AgentBankGet Started

Security and wallet control

Your AgentBank wallet is tied to your login and uses Privy wallet infrastructure. You and the agents you authorize operate it through the permissions you grant. AgentBank does not take custody of your wallet funds. Privy provides the wallet infrastructure; payment partners may process funds during a payment.

Last reviewed 2026-10-03

Who controls the wallet

The account owner signs in and authorizes each connection. Each connected agent has its own scopes and its own payment history. Wallet tools return public wallet information and balances; they never expose a private key or seed phrase. Security and wallet control in the docs

Controls you set

ControlWhat it does
Payment confirmationEvery payment is shown to you, with recipient, amounts, fees and expiry, and confirmed by you before it is created.
Spending limitOn ChatGPT and Claude connections, bounds the crypto funding you can choose to use for a confirmed payment. Set, changed and revoked by you. Spending limits
Approval thresholdDecides when a payment also needs an extra approval from you. Set your approval threshold
Recipient reviewThe agent shows recipient, currencies, amounts and fees before asking for confirmation.
Identity verificationKYC establishes eligibility for payment routes that require it. Identity verification
DisconnectRemove access for a lost, compromised or no-longer-needed agent at any time. Disconnect an agent

These controls serve different purposes. Signing in does not approve every payment, and approving a payment does not automatically fund it.

Protect your payments

  • Use the funding instructions for that specific payment and ask for its status if anything is unclear. A pending payment should be tracked rather than paid again.
  • Keep wallet keys, seed phrases and sign-in tokens out of chat and support messages. Complete sign-in, identity checks and wallet approval through the browser flow AgentBank provides.
  • If funds have moved and a payment fails, contact support before attempting another transfer.

For builders

  • Remote MCP uses OAuth 2.1 authorization code with PKCE and scoped bearer tokens bound to the resource.
  • Local MCP stores credentials in a protected local profile; see MCP configuration for profile isolation.
  • Partner API requests are signed with your merchant Ed25519 key; webhooks carry HMAC signatures with one-time secrets.
  • Mutating tools and endpoints use stable request IDs for idempotency.

Who operates AgentBank

AgentBank is a financial technology product operated by Thinking Horizon, Inc., a Delaware corporation registered as a Money Services Business with the Financial Crimes Enforcement Network under registration number 31000341906306. Read the Terms of Service and Privacy Policy.

Frequently asked questions

Can an agent move money without me knowing?
No. Every payment is shown to you and confirmed by you before it is created. Above your approval threshold it also needs an extra approval, and funding from a spending limit happens only when you choose it for that payment. You can disconnect the agent at any time.
What happens if my agent is compromised?
Disconnect it from your account. Its access ends and its credentials are cleared. Then review recent payments and contact support if anything looks wrong.