# Openfort (slim) > Openfort is wallet infrastructure from Alamas Labs. Its REST API, Node SDK and CLI create backend wallets held in a trusted execution environment, with signing policies, session keys and gas sponsorship. It also sells embedded wallets for apps. - Full: https://www.anchorterminal.com/tools/openfort.md (~8,300 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/openfort.json · canonical https://www.anchorterminal.com/tools/openfort - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **BB · 70.1/100 · rank #163 of 950 · #4 in Agent wallets & spending controls · agent-ready · confidence medium** Assessment: Backend wallets sign inside a GCP Confidential Space enclave, secret keys carry 26 scopes, and rate limits, errors and prices are published. On EVM, a backend send reaches the policy engine only as a hash, so address and value rules bind only when the caller runs the pre-flight check first. ## Facts - Kind: HTTP API · vendor: Openfort (Alamas Labs Inc.) · category: Agent wallets & spending controls · legal entity: Alamas Labs Inc. · provenance 73/100 - Endpoint: `https://api.openfort.io` (HTTP, stdio) - Auth: API key · pricing: Freemium · x402: payer tooling only · licence: Proprietary service under the Openfort Developer Terms of Service. The Node SDK and OpenSigner are MIT. The CLI repository and package state no licence - Probe metrics: not measured yet (probes haven't run) - Custody: Backend wallet keys are generated and stored encrypted by Openfort and used only inside a GCP Confidential Space enclave. The developer controls signing through the secret key and wallet secret. The terms call this non-custodial and the docs index calls backend wallets developer-controlled, custodial wallets - Spending limits: Signing policies with per-transaction value caps (`ethValue`, `solValue`, `splValue`), address allow and deny lists, chain ids, decoded calldata and Solana program and mint addresses. First match wins and no match means reject. For EVM backend sends these run only in the pre-flight evaluation. Session keys (ERC-7715) carry a spend cap, contract, function and expiry enforced on-chain - Chains: EVM chains and Solana for backend wallets. `POST /v2/transactions` is EVM only, and Solana backend wallets sign through `POST /v2/accounts/backend/{id}/sign` - Revocation: Roll the secret key or rotate the wallet secret in the dashboard, disable or update a policy, or revoke a session key with `POST /v1/sessions/revoke` - API: OpenAPI 3.0.3, 94 operations on 80 paths at https://api.openfort.io, under `/v1`, `/v2` and `/iam/v2` - Rate limits: Per project environment per minute. Free 100, Growth 300, Pro 600, Scale 1,200, Enterprise unlimited. 429 carries `Retry-After`. Bundler, paymaster and Solana RPC endpoints are metered separately - Errors: One JSON envelope with `error.type` of `invalid_request_error` or `api_error`, field-level `details` on 422, and an `x-request-id` header on every response - Agent tooling: CLI `@openfort/cli` 0.2.2 (Node 22 or later) that also runs as a stdio MCP server with 72 commands as tools. A hosted docs MCP server at https://www.openfort.io/api/mcp with nine documentation and source tools. An agent skill in openfort-xyz/agent-skills - SDKs: Node `@openfort/openfort-node` 0.13.1 (26 September 2026, MIT) for servers. JavaScript, React, React Native, Swift and Unity for embedded wallets - Status: status.openfort.io on Better Stack, six components with 90-day bars. API 99.987 per cent, no incidents listed for August to October 2026, three maintenance windows in September - Audits: CertiK and Omniscia (smart contract wallet), Cure53 (Shamir secret sharing), Quantstamp (7702 delegator and key management). Reports are in a shared folder for customers and partners. No SOC 2 - Data handling: Privacy policy of 4 September 2026. Transaction logs kept up to 7 years, usage data up to 2 years, support messages 3 years. Processors named are Google Cloud, PostHog and Sentry. Based in the United States - Prices: Growth plan $99 per month (plan); Pro plan $249 per month (plan); Scale plan $599 per month (plan); Extra operation, Free plan $0.01 per call; Extra operation, Growth plan $0.008 per call; Extra operation, Scale plan $0.004 per call - Scores: Reliability 88, Performance pending, Schema & documentation 89, Agent ergonomics 65, Security & auth 65, Payments & pricing 60, Task success pending, Maintenance & community 87, Transparency & trust 69 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Hosted lines. · Schema & documentation, Public OpenAPI 3.0.3 file with 94 operations on 80 paths (25). · Agent ergonomics, Graded on the REST API, which is what an agent's backend calls. · Security & auth, Secret keys carry 26 named scopes and can be rolled, test and live are isolated, and backend signing needs a second credential, a wallet sec… · Payments & pricing, Wallets take the highest step that applies on the 40-point protocol line, as for the other wallet listings. · Maintenance & community, Latest changelog entry 28 September 2026 and Node SDK 0.13.1 on 26 September (30). · Transparency & trust, Closed service under developer terms that name the entity. - Sources: 23, open questions: 11, both in the full twin - Capabilities: wallet.onchain, wallet.spend-limits, wallet.custody, payments.x402 - JSON: https://www.anchorterminal.com/api/v1/tools/openfort.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/openfort.svg` or a link to https://www.anchorterminal.com/tools/openfort from a page on openfort.io or one of its subdomains, or the README of github.com/openfort-xyz/openfort-node, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `policies.evaluate` with operation `signEvmTransaction` before every EVM backend send. The send itself is checked only as `signEvmHash` 2. Keep the signing policy and the gas sponsorship policy separate. Linking a signing policy to a fee sponsorship stops it working as a guardrail 3. Pass a fee sponsorship on EVM sends. Without one the transaction stays pending with no error 4. Give an agent a secret key without `accounts:export`, and limit the CLI MCP server to the tools it needs 5. On a 5xx after a write, read the resource before retrying. On a 429, wait the full `Retry-After` ## Connect ```bash npm install @openfort/openfort-node ``` ```bash curl https://api.openfort.io/v2/transactions -H "Authorization: Bearer sk_test_..." ``` ```bash claude mcp add --transport http openfort-docs https://www.openfort.io/api/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/openfort ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Turnkey Agentic Wallets | BB | 76 | wallet.onchain, wallet.spend-limits, wallet.custody, payments.x402 | https://www.anchorterminal.com/tools/turnkey-agentic-wallets.min.md | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 73.9 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/circle-wallets.min.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.2 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.min.md | | Privy Wallets (server wallets, agent wallets, policy engine) | B | 69.9 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/privy.min.md | | Sponge Wallet | E | 43.2 | wallet.onchain, wallet.spend-limits, payments.x402, wallet.custody | https://www.anchorterminal.com/tools/sponge-wallet.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)