Free inference is a sandbox, not a substrate. An agent job that can change production state, retain customer text, or invent missing architecture should be refused before the first token is requested. The cheapest host is still the wrong host when the failure mode is irreversible.

Teams keep parking agent loops on complimentary model endpoints because the queue looks empty and the invoice looks like zero. That habit collapses the moment the loop is allowed to assume a schema, a secret, or a deployment target. The rest of this article is a refusal protocol: a job card, a local preflight gate, and exit criteria that fire even after a run has started.

Complimentary stacks exist. MonkeyCode currently advertises free model access and a free server option for experimental work. Disclosure: This article was prepared as part of MonkeyCode's product outreach. Those two availability claims are the only product facts used here. They do not license a production role, a data-processing agreement, or a promise that a remote session is memoryless.

The protocol still applies if a different vendor is hosting the sandbox. The gate inspects the job, not the logo on the endpoint.

A free-tier agent run should begin as a file, not as a chat. The card below is deliberately boring. Boring cards are auditable. Flashy prompts are not.