{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "sponge-wallet",
    "name": "Sponge Wallet",
    "vendor": "Sponge Inc.",
    "vendorUrl": "https://paysponge.com",
    "kind": "http-api",
    "category": "agent-wallets",
    "summary": "Sponge Wallet is a hosted wallet for AI agents. It holds stablecoins on Ethereum, Base, Tempo and Solana, pays x402 and MPP endpoints, issues virtual cards, and is reached by a REST API, an MCP server, SDKs and a CLI.",
    "url": "https://www.anchorterminal.com/tools/sponge-wallet",
    "markdownUrl": "https://www.anchorterminal.com/tools/sponge-wallet.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sponge-wallet.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sponge-wallet.json",
    "license": "Proprietary service under Sponge's terms of service. The SDK and CLI packages on npm are MIT, and the repository they name is private",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.wallet.paysponge.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@paysponge/sdk"
      },
      {
        "registry": "npm",
        "name": "spongewallet"
      },
      {
        "registry": "pypi",
        "name": "paysponge"
      }
    ],
    "auth": "mixed",
    "authNotes": "Self-serve. An agent calls `POST /api/agents/register` with no credential and, with `agentFirst`, receives an agent API key at once. A person claims the wallet later through a claim URL. Requests carry the key as a bearer token plus a `Sponge-Version` header. Master keys, created in the dashboard, manage agents. The MCP server also accepts OAuth from app connectors.",
    "pricing": "free",
    "pricingNotes": "No fee schedule for the wallet was found. The home page's structured data lists a price of 0, a wallet needs no card or contract to start, and network and venue costs apply. Sponge Card (US) has no annual fee and charges 1 per cent on international transactions (https://paysponge.com/legal/sponge-card-terms-us, checked 2026-10-09). Fees on swaps, bridges, bank transfers and onramps were not found.",
    "priceSummary": "Free",
    "where": "hosted",
    "x402": {
      "level": "partial",
      "evidence": "The wallet pays x402 endpoints through `POST /api/x402/fetch`, `wallet.x402Fetch()` and `spongewallet pay x402`, pays MPP endpoints on Tempo, and creates x402 payment links. Sponge's own wallet API is not paid over either protocol (https://docs.paysponge.com/wallet/x402-payments.md; https://docs.paysponge.com/wallet/mpp-payments.md, checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 126,
      "pypiWeekly": 20,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.paysponge.com",
    "llmsTxt": "https://docs.paysponge.com/llms.txt",
    "openapi": "https://docs.paysponge.com/api-reference/public-openapi.json",
    "capabilities": [
      "wallet.onchain",
      "wallet.spend-limits",
      "payments.x402",
      "payments.card",
      "wallet.custody"
    ],
    "tags": [
      "hosted",
      "free",
      "openapi",
      "llms-txt",
      "mcp",
      "typescript",
      "python",
      "cli",
      "wallet",
      "x402",
      "mpp",
      "virtual-cards",
      "stablecoins",
      "closed-source",
      "skills"
    ],
    "lastRelease": "2026-07-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 43.2,
      "grade": "E",
      "agentReady": false,
      "rank": 785,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 43,
        "maintenance": 27,
        "payments": 70,
        "reliability": 13,
        "schema": 66,
        "security": 48,
        "transparency": 39
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 13,
          "points": 2.6,
          "reason": "Graded as a hosted service on the REST API and the MCP server at api.wallet.paysponge.com. No status page was found. The site and docs link none and status.paysponge.com did not resolve (0). With no readable incident history the record takes the default (5). No rate limit with numbers was found in the docs, the OpenAPI file or the skill file (0). The skill file lists 429 as rate limited with the advice to back off and retry, and 409 for a duplicate action. No `Retry-After` header, backoff schedule or idempotency key is documented for transfers (4 of 15). No SLA was found (0). The terms say the service may be offered in beta and may change or be discontinued at any time, the SDK and CLI are at 0.1.x, and Sponge Card is labelled a beta preview. The wallet API itself carries no beta label (4 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 66,
          "points": 10.73,
