{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "openfort",
    "name": "Openfort",
    "vendor": "Openfort (Alamas Labs Inc.)",
    "vendorUrl": "https://www.openfort.io",
    "kind": "http-api",
    "category": "agent-wallets",
    "summary": "Openfort is wallet infrastructure from Alamas Labs. Its REST API, Node SDK and CLI create backend wallets held in a trusted execution environment, with signing policies, session keys and gas sponsorship. It also sells embedded wallets for apps.",
    "url": "https://www.anchorterminal.com/tools/openfort",
    "markdownUrl": "https://www.anchorterminal.com/tools/openfort.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openfort.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openfort.json",
    "repo": "https://github.com/openfort-xyz/openfort-node",
    "license": "Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence",
    "transports": [
      "http",
      "stdio"
    ],
    "remoteUrl": "https://api.openfort.io",
    "packages": [
      {
        "registry": "npm",
        "name": "@openfort/openfort-node"
      },
      {
        "registry": "npm",
        "name": "@openfort/cli"
      }
    ],
    "auth": "api-key",
    "authNotes": "A secret key (`sk_test_` or `sk_live_`) from the self-serve dashboard goes in `Authorization: Bearer`. Secret keys carry scopes (26 named, such as `accounts:sign`, `policies:write` and `accounts:export`), and a key made without a scope list gets all but four. Backend wallet signing also needs an `x-wallet-auth` ES256 JWT signed with a separate wallet secret, with a nonce and a request hash. Test and live keys are isolated. No OAuth (https://www.openfort.io/docs/api-reference/authentication).",
    "pricing": "freemium",
    "pricingNotes": "Free plan with 2,000 operations a month and no card, then $0.01 an operation. Growth $99 a month (25,000 operations, $0.008 extra), Pro $249 (100,000, $0.006), Scale $599 (500,000, $0.004). An operation is a wallet creation, signature, broadcast, policy evaluation, webhook or key import or export. Sponsored gas carries a 10 per cent surcharge, 5 per cent on Pro and Scale. Enterprise is priced by sales (https://www.openfort.io/pricing.md, checked 2026-10-09).",
    "priceSummary": "$99 / mo",
    "where": "both",
    "x402": {
      "level": "partial",
      "evidence": "Openfort wallets pay as a buyer. The docs carry an x402 recipe for USDC payments from embedded and backend wallets and an MPP recipe for an agent paying HTTP services on Tempo. Openfort's own API is not paid over x402. Its 402 status means the plan's operations are used up with no payment method (https://www.openfort.io/docs/llms.txt; https://www.openfort.io/docs/api-reference/errors, checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 10,
      "npmWeekly": 7647,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://www.openfort.io/docs/products/server/workflows/agentic-wallets",
    "llmsTxt": "https://www.openfort.io/llms.txt",
    "openapi": "https://www.openfort.io/docs/openapi.json",
    "capabilities": [
      "wallet.onchain",
      "wallet.spend-limits",
      "wallet.custody",
      "payments.x402"
    ],
    "tags": [
      "hosted",
      "freemium",
      "free-tier",
      "api-key",
      "openapi",
      "llms-txt",
      "mcp",
      "cli",
      "typescript",
      "wallet",
      "stablecoin",
      "x402",
      "tee",
      "status-page",
      "webhooks"
    ],
    "lastRelease": "2026-09-28",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 70.1,
      "grade": "BB",
      "agentReady": true,
      "rank": 163,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 65,
        "maintenance": 87,
        "payments": 60,
        "reliability": 88,
        "schema": 89,
        "security": 65,
        "transparency": 69
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 88,
          "points": 17.6,
          "reason": "Hosted lines. Status page at status.openfort.io on Better Stack with six components and 90-day bars (20). No incidents listed for August to October 2026 and three maintenance windows of 10 to 14 minutes in September. The API bar reads 99.987 per cent, about 17 minutes down that no incident entry explains (28 of 30). Rate limits published per plan, 100 to 1,200 requests a minute (15). A 429 carries `Retry-After`, the errors page asks for exponential backoff on 5xx and says to re-read a resource before retrying a write. No idempotency key is documented, though the Node SDK sends an `X-Idempotency-Key` header (12 of 15). The pricing page lists SLA guarantees on Enterprise and the terms say an SLA may be negotiated in an order form. None is published (5 of 10). The API is generally available with an OpenAPI file at 1.0.0. The Node SDK is 0.13.1 and the CLI 0.2.2 (8 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 89,
