
- the agent has to ask again, as a new call.
The prompt in the chat does not extend this.
Next
- Set what is held and for how long → KIFF Cards.
- What the agent sees, field by field → Use the KIFF MCP gateway.