{
  "data": {
    "a": {
      "slug": "openfort",
      "name": "Openfort",
      "vendor": "Openfort (Alamas Labs Inc.)",
      "vendorUrl": "https://www.openfort.io",
      "kind": "http-api",
      "category": "agent-wallets",
      "summary": "Openfort is wallet infrastructure from Alamas Labs. Its REST API, Node SDK and CLI create backend wallets held in a trusted execution environment, with signing policies, session keys and gas sponsorship. It also sells embedded wallets for apps.",
      "url": "https://www.anchorterminal.com/tools/openfort",
      "markdownUrl": "https://www.anchorterminal.com/tools/openfort.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openfort.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openfort.json",
      "repo": "https://github.com/openfort-xyz/openfort-node",
      "license": "Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.openfort.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@openfort/openfort-node"
        },
        {
          "registry": "npm",
          "name": "@openfort/cli"
        }
      ],
      "auth": "api-key",
      "authNotes": "A secret key (`sk_test_` or `sk_live_`) from the self-serve dashboard goes in `Authorization: Bearer`. Secret keys carry scopes (26 named, such as `accounts:sign`, `policies:write` and `accounts:export`), and a key made without a scope list gets all but four. Backend wallet signing also needs an `x-wallet-auth` ES256 JWT signed with a separate wallet secret, with a nonce and a request hash. Test and live keys are isolated. No OAuth (https://www.openfort.io/docs/api-reference/authentication).",
      "pricing": "freemium",
      "pricingNotes": "Free plan with 2,000 operations a month and no card, then $0.01 an operation. Growth $99 a month (25,000 operations, $0.008 extra), Pro $249 (100,000, $0.006), Scale $599 (500,000, $0.004). An operation is a wallet creation, signature, broadcast, policy evaluation, webhook or key import or export. Sponsored gas carries a 10 per cent surcharge, 5 per cent on Pro and Scale. Enterprise is priced by sales (https://www.openfort.io/pricing.md, checked 2026-10-09).",
      "priceSummary": "$99 / mo",
      "where": "both",
      "x402": {
        "level": "partial",
        "evidence": "Openfort wallets pay as a buyer. The docs carry an x402 recipe for USDC payments from embedded and backend wallets and an MPP recipe for an agent paying HTTP services on Tempo. Openfort's own API is not paid over x402. Its 402 status means the plan's operations are used up with no payment method (https://www.openfort.io/docs/llms.txt; https://www.openfort.io/docs/api-reference/errors, checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 10,
        "npmWeekly": 7647,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://www.openfort.io/docs/products/server/workflows/agentic-wallets",
      "llmsTxt": "https://www.openfort.io/llms.txt",
      "openapi": "https://www.openfort.io/docs/openapi.json",
      "capabilities": [
        "wallet.onchain",
        "wallet.spend-limits",
        "wallet.custody",
        "payments.x402"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "api-key",
        "openapi",
        "llms-txt",
        "mcp",
        "cli",
        "typescript",
        "wallet",
        "stablecoin",
        "x402",
        "tee",
        "status-page",
        "webhooks"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.1,
        "grade": "BB",
        "agentReady": true,
        "rank": 163,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 60,
          "reliability": 88,
          "schema": 89,
          "security": 65,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -5,
        "negativeNotes": [
          "9 October 2026. The agent wallets page says a signing policy is evaluated server-side on every operation against value caps and allowlists and that caps are enforced at signing time. The policies docs say an EVM backend send is evaluated only as `signEvmHash`, so those rules cannot block one. The docs disclose this plainly, so 3 points (https://www.openfort.io/agent-wallets; https://www.openfort.io/docs/configuration/policies).",
          "28 September 2026. The changelog says tokens from a third-party login provider were still accepted after the provider was disabled. Fixed and documented in the changelog, with no advisory found, so 2 points (https://www.openfort.io/changelog)."
