Sponge Wallet
by Sponge Inc. HTTP API in Agent wallets & spending controls
Hosted x402 payer
Sponge Inc. · paysponge.com since 2026 · who's behind it
Sponge Wallet is a hosted wallet for AI agents. It holds stablecoins on Ethereum, Base, Tempo and Solana, pays x402 and MPP endpoints, issues virtual cards, and is reached by a REST API, an MCP server, SDKs and a CLI.
Good for A developer who wants an agent to hold stablecoins and pay x402 or MPP endpoints within minutes, with cards, bank rails and Hyperliquid or Polymarket trading behind the same key.
Is this your product? Claim this listing or verify it
Assessment. An agent can register a wallet with one unauthenticated call and pay x402 or MPP endpoints under daily, weekly and monthly limits enforced on Sponge's servers. No status page, rate limits, fee schedule, custody statement or security contact was found, the terms run to eleven short clauses, and the SDK was last published on 7 July 2026.
Facts
- Transport
- HTTP
- Endpoint
https://api.wallet.paysponge.com- Auth
- OAuth or key
- Pricing
- Free · Free
- x402
- Payer tooling only
- Licence
- Proprietary service under Sponge's terms of service. The SDK and CLI packages on npm are MIT, and the repository they name is private
- Packages
npm@paysponge/sdknpmspongewalletpypipaysponge- llms.txt
- published
- Last release
- npm / week
- 126
- PyPI / week
- 20
- Custody
- Not stated in the docs or the terms. The skill file describes a managed wallet tied to a human owner. The card terms say card collateral stays in the holder's custody
- Spending limits
- Daily, weekly and monthly limits per agent, set with a master key and enforced server-side. Address allowlists return 403. A per-transaction limit is named on the home page and was not found in the docs
- Approvals
- The owner approves each browser checkout in the dashboard. Plans (
submit_plan,approve_plan) and trade proposals wait for a person. Link card credentials can returnapproval_required - Revocation
- Regenerate an agent's key or delete the agent with a master key. Master keys are created and revoked in the dashboard
- Chains
- Ethereum, Base, Tempo and Solana per the docs. The skill file adds Polygon and Arbitrum. One address across EVM chains and a separate Solana keypair
- Assets
- ETH, USDC and pathUSD on EVM chains, SOL and USDC on Solana per the transfers page. Swaps on Solana, Base and Tempo, and bridging between chains
- Machine payments
- Pays x402 (
exactanduptoschemes) and MPP, with MPP sessions on Tempo. Creates x402 payment links. A catalogue of paid services is reached through/api/discoverand/api/paid/fetch - Cards
- Sponge Card, a credit card issued by Rain against USDC collateral, after an identity check. Per-checkout virtual cards, stored cards tokenised by Basis Theory, and Link payment methods
- Banking
- Virtual USD accounts whose deposits settle as USDC, and withdrawals to a linked US bank account by ACH in 1 to 3 business days, both after an identity check
- Trading
- Hyperliquid perpetuals and Polymarket orders through one tool each
- API
- REST at https://api.wallet.paysponge.com, OpenAPI 3.0.3 with 51 paths and 57 operations. A
Sponge-Versionheader is required on each request - MCP
- Streamable HTTP at
/mcpwith a bearer key or OAuth, and a trading-only server at/trade/mcpwith seven tools. 53 tool definitions in the SDK - Credentials
- Agent keys
sponge_live_andsponge_test_for one agent, master keyssponge_master_for agent management. OAuth scopesmcp:tools,wallet:read,wallet:transferandsponge:all - Errors
- HTTP status with
{"error":"message"}. 403 for an address outside the allowlist, 409 for a duplicate action, 429 with advice to back off - SDKs
@paysponge/sdk0.1.147 and thespongewalletCLI 0.1.127 on npm (7 July 2026),paysponge0.1.5 on PyPI (17 May 2026)- Status
- No status page, SLA or published rate limit found
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
POST /api/agents/registerwithagentFirstreturns an agent key at once, and a person claims the wallet later through a claim URL- Daily, weekly and monthly spending limits are set per agent and enforced server-side, with address allowlists that return 403
- One wallet pays x402 and MPP endpoints, opens MPP sessions on Tempo and creates x402 payment links
- Agent keys cover one agent and can be regenerated. Master keys create agents and, per the docs, never touch wallets
- Public OpenAPI 3.0.3 file with 57 operations, llms.txt, Markdown docs and a 73 KB skill file written for agents
Weaknesses
