mepa8
Docs · Kill switch

Propose, confirm, restore.

Two steps on purpose, reversible on purpose, never automatic. This page says exactly what happens at each vendor when you press the red button.

The three steps

The Mepa8 kill switch is a two-step, reversible procedure for stopping a vendor from spending or serving. It has 3 screens and a log.

Propose

Read the blast radius

Mepa8 shows the vendor, the exact resource it will act on by name, what stops when it does, and whether the action is an API call or guided steps. It issues a single-use token that expires in 10 minutes. Nothing has happened yet.

Confirm

Make the call

You, or an agent you explicitly authorised, submit the token. For API vendors Mepa8 makes the call and shows the vendor's response. For guided vendors it walks you through the dashboard steps and records that you did them. Either way the audit log gets who, when, what.

Restore

Put it back

One press runs the undo call or shows the undo steps. Nothing is ever deleted by a kill, so restore always has something to restore. Also logged.

“No alert, no agent and no schedule may kill a vendor on a single signal.”Mepa8 operating rule, 2026-10-08

API kill or guided kill, per vendor

A kill is only an API call where the vendor publishes one that is reversible. Where there is none, the kill is guided: the same two steps, with a person doing the dashboard part. The table is the truth as of October 9, 2026, with the vendor page each fact came from.

VendorKillRestoreSource
NeonPOST …/endpoints/{id}/suspendPOST …/endpoints/{id}/startNeon API reference
RailwaydeploymentStop mutationdeploymentRedeploy mutationRailway deployment guide
CloudflareDELETE /zones/{zone}/workers/routes/{route}Recreate the routeCloudflare API reference
ElevenLabsGuided: revoke the spending key or set its credit quota to 0 in the dashboardGuided: create a key againElevenLabs authentication, no revoke endpoint documented
HeyGen, Vonage, Manual vendorsGuided: the steps written on the vendor cardGuidedVendor card

Blast radius is written before it is needed

Every vendor card has a blast-radius line, and Mepa8 refuses to propose a kill on a card that has none. The line is yours to write, in plain words, and the propose screen shows it back. Ours for ElevenLabs reads “every phone agent goes down,” because on September 13, 2026 that is what happened when the account went past due and we learned the blast radius the hard way. Write it the day you connect the vendor, not the day you need it.

The kill drill in the start checklist exists for the same reason. On our own board a drill takes about 20 seconds: open the vendor, press Kill, read the radius, see the token, stop. The audit log records it as a drill. A first real kill at 2 a.m. should be the second time you have seen that screen.

Agents and the kill switch

An agent can propose and confirm through the API with the same two steps and the same token, if you have authorised that agent's key for kills. It cannot skip the propose step, the token still expires in 10 minutes, and its name is in the audit log like a person's. An agent that spends your money on a metered API is exactly the kind of caller that should be able to stop itself, within the same rules you would face.

Questions people ask

Straight answers

Can a kill ever fire automatically?

No. Not from an alert, not from a schedule, not from an agent acting on its own. Every kill needs a propose step and a confirm step with a 10-minute single-use token, and the confirm comes from a person or an agent you explicitly authorised. That rule is the first line of the kill code and it is on every vendor card.

What if I confirm and the vendor API fails?

Mepa8 shows the vendor's response, marks the kill as failed in the audit log, and shows the guided steps for that vendor so you can finish by hand. For Neon and Railway the kill is a single documented call, suspend or deploymentStop, so the usual failure is an expired or under-scoped key, which the message names.

Does restore really put everything back?

For API vendors it runs the documented undo: Neon start, Railway deploymentRedeploy, Cloudflare recreating the route. Nothing is deleted by a kill, so there is always something to restore. For guided vendors restore shows the undo steps, such as creating a new ElevenLabs key, and records that you did them.

Sources

  1. Neon — API reference (suspend and start endpoints) — read 2026-10-09
  2. Railway — manage deployments — read 2026-10-09
  3. Cloudflare — delete Worker route — read 2026-10-09
  4. ElevenLabs — authentication — read 2026-10-09

Change log: October 9, 2026 — First published with the API-versus-guided table.

Start here

Find out what you are paying before the next invoice does.

Five business days. Every vendor listed with real cost, every leak named with its fix, and a board you keep.

Book a vendor audit →See the plansNo card on the form. A person replies within one business day.