Freeze
With an admin key for your org:
curl -X POST https://engine.example.com/v1/agents/agt_01J.../freeze \
-H "Authorization: Bearer $REIN_ADMIN_KEY"
Or from code, with the SDK's engine client:
import { EngineClient } from '@reinconsole/sdk';
const client = new EngineClient({
baseUrl: 'https://engine.example.com',
apiKey: process.env.REIN_ADMIN_KEY,
});
await client.freeze('agt_01J...'); // every payment now: DENIED, agent-frozen
// await client.unfreeze('agt_01J...');
Why the agent cannot undo it
The agent's own key can ask for permission to pay and report what settled. It cannot freeze, unfreeze, change a policy or approve its own payment; those need an admin key or an approver's signature. A kill switch the agent can reach is not a kill switch, which is also why "stop spending" in a prompt is not one.
Then, if you need to, revoke the key
A freeze is the first brake: instant and reversible. If the agent's key itself may be compromised, revoke it as well, and the engine refuses that key outright. Freeze first, revoke second: the freeze keeps the record of everything the agent tried.
Brakes that pull themselves
You will not always be watching. A breaker is an envelope such as "20 payments or $5 in 24 hours"; the payment that would cross it is parked for a human instead of paid. Nothing is released until someone signs the decision, and a parked payment that nobody signs expires into a refusal.
"breakers": [{ "id": "velocity", "window": "24h", "txCount": 20, "valueCap": "5.00" }]
The live console shows agents, breakers and every decision on Rein's own hosted engine. To try a freeze locally, follow the runbook.