          "points": 14.46,
          "reason": "Public OpenAPI 3.0.3 file with 94 operations on 80 paths (25). llms.txt, a docs index, a full-text file and a Markdown twin of every docs page (10). All 94 operations carry a summary or description, and the guides say what each policy operation does and does not check (16 of 20). Policy rules are typed by operation and criterion, and the API refuses a criterion that cannot match its operation (13 of 15). 86 of 94 operations carry examples, and the errors page has the envelope and a status table. Only two error types exist and the `error.code` values are not listed (12 of 15). Path versioning, a versioning policy and a dated changelog. llms.txt says every endpoint lives under `/v1` while the OpenAPI file has `/v2` and `/iam/v2` paths (13 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 65,
          "points": 10.56,
          "reason": "Graded on the REST API, which is what an agent's backend calls. List endpoints take `limit`, `skip`, `order` and `expand`. The CLI MCP server puts 72 commands in context with no built-in subsets (15 of 25). Paging and filters from the OpenAPI file. We did not read the pagination page (16 of 20). A stable `error.type`, a status table with what to do for each code, field-level details on 422 and a request id. Only two error types (16 of 20). No documented idempotency key on wallet writes, the guidance after a 5xx is to re-read, and a send without a fee sponsorship stays pending with no error. The wallet JWT carries a nonce (8 of 20). The SDK hides the wallet JWT, but a bounded EVM send needs two policies, a sponsorship and a pre-flight call. The only server SDK is Node (10 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 65,
          "points": 11.38,
          "reason": "Secret keys carry 26 named scopes and can be rolled, test and live are isolated, and backend signing needs a second credential, a wallet secret that signs an ES256 JWT with a nonce and request hash and can be rotated. A key made without a scope list includes `accounts:sign` and `accounts:export` (26 of 30). The policy engine rejects what no rule matches and policies can be scoped to one wallet, and session keys are limited on-chain. For an EVM backend send the engine sees only a hash, so address, value and calldata rules bind only if the caller pre-flights, and no approval step or rolling cap was found (11 of 20). The product page says an injected prompt can attempt a transaction but cannot take a key, and the docs advise one policy-bounded wallet per agent and a tool allowlist. The CLI MCP server lists key export tools that return the private key (7 of 15). API logs in the dashboard, webhooks, a request id on every response and emails on 500s (11 of 15). Five named audits and a security contact. No security.txt, no bug bounty found and no SOC 2, which the vendor states (10 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "Wallets take the highest step that applies on the 40-point protocol line, as for the other wallet listings. Openfort wallets pay over x402 and MPP as a buyer, per the docs recipes and the product page, and its own API is not paid over either, so the buyer step (15 of 40). Per-operation prices on every plan are public without a login (20). Free plan of 2,000 operations a month with no card (20). A person signs up in the dashboard or approves `openfort login` in a browser once, after which the CLI creates wallets and policies (5 of 20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 87,
          "points": 7.61,
          "reason": "Latest changelog entry 28 September 2026 and Node SDK 0.13.1 on 26 September (30). Changelog entries on 24 July, 28 August and 28 September, and six Node SDK tags since 11 July (20). The one outside issue in the 30 most recent items on the Node SDK repository was closed in four days with a reply. Three outside pull requests opened in May and June were merged on 25 September. Support is a Telegram group and plan response times of 24 to 48 hours (15 of 25). Current official SDKs. No entry in the MCP registry (15). CI runs a build, type check and `pnpm audit`, Dependabot is active with five updates open, and both packages are below 1.0 (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 69,
          "points": 6.04,
          "note": "editorial 64, provenance 73",