- No status page, SLA or numeric rate limit was found, and the terms say the service may be offered in beta
- Who holds the wallet keys is not stated in the docs or the terms. The skill file calls the wallet managed
- The terms of 30 June 2026 are eleven short clauses that do not mention wallets, funds, custody or fees
- No security.txt, disclosure policy, certification or bug bounty was found
@paysponge/sdkwas last published on 7 July 2026 after 115 versions in five months. The source repository is private- The transfers page separates
wallet.transfer()from enforced helpers that apply allowlists and limits, while another page says limits apply to every transfer
Before you call it notes for agents
- Send
Sponge-Versionon every REST request. The skill file marks it required and the API answers with version status headers - Use
evmTransferandsolanaTransfer, the helpers the docs describe as enforcing allowlists and spending limits, not plaintransfer - Store the
apiKeyfrom registration at once. It is returned a single time, and losing it means registering again - Call
GET /api/discover/{serviceId}beforePOST /api/paid/fetch. The skill file says direct service URLs fail with auth errors - Treat
card detailsoutput as secret. It returns an encrypted card number and CVC with a one-timesecret_key
Who's behind it provenance 51/100
- Legal entity namedSponge Inc.20/20
- Domain agepaysponge.com, registered 2026-01-09 (under a year)0/15
- Endpoint on the vendor's domainapi.wallet.paysponge.com15/15
- Terms of serviceread, states 5 of the 7 things a reader expects8.3/10
- Privacy policyread, states 5 of the 8 things a reader expects7.8/10
- Status pagenot found0/10
- Changelognot found0/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-06-30, states 5 of 7, 1 to know
TL;DR Dated 2026-06-30. States 5 of the 7 things a reader expects, and we didn't find how changes are announced or a service level. To know before relying on it, cut-off without notice or for any reason.
Says access can be ended without notice or for any reason
We may suspend or terminate access to the Service at any time, with or without notice, for any reason.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated Last updated 2026-06-30
Last updated: June 30, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the United States
These Terms shall be governed by and construed in accordance with the laws of the United States, without regard to conflict of law principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
To the maximum extent permitted by law, Sponge shall not be liable for any indirect, incidental, or consequential damages arising out of your use of the Service.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
We may suspend or terminate access to the Service at any time, with or without notice, for any reason.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced
Not found in the text.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
You are responsible for how you use any outputs generated by the Service.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
The service may be in beta and may change or be discontinued at any time.
The Service may be offered in beta and may change or be discontinued at any time.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 314 words
Privacy policy dated 2026-06-30, states 5 of 8
TL;DR Dated 2026-06-30. States 5 of the 8 things a reader expects, and we didn't find whether data is sold, people's rights or where data goes. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-06-30
Last updated: June 30, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
Usage data such as interaction timestamps and feature usage
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We retain information only for as long as necessary to provide and improve the Service, comply with legal obligations, or resolve disputes.
Says when data sent to the service is deleted.
Says who else receives the data
Our Service may rely on third-party providers, including AI model providers, hosting services, and analytics tools, to process data on our behalf.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
Not found in the text.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact Gives an email address, hidden from our reader by the page
You may contact us at [email protected] to make such requests.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Third-party providers, including AI model providers, may process data on Sponge's behalf.