          "reason": "A public OpenAPI 3.0.3 file at docs.paysponge.com/api-reference/public-openapi.json with 51 paths and 57 operations. It leaves out endpoints the skill file documents, among them `/api/agents/register`, `/api/paid/fetch`, `/api/discover`, the bank routes and `/api/payment-links` (20 of 25). llms.txt, a Markdown twin of each docs page and two skill files for agents (10). Most operation descriptions in the OpenAPI file repeat the title, such as \"Get wallet details via GET.\", while the skill file and the SDK's 53 tool definitions say when to use each call (12 of 20). The spec has 48 enums and 123 required lists. Amounts travel as strings and the `hyperliquid` and `polymarket` tools take an action name plus loosely typed arguments (10 of 15). The docs carry TypeScript, Python and curl examples for each workflow. Errors are a seven-row table in the skill file, the OpenAPI file documents only 200 and 204 responses, and the `SpongeApiError` codes are not listed (8 of 15). Every request carries a `Sponge-Version` header and the API returns version status and minimum-version headers. No changelog was found (6 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 43,
          "points": 6.99,
          "reason": "`@paysponge/sdk` 0.1.147 defines 53 tools for the MCP server, from `get_balance` to `polymarket`, which is the more-than-30 band (5). A second, trading-only server at `/trade/mcp` exposes seven tools, and `get_balance` can be narrowed by chain or to USDC (5 back, 10 of 25). We did not connect to the live server, so the count is from the package. Transaction history and MPP sessions take a `limit` and a chain or status filter and service discovery takes `limit` and `offset`. No cursor was found (8 of 20). Errors are an HTTP status and `{\"error\":\"message\"}`, with seven statuses explained and no list of machine-readable codes (9 of 20). No idempotency key was found for transfers, swaps or bank sends. 409 is described as a duplicate action, creating a virtual account is described as idempotent, and the SDK's tool definitions carry no read-only or destructive annotations (4 of 20). SDKs in TypeScript and Python, a CLI, and wallets created on every supported chain with no parameters. The Python package is at 0.1.5 from May 2026, and spending limits and banking are documented for TypeScript only (12 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 48,
          "points": 8.4,
          "reason": "Agent keys (`sponge_live_`, `sponge_test_`) cover one agent and can be regenerated. Master keys (`sponge_master_`) create and delete agents and per the docs never touch wallets. The MCP server also takes OAuth, and its resource metadata lists the scopes `mcp:tools`, `wallet:read`, `wallet:transfer` and `sponge:all`. An agent key is described as full access to one agent, and how scopes attach to keys is not documented. No secret travels in a URL (22 of 30). Daily, weekly and monthly spending limits are set per agent and enforced server-side, transfers to an address outside the allowlist return 403, checkouts need the owner's approval, and plans and trade proposals wait for a person. The transfers page describes `evmTransfer` and `solanaTransfer` as the enforced helpers next to a plain `transfer`, which leaves open whether every path applies the limits, and an agent-first key works before any person has claimed the wallet (14 of 20). `paid_fetch` returns third-party content and service discovery returns free-text `instructions` written by sellers. No guidance on treating that content as untrusted was found. The docs do warn against pasting or logging card details (3 of 15). Transaction history, MPP session lists and last-used times on master keys are readable by API. The dashboard's logs were not read (7 of 15). No security.txt (404), disclosure policy, certification or bug bounty was found. The terms name Basis Theory for card tokenisation and the docs name Persona for identity checks (2 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 70,
          "points": 8.75,
          "reason": "Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. The wallet pays x402 and MPP endpoints and creates x402 payment links so that another agent can pay its holder, and Sponge's separate Gateway product puts x402 and MPP in front of a seller's API. The wallet API itself is not paid over either, so the merchant step (25 of 40). No fee schedule for the wallet was found. The home page's structured data lists a price of 0, and the Sponge Card terms for the US give no annual fee and 1 per cent on international transactions. Fees on swaps, bridges, bank transfers and onramps were not found (5 of 20). A wallet costs nothing to create and needs no card, and the SDK defines a `claim_signup_bonus` tool that sends 1 USDC on Base (20). `POST /api/agents/register` needs no authentication and with `agentFirst` returns an API key at once, and `npx spongewallet init` does the same from a terminal. A person claims the agent later (20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 27,
          "points": 2.36,