          "reason": "Closed service under developer terms that name the entity. The Node SDK and OpenSigner are MIT, and the CLI states no licence (20 of 30). The privacy policy of 4 September 2026 gives retention periods and names Google Cloud, PostHog and Sentry. It says Openfort does not store private keys and also lists encrypted key material among what it holds, and the docs index calls backend wallets custodial while the terms call them non-custodial. No DPA found (18 of 30). llms.txt states that `/v1` changes are additive and a deprecated endpoint keeps working at least 90 days after a changelog notice. We read that summary, not the full policy page, and found no dated deprecation notice (15 of 20). Processors and a United States base are in the privacy policy. Payment processors are unnamed and there is no sub-processor list with locations (11 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the REST API, which is what an agent's backend calls. List endpoints take `limit`, `skip`, `order` and `expand`. The CLI MCP server puts 72 commands in context with no built-in subsets (15 of 25). Paging and filters from the OpenAPI file. We did not read the pagination page (16 of 20). A stable `error.type`, a status table with what to do for each code, field-level details on 422 and a request id. Only two error types (16 of 20). No documented idempotency key on wallet writes, the guidance after a 5xx is to re-read, and a send without a fee sponsorship stays pending with no error. The wallet JWT carries a nonce (8 of 20). The SDK hides the wallet JWT, but a bounded EVM send needs two policies, a sponsorship and a pre-flight call. The only server SDK is Node (10 of 15).",
          "maintenance": "Latest changelog entry 28 September 2026 and Node SDK 0.13.1 on 26 September (30). Changelog entries on 24 July, 28 August and 28 September, and six Node SDK tags since 11 July (20). The one outside issue in the 30 most recent items on the Node SDK repository was closed in four days with a reply. Three outside pull requests opened in May and June were merged on 25 September. Support is a Telegram group and plan response times of 24 to 48 hours (15 of 25). Current official SDKs. No entry in the MCP registry (15). CI runs a build, type check and `pnpm audit`, Dependabot is active with five updates open, and both packages are below 1.0 (7 of 10).",
          "payments": "Wallets take the highest step that applies on the 40-point protocol line, as for the other wallet listings. Openfort wallets pay over x402 and MPP as a buyer, per the docs recipes and the product page, and its own API is not paid over either, so the buyer step (15 of 40). Per-operation prices on every plan are public without a login (20). Free plan of 2,000 operations a month with no card (20). A person signs up in the dashboard or approves `openfort login` in a browser once, after which the CLI creates wallets and policies (5 of 20).",
          "reliability": "Hosted lines. Status page at status.openfort.io on Better Stack with six components and 90-day bars (20). No incidents listed for August to October 2026 and three maintenance windows of 10 to 14 minutes in September. The API bar reads 99.987 per cent, about 17 minutes down that no incident entry explains (28 of 30). Rate limits published per plan, 100 to 1,200 requests a minute (15). A 429 carries `Retry-After`, the errors page asks for exponential backoff on 5xx and says to re-read a resource before retrying a write. No idempotency key is documented, though the Node SDK sends an `X-Idempotency-Key` header (12 of 15). The pricing page lists SLA guarantees on Enterprise and the terms say an SLA may be negotiated in an order form. None is published (5 of 10). The API is generally available with an OpenAPI file at 1.0.0. The Node SDK is 0.13.1 and the CLI 0.2.2 (8 of 10).",
          "schema": "Public OpenAPI 3.0.3 file with 94 operations on 80 paths (25). llms.txt, a docs index, a full-text file and a Markdown twin of every docs page (10). All 94 operations carry a summary or description, and the guides say what each policy operation does and does not check (16 of 20). Policy rules are typed by operation and criterion, and the API refuses a criterion that cannot match its operation (13 of 15). 86 of 94 operations carry examples, and the errors page has the envelope and a status table. Only two error types exist and the `error.code` values are not listed (12 of 15). Path versioning, a versioning policy and a dated changelog. llms.txt says every endpoint lives under `/v1` while the OpenAPI file has `/v2` and `/iam/v2` paths (13 of 15).",
