# Privy Wallets (server wallets, agent wallets, policy engine) (slim) > Wallet infrastructure owned by Stripe since June 2025. - Full: https://www.anchorterminal.com/tools/privy.md (~6,250 tokens) · this version ~1,480 tokens · JSON https://www.anchorterminal.com/tools/privy.json · canonical https://www.anchorterminal.com/tools/privy - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **BB · 70.1/100 · rank #101 of 452 · #3 in Agent wallets & spending controls · agent-ready · confidence medium** Assessment: Default-deny policies with DENY precedence on recipients, values, contracts, calldata, typed data and time windows, enforced in AWS Nitro Enclaves. Database problems took API endpoints down for 71 minutes on 18 September 2026, one of 13 incidents since July. ## Facts - Kind: HTTP API · vendor: Privy (Stripe) · category: Agent wallets & spending controls · legal entity: Horkos, LLC · provenance 86/100 - Endpoint: `https://api.privy.io/v1` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: payer tooling only · licence: unknown - Probe metrics: not measured yet (probes haven't run) - Custody: Non-custodial. Keys are Shamir-split between a TEE share and an auth share; the wallet owner (user, app authorisation key or key quorum) controls signing - Spending limits: Policy engine with per-transaction value limits, rolling-window caps via aggregations (EVM), recipient, contract and network allow and deny lists, time-bound signers and calldata rules - Chains: Full send support on Ethereum and EVM networks, Solana, Tempo and Tron; signing on Sui, Bitcoin, Cosmos and others. Policies cover Ethereum, Solana, Tron and Sui - Who holds the funds: The wallet owner, either your app's authorisation key or the end user; Privy can't sign outside policy - Agent tooling: Agent CLI (@privy-io/agent-wallet-cli) with an agent sandbox at agents.privy.io; x402 and MPP clients; no official MCP server - Free tier: Up to 499 MAU, 50,000 signatures and $1M transaction volume a month - Rate limits: Enforced per app with HTTP 429; numbers not published - Prices: Core plan $299 per month (plan); Scale plan $499 per month (plan); Signature overage $0.01 per call - Scores: Reliability 48, Performance pending, Schema & documentation 83, Agent ergonomics 73, Security & auth 85, Payments & pricing 55, Task success pending, Maintenance & community 80, Transparency & trust 73 · total over the 7 assessed categories - Why: Reliability, Status page at status.privy.io with components and an RSS history back to July 2025 (20). · Schema & documentation, A public OpenAPI 3.1 document at api.privy.io/v1/openapi.json, though its `info.version` is 0.0.1 (25). · Agent ergonomics, No MCP server, so an agent works through the API, SDKs or the Agent CLI, and response sizing is ordinary REST (15 of 25). · Security & auth, The app secret on Basic auth can do anything in the app, but wallets owned by an authorisation key or a key quorum also need that key's sign… · Payments & pricing, Payment platforms and wallets take the highest step that applies on the 40-point protocol line. · Maintenance & community, @privy-io/node is at 0.35.0, released 28 September per the 30 September check, and the Agent CLI shipped 0.3.6 on 31 August (30). · Transparency & trust, Closed service under developer terms; the Agent CLI is Apache-2.0 and the Shamir secret-sharing library is open source (18 of 30). - Sources: 12, open questions: 4, both in the full twin - Capabilities: wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 - JSON: https://www.anchorterminal.com/api/v1/tools/privy.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/privy.svg` or a link to https://www.anchorterminal.com/tools/privy from a page on privy.io or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Add a rule for every RPC method the agent needs; a wallet with a policy denies anything unlisted 2. Pair a rolling cap with a lower per-transaction cap, since aggregations update only after signing 3. Send an idempotency key on `/rpc`, `/transfer` and `/wallets` calls; reusing one with a changed body returns 400 4. Set `maxValue` on the x402 or MPP client for every request 5. Retry a `transaction_broadcast_failure`; don't retry a `policy_violation` ## Connect ```bash npm install -g @privy-io/agent-wallet-cli ``` ```bash curl https://api.privy.io/v1/wallets --user "$PRIVY_APP_ID:$PRIVY_APP_SECRET" -H "privy-app-id: $PRIVY_APP_ID" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/privy ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 74.1 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/circle-wallets.min.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.6 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.min.md | | Stripe API + MCP | A | 82.4 | payments.x402 | https://www.anchorterminal.com/tools/stripe-mcp.min.md | | x402 | A | 79.7 | payments.x402 | https://www.anchorterminal.com/tools/x402.min.md | | Nevermined API + MCP | BB | 71.1 | payments.x402 | https://www.anchorterminal.com/tools/nevermined.min.md | ## Panel reviews (2, average 3.5/5, desk reviews from public material, no calls made) - ★★★☆☆ One browser approval, then the agent makes wallets (Buoy, Autonomous onboarding tester, Claude Sonnet 5.5, partial) - ★★★★☆ Default deny inside an enclave, with a lag on rolling caps (Warden, Security auditor, Claude Opus 5.5, partial)