Our Service may rely on third-party providers, including AI model providers, hosting services, and analytics tools, to process data on our behalf.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 329 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (updated 30 June 2026) say they govern the Sponge platform and related services. They are eleven short clauses, name no legal entity or address, and choose the laws of the United States.
The site footer names Sponge Inc. No company address or registration was found on the pages read.
The privacy policy (updated 30 June 2026) covers the platform and related services. A separate account opening privacy notice and card terms cover the Sponge Card, whose issuer is Rain.
The API and MCP server answer at api.wallet.paysponge.com and the dashboard at wallet.paysponge.com. The MCP resource metadata names spongewallet.com for documentation.
paysponge.com/.well-known/security.txt returned 404. No status page or changelog was found.
RDAP for paysponge.com gives a registration date of 2026-01-09.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-09 08:59 UTC
Probed every five minutes at https://api.wallet.paysponge.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/sponge-wallet.json
Notable
- An agent registers its own wallet with
POST /api/agents/registerand no credential. WithagentFirstthe key is returned at once and a person claims the wallet later source - Spending limits are daily, weekly and monthly per agent, set with a master key and enforced server-side per the docs source
- The transfers page says to use the enforced helpers
evmTransferandsolanaTransferfor allowlist and limit checks, next to a plaintransfersource - The MCP server is at https://api.wallet.paysponge.com/mcp, with a seven-tool trading-only server at
/trade/mcp.@paysponge/sdk0.1.147 defines 53 tools source - The terms of service, updated 30 June 2026, are eleven short clauses and say the service may be offered in beta and may be discontinued at any time source
- Sponge Card is a credit card issued by Rain, backed by USDC collateral, and labelled a beta preview in the skill file source source 2
@paysponge/sdkandspongewalletwere last published on 7 July 2026, after 115 SDK versions since 31 January 2026 source- The CLI sends usage events to PostHog, disclosed in the npm README. No opt-out setting was found in the package source
- The skill files at wallet.paysponge.com are instructions addressed to AI agents, among them a rule to register and never log in source
- paysponge.com was registered on 9 January 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 2.6 | |
Graded as a hosted service on the REST API and the MCP server at api.wallet.paysponge.com. No status page was found. The site and docs link none and status.paysponge.com did not resolve (0). With no readable incident history the record takes the default (5). No rate limit with numbers was found in the docs, the OpenAPI file or the skill file (0). The skill file lists 429 as rate limited with the advice to back off and retry, and 409 for a duplicate action. No Retry-After header, backoff schedule or idempotency key is documented for transfers (4 of 15). No SLA was found (0). The terms say the service may be offered in beta and may change or be discontinued at any time, the SDK and CLI are at 0.1.x, and Sponge Card is labelled a beta preview. The wallet API itself carries no beta label (4 of 10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.7 | |
A public OpenAPI 3.0.3 file at docs.paysponge.com/api-reference/public-openapi.json with 51 paths and 57 operations. It leaves out endpoints the skill file documents, among them /api/agents/register, /api/paid/fetch, /api/discover, the bank routes and /api/payment-links (20 of 25). llms.txt, a Markdown twin of each docs page and two skill files for agents (10). Most operation descriptions in the OpenAPI file repeat the title, such as "Get wallet details via GET.", while the skill file and the SDK's 53 tool definitions say when to use each call (12 of 20). The spec has 48 enums and 123 required lists. Amounts travel as strings and the hyperliquid and polymarket tools take an action name plus loosely typed arguments (10 of 15). The docs carry TypeScript, Python and curl examples for each workflow. Errors are a seven-row table in the skill file, the OpenAPI file documents only 200 and 204 responses, and the SpongeApiError codes are not listed (8 of 15). Every request carries a Sponge-Version header and the API returns version status and minimum-version headers. No changelog was found (6 of 15). | |||
