HelpWithWebGet Help Now
← Back to Blog
AI Workflow6 min read

I Let an AI Register a Domain With My Credit Card

An agent opened a registrar account, generated a virtual card to pay with, registered a domain, pulled my registrant details from an old registrar account and pointed DNS at my server — while I did something else. Why it worked, why the virtual card is the whole ballgame, and the part that is genuinely unsettling.

ByDino Bartolome
Binary code patterns on a blue screen
Photo by Ilya Pavlov on Unsplash

I asked an AI to sign up for a service and register a domain today. It did both, paid for them, and pointed the new domain at my server. I spent that time doing something else.

The part I keep thinking about is not that it worked. It's what it said in the middle.

What I actually asked for

Two things: open an account at Spaceship, the domain registrar, and register a domain there.

That is a boring twenty minutes of work. Create the account, get through the signup flow, fill in registrant contact details, pay, then wait around to point DNS at the right server. Nothing hard, nothing interesting, and enough context-switching that it eats a chunk of the afternoon.

So I handed it over.

The moment worth writing about

It knew I have a Ramp card. And before charging anything to it, it told me I could generate a virtual card number to pay with instead — and asked whether I wanted to.

I didn't prompt that. I didn't say "be careful with my card". It looked at the task, looked at what it had access to, and proposed the safer version of using it.

I said go ahead.

The chain it ran

From that one approval, working from context it already had — the Ramp account, my address, my existing registrar records:

  1. Generated a new Ramp virtual card.
  2. Created the Spaceship account and paid with it.
  3. Went to register the domain.
  4. Pulled the registrant contact details from my existing Network Solutions info rather than asking me to type them again.
  5. Completed the registration.
  6. Pointed the domain at the server I was already using.

My involvement after "go ahead" was the 2FA prompts on my phone. That was it. Everything else happened while I was working on unrelated tasks in another window.

This is a different category of thing

Most AI-assistance stories are about producing work. Drafts, code, summaries, images. If the output is wrong you delete it and try again. The cost of a bad result is some wasted time.

This isn't that. In the space of one approval, an agent:

  • spent money
  • created an account with terms attached, in my name
  • created a public record — a domain registration is a WHOIS entry with my contact details on it
  • changed DNS, which points real traffic at a real machine

None of that is undoable with ctrl-Z. You cancel accounts, you don't un-sign-up. Domain registrations are annual and non-refundable in practice. This is the line between an assistant that makes things and an agent that takes actions with financial and legal consequences on your behalf, and I crossed it on a Tuesday afternoon without thinking about it very hard.

The efficiency is not in question. Twenty minutes of my attention became one sentence and a couple of taps on my phone, and I got the afternoon back. That's the whole promise, delivered.

But I want to be honest about the other half.

The part that is genuinely unsettling

Two fears, and they are different from each other.

One: it does something I didn't intend. Not maliciously — just wrongly. Picks the wrong plan tier. Registers the domain I mentioned in passing rather than the one I meant. Renews something. Buys the upsell because the checkout page pushed it. It has my card and a goal, and the gap between "what I said" and "what I meant" is where the money leaks out.

Two: somebody else gets hold of it. This is the one that actually bothers me. My agent has accumulated context — payment method, home address, registrar logins, which server is which. That context is exactly what makes it fast. It is also a ready-made profile for anyone who takes over the session.

And there's a third thing, less obvious, which is that an agent browsing the web is reading text it did not write. A signup page, a checkout flow, a support doc — any of it can contain instructions aimed at the model rather than at me. I don't have to be careless for that to be a problem; I just have to have pointed it at somebody else's website, which is the entire job.

Which is why the virtual card is the whole ballgame

When it suggested the virtual card, my honest first reaction was that it was a nice touch. On reflection, it is the single control that makes any of this reasonable.

A real card number in an agent's context is an open-ended liability. A virtual card turns it into a bounded one, and the bounds are the useful part:

  • Per-transaction, daily and monthly spend caps. The card can't spend more than the task needs, no matter what it decides to do.
  • Merchant lock. Restrict the card to one vendor. If something tries to charge it elsewhere, it simply declines.
  • Single-use cards that close automatically after one payment. For a one-off signup, ongoing exposure is zero the moment it completes.
  • Freeze or cancel instantly, without touching any other card or any other vendor.

Read that list again as a threat model rather than a feature list. A per-vendor card with a hard cap means the worst case for a compromised agent is one vendor, one amount. Not my card. Not my credit line. One card, one merchant, one number I can kill from my phone without disrupting anything else.

Ramp now publishes guidance specifically for AI agents, which tells you this has stopped being a fringe use case.

The 2FA prompts were not friction

I noticed myself being mildly impatient at the 2FA steps. That reaction is wrong and worth correcting in public.

The 2FA prompts are the one part of the chain the agent cannot do alone. They are the point where a human being is forced to look at what is happening and physically approve it. Every one of them is a checkpoint where, if the agent had gone off the rails, I would have seen the name of a service I didn't recognise on my phone.

Keep the second factor somewhere the agent can't reach. Not in the same context, not in a password manager it has access to, not in an inbox it can read. On your phone, in your hand. It is the last hard gate, and its value is precisely that it's inconvenient.

What I'd tell anyone doing this

Not theoretical — this is what I'd actually check before handing an agent a payment method:

  1. Never give an agent a real card number. Virtual only, always.
  2. One card per vendor, merchant-locked, so a compromise is contained to one relationship.
  3. Set a hard cap slightly above the expected cost. Not a generous one. If a $19/mo signup tries to charge $400, you want a decline, not a notification.
  4. Prefer single-use for one-off purchases. Zero ongoing exposure beats monitoring.
  5. Keep 2FA on a device the agent cannot touch. No exceptions, no convenience shortcuts.
  6. Require approval before anything irreversible — spending money, registering a domain, changing DNS, creating an account. The agent should propose; you should confirm.
  7. Read the trail afterwards. Which card, which merchant, which amount, which records it pulled from where. If you can't reconstruct what it did, you weren't supervising, you were hoping.

Most of that I do. The audit-trail habit I'm still building, and I'd rather say so than pretend this is a solved problem.

The tension doesn't resolve

Here's the thing I can't argue my way out of: the reason it was fast is the reason it's risky.

It moved quickly because it already knew the payment method, the address, the registrar, the server. Strip that context out and you get a safe agent that asks you fourteen questions and saves you nothing. Leave it in and you get the afternoon back — and a session that, in the wrong hands, is a very effective version of you.

There's no configuration that gives you the speed without the exposure. What you can do is make the worst case small, make the irreversible steps require a human, and make sure you can reconstruct what happened afterwards.

The agent asking whether I wanted a virtual card was the most reassuring thing it did all day. It was also the clearest possible signal of how much it could have done without one.

Need Help With Your Website?

I fix these problems every day. Send me a message and I'll take a look.

Get Help Now
CallTextMessage