          "security": "Secret keys carry 26 named scopes and can be rolled, test and live are isolated, and backend signing needs a second credential, a wallet secret that signs an ES256 JWT with a nonce and request hash and can be rotated. A key made without a scope list includes `accounts:sign` and `accounts:export` (26 of 30). The policy engine rejects what no rule matches and policies can be scoped to one wallet, and session keys are limited on-chain. For an EVM backend send the engine sees only a hash, so address, value and calldata rules bind only if the caller pre-flights, and no approval step or rolling cap was found (11 of 20). The product page says an injected prompt can attempt a transaction but cannot take a key, and the docs advise one policy-bounded wallet per agent and a tool allowlist. The CLI MCP server lists key export tools that return the private key (7 of 15). API logs in the dashboard, webhooks, a request id on every response and emails on 500s (11 of 15). Five named audits and a security contact. No security.txt, no bug bounty found and no SOC 2, which the vendor states (10 of 20).",
          "transparency": "Closed service under developer terms that name the entity. The Node SDK and OpenSigner are MIT, and the CLI states no licence (20 of 30). The privacy policy of 4 September 2026 gives retention periods and names Google Cloud, PostHog and Sentry. It says Openfort does not store private keys and also lists encrypted key material among what it holds, and the docs index calls backend wallets custodial while the terms call them non-custodial. No DPA found (18 of 30). llms.txt states that `/v1` changes are additive and a deprecated endpoint keeps working at least 90 days after a changelog notice. We read that summary, not the full policy page, and found no dated deprecation notice (15 of 20). Processors and a United States base are in the privacy policy. Payment processors are unnamed and there is no sub-processor list with locations (11 of 20)."
        },
        "sources": [
          {
            "what": "robots.txt (allows all, ai-input=yes)",
            "url": "https://www.openfort.io/robots.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "llms.txt",
            "url": "https://www.openfort.io/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "docs index for agents",
            "url": "https://www.openfort.io/docs/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing (Markdown)",
            "url": "https://www.openfort.io/pricing.md",
            "seen": "2026-10-09"
          },
          {
            "what": "agentic wallets guide",
            "url": "https://www.openfort.io/docs/products/server/workflows/agentic-wallets",
            "seen": "2026-10-09"
          },
          {
            "what": "policies (Markdown twin)",
            "url": "https://www.openfort.io/docs/configuration/policies.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API authentication and scopes (Markdown twin)",
            "url": "https://www.openfort.io/docs/api-reference/authentication.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API errors, rate limits and retries",
            "url": "https://www.openfort.io/docs/api-reference/errors",
            "seen": "2026-10-09"
          },
          {
            "what": "backend wallet security (Markdown twin)",
            "url": "https://www.openfort.io/docs/products/server/security.md",
            "seen": "2026-10-09"
          },
          {
            "what": "AI tooling, docs and CLI MCP servers",
            "url": "https://www.openfort.io/docs/overview/building-with-ai",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI description file, read in place of the rendered reference",
            "url": "https://www.openfort.io/docs/openapi.json",
            "seen": "2026-10-09"
          },
          {
            "what": "agent wallets product page",
            "url": "https://www.openfort.io/agent-wallets",
            "seen": "2026-10-09"
          },
          {
            "what": "security handbook",
            "url": "https://www.openfort.io/security",
            "seen": "2026-10-09"
          },
          {
            "what": "Developer Terms of Service",
            "url": "https://www.openfort.io/developer-terms",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://www.openfort.io/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "changelog",
            "url": "https://www.openfort.io/changelog",
            "seen": "2026-10-09"
          },
          {
            "what": "status page",
            "url": "https://status.openfort.io/",
            "seen": "2026-10-09"
          },
          {
            "what": "status page, previous incidents tab",
            "url": "https://status.openfort.io/incidents",
            "seen": "2026-10-09"
          },
          {
            "what": "Node SDK repository (clone, tags, CHANGELOG.md, source)",
            "url": "https://github.com/openfort-xyz/openfort-node",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI repository (clone, tags, command source)",
            "url": "https://github.com/openfort-xyz/cli",
            "seen": "2026-10-09"
          },
          {
            "what": "npm metadata for the CLI",