| Agent ergonomics | 13%16.2 | 7.0 | |
@paysponge/sdk 0.1.147 defines 53 tools for the MCP server, from get_balance to polymarket, which is the more-than-30 band (5). A second, trading-only server at /trade/mcp exposes seven tools, and get_balance can be narrowed by chain or to USDC (5 back, 10 of 25). We did not connect to the live server, so the count is from the package. Transaction history and MPP sessions take a limit and a chain or status filter and service discovery takes limit and offset. No cursor was found (8 of 20). Errors are an HTTP status and {"error":"message"}, with seven statuses explained and no list of machine-readable codes (9 of 20). No idempotency key was found for transfers, swaps or bank sends. 409 is described as a duplicate action, creating a virtual account is described as idempotent, and the SDK's tool definitions carry no read-only or destructive annotations (4 of 20). SDKs in TypeScript and Python, a CLI, and wallets created on every supported chain with no parameters. The Python package is at 0.1.5 from May 2026, and spending limits and banking are documented for TypeScript only (12 of 15). | |||
| Security & auth | 14%17.5 | 8.4 | |
Agent keys (sponge_live_, sponge_test_) cover one agent and can be regenerated. Master keys (sponge_master_) create and delete agents and per the docs never touch wallets. The MCP server also takes OAuth, and its resource metadata lists the scopes mcp:tools, wallet:read, wallet:transfer and sponge:all. An agent key is described as full access to one agent, and how scopes attach to keys is not documented. No secret travels in a URL (22 of 30). Daily, weekly and monthly spending limits are set per agent and enforced server-side, transfers to an address outside the allowlist return 403, checkouts need the owner's approval, and plans and trade proposals wait for a person. The transfers page describes evmTransfer and solanaTransfer as the enforced helpers next to a plain transfer, which leaves open whether every path applies the limits, and an agent-first key works before any person has claimed the wallet (14 of 20). paid_fetch returns third-party content and service discovery returns free-text instructions written by sellers. No guidance on treating that content as untrusted was found. The docs do warn against pasting or logging card details (3 of 15). Transaction history, MPP session lists and last-used times on master keys are readable by API. The dashboard's logs were not read (7 of 15). No security.txt (404), disclosure policy, certification or bug bounty was found. The terms name Basis Theory for card tokenisation and the docs name Persona for identity checks (2 of 20). | |||
| Payments & pricing | 10%12.5 | 8.8 | |
Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. The wallet pays x402 and MPP endpoints and creates x402 payment links so that another agent can pay its holder, and Sponge's separate Gateway product puts x402 and MPP in front of a seller's API. The wallet API itself is not paid over either, so the merchant step (25 of 40). No fee schedule for the wallet was found. The home page's structured data lists a price of 0, and the Sponge Card terms for the US give no annual fee and 1 per cent on international transactions. Fees on swaps, bridges, bank transfers and onramps were not found (5 of 20). A wallet costs nothing to create and needs no card, and the SDK defines a claim_signup_bonus tool that sends 1 USDC on Base (20). POST /api/agents/register needs no authentication and with agentFirst returns an API key at once, and npx spongewallet init does the same from a terminal. A person claims the agent later (20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 2.4 | |
@paysponge/sdk 0.1.147 and spongewallet 0.1.127 were published on 7 July 2026, 94 days before this check. The docs sitemap's newest date is 27 May 2026 and the wallet skill file was last modified on 23 June 2026 (10 of 30). No release or dated changelog entry falls in the last 90 days (0). The service is closed and the repository named in the packages, github.com/paysponge/sponge, is private. Support is a Discord server and a contact address, neither tested, and no changelog was found (4 of 15). Official SDKs exist in TypeScript and Python. The TypeScript SDK had 115 versions between 31 January and 7 July 2026 and the Python package six, all in May 2026 (10 of 15). The SDK has six runtime dependencies. CI is not visible because the repository is private (3 of 10). | |||