        ],
        "verdict": "Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.",
        "bestFor": "A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.",
        "strengths": [
          "Backend wallet keys are generated and used inside a GCP Confidential Space enclave with AMD SEV-SNP, wrapped by an HSM-backed Cloud KMS key",
          "Secret keys carry 26 named scopes, and backend signing also needs an ES256 JWT from a separate wallet secret that can be rotated",
          "Policy engine rejects any operation no rule matches, with account and project scopes and a pre-flight `POST /v2/policies/evaluate`",
          "Rate limits are published per plan (100 to 1,200 requests a minute) and a 429 carries `Retry-After`",
          "Free plan of 2,000 operations a month with no card, and per-operation overage prices on every plan"
        ],
        "weaknesses": [
          "An EVM backend send is evaluated only as `signEvmHash`, so address, value and calldata rules do not block it unless the caller pre-flights",
          "Signing policies cap value per transaction. No daily or rolling cap was found in the reviewed policy pages",
          "The CLI MCP server exposes 72 commands as tools, among them `accounts_evm_export`, which returns a private key",
          "A default secret key includes `accounts:export` and `accounts:sign`",
          "No SOC 2 report (the vendor says so), no security.txt and no bug bounty found"
        ],
        "agentNotes": [
          "Call `policies.evaluate` with operation `signEvmTransaction` before every EVM backend send. The send itself is checked only as `signEvmHash`",
          "Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail",
          "Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error",
          "Give an agent a secret key without `accounts:export`, and limit the CLI MCP server to the tools it needs",
          "On a 5xx after a write, read the resource before retrying. On a 429, wait the full `Retry-After`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.1
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 87,
          "payments": 60,
          "reliability": 88,
          "schema": 89,
          "security": 65,
          "transparency": 64
        },
        "provenanceScore": 73
      },
      "connect": {
        "install": "npm install @openfort/openfort-node",
        "http": "curl https://api.openfort.io/v2/transactions -H \"Authorization: Bearer sk_test_...\"",
        "claudeCode": "claude mcp add --transport http openfort-docs https://www.openfort.io/api/mcp",
        "config": {
          "mcpServers": {
            "openfort": {
              "args": [
                "@openfort/cli",
                "--mcp"
              ],
              "command": "npx",
              "env": {
                "OPENFORT_API_KEY": "${OPENFORT_API_KEY}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/wallet.onchain",
        "tool": "https://letme.dev/openfort"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "Growth plan",
          "unit": "month",
          "usd": 99,
          "note": "25,000 operations included"
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 249,
          "note": "100,000 operations included"
        },
        {
          "item": "Scale plan",
          "unit": "month",
          "usd": 599,
          "note": "500,000 operations included"
        },
        {
          "item": "Extra operation, Free plan",
          "unit": "call",
          "usd": 0.01,
          "note": "per operation above 2,000 a month"
        },
        {
          "item": "Extra operation, Growth plan",
          "unit": "call",
          "usd": 0.008,
          "note": "per operation above 25,000 a month"
        },
        {
          "item": "Extra operation, Scale plan",
          "unit": "call",
          "usd": 0.004,
          "note": "per operation above 500,000 a month"
        }
      ],
      "provenance": {
        "legalEntity": "Alamas Labs Inc.",
        "domain": "openfort.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.openfort.io/developer-terms",
        "privacy": "https://www.openfort.io/privacy",
        "statusPage": "https://status.openfort.io",
        "changelog": "https://www.openfort.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Developer Terms of Service (last updated 16 January 2026) and the privacy policy (last updated 4 September 2026) both name Alamas Labs Inc. doing business as Openfort. The terms are governed by Delaware law.",
          "The API answers at https://api.openfort.io and the docs, OpenAPI file and docs MCP server at www.openfort.io.",
          "https://www.openfort.io/.well-known/security.txt answered 404. The security page gives security@openfort.io for reports.",
          "rdap.org answered that no RDAP service is available for openfort.io, so the registration date is not recorded.",
          "robots.txt on www.openfort.io allows every path and carries `Content-Signal: search=yes, ai-input=yes, ai-train=no`."
