Skip to main content
Wallet access is the attachment between an owned or customer-connected Agent and one of your Wallets. A new agent is attached to the wallet named at creation, or to your default wallet when none is named. Access is granted per wallet, so you decide which balances each agent can touch. It isn’t a standalone resource: an attachment is addressed by its wallet-agent pair. See Wallet access.

Attachments

Attaching an agent with POST /wallets/{walletId}/agents lets it move money from that wallet; detaching takes that away. The first attached wallet becomes the agent’s default, used when a request omits walletId. Additional attachments preserve that default. Each customer connection has its own default, independent of other customers and the developer. The Vault cannot be attached for agent spending: attaching to it returns vault_not_allowed, and attaching a revoked agent returns agent_not_active.

Who manages access

You do, from a user session or an API key on your own party; an agent cannot attach itself or a sibling. To let an agent operate a customer’s wallet, the customer first accepts a customer invitation. The customer can then add wallets, remove non-default wallets, or change the connection default through these routes. Developers cannot change their customers’ wallet access.