| Transparency & trusteditorial 27, provenance 51 | 7%8.8 | 3.4 | |
| A closed service. The SDK and CLI are MIT on npm, and the repository they name is private. The terms of service, updated 30 June 2026, are eleven short clauses that describe the service as AI-powered functionality and do not mention wallets, funds, custody, fees or API use (10 of 30). The privacy policy of the same date lists prompts, usage data and IP addresses, names no provider, gives no retention period beyond as long as necessary, and does not mention payment, card, bank or identity data. Separate card terms and an account opening privacy notice cover the Sponge Card (8 of 30). The API reports version status and a minimum version in response headers. No deprecation policy or dated notice was found (3 of 20). Basis Theory is named in the terms, Rain as card issuer on the home page, and Persona, Stripe and Coinbase in the docs, with no subprocessor list or data location. The CLI sends usage events to PostHog, which the npm README discloses, and no opt-out setting was found in the package (6 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 43.2 · E | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 28 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Sponge Wallet, or have the agent fetch /fixes/sponge-wallet.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Sponge Wallet
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/sponge-wallet, the October 2026 research run, assessed 9 October 2026. Grade E, 43.2 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Sponge Wallet: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Reliability, 13 out of 100, up to 17.4 more on the total
Why it scored 13: Graded as a hosted service on the REST API and the MCP server at api.wallet.paysponge.com. No status page was found. The site and docs link none and status.paysponge.com did not resolve (0). With no readable incident history the record takes the default (5). No rate limit with numbers was found in the docs, the OpenAPI file or the skill file (0). The skill file lists 429 as rate limited with the advice to back off and retry, and 409 for a duplicate action. No `Retry-After` header, backoff schedule or idempotency key is documented for transfers (4 of 15). No SLA was found (0). The terms say the service may be offered in beta and may change or be discontinued at any time, the SDK and CLI are at 0.1.x, and Sponge Card is labelled a beta preview. The wallet API itself carries no beta label (4 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 2. Agent ergonomics, 43 out of 100, up to 9.3 more on the total
Why it scored 43: `@paysponge/sdk` 0.1.147 defines 53 tools for the MCP server, from `get_balance` to `polymarket`, which is the more-than-30 band (5). A second, trading-only server at `/trade/mcp` exposes seven tools, and `get_balance` can be narrowed by chain or to USDC (5 back, 10 of 25). We did not connect to the live server, so the count is from the package. Transaction history and MPP sessions take a `limit` and a chain or status filter and service discovery takes `limit` and `offset`. No cursor was found (8 of 20). Errors are an HTTP status and `{"error":"message"}`, with seven statuses explained and no list of machine-readable codes (9 of 20). No idempotency key was found for transfers, swaps or bank sends. 409 is described as a duplicate action, creating a virtual account is described as idempotent, and the SDK's tool definitions carry no read-only or destructive annotations (4 of 20). SDKs in TypeScript and Python, a CLI, and wallets created on every supported chain with no parameters. The Python package is at 0.1.5 from May 2026, and spending limits and banking are documented for TypeScript only (12 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 3. Security & auth, 48 out of 100, up to 9.1 more on the total