          "reason": "`@paysponge/sdk` 0.1.147 and `spongewallet` 0.1.127 were published on 7 July 2026, 94 days before this check. The docs sitemap's newest date is 27 May 2026 and the wallet skill file was last modified on 23 June 2026 (10 of 30). No release or dated changelog entry falls in the last 90 days (0). The service is closed and the repository named in the packages, github.com/paysponge/sponge, is private. Support is a Discord server and a contact address, neither tested, and no changelog was found (4 of 15). Official SDKs exist in TypeScript and Python. The TypeScript SDK had 115 versions between 31 January and 7 July 2026 and the Python package six, all in May 2026 (10 of 15). The SDK has six runtime dependencies. CI is not visible because the repository is private (3 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 39,
          "points": 3.41,
          "note": "editorial 27, provenance 51",
          "reason": "A closed service. The SDK and CLI are MIT on npm, and the repository they name is private. The terms of service, updated 30 June 2026, are eleven short clauses that describe the service as AI-powered functionality and do not mention wallets, funds, custody, fees or API use (10 of 30). The privacy policy of the same date lists prompts, usage data and IP addresses, names no provider, gives no retention period beyond as long as necessary, and does not mention payment, card, bank or identity data. Separate card terms and an account opening privacy notice cover the Sponge Card (8 of 30). The API reports version status and a minimum version in response headers. No deprecation policy or dated notice was found (3 of 20). Basis Theory is named in the terms, Rain as card issuer on the home page, and Persona, Stripe and Coinbase in the docs, with no subprocessor list or data location. The CLI sends usage events to PostHog, which the npm README discloses, and no opt-out setting was found in the package (6 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`@paysponge/sdk` 0.1.147 defines 53 tools for the MCP server, from `get_balance` to `polymarket`, which is the more-than-30 band (5). A second, trading-only server at `/trade/mcp` exposes seven tools, and `get_balance` can be narrowed by chain or to USDC (5 back, 10 of 25). We did not connect to the live server, so the count is from the package. Transaction history and MPP sessions take a `limit` and a chain or status filter and service discovery takes `limit` and `offset`. No cursor was found (8 of 20). Errors are an HTTP status and `{\"error\":\"message\"}`, with seven statuses explained and no list of machine-readable codes (9 of 20). No idempotency key was found for transfers, swaps or bank sends. 409 is described as a duplicate action, creating a virtual account is described as idempotent, and the SDK's tool definitions carry no read-only or destructive annotations (4 of 20). SDKs in TypeScript and Python, a CLI, and wallets created on every supported chain with no parameters. The Python package is at 0.1.5 from May 2026, and spending limits and banking are documented for TypeScript only (12 of 15).",
          "maintenance": "`@paysponge/sdk` 0.1.147 and `spongewallet` 0.1.127 were published on 7 July 2026, 94 days before this check. The docs sitemap's newest date is 27 May 2026 and the wallet skill file was last modified on 23 June 2026 (10 of 30). No release or dated changelog entry falls in the last 90 days (0). The service is closed and the repository named in the packages, github.com/paysponge/sponge, is private. Support is a Discord server and a contact address, neither tested, and no changelog was found (4 of 15). Official SDKs exist in TypeScript and Python. The TypeScript SDK had 115 versions between 31 January and 7 July 2026 and the Python package six, all in May 2026 (10 of 15). The SDK has six runtime dependencies. CI is not visible because the repository is private (3 of 10).",
          "payments": "Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. The wallet pays x402 and MPP endpoints and creates x402 payment links so that another agent can pay its holder, and Sponge's separate Gateway product puts x402 and MPP in front of a seller's API. The wallet API itself is not paid over either, so the merchant step (25 of 40). No fee schedule for the wallet was found. The home page's structured data lists a price of 0, and the Sponge Card terms for the US give no annual fee and 1 per cent on international transactions. Fees on swaps, bridges, bank transfers and onramps were not found (5 of 20). A wallet costs nothing to create and needs no card, and the SDK defines a `claim_signup_bonus` tool that sends 1 USDC on Base (20). `POST /api/agents/register` needs no authentication and with `agentFirst` returns an API key at once, and `npx spongewallet init` does the same from a terminal. A person claims the agent later (20).",
          "reliability": "Graded as a hosted service on the REST API and the MCP server at api.wallet.paysponge.com. No status page was found. The site and docs link none and status.paysponge.com did not resolve (0). With no readable incident history the record takes the default (5). No rate limit with numbers was found in the docs, the OpenAPI file or the skill file (0). The skill file lists 429 as rate limited with the advice to back off and retry, and 409 for a duplicate action. No `Retry-After` header, backoff schedule or idempotency key is documented for transfers (4 of 15). No SLA was found (0). The terms say the service may be offered in beta and may change or be discontinued at any time, the SDK and CLI are at 0.1.x, and Sponge Card is labelled a beta preview. The wallet API itself carries no beta label (4 of 10).",