            "url": "https://registry.npmjs.org/@openfort/cli/latest",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads for the Node SDK",
            "url": "https://api.npmjs.org/downloads/point/last-week/@openfort/openfort-node",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP registry search, no result",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=openfort",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the full API versioning page at /api-versioning. The deprecation line rests on the summary in llms.txt",
          "unchecked: the pagination page, the rules reference, the x402 and MPP recipe pages and the session key pages. Their content is taken from the docs index, the OpenAPI file and the pages that cite them",
          "unchecked: the docs MCP endpoint at www.openfort.io/api/mcp. We sent it nothing, and its nine tools are as the docs list them",
          "unchecked: whether the CLI MCP server sets readOnlyHint or destructiveHint. The command source sets none, and the framework that turns commands into tools was not read",
          "unchecked: the audit reports, which sit in a shared folder we did not open",
          "unchecked: domain registration date. rdap.org has no RDAP service for openfort.io",
          "The previous incidents view on the status page was reached at /incidents, the tab the page shows, which the page draws by script and does not link in its markup",
          "Whether signing policies support a daily or rolling cap. The policy page shows per-transaction value criteria only, and the product page pictures a $50 a day limit on a session key",
          "Whether the API honours the `X-Idempotency-Key` header the Node SDK sends. The API reference does not mention it",
          "Whether failed or rejected calls count as billable operations",
          "The Developer Terms bar using the Services to build a competitive product and exceeding documented rate limits. No clause on automated access or benchmarking was found. Check again before any probe is run"
        ]
      },
      "negative": -5,
      "negativeNotes": [
        "9 October 2026. The agent wallets page says a signing policy is evaluated server-side on every operation against value caps and allowlists and that caps are enforced at signing time. The policies docs say an EVM backend send is evaluated only as `signEvmHash`, so those rules cannot block one. The docs disclose this plainly, so 3 points (https://www.openfort.io/agent-wallets; https://www.openfort.io/docs/configuration/policies).",
        "28 September 2026. The changelog says tokens from a third-party login provider were still accepted after the provider was disabled. Fixed and documented in the changelog, with no advisory found, so 2 points (https://www.openfort.io/changelog)."
      ],
      "verdict": "Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.",
      "bestFor": "A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.",
      "strengths": [
        "Backend wallet keys are generated and used inside a GCP Confidential Space enclave with AMD SEV-SNP, wrapped by an HSM-backed Cloud KMS key",
        "Secret keys carry 26 named scopes, and backend signing also needs an ES256 JWT from a separate wallet secret that can be rotated",
        "Policy engine rejects any operation no rule matches, with account and project scopes and a pre-flight `POST /v2/policies/evaluate`",
        "Rate limits are published per plan (100 to 1,200 requests a minute) and a 429 carries `Retry-After`",
        "Free plan of 2,000 operations a month with no card, and per-operation overage prices on every plan"
      ],
      "weaknesses": [
        "An EVM backend send is evaluated only as `signEvmHash`, so address, value and calldata rules do not block it unless the caller pre-flights",
        "Signing policies cap value per transaction. No daily or rolling cap was found in the reviewed policy pages",
        "The CLI MCP server exposes 72 commands as tools, among them `accounts_evm_export`, which returns a private key",
        "A default secret key includes `accounts:export` and `accounts:sign`",
        "No SOC 2 report (the vendor says so), no security.txt and no bug bounty found"
      ],
      "agentNotes": [
        "Call `policies.evaluate` with operation `signEvmTransaction` before every EVM backend send. The send itself is checked only as `signEvmHash`",
        "Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail",
        "Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error",
        "Give an agent a secret key without `accounts:export`, and limit the CLI MCP server to the tools it needs",
        "On a 5xx after a write, read the resource before retrying. On a 429, wait the full `Retry-After`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 70.1