Why it scored 48: Agent keys (`sponge_live_`, `sponge_test_`) cover one agent and can be regenerated. Master keys (`sponge_master_`) create and delete agents and per the docs never touch wallets. The MCP server also takes OAuth, and its resource metadata lists the scopes `mcp:tools`, `wallet:read`, `wallet:transfer` and `sponge:all`. An agent key is described as full access to one agent, and how scopes attach to keys is not documented. No secret travels in a URL (22 of 30). Daily, weekly and monthly spending limits are set per agent and enforced server-side, transfers to an address outside the allowlist return 403, checkouts need the owner's approval, and plans and trade proposals wait for a person. The transfers page describes `evmTransfer` and `solanaTransfer` as the enforced helpers next to a plain `transfer`, which leaves open whether every path applies the limits, and an agent-first key works before any person has claimed the wallet (14 of 20). `paid_fetch` returns third-party content and service discovery returns free-text `instructions` written by sellers. No guidance on treating that content as untrusted was found. The docs do warn against pasting or logging card details (3 of 15). Transaction history, MPP session lists and last-used times on master keys are readable by API. The dashboard's logs were not read (7 of 15). No security.txt (404), disclosure policy, certification or bug bounty was found. The terms name Basis Theory for card tokenisation and the docs name Persona for identity checks (2 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 4. Maintenance & community, 27 out of 100, up to 6.4 more on the total
Why it scored 27: `@paysponge/sdk` 0.1.147 and `spongewallet` 0.1.127 were published on 7 July 2026, 94 days before this check. The docs sitemap's newest date is 27 May 2026 and the wallet skill file was last modified on 23 June 2026 (10 of 30). No release or dated changelog entry falls in the last 90 days (0). The service is closed and the repository named in the packages, github.com/paysponge/sponge, is private. Support is a Discord server and a contact address, neither tested, and no changelog was found (4 of 15). Official SDKs exist in TypeScript and Python. The TypeScript SDK had 115 versions between 31 January and 7 July 2026 and the Python package six, all in May 2026 (10 of 15). The SDK has six runtime dependencies. CI is not visible because the repository is private (3 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## 5. Schema & documentation, 66 out of 100, up to 5.5 more on the total
Why it scored 66: A public OpenAPI 3.0.3 file at docs.paysponge.com/api-reference/public-openapi.json with 51 paths and 57 operations. It leaves out endpoints the skill file documents, among them `/api/agents/register`, `/api/paid/fetch`, `/api/discover`, the bank routes and `/api/payment-links` (20 of 25). llms.txt, a Markdown twin of each docs page and two skill files for agents (10). Most operation descriptions in the OpenAPI file repeat the title, such as "Get wallet details via GET.", while the skill file and the SDK's 53 tool definitions say when to use each call (12 of 20). The spec has 48 enums and 123 required lists. Amounts travel as strings and the `hyperliquid` and `polymarket` tools take an action name plus loosely typed arguments (10 of 15). The docs carry TypeScript, Python and curl examples for each workflow. Errors are a seven-row table in the skill file, the OpenAPI file documents only 200 and 204 responses, and the `SpongeApiError` codes are not listed (8 of 15). Every request carries a `Sponge-Version` header and the API returns version status and minimum-version headers. No changelog was found (6 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 6. Transparency & trust, 39 out of 100, up to 5.3 more on the total
Made of editorial 27, provenance 51.
Why it scored 39: A closed service. The SDK and CLI are MIT on npm, and the repository they name is private. The terms of service, updated 30 June 2026, are eleven short clauses that describe the service as AI-powered functionality and do not mention wallets, funds, custody, fees or API use (10 of 30). The privacy policy of the same date lists prompts, usage data and IP addresses, names no provider, gives no retention period beyond as long as necessary, and does not mention payment, card, bank or identity data. Separate card terms and an account opening privacy notice cover the Sponge Card (8 of 30). The API reports version status and a minimum version in response headers. No deprecation policy or dated notice was found (3 of 20). Basis Theory is named in the terms, Rain as card issuer on the home page, and Persona, Stripe and Coinbase in the docs, with no subprocessor list or data location. The CLI sends usage events to PostHog, which the npm README discloses, and no opt-out setting was found in the package (6 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Domain age: paysponge.com, registered 2026-01-09 (under a year) (0 of 15)
- Terms of service: read, states 5 of the 7 things a reader expects (8.3 of 10)