          "schema": "A public OpenAPI 3.0.3 file at docs.paysponge.com/api-reference/public-openapi.json with 51 paths and 57 operations. It leaves out endpoints the skill file documents, among them `/api/agents/register`, `/api/paid/fetch`, `/api/discover`, the bank routes and `/api/payment-links` (20 of 25). llms.txt, a Markdown twin of each docs page and two skill files for agents (10). Most operation descriptions in the OpenAPI file repeat the title, such as \"Get wallet details via GET.\", while the skill file and the SDK's 53 tool definitions say when to use each call (12 of 20). The spec has 48 enums and 123 required lists. Amounts travel as strings and the `hyperliquid` and `polymarket` tools take an action name plus loosely typed arguments (10 of 15). The docs carry TypeScript, Python and curl examples for each workflow. Errors are a seven-row table in the skill file, the OpenAPI file documents only 200 and 204 responses, and the `SpongeApiError` codes are not listed (8 of 15). Every request carries a `Sponge-Version` header and the API returns version status and minimum-version headers. No changelog was found (6 of 15).",
          "security": "Agent keys (`sponge_live_`, `sponge_test_`) cover one agent and can be regenerated. Master keys (`sponge_master_`) create and delete agents and per the docs never touch wallets. The MCP server also takes OAuth, and its resource metadata lists the scopes `mcp:tools`, `wallet:read`, `wallet:transfer` and `sponge:all`. An agent key is described as full access to one agent, and how scopes attach to keys is not documented. No secret travels in a URL (22 of 30). Daily, weekly and monthly spending limits are set per agent and enforced server-side, transfers to an address outside the allowlist return 403, checkouts need the owner's approval, and plans and trade proposals wait for a person. The transfers page describes `evmTransfer` and `solanaTransfer` as the enforced helpers next to a plain `transfer`, which leaves open whether every path applies the limits, and an agent-first key works before any person has claimed the wallet (14 of 20). `paid_fetch` returns third-party content and service discovery returns free-text `instructions` written by sellers. No guidance on treating that content as untrusted was found. The docs do warn against pasting or logging card details (3 of 15). Transaction history, MPP session lists and last-used times on master keys are readable by API. The dashboard's logs were not read (7 of 15). No security.txt (404), disclosure policy, certification or bug bounty was found. The terms name Basis Theory for card tokenisation and the docs name Persona for identity checks (2 of 20).",
          "transparency": "A closed service. The SDK and CLI are MIT on npm, and the repository they name is private. The terms of service, updated 30 June 2026, are eleven short clauses that describe the service as AI-powered functionality and do not mention wallets, funds, custody, fees or API use (10 of 30). The privacy policy of the same date lists prompts, usage data and IP addresses, names no provider, gives no retention period beyond as long as necessary, and does not mention payment, card, bank or identity data. Separate card terms and an account opening privacy notice cover the Sponge Card (8 of 30). The API reports version status and a minimum version in response headers. No deprecation policy or dated notice was found (3 of 20). Basis Theory is named in the terms, Rain as card issuer on the home page, and Persona, Stripe and Coinbase in the docs, with no subprocessor list or data location. The CLI sends usage events to PostHog, which the npm README discloses, and no opt-out setting was found in the package (6 of 20)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://docs.paysponge.com/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "OpenAPI file",
            "url": "https://docs.paysponge.com/api-reference/public-openapi.json",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP server guide",
            "url": "https://docs.paysponge.com/wallet/mcp.md",
            "seen": "2026-10-09"
          },
          {
            "what": "agent authentication",
            "url": "https://docs.paysponge.com/wallet/ai-agents.md",
            "seen": "2026-10-09"
          },
          {
            "what": "platforms, master keys and spending limits",
            "url": "https://docs.paysponge.com/wallet/platforms.md",
            "seen": "2026-10-09"
          },
          {
            "what": "master keys",
            "url": "https://docs.paysponge.com/wallet/master-keys.md",
            "seen": "2026-10-09"
          },
          {