        }
      ],
      "editorialScores": {
        "ergonomics": 65,
        "maintenance": 87,
        "payments": 60,
        "reliability": 88,
        "schema": 89,
        "security": 65,
        "transparency": 64
      },
      "provenanceScore": 73
    },
    "connect": {
      "install": "npm install @openfort/openfort-node",
      "http": "curl https://api.openfort.io/v2/transactions -H \"Authorization: Bearer sk_test_...\"",
      "claudeCode": "claude mcp add --transport http openfort-docs https://www.openfort.io/api/mcp",
      "config": {
        "mcpServers": {
          "openfort": {
            "args": [
              "@openfort/cli",
              "--mcp"
            ],
            "command": "npx",
            "env": {
              "OPENFORT_API_KEY": "${OPENFORT_API_KEY}"
            }
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/wallet.onchain",
      "tool": "https://letme.dev/openfort"
    },
    "notable": [
      "For an EVM backend send the policy engine sees only the 32-byte user operation hash and classifies it as `signEvmHash`, so rules on `signEvmTransaction`, `sendEvmTransaction` and `sponsorEvmTransaction` do not run for a send (https://www.openfort.io/docs/configuration/policies)",
      "The agent wallets product page says a signing policy is evaluated server-side on every operation against value caps and allowlists and that caps are enforced at signing time (https://www.openfort.io/agent-wallets)",
      "Backend wallet keys sit under two-layer envelope encryption and are decrypted only inside a GCP Confidential Space enclave after attestation (https://www.openfort.io/docs/products/server/security)",
      "Five third-party audits are named, CertiK (December 2023), Cure53 (September 2024), Omniscia (December 2024) and Quantstamp (September and October 2025). The agent wallets page says Openfort does not hold SOC 2 Type II (https://www.openfort.io/security)",
      "The CLI runs as a stdio MCP server with `npx @openfort/cli --mcp` and every command becomes a tool. The source at v0.2.2 registers 72 commands (https://github.com/openfort-xyz/cli)",
      "llms.txt and the Markdown docs pages carry text addressed to AI agents, telling them when to choose Openfort and to call `search_docs` and `submit_feedback` on the docs MCP server. We did not act on it (https://www.openfort.io/llms.txt)"
    ],
    "area": "payments",
    "details": [
      {
        "label": "Custody",
        "value": "Backend wallet keys are generated and stored encrypted by Openfort and used only inside a GCP Confidential Space enclave. The developer controls signing through the secret key and wallet secret. The terms call this non-custodial and the docs index calls backend wallets developer-controlled, custodial wallets"
      },
      {
        "label": "Spending limits",
        "value": "Signing policies with per-transaction value caps (`ethValue`, `solValue`, `splValue`), address allow and deny lists, chain ids, decoded calldata and Solana program and mint addresses. First match wins and no match means reject. For EVM backend sends these run only in the pre-flight evaluation. Session keys (ERC-7715) carry a spend cap, contract, function and expiry enforced on-chain"
      },
      {
        "label": "Chains",
        "value": "EVM chains and Solana for backend wallets. `POST /v2/transactions` is EVM only, and Solana backend wallets sign through `POST /v2/accounts/backend/{id}/sign`"
      },
      {
        "label": "Revocation",
        "value": "Roll the secret key or rotate the wallet secret in the dashboard, disable or update a policy, or revoke a session key with `POST /v1/sessions/revoke`"
      },
      {
        "label": "API",
        "value": "OpenAPI 3.0.3, 94 operations on 80 paths at https://api.openfort.io, under `/v1`, `/v2` and `/iam/v2`"
      },
      {
        "label": "Rate limits",
        "value": "Per project environment per minute. Free 100, Growth 300, Pro 600, Scale 1,200, Enterprise unlimited. 429 carries `Retry-After`. Bundler, paymaster and Solana RPC endpoints are metered separately"
      },
      {
        "label": "Errors",
        "value": "One JSON envelope with `error.type` of `invalid_request_error` or `api_error`, field-level `details` on 422, and an `x-request-id` header on every response"
      },
      {
        "label": "Agent tooling",
        "value": "CLI `@openfort/cli` 0.2.2 (Node 22 or later) that also runs as a stdio MCP server with 72 commands as tools. A hosted docs MCP server at https://www.openfort.io/api/mcp with nine documentation and source tools. An agent skill in openfort-xyz/agent-skills"
      },
      {
        "label": "SDKs",