- Privacy policy: read, states 5 of the 8 things a reader expects (7.8 of 10)
- Status page: not found (0 of 10)
- Changelog: not found (0 of 10)
- security.txt: not found (0 of 10)
## 7. Payments & pricing, 70 out of 100, up to 3.8 more on the total
Why it scored 70: Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. The wallet pays x402 and MPP endpoints and creates x402 payment links so that another agent can pay its holder, and Sponge's separate Gateway product puts x402 and MPP in front of a seller's API. The wallet API itself is not paid over either, so the merchant step (25 of 40). No fee schedule for the wallet was found. The home page's structured data lists a price of 0, and the Sponge Card terms for the US give no annual fee and 1 per cent on international transactions. Fees on swaps, bridges, bank transfers and onramps were not found (5 of 20). A wallet costs nothing to create and needs no card, and the SDK defines a `claim_signup_bonus` tool that sends 1 USDC on Base (20). `POST /api/agents/register` needs no authentication and with `agentFirst` returns an API key at once, and `npx spongewallet init` does the same from a terminal. A person claims the agent later (20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: the tools the live MCP server lists and whether they carry annotations. We did not connect with a key. The count of 53 is from `@paysponge/sdk` 0.1.147
- unchecked: the dashboard at wallet.paysponge.com, so per-transaction limits, merchant lists, key scopes and activity logs were not seen
- unchecked: the source repository github.com/paysponge/sponge, which asked for credentials, so CI, issues and star counts were not read
- unchecked: the account opening privacy notice, the international card terms and the electronic communications notice
- unchecked: whether Discord or the contact address answers
- Who holds wallet keys was not established. The docs and terms are silent, the skill file says managed wallet, and the card terms say card collateral stays in the holder's custody
- The home page FAQ names per-transaction limits and approved merchant lists. The docs show daily, weekly and monthly limits and address allowlists only
- The master keys page says the SDK has no admin client, and the platforms page documents `SpongePlatform` for the same job
- Chain lists differ. The docs name Ethereum, Base, Tempo and Solana, the skill file adds Polygon and Arbitrum, and the home page FAQ adds Monad and Hyperliquid
- The payment links page points to the API reference for `/api/payment-links`, and the OpenAPI file has no such path
- No package release, docs change or legal update dated after 7 July 2026 was found. The API and MCP server answered on the day
- The MCP resource metadata gives spongewallet.com as its documentation address, a second domain we did not read
- The lead said wires are accepted. The docs name virtual USD accounts and ACH withdrawals, and only the skill file names wire payouts
- The skill files are instructions addressed to AI agents, including a rule to register and never log in. We recorded them as facts and did not act on them
- paysponge.com was registered on 9 January 2026
## Weaknesses
- No status page, SLA or numeric rate limit was found, and the terms say the service may be offered in beta
- Who holds the wallet keys is not stated in the docs or the terms. The skill file calls the wallet managed
- The terms of 30 June 2026 are eleven short clauses that do not mention wallets, funds, custody or fees
- No security.txt, disclosure policy, certification or bug bounty was found
- `@paysponge/sdk` was last published on 7 July 2026 after 115 versions in five months. The source repository is private
- The transfers page separates `wallet.transfer()` from enforced helpers that apply allowlists and limits, while another page says limits apply to every transfer
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Send `Sponge-Version` on every REST request. The skill file marks it required and the API answers with version status headers
- Use `evmTransfer` and `solanaTransfer`, the helpers the docs describe as enforcing allowlists and spending limits, not plain `transfer`
- Store the `apiKey` from registration at once. It is returned a single time, and losing it means registering again
- Call `GET /api/discover/{serviceId}` before `POST /api/paid/fetch`. The skill file says direct service URLs fail with auth errors
- Treat `card details` output as secret. It returns an encrypted card number and CVC with a one-time `secret_key`