            "what": "platform SDK reference",
            "url": "https://docs.paysponge.com/wallet/sdk-platform.md",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI",
            "url": "https://docs.paysponge.com/wallet/cli.md",
            "seen": "2026-10-09"
          },
          {
            "what": "transfers",
            "url": "https://docs.paysponge.com/wallet/wallet-transfers.md",
            "seen": "2026-10-09"
          },
          {
            "what": "supported networks",
            "url": "https://docs.paysponge.com/wallet/wallets-and-transfers.md",
            "seen": "2026-10-09"
          },
          {
            "what": "x402 payments",
            "url": "https://docs.paysponge.com/wallet/x402-payments.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MPP payments",
            "url": "https://docs.paysponge.com/wallet/mpp-payments.md",
            "seen": "2026-10-09"
          },
          {
            "what": "payment links",
            "url": "https://docs.paysponge.com/wallet/payment-links.md",
            "seen": "2026-10-09"
          },
          {
            "what": "browser checkout approvals",
            "url": "https://docs.paysponge.com/wallet/browser-checkout.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Sponge Card",
            "url": "https://docs.paysponge.com/wallet/sponge-card.md",
            "seen": "2026-10-09"
          },
          {
            "what": "bank withdrawals",
            "url": "https://docs.paysponge.com/wallet/bank-withdrawals.md",
            "seen": "2026-10-09"
          },
          {
            "what": "docs sitemap dates",
            "url": "https://docs.paysponge.com/sitemap.xml",
            "seen": "2026-10-09"
          },
          {
            "what": "wallet skill file 0.2.2",
            "url": "https://wallet.paysponge.com/skill.md",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI skill file 0.1.3",
            "url": "https://wallet.paysponge.com/cli-skill.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP OAuth resource metadata",
            "url": "https://api.wallet.paysponge.com/.well-known/oauth-protected-resource",
            "seen": "2026-10-09"
          },
          {
            "what": "home page and FAQ",
            "url": "https://paysponge.com/",
            "seen": "2026-10-09"
          },
          {
            "what": "terms of service",
            "url": "https://paysponge.com/terms",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://paysponge.com/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "Sponge Card terms (US)",
            "url": "https://paysponge.com/legal/sponge-card-terms-us",
            "seen": "2026-10-09"
          },
          {
            "what": "prohibitions list",
            "url": "https://paysponge.com/legal/prohibitions",
            "seen": "2026-10-09"
          },
          {
            "what": "security.txt (404)",
            "url": "https://paysponge.com/.well-known/security.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "npm registry, @paysponge/sdk",
            "url": "https://registry.npmjs.org/@paysponge/sdk",
            "seen": "2026-10-09"
          },
          {
            "what": "npm registry, spongewallet",
            "url": "https://registry.npmjs.org/spongewallet",
            "seen": "2026-10-09"
          },
          {
            "what": "npm downloads for @paysponge/sdk",
            "url": "https://api.npmjs.org/downloads/point/last-week/@paysponge/sdk",
            "seen": "2026-10-09"
          },
          {
            "what": "PyPI, paysponge",
            "url": "https://pypi.org/pypi/paysponge/json",
            "seen": "2026-10-09"
          },
          {
            "what": "RDAP for paysponge.com",
            "url": "https://rdap.verisign.com/com/v1/domain/paysponge.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the tools the live MCP server lists and whether they carry annotations. We did not connect with a key. The count of 53 is from `@paysponge/sdk` 0.1.147",
          "unchecked: the dashboard at wallet.paysponge.com, so per-transaction limits, merchant lists, key scopes and activity logs were not seen",
          "unchecked: the source repository github.com/paysponge/sponge, which asked for credentials, so CI, issues and star counts were not read",
          "unchecked: the account opening privacy notice, the international card terms and the electronic communications notice",
          "unchecked: whether Discord or the contact address answers",
          "Who holds wallet keys was not established. The docs and terms are silent, the skill file says managed wallet, and the card terms say card collateral stays in the holder's custody",
          "The home page FAQ names per-transaction limits and approved merchant lists. The docs show daily, weekly and monthly limits and address allowlists only",
          "The master keys page says the SDK has no admin client, and the platforms page documents `SpongePlatform` for the same job",