        ],
        "score": 73
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openfort.json",
      "live": {
        "slug": "openfort",
        "probe": {
          "target": "https://api.openfort.io",
          "method": "get",
          "lastAt": "2026-10-10T04:40:58.442608474Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 111,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 119,
          "p95ms24h": 216,
          "samples24h": 133,
          "samples30d": 133,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 85,
              "ok": 85
            },
            {
              "date": "2026-10-10",
              "probes": 48,
              "ok": 48
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.openfort.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-10T00:51:06.10917188Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "openfort-xyz/openfort-node",
            "version": "v0.13.1",
            "released": "2026-09-26",
            "seenAt": "2026-10-09T17:10:51.27158188Z"
          },
          {
            "registry": "npm",
            "name": "@openfort/cli",
            "version": "0.2.2",
            "seenAt": "2026-10-09T17:10:50.094981492Z"
          },
          {
            "registry": "npm",
            "name": "@openfort/openfort-node",
            "version": "0.13.1",
            "seenAt": "2026-10-09T17:10:49.071091624Z"
          }
        ],
        "githubStars": 10,
        "npmWeekly": 7647,
        "pages": [
          {
            "url": "https://www.openfort.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:45.881124774Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f46241d68d76"
          },
          {
            "url": "https://www.openfort.io/pricing.md",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:49.918241068Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "85d4cce5d750"
          },
          {
            "url": "https://www.openfort.io/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:51.997983732Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "92d5a24cf4eb"
          },
          {
            "url": "https://www.openfort.io/developer-terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:52:48.217259445Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c5c4280eac9f"
          }
        ],
        "updatedAt": "2026-10-10T04:40:58.442608474Z"
      }
    },
    "answer": "Openfort scores 70.1 (BB) on agent readiness against Sponge Wallet's 43.2 (E), and leads in 6 of 7 scored categories. Sponge Wallet leads on payments \u0026 pricing.",
    "b": {
      "slug": "sponge-wallet",
      "name": "Sponge Wallet",
      "vendor": "Sponge Inc.",
      "vendorUrl": "https://paysponge.com",
      "kind": "http-api",
      "category": "agent-wallets",
      "summary": "Sponge Wallet is a hosted wallet for AI agents. It holds stablecoins on Ethereum, Base, Tempo and Solana, pays x402 and MPP endpoints, issues virtual cards, and is reached by a REST API, an MCP server, SDKs and a CLI.",
      "url": "https://www.anchorterminal.com/tools/sponge-wallet",
      "markdownUrl": "https://www.anchorterminal.com/tools/sponge-wallet.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sponge-wallet.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sponge-wallet.json",
      "license": "Proprietary service under Sponge's terms of service. The SDK and CLI packages on npm are MIT, and the repository they name is private",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.wallet.paysponge.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@paysponge/sdk"
        },
        {
          "registry": "npm",
          "name": "spongewallet"
        },
        {
          "registry": "pypi",
          "name": "paysponge"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. An agent calls `POST /api/agents/register` with no credential and, with `agentFirst`, receives an agent API key at once. A person claims the wallet later through a claim URL. Requests carry the key as a bearer token plus a `Sponge-Version` header. Master keys, created in the dashboard, manage agents. The MCP server also accepts OAuth from app connectors.",
      "pricing": "free",
      "pricingNotes": "No fee schedule for the wallet was found. The home page's structured data lists a price of 0, a wallet needs no card or contract to start, and network and venue costs apply. Sponge Card (US) has no annual fee and charges 1 per cent on international transactions (https://paysponge.com/legal/sponge-card-terms-us, checked 2026-10-09). Fees on swaps, bridges, bank transfers and onramps were not found.",
      "priceSummary": "Free",
      "where": "hosted",
      "x402": {
        "level": "partial",
        "evidence": "The wallet pays x402 endpoints through `POST /api/x402/fetch`, `wallet.x402Fetch()` and `spongewallet pay x402`, pays MPP endpoints on Tempo, and creates x402 payment links. Sponge's own wallet API is not paid over either protocol (https://docs.paysponge.com/wallet/x402-payments.md; https://docs.paysponge.com/wallet/mpp-payments.md, checked 2026-10-09).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 126,
        "pypiWeekly": 20,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.paysponge.com",
      "llmsTxt": "https://docs.paysponge.com/llms.txt",
      "openapi": "https://docs.paysponge.com/api-reference/public-openapi.json",
      "capabilities": [
        "wallet.onchain",
        "wallet.spend-limits",
        "payments.x402",
        "payments.card",
        "wallet.custody"
      ],
      "tags": [
        "hosted",
        "free",
        "openapi",
        "llms-txt",
        "mcp",
        "typescript",
        "python",
        "cli",
        "wallet",