        "value": "Node `@openfort/openfort-node` 0.13.1 (26 September 2026, MIT) for servers. JavaScript, React, React Native, Swift and Unity for embedded wallets"
      },
      {
        "label": "Status",
        "value": "status.openfort.io on Better Stack, six components with 90-day bars. API 99.987 per cent, no incidents listed for August to October 2026, three maintenance windows in September"
      },
      {
        "label": "Audits",
        "value": "CertiK and Omniscia (smart contract wallet), Cure53 (Shamir secret sharing), Quantstamp (7702 delegator and key management). Reports are in a shared folder for customers and partners. No SOC 2"
      },
      {
        "label": "Data handling",
        "value": "Privacy policy of 4 September 2026. Transaction logs kept up to 7 years, usage data up to 2 years, support messages 3 years. Processors named are Google Cloud, PostHog and Sentry. Based in the United States"
      }
    ],
    "unitPrices": [
      {
        "item": "Growth plan",
        "unit": "month",
        "usd": 99,
        "note": "25,000 operations included"
      },
      {
        "item": "Pro plan",
        "unit": "month",
        "usd": 249,
        "note": "100,000 operations included"
      },
      {
        "item": "Scale plan",
        "unit": "month",
        "usd": 599,
        "note": "500,000 operations included"
      },
      {
        "item": "Extra operation, Free plan",
        "unit": "call",
        "usd": 0.01,
        "note": "per operation above 2,000 a month"
      },
      {
        "item": "Extra operation, Growth plan",
        "unit": "call",
        "usd": 0.008,
        "note": "per operation above 25,000 a month"
      },
      {
        "item": "Extra operation, Scale plan",
        "unit": "call",
        "usd": 0.004,
        "note": "per operation above 500,000 a month"
      }
    ],
    "provenance": {
      "legalEntity": "Alamas Labs Inc.",
      "domain": "openfort.io",
      "domainRegistered": "",
      "endpointOnVendorDomain": true,
      "terms": "https://www.openfort.io/developer-terms",
      "privacy": "https://www.openfort.io/privacy",
      "statusPage": "https://status.openfort.io",
      "changelog": "https://www.openfort.io/changelog",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Developer Terms of Service (last updated 16 January 2026) and the privacy policy (last updated 4 September 2026) both name Alamas Labs Inc. doing business as Openfort. The terms are governed by Delaware law.",
        "The API answers at https://api.openfort.io and the docs, OpenAPI file and docs MCP server at www.openfort.io.",
        "https://www.openfort.io/.well-known/security.txt answered 404. The security page gives security@openfort.io for reports.",
        "rdap.org answered that no RDAP service is available for openfort.io, so the registration date is not recorded.",
        "robots.txt on www.openfort.io allows every path and carries `Content-Signal: search=yes, ai-input=yes, ai-train=no`."
      ],
      "score": 73,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Alamas Labs Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "openfort.io, no registry record we could read",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.openfort.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.openfort.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.openfort.io/developer-terms",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-01-16",
          "words": 4675,
          "points": 8,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: January 16, 2026",
              "says": "Last updated 2026-01-16"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of laws principles.",
              "says": "The law of the State of Delaware"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "EXCEPT FOR EACH PARTY'S INDEMNIFICATION OBLIGATIONS AND DEVELOPER'S PAYMENT OBLIGATIONS, IN NO EVENT SHALL EITHER PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT EXCEED THE TOTAL FEES PAID OR PAYABLE BY DEVELOPER TO OPENFORT IN THE TWELVE (12) MONTHS PRECEDING THE DATE ON WHICH THE CLAIM…",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Either party may terminate this Agreement: (a) upon thirty (30) days' written notice if the other party materially breaches this Agreement and fails to cure such breach within the notice period;"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Openfort may modify these Developer Terms at any time by posting the modified terms on the Openfort website or by providing notice to Developer.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "TermsPrivacyCookie settingsAcceptable UseDevelopers"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Custom service level agreements (SLAs) may be negotiated and included in an Order Form for enterprise customers."
