Head to head · Onchain wallets · October 2026 research run

Kite Agent Passport vs Openfort

Openfort scores 70.1 (BB) on agent readiness against Kite Agent Passport's 51.5 (D), and leads in 5 of 7 scored categories. Kite Agent Passport leads on security & auth. Both do onchain wallets.

Best agent wallets and spending controls · All 30 wallets comparisons

Which one, for what

Kite Agent Passport D

Best for Coding agents such as Claude Code or Codex that need to pay x402 or MPP services within budgets a person approves by passkey.

Ahead on

  • Security & auth, 72 against 65

Watch for

A person signs up by email, clicks a verification link and creates a passkey in a browser before any agent can spend

Openfort BB

Best for A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.

Ahead on

  • Reliability, 88 against 35
  • Schema & documentation, 89 against 64
  • Payments & pricing, 60 against 35
  • Maintenance & community, 87 against 71
  • Transparency & trust, 69 against 56

Also in its favour

  • Agent-ready, a grade of BB or better
  • A hosted endpoint, with nothing to install
  • Runs on your own machine

Watch for

An EVM backend send is evaluated only as signEvmHash, so address, value and calldata rules do not block it unless the caller pre-flights

Score by category

CategoryWeight this runKite Agent PassportOpenfortEdge
Reliability16%203588Openfort +53
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26489Openfort +25
Agent ergonomics13%16.26865Kite Agent Passport +3
Security & auth14%17.57265Kite Agent Passport +7
Payments & pricing10%12.53560Openfort +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87187Openfort +16
Transparency & trust7%8.85669Openfort +13
Negative events≤15-5-5
TotalD 51.5/100BB 70.1/100

Facts side by side

FactKite Agent PassportOpenfort
KindPlatformHTTP API
VendorKite AIOpenfort (Alamas Labs Inc.)
Hosted endpointno (local only)https://api.openfort.io
TransportsHTTPHTTP, stdio
AuthOAuth or keyAPI key
PricingPay per useFreemium
x402payer tooling onlypayer tooling only
LicenceClosed service under terms from Datalego Inc. dated 29 April 2026. The Passport Skills repository is MIT. The kpass CLI is distributed as binaries and its source repository is private.Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-09-28
Terms last updated2026-01-16
Privacy policy last updated2026-09-04
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularitynone10 stars, 7.6k npm/wk

Verdicts

Kite Agent Passport

Spending sessions with per-transaction and total caps, a lifetime and passkey approval are enforced by the service, with step-up checks and an audit log. A person must sign up by email and create a passkey before an agent can pay. No published fee rate, OpenAPI file or Passport status page was found.

Openfort

Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.

Before you call either

Kite Agent Passport

  1. Run kpass with --output json --no-interactive and branch on the exit code and error_code. Exit 6 is a session policy breach, so request a new session rather than logging in again
  2. Pass --idempotency-key on every kpass session execute so a retry after a timeout does not pay twice
  3. Ask the person for a session with a small per-transaction cap and a short --ttl, and confirm the merchant URL before executing
  4. Use kpass sandbox test mode and the faucet to try a payment flow without real funds. Scoped cards are not available in sandbox
  5. Check the kite-passport skill's trigger rules before installing it, since it directs the agent to paid services ahead of free tools

Openfort

  1. Call policies.evaluate with operation signEvmTransaction before every EVM backend send. The send itself is checked only as signEvmHash
  2. Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail
  3. Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error
  4. Give an agent a secret key without accounts:export, and limit the CLI MCP server to the tools it needs
  5. On a 5xx after a write, read the resource before retrying. On a 429, wait the full Retry-After

Questions

Which is better for AI agents, Kite Agent Passport or Openfort?

Openfort scores 70.1 (BB) on agent readiness against Kite Agent Passport's 51.5 (D), and leads in 5 of 7 scored categories. Kite Agent Passport leads on security & auth.

Can an agent call Kite Agent Passport and Openfort without installing anything?

No hosted endpoint is listed for Kite Agent Passport. Openfort has a hosted endpoint at https://api.openfort.io.

Other comparisons with Kite Agent Passport or Openfort

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.