        "x402",
        "mpp",
        "virtual-cards",
        "stablecoins",
        "closed-source",
        "skills"
      ],
      "lastRelease": "2026-07-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 43.2,
        "grade": "E",
        "agentReady": false,
        "rank": 884,
        "ranked": true,
        "rankOf": 950,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 43,
          "maintenance": 27,
          "payments": 70,
          "reliability": 13,
          "schema": 66,
          "security": 48,
          "transparency": 39
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": 0,
        "verdict": "An agent can register a wallet with one unauthenticated call and pay x402 or MPP endpoints under daily, weekly and monthly limits enforced on Sponge's servers. No status page, rate limits, fee schedule, custody statement or security contact was found, the terms run to eleven short clauses, and the SDK was last published on 7 July 2026.",
        "bestFor": "A developer who wants an agent to hold stablecoins and pay x402 or MPP endpoints within minutes, with cards, bank rails and Hyperliquid or Polymarket trading behind the same key.",
        "strengths": [
          "`POST /api/agents/register` with `agentFirst` returns an agent key at once, and a person claims the wallet later through a claim URL",
          "Daily, weekly and monthly spending limits are set per agent and enforced server-side, with address allowlists that return 403",
          "One wallet pays x402 and MPP endpoints, opens MPP sessions on Tempo and creates x402 payment links",
          "Agent keys cover one agent and can be regenerated. Master keys create agents and, per the docs, never touch wallets",
          "Public OpenAPI 3.0.3 file with 57 operations, llms.txt, Markdown docs and a 73 KB skill file written for agents"
        ],
        "weaknesses": [
          "No status page, SLA or numeric rate limit was found, and the terms say the service may be offered in beta",
          "Who holds the wallet keys is not stated in the docs or the terms. The skill file calls the wallet managed",
          "The terms of 30 June 2026 are eleven short clauses that do not mention wallets, funds, custody or fees",
          "No security.txt, disclosure policy, certification or bug bounty was found",
          "`@paysponge/sdk` was last published on 7 July 2026 after 115 versions in five months. The source repository is private",
          "The transfers page separates `wallet.transfer()` from enforced helpers that apply allowlists and limits, while another page says limits apply to every transfer"
        ],
        "agentNotes": [
          "Send `Sponge-Version` on every REST request. The skill file marks it required and the API answers with version status headers",
          "Use `evmTransfer` and `solanaTransfer`, the helpers the docs describe as enforcing allowlists and spending limits, not plain `transfer`",
          "Store the `apiKey` from registration at once. It is returned a single time, and losing it means registering again",
          "Call `GET /api/discover/{serviceId}` before `POST /api/paid/fetch`. The skill file says direct service URLs fail with auth errors",
          "Treat `card details` output as secret. It returns an encrypted card number and CVC with a one-time `secret_key`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "E",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 43.2
          }
        ],
        "editorialScores": {
          "ergonomics": 43,
          "maintenance": 27,
          "payments": 70,
          "reliability": 13,
          "schema": 66,
          "security": 48,
          "transparency": 27
        },
        "provenanceScore": 51
      },
      "connect": {
        "install": "npm install @paysponge/sdk",
        "http": "curl -sS -X POST https://api.wallet.paysponge.com/api/agents/register -H \"Sponge-Version: 0.2.2\" -H \"Content-Type: application/json\" -d '{\"name\":\"YourAgentName\",\"agentFirst\":true}'",
        "claudeCode": "claude mcp add -s user --transport http sponge https://api.wallet.paysponge.com/mcp --header \"Authorization: Bearer \u003cSPONGE_API_KEY\u003e\""
      },
      "letme": {
        "capability": "https://letme.dev/wallet.onchain",
        "tool": "https://letme.dev/sponge-wallet"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "Sponge Card international transaction (US terms)",
          "unit": "pct",
          "usd": 1,
          "note": "no annual fee, 0 per cent APR"
        }
      ],
      "provenance": {
        "legalEntity": "Sponge Inc.",
        "domain": "paysponge.com",
        "domainRegistered": "2026-01-09",
        "endpointOnVendorDomain": true,
        "terms": "https://paysponge.com/terms",
        "privacy": "https://paysponge.com/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The terms of service (updated 30 June 2026) say they govern the Sponge platform and related services. They are eleven short clauses, name no legal entity or address, and choose the laws of the United States.",
          "The site footer names Sponge Inc. No company address or registration was found on the pages read.",
          "The privacy policy (updated 30 June 2026) covers the platform and related services. A separate account opening privacy notice and card terms cover the Sponge Card, whose issuer is Rain.",
          "The API and MCP server answer at api.wallet.paysponge.com and the dashboard at wallet.paysponge.com. The MCP resource metadata names spongewallet.com for documentation.",
          "paysponge.com/.well-known/security.txt returned 404. No status page or changelog was found.",
          "RDAP for paysponge.com gives a registration date of 2026-01-09."