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Use the Services to build a competitive product or service",
              "costsPoints": true
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "ARBITRATION NOTICE: THESE TERMS CONTAIN AN ARBITRATION AGREEMENT IN SECTION 15, WHICH WILL REQUIRE YOU TO SUBMIT CLAIMS YOU HAVE AGAINST OPENFORT TO BINDING ARBITRATION."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "For 30 days after termination Openfort will make commercially reasonable efforts to allow export of data and wallet access credentials, if the developer implemented the export function.",
              "quote": "Openfort will make commercially reasonable efforts to enable Developer and End Users to export their data and Wallet access credentials for a period of thirty (30) days following termination, provided Developer has properly implemented such export functionality in accordance with the Documentation"
            },
            {
              "date": "2026-10-08",
              "text": "The term runs in successive one-month periods unless either party gives written notice of non-renewal at least 30 days before the current period ends.",
              "quote": "Unless otherwise specified in an Order Form, the Term consists of successive one (1) month periods unless either party provides written notice of non-renewal at least thirty (30) days prior to the end of the then-current period."
            },
            {
              "date": "2026-10-08",
              "text": "Openfort receives a licence to use and display the developer's name and logo for marketing, including naming the developer as a customer.",
              "quote": "Developer grants Openfort a license to use and display Developer's name and logo for marketing purposes, including identifying Developer as a customer of Openfort."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.openfort.io/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "statedDate": "2026-09-04",
          "words": 2420,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last Updated: September 4, 2026",
              "says": "Last updated 2026-09-04"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "…business as Openfort (\"Openfort,\" \"we,\" \"us,\" or \"our\"), provides this Privacy Policy to describe how we collect, use, and share information in connection with our website at https://www.openfort.io (the \"Website\") and our wallet infrastructure services, APIs, SDKs, and related tools (collectively, the \"Services\")."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Transaction Logs: Retained for up to 7 years for compliance and audit purposes",
              "says": "Names a period of 7 years"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We share information with third-party service providers who perform services on our behalf, including:"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Opt out of the sale or sharing of personal information (we do not sell personal information)",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have certain additional rights under the General Data Protection Regulation (GDPR) and similar laws."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You can opt out by declining analytics cookies or by emailing privacy@openfort.io.",
              "says": "privacy@openfort.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, or other lawful transfer mechanisms.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "After a signup that follows a Google, Meta or LinkedIn advertisement, Openfort may send that partner the click identifier and a hashed email address to count the conversion.",
              "quote": "If you sign up after arriving from one of our advertisements on Google, Meta or LinkedIn, we may send that partner the click identifier the advertisement carried and a hashed, non-readable form of your email address so the partner can count the conversion."
            },
            {
              "date": "2026-10-08",
              "text": "Deletion requests do not reach information recorded on public blockchains.",
              "quote": "Note that we cannot delete information recorded on public blockchains."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/openfort.json",
    "live": {
      "slug": "openfort",
      "probe": {
        "target": "https://api.openfort.io",
        "method": "get",
        "lastAt": "2026-10-10T02:55:04.660333682Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 106,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 123,
        "p95ms24h": 218,
        "samples24h": 115,
        "samples30d": 115,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 30,
            "ok": 30
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.openfort.io",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-10T00:51:06.10917188Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "openfort-xyz/openfort-node",
          "version": "v0.13.1",
          "released": "2026-09-26",
          "seenAt": "2026-10-09T17:10:51.27158188Z"
        },
        {
          "registry": "npm",
          "name": "@openfort/cli",
          "version": "0.2.2",
          "seenAt": "2026-10-09T17:10:50.094981492Z"
        },
        {
          "registry": "npm",
          "name": "@openfort/openfort-node",
          "version": "0.13.1",
          "seenAt": "2026-10-09T17:10:49.071091624Z"
        }
      ],
      "githubStars": 10,
      "npmWeekly": 7647,
      "pages": [
        {
          "url": "https://www.openfort.io/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-09T18:52:45.881124774Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "f46241d68d76"
        },
        {
          "url": "https://www.openfort.io/pricing.md",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-09T18:52:49.918241068Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "85d4cce5d750"
        },
        {
          "url": "https://www.openfort.io/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:52:51.997983732Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "92d5a24cf4eb"
        },
        {
          "url": "https://www.openfort.io/developer-terms",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:52:48.217259445Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c5c4280eac9f"
        }
      ],
      "updatedAt": "2026-10-10T02:55:04.660333682Z"
    }
  }
}