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the tools the live MCP server lists and whether they carry annotations. We did not connect with a key. The count of 53 is from
@paysponge/sdk0.1.147 - unchecked: the dashboard at wallet.paysponge.com, so per-transaction limits, merchant lists, key scopes and activity logs were not seen
- unchecked: the source repository github.com/paysponge/sponge, which asked for credentials, so CI, issues and star counts were not read
- unchecked: the account opening privacy notice, the international card terms and the electronic communications notice
- unchecked: whether Discord or the contact address answers
- Who holds wallet keys was not established. The docs and terms are silent, the skill file says managed wallet, and the card terms say card collateral stays in the holder's custody
- The home page FAQ names per-transaction limits and approved merchant lists. The docs show daily, weekly and monthly limits and address allowlists only
- The master keys page says the SDK has no admin client, and the platforms page documents
SpongePlatformfor the same job - Chain lists differ. The docs name Ethereum, Base, Tempo and Solana, the skill file adds Polygon and Arbitrum, and the home page FAQ adds Monad and Hyperliquid
- The payment links page points to the API reference for
/api/payment-links, and the OpenAPI file has no such path - No package release, docs change or legal update dated after 7 July 2026 was found. The API and MCP server answered on the day
- The MCP resource metadata gives spongewallet.com as its documentation address, a second domain we did not read
- The lead said wires are accepted. The docs name virtual USD accounts and ACH withdrawals, and only the skill file names wire payouts
- The skill files are instructions addressed to AI agents, including a rule to register and never log in. We recorded them as facts and did not act on them
- paysponge.com was registered on 9 January 2026
Sources 31
- docs index for agents docs.paysponge.com · seen 2026-10-09
- OpenAPI file docs.paysponge.com · seen 2026-10-09
- MCP server guide docs.paysponge.com · seen 2026-10-09
- agent authentication docs.paysponge.com · seen 2026-10-09
- platforms, master keys and spending limits docs.paysponge.com · seen 2026-10-09
- master keys docs.paysponge.com · seen 2026-10-09
- platform SDK reference docs.paysponge.com · seen 2026-10-09
- CLI docs.paysponge.com · seen 2026-10-09
- transfers docs.paysponge.com · seen 2026-10-09
- supported networks docs.paysponge.com · seen 2026-10-09
- x402 payments docs.paysponge.com · seen 2026-10-09
- MPP payments docs.paysponge.com · seen 2026-10-09
- payment links docs.paysponge.com · seen 2026-10-09
- browser checkout approvals docs.paysponge.com · seen 2026-10-09
- Sponge Card docs.paysponge.com · seen 2026-10-09
- bank withdrawals docs.paysponge.com · seen 2026-10-09
- docs sitemap dates docs.paysponge.com · seen 2026-10-09
- wallet skill file 0.2.2 wallet.paysponge.com · seen 2026-10-09
- CLI skill file 0.1.3 wallet.paysponge.com · seen 2026-10-09
- MCP OAuth resource metadata api.wallet.paysponge.com · seen 2026-10-09
- home page and FAQ paysponge.com · seen 2026-10-09
- terms of service paysponge.com · seen 2026-10-09
- privacy policy paysponge.com · seen 2026-10-09
- Sponge Card terms (US) paysponge.com · seen 2026-10-09
- prohibitions list paysponge.com · seen 2026-10-09
- security.txt (404) paysponge.com · seen 2026-10-09
- npm registry, @paysponge/sdk registry.npmjs.org · seen 2026-10-09
- npm registry, spongewallet registry.npmjs.org · seen 2026-10-09
- npm downloads for @paysponge/sdk api.npmjs.org · seen 2026-10-09
- PyPI, paysponge pypi.org · seen 2026-10-09
- RDAP for paysponge.com rdap.verisign.com · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Free Free No fee schedule for the wallet was found. The home page's structured data lists a price of 0, a wallet needs no card or contract to start, and network and venue costs apply. Sponge Card (US) has no annual fee and charges 1 per cent on international transactions (https://paysponge.com/legal/sponge-card-terms-us, checked 2026-10-09). Fees on swaps, bridges, bank transfers and onramps were not found.
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Sponge Card international transaction (US terms) | 1% | percentage fee | no annual fee, 0 per cent APR |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/sponge-wallet.xml, or this listing's score history at history.json.
Connect
Install
npm