        ],
        "score": 51
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/sponge-wallet.json",
      "live": {
        "slug": "sponge-wallet",
        "probe": {
          "target": "https://api.wallet.paysponge.com",
          "method": "get",
          "lastAt": "2026-10-10T04:41:05.110032074Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 221,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 241,
          "p95ms24h": 581,
          "samples24h": 217,
          "samples30d": 217,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 169,
              "ok": 169
            },
            {
              "date": "2026-10-10",
              "probes": 48,
              "ok": 48
            }
          ]
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@paysponge/sdk",
            "version": "0.1.147",
            "seenAt": "2026-10-09T17:21:26.507188432Z"
          },
          {
            "registry": "npm",
            "name": "spongewallet",
            "version": "0.1.127",
            "seenAt": "2026-10-09T17:21:27.357449876Z"
          },
          {
            "registry": "pypi",
            "name": "paysponge",
            "version": "0.1.5",
            "released": "2026-05-17",
            "seenAt": "2026-10-09T17:21:28.707941804Z"
          }
        ],
        "npmWeekly": 219,
        "pypiWeekly": 15,
        "securityTxt": {
          "url": "https://paysponge.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-09T15:39:31.422053061Z"
        },
        "llmsTxt": {
          "url": "https://docs.paysponge.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-09T14:02:50.623338928Z"
        },
        "pages": [
          {
            "url": "https://paysponge.com/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:06.350420913Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e0bb0a039144"
          },
          {
            "url": "https://paysponge.com/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-09T18:43:08.565756542Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ec8eb426955c"
          }
        ],
        "updatedAt": "2026-10-10T04:41:05.110032074Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Openfort (Alamas Labs Inc.)",
        "b": "Sponge Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://api.openfort.io",
        "b": "https://api.wallet.paysponge.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "payer tooling only",
        "b": "payer tooling only",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence",
        "b": "Proprietary service under Sponge's terms of service. The SDK and CLI packages on npm are MIT, and the repository they name is private",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-28",
        "b": "2026-07-07",
        "name": "Last release"
      },
      {
        "a": "2026-01-16",
        "b": "2026-06-30",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-04",
        "b": "2026-06-30",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "10 stars, 7.6k npm/wk",
        "b": "126 npm/wk, 20 PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Openfort scores 70.1 (BB) on agent readiness against Sponge Wallet's 43.2 (E), and leads in 6 of 7 scored categories. Sponge Wallet leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Openfort or Sponge Wallet?"
      },
      {
        "answer": "Openfort needs an API key. Sponge Wallet takes an API key or an OAuth sign-in.",
        "question": "Do Openfort and Sponge Wallet need an API key?"
