Skip to main content
Agents and bots should never hold broad signing rights. Company Wallets let you issue an API-only user, tag it agent, and allow only the exact actions you intend.

Pattern

  1. Create an API-only user + tag agent
  2. Deny broad signRawPayload for that tag
  3. Allow a specific contract selector / recipient / chain
  4. Optional consensus for first-seen contracts
  5. Meter usage via billing / webhooks; revoke by deleting the API key

Controls

  • Prefer contract allowlists over “sign anything”
  • Keep agent keys out of root quorum
  • Use short-lived keys and rotate on incident