          "Chain lists differ. The docs name Ethereum, Base, Tempo and Solana, the skill file adds Polygon and Arbitrum, and the home page FAQ adds Monad and Hyperliquid",
          "The payment links page points to the API reference for `/api/payment-links`, and the OpenAPI file has no such path",
          "No package release, docs change or legal update dated after 7 July 2026 was found. The API and MCP server answered on the day",
          "The MCP resource metadata gives spongewallet.com as its documentation address, a second domain we did not read",
          "The lead said wires are accepted. The docs name virtual USD accounts and ACH withdrawals, and only the skill file names wire payouts",
          "The skill files are instructions addressed to AI agents, including a rule to register and never log in. We recorded them as facts and did not act on them",
          "paysponge.com was registered on 9 January 2026"
        ]
      },
      "negative": 0,
      "verdict": "An agent can register a wallet with one unauthenticated call and pay x402 or MPP endpoints under daily, weekly and monthly limits enforced on Sponge's servers. No status page, rate limits, fee schedule, custody statement or security contact was found, the terms run to eleven short clauses, and the SDK was last published on 7 July 2026.",
      "bestFor": "A developer who wants an agent to hold stablecoins and pay x402 or MPP endpoints within minutes, with cards, bank rails and Hyperliquid or Polymarket trading behind the same key.",
      "strengths": [
        "`POST /api/agents/register` with `agentFirst` returns an agent key at once, and a person claims the wallet later through a claim URL",
        "Daily, weekly and monthly spending limits are set per agent and enforced server-side, with address allowlists that return 403",
        "One wallet pays x402 and MPP endpoints, opens MPP sessions on Tempo and creates x402 payment links",
        "Agent keys cover one agent and can be regenerated. Master keys create agents and, per the docs, never touch wallets",
        "Public OpenAPI 3.0.3 file with 57 operations, llms.txt, Markdown docs and a 73 KB skill file written for agents"
      ],
      "weaknesses": [
        "No status page, SLA or numeric rate limit was found, and the terms say the service may be offered in beta",
        "Who holds the wallet keys is not stated in the docs or the terms. The skill file calls the wallet managed",
        "The terms of 30 June 2026 are eleven short clauses that do not mention wallets, funds, custody or fees",
        "No security.txt, disclosure policy, certification or bug bounty was found",
        "`@paysponge/sdk` was last published on 7 July 2026 after 115 versions in five months. The source repository is private",
        "The transfers page separates `wallet.transfer()` from enforced helpers that apply allowlists and limits, while another page says limits apply to every transfer"
      ],
      "agentNotes": [
        "Send `Sponge-Version` on every REST request. The skill file marks it required and the API answers with version status headers",
        "Use `evmTransfer` and `solanaTransfer`, the helpers the docs describe as enforcing allowlists and spending limits, not plain `transfer`",
        "Store the `apiKey` from registration at once. It is returned a single time, and losing it means registering again",
        "Call `GET /api/discover/{serviceId}` before `POST /api/paid/fetch`. The skill file says direct service URLs fail with auth errors",
        "Treat `card details` output as secret. It returns an encrypted card number and CVC with a one-time `secret_key`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 43.2
        }
      ],
      "editorialScores": {
        "ergonomics": 43,
        "maintenance": 27,
        "payments": 70,
        "reliability": 13,
        "schema": 66,
        "security": 48,
        "transparency": 27
      },
      "provenanceScore": 51
    },
    "connect": {
      "install": "npm install @paysponge/sdk",
      "http": "curl -sS -X POST https://api.wallet.paysponge.com/api/agents/register -H \"Sponge-Version: 0.2.2\" -H \"Content-Type: application/json\" -d '{\"name\":\"YourAgentName\",\"agentFirst\":true}'",
      "claudeCode": "claude mcp add -s user --transport http sponge https://api.wallet.paysponge.com/mcp --header \"Authorization: Bearer \u003cSPONGE_API_KEY\u003e\""
    },
    "letme": {
      "capability": "https://letme.dev/wallet.onchain",
      "tool": "https://letme.dev/sponge-wallet"
    },
    "notable": [
      "An agent registers its own wallet with `POST /api/agents/register` and no credential. With `agentFirst` the key is returned at once and a person claims the wallet later (https://wallet.paysponge.com/skill.md)",
      "Spending limits are daily, weekly and monthly per agent, set with a master key and enforced server-side per the docs (https://docs.paysponge.com/wallet/platforms.md)",
      "The transfers page says to use the enforced helpers `evmTransfer` and `solanaTransfer` for allowlist and limit checks, next to a plain `transfer` (https://docs.paysponge.com/wallet/wallet-transfers.md)",
      "The MCP server is at https://api.wallet.paysponge.com/mcp, with a seven-tool trading-only server at `/trade/mcp`. `@paysponge/sdk` 0.1.147 defines 53 tools (https://docs.paysponge.com/wallet/mcp.md)",
      "The terms of service, updated 30 June 2026, are eleven short clauses and say the service may be offered in beta and may be discontinued at any time (https://paysponge.com/terms)",
      "Sponge Card is a credit card issued by Rain, backed by USDC collateral, and labelled a beta preview in the skill file (https://paysponge.com/; https://wallet.paysponge.com/skill.md)",
      "`@paysponge/sdk` and `spongewallet` were last published on 7 July 2026, after 115 SDK versions since 31 January 2026 (https://registry.npmjs.org/@paysponge/sdk)",
      "The CLI sends usage events to PostHog, disclosed in the npm README. No opt-out setting was found in the package (https://registry.npmjs.org/@paysponge/sdk)",
      "The skill files at wallet.paysponge.com are instructions addressed to AI agents, among them a rule to register and never log in (https://wallet.paysponge.com/skill.md)",
      "paysponge.com was registered on 9 January 2026 (https://rdap.verisign.com/com/v1/domain/paysponge.com)"
    ],
    "area": "payments",
    "details": [
      {
        "label": "Custody",
        "value": "Not stated in the docs or the terms. The skill file describes a managed wallet tied to a human owner. The card terms say card collateral stays in the holder's custody"
      },
      {
        "label": "Spending limits",
        "value": "Daily, weekly and monthly limits per agent, set with a master key and enforced server-side. Address allowlists return 403. A per-transaction limit is named on the home page and was not found in the docs"
      },
      {
        "label": "Approvals",
        "value": "The owner approves each browser checkout in the dashboard. Plans (`submit_plan`, `approve_plan`) and trade proposals wait for a person. Link card credentials can return `approval_required`"
      },
      {
        "label": "Revocation",
        "value": "Regenerate an agent's key or delete the agent with a master key. Master keys are created and revoked in the dashboard"
      },
      {
        "label": "Chains",
        "value": "Ethereum, Base, Tempo and Solana per the docs. The skill file adds Polygon and Arbitrum. One address across EVM chains and a separate Solana keypair"
      },
      {
        "label": "Assets",
        "value": "ETH, USDC and pathUSD on EVM chains, SOL and USDC on Solana per the transfers page. Swaps on Solana, Base and Tempo, and bridging between chains"
      },
      {
        "label": "Machine payments",
        "value": "Pays x402 (`exact` and `upto` schemes) and MPP, with MPP sessions on Tempo. Creates x402 payment links. A catalogue of paid services is reached through `/api/discover` and `/api/paid/fetch`"
      },
      {
        "label": "Cards",
        "value": "Sponge Card, a credit card issued by Rain against USDC collateral, after an identity check. Per-checkout virtual cards, stored cards tokenised by Basis Theory, and Link payment methods"
      },
      {
        "label": "Banking",
        "value": "Virtual USD accounts whose deposits settle as USDC, and withdrawals to a linked US bank account by ACH in 1 to 3 business days, both after an identity check"
      },
      {
        "label": "Trading",
        "value": "Hyperliquid perpetuals and Polymarket orders through one tool each"
      },
      {
        "label": "API",
        "value": "REST at https://api.wallet.paysponge.com, OpenAPI 3.0.3 with 51 paths and 57 operations. A `Sponge-Version` header is required on each request"
      },
      {
        "label": "MCP",
        "value": "Streamable HTTP at `/mcp` with a bearer key or OAuth, and a trading-only server at `/trade/mcp` with seven tools. 53 tool definitions in the SDK"
      },
      {
        "label": "Credentials",
        "value": "Agent keys `sponge_live_` and `sponge_test_` for one agent, master keys `sponge_master_` for agent management. OAuth scopes `mcp:tools`, `wallet:read`, `wallet:transfer` and `sponge:all`"
      },
      {
        "label": "Errors",
        "value": "HTTP status with `{\"error\":\"message\"}`. 403 for an address outside the allowlist, 409 for a duplicate action, 429 with advice to back off"
      },
      {
        "label": "SDKs",
        "value": "`@paysponge/sdk` 0.1.147 and the `spongewallet` CLI 0.1.127 on npm (7 July 2026), `paysponge` 0.1.5 on PyPI (17 May 2026)"
      },
      {
        "label": "Status",
        "value": "No status page, SLA or published rate limit found"
      }
    ],
    "unitPrices": [
      {
        "item": "Sponge Card international transaction (US terms)",
        "unit": "pct",
        "usd": 1,
        "note": "no annual fee, 0 per cent APR"
      }
    ],
    "provenance": {
      "legalEntity": "Sponge Inc.",
      "domain": "paysponge.com",
      "domainRegistered": "2026-01-09",
      "endpointOnVendorDomain": true,
      "terms": "https://paysponge.com/terms",
      "privacy": "https://paysponge.com/privacy",
      "statusPage": "",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The terms of service (updated 30 June 2026) say they govern the Sponge platform and related services. They are eleven short clauses, name no legal entity or address, and choose the laws of the United States.",
        "The site footer names Sponge Inc. No company address or registration was found on the pages read.",
        "The privacy policy (updated 30 June 2026) covers the platform and related services. A separate account opening privacy notice and card terms cover the Sponge Card, whose issuer is Rain.",
        "The API and MCP server answer at api.wallet.paysponge.com and the dashboard at wallet.paysponge.com. The MCP resource metadata names spongewallet.com for documentation.",
        "paysponge.com/.well-known/security.txt returned 404. No status page or changelog was found.",
        "RDAP for paysponge.com gives a registration date of 2026-01-09."
      ],
      "score": 51,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Sponge Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "paysponge.com, registered 2026-01-09 (under a year)",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.wallet.paysponge.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 5 of the 8 things a reader expects",
          "points": 7.8,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://paysponge.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-30",
          "words": 314,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: June 30, 2026",
              "says": "Last updated 2026-06-30"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms shall be governed by and construed in accordance with the laws of the United States, without regard to conflict of law principles.",
              "says": "The law of the United States"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "To the maximum extent permitted by law, Sponge shall not be liable for any indirect, incidental, or consequential damages arising out of your use of the Service.",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may suspend or terminate access to the Service at any time, with or without notice, for any reason."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You are responsible for how you use any outputs generated by the Service."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may suspend or terminate access to the Service at any time, with or without notice, for any reason."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The service may be in beta and may change or be discontinued at any time.",
              "quote": "The Service may be offered in beta and may change or be discontinued at any time."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://paysponge.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-30",
          "words": 329,
          "points": 7.8,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: June 30, 2026",
              "says": "Last updated 2026-06-30"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "Usage data such as interaction timestamps and feature usage"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain information only for as long as necessary to provide and improve the Service, comply with legal obligations, or resolve disputes.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Our Service may rely on third-party providers, including AI model providers, hosting services, and analytics tools, to process data on our behalf."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": false
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You may contact us at [email protected] to make such requests.",
              "says": "Gives an email address, hidden from our reader by the page"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Third-party providers, including AI model providers, may process data on Sponge's behalf.",
              "quote": "Our Service may rely on third-party providers, including AI model providers, hosting services, and analytics tools, to process data on our behalf."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/sponge-wallet.json",
    "live": {
      "slug": "sponge-wallet",
      "probe": {
        "target": "https://api.wallet.paysponge.com",
        "method": "get",
        "lastAt": "2026-10-09T10:14:28.679608977Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 503,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 233,
        "p95ms24h": 581,
        "samples24h": 28,
        "samples30d": 28,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 28,
            "ok": 28
          }
        ]
      },
      "updatedAt": "2026-10-09T10:14:28.679608977Z"
    }
  }
}