      },
      {
        "answer": "Yes. Openfort has a hosted endpoint at https://api.openfort.io and Sponge Wallet at https://api.wallet.paysponge.com.",
        "question": "Can an agent call Openfort and Sponge Wallet without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 88 against 13",
          "Schema \u0026 documentation, 89 against 66",
          "Agent ergonomics, 65 against 43",
          "Security \u0026 auth, 65 against 48",
          "Maintenance \u0026 community, 87 against 27",
          "Transparency \u0026 trust, 69 against 39"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Runs on your own machine"
        ],
        "goodFor": "A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.",
        "slug": "openfort",
        "watchFor": "An EVM backend send is evaluated only as `signEvmHash`, so address, value and calldata rules do not block it unless the caller pre-flights"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 70 against 60"
        ],
        "also": [
          "No incidents deducted, where Openfort loses 5 points for them"
        ],
        "goodFor": "A developer who wants an agent to hold stablecoins and pay x402 or MPP endpoints within minutes, with cards, bank rails and Hyperliquid or Polymarket trading behind the same key.",
        "slug": "sponge-wallet",
        "watchFor": "No status page, SLA or numeric rate limit was found, and the terms say the service may be offered in beta"
      }
    ],
    "job": {
      "capability": "wallet.onchain",
      "name": "Onchain wallets"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-sponge-wallet.json",
        "title": "Agentcard vs Sponge Wallet",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-sponge-wallet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/circle-wallets-vs-openfort.json",
        "title": "Circle Wallets (Agent Wallets, Programmable Wallets) vs Openfort",
        "url": "https://www.anchorterminal.com/compare/circle-wallets-vs-openfort"
      },
      {
        "json": "https://www.anchorterminal.com/compare/circle-wallets-vs-sponge-wallet.json",
        "title": "Circle Wallets (Agent Wallets, Programmable Wallets) vs Sponge Wallet",
        "url": "https://www.anchorterminal.com/compare/circle-wallets-vs-sponge-wallet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-openfort.json",
        "title": "Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Openfort",
        "url": "https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-openfort"
      },
      {
        "json": "https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-sponge-wallet.json",
        "title": "Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Sponge Wallet",
        "url": "https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-sponge-wallet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openfort-vs-privy.json",
        "title": "Openfort vs Privy Wallets (server wallets, agent wallets, policy engine)",
        "url": "https://www.anchorterminal.com/compare/openfort-vs-privy"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openfort-vs-turnkey-agentic-wallets.json",
        "title": "Openfort vs Turnkey Agentic Wallets",
        "url": "https://www.anchorterminal.com/compare/openfort-vs-turnkey-agentic-wallets"
      },
      {
        "json": "https://www.anchorterminal.com/compare/privy-vs-sponge-wallet.json",
        "title": "Privy Wallets (server wallets, agent wallets, policy engine) vs Sponge Wallet",
        "url": "https://www.anchorterminal.com/compare/privy-vs-sponge-wallet"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sponge-wallet-vs-turnkey-agentic-wallets.json",
        "title": "Sponge Wallet vs Turnkey Agentic Wallets",
        "url": "https://www.anchorterminal.com/compare/sponge-wallet-vs-turnkey-agentic-wallets"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcard-vs-openfort.json",
        "title": "Agentcard vs Openfort",
        "url": "https://www.anchorterminal.com/compare/agentcard-vs-openfort"
      }
    ],
    "scores": [
      {
        "by": 75,
        "edge": "openfort",
        "key": "reliability",
        "name": "Reliability",
        "openfort": 88,
        "sponge-wallet": 13,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 23,
        "edge": "openfort",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "openfort": 89,
        "sponge-wallet": 66,
        "weight": 13
      },
      {
        "by": 22,
        "edge": "openfort",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "openfort": 65,
        "sponge-wallet": 43,
        "weight": 13
      },
      {
        "by": 17,
        "edge": "openfort",
        "key": "security",
        "name": "Security \u0026 auth",
        "openfort": 65,
        "sponge-wallet": 48,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "sponge-wallet",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "openfort": 60,
        "sponge-wallet": 70,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 60,
        "edge": "openfort",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "openfort": 87,
        "sponge-wallet": 27,
        "weight": 7
      },
      {
        "by": 30,
        "edge": "openfort",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "openfort": 69,
        "sponge-wallet": 39,
        "weight": 7
      }
    ],
    "summary": "Openfort scores 70.1 (BB) on agent readiness against Sponge Wallet's 43.2 (E), and leads in 6 of 7 scored categories. Sponge Wallet leads on payments \u0026 pricing. Both do onchain wallets.",
    "verdicts": {
      "openfort": "Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.",
      "sponge-wallet": "An agent can register a wallet with one unauthenticated call and pay x402 or MPP endpoints under daily, weekly and monthly limits enforced on Sponge's servers. No status page, rate limits, fee schedule, custody statement or security contact was found, the terms run to eleven short clauses, and the SDK was last published on 7 July 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet",
    "json": "https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet.md",
    "slim": "https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet.min.md"
  },
  "markdown": "Openfort scores 70.1 (BB) on agent readiness against Sponge Wallet's 43.2 (E), and leads in 6 of 7 scored categories. Sponge Wallet leads on payments \u0026 pricing. Both do onchain wallets.\n\n- Openfort: grade BB, 70.1/100, rank #163 of 950. Markdown https://www.anchorterminal.com/tools/openfort.md · JSON https://www.anchorterminal.com/api/v1/tools/openfort.json\n- Sponge Wallet: grade E, 43.2/100, rank #884 of 950. Markdown https://www.anchorterminal.com/tools/sponge-wallet.md · JSON https://www.anchorterminal.com/api/v1/tools/sponge-wallet.json\n- Best agent wallets and spending controls: https://www.anchorterminal.com/best/agent-wallets/index.md\n- All 23 wallets comparisons: https://www.anchorterminal.com/compare/agent-wallets/index.md\n\n## Which one, for what\n\n### Openfort (BB)\n\nGood for: A team that wants server-held wallets for agents on EVM chains and Solana with enclave signing, a free start and a CLI an agent can drive.\n\nAhead on:\n- Reliability, 88 against 13\n- Schema \u0026 documentation, 89 against 66\n- Agent ergonomics, 65 against 43\n- Security \u0026 auth, 65 against 48\n- Maintenance \u0026 community, 87 against 27\n- Transparency \u0026 trust, 69 against 39\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Runs on your own machine\n\nWatch for: An EVM backend send is evaluated only as `signEvmHash`, so address, value and calldata rules do not block it unless the caller pre-flights\n\n### Sponge Wallet (E)\n\nGood for: A developer who wants an agent to hold stablecoins and pay x402 or MPP endpoints within minutes, with cards, bank rails and Hyperliquid or Polymarket trading behind the same key.\n\nAhead on:\n- Payments \u0026 pricing, 70 against 60\n\nAlso in its favour:\n- No incidents deducted, where Openfort loses 5 points for them\n\nWatch for: No status page, SLA or numeric rate limit was found, and the terms say the service may be offered in beta\n\n\n## Score by category\n\n| Category | Weight | Openfort | Sponge Wallet | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 88 | 13 | Openfort +75 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 89 | 66 | Openfort +23 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 43 | Openfort +22 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 48 | Openfort +17 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 70 | Sponge Wallet +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 87 | 27 | Openfort +60 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 39 | Openfort +30 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **70.1 · BB** | **43.2 · E** | |\n\n## Facts side by side\n\n| Fact | Openfort | Sponge Wallet |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Openfort (Alamas Labs Inc.) | Sponge Inc. |\n| Hosted endpoint | `https://api.openfort.io` | `https://api.wallet.paysponge.com` |\n| Transports | HTTP, stdio | HTTP |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | payer tooling only | payer tooling only |\n| Licence | Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence | Proprietary service under Sponge's terms of service. The SDK and CLI packages on npm are MIT, and the repository they name is private |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-28 | 2026-07-07 |\n| Terms last updated | 2026-01-16 | 2026-06-30 |\n| Privacy policy last updated | 2026-09-04 | 2026-06-30 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 10 stars, 7.6k npm/wk | 126 npm/wk, 20 PyPI/wk |\n\n## Verdicts\n\n**Openfort.** Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first.\n\n**Sponge Wallet.** An agent can register a wallet with one unauthenticated call and pay x402 or MPP endpoints under daily, weekly and monthly limits enforced on Sponge's servers. No status page, rate limits, fee schedule, custody statement or security contact was found, the terms run to eleven short clauses, and the SDK was last published on 7 July 2026.\n\n## Before you call either\n\n### Openfort\n\n1. Call `policies.evaluate` with operation `signEvmTransaction` before every EVM backend send. The send itself is checked only as `signEvmHash`\n2. Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail\n3. Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error\n4. Give an agent a secret key without `accounts:export`, and limit the CLI MCP server to the tools it needs\n5. On a 5xx after a write, read the resource before retrying. On a 429, wait the full `Retry-After`\n\n### Sponge Wallet\n\n1. Send `Sponge-Version` on every REST request. The skill file marks it required and the API answers with version status headers\n2. Use `evmTransfer` and `solanaTransfer`, the helpers the docs describe as enforcing allowlists and spending limits, not plain `transfer`\n3. Store the `apiKey` from registration at once. It is returned a single time, and losing it means registering again\n4. Call `GET /api/discover/{serviceId}` before `POST /api/paid/fetch`. The skill file says direct service URLs fail with auth errors\n5. Treat `card details` output as secret. It returns an encrypted card number and CVC with a one-time `secret_key`\n\n## Questions\n\n### Which is better for AI agents, Openfort or Sponge Wallet?\n\nOpenfort scores 70.1 (BB) on agent readiness against Sponge Wallet's 43.2 (E), and leads in 6 of 7 scored categories. Sponge Wallet leads on payments \u0026 pricing.\n\n### Do Openfort and Sponge Wallet need an API key?\n\nOpenfort needs an API key. Sponge Wallet takes an API key or an OAuth sign-in.\n\n### Can an agent call Openfort and Sponge Wallet without installing anything?\n\nYes. Openfort has a hosted endpoint at https://api.openfort.io and Sponge Wallet at https://api.wallet.paysponge.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet.json, and with the fewest tokens: https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"openfort\", \"b\": \"sponge-wallet\"}`. From a terminal: `anchor compare openfort sponge-wallet`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/openfort.json and https://www.anchorterminal.com/api/v1/tools/sponge-wallet.json\n\n## Other comparisons with Openfort or Sponge Wallet\n\n- [Agentcard vs Sponge Wallet](https://www.anchorterminal.com/compare/agentcard-vs-sponge-wallet.md)\n- [Circle Wallets (Agent Wallets, Programmable Wallets) vs Openfort](https://www.anchorterminal.com/compare/circle-wallets-vs-openfort.md)\n- [Circle Wallets (Agent Wallets, Programmable Wallets) vs Sponge Wallet](https://www.anchorterminal.com/compare/circle-wallets-vs-sponge-wallet.md)\n- [Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Openfort](https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-openfort.md)\n- [Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Sponge Wallet](https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-sponge-wallet.md)\n- [Openfort vs Privy Wallets (server wallets, agent wallets, policy engine)](https://www.anchorterminal.com/compare/openfort-vs-privy.md)\n- [Openfort vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/openfort-vs-turnkey-agentic-wallets.md)\n- [Privy Wallets (server wallets, agent wallets, policy engine) vs Sponge Wallet](https://www.anchorterminal.com/compare/privy-vs-sponge-wallet.md)\n- [Sponge Wallet vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/sponge-wallet-vs-turnkey-agentic-wallets.md)\n- [Agentcard vs Openfort](https://www.anchorterminal.com/compare/agentcard-vs-openfort.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Openfort vs Sponge Wallet",
        "url": ""
      }
    ],
    "description": "Openfort scores 70.1 (BB) to Sponge Wallet's 43.2 (E) for onchain wallets. Prices, MCP, x402, uptime and agent notes side by side.",
    "facts": [
      "Openfort BB 70.1",
      "Sponge Wallet E 43.2",
      "scores"
    ],
    "h1": "Openfort vs Sponge Wallet",
    "image": "https://www.anchorterminal.com/assets/og/compare-openfort-vs-sponge-wallet.png",
    "path": "/compare/openfort-vs-sponge-wallet",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Openfort vs Sponge Wallet for AI agents in 2026: scores and prices",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/openfort-vs-sponge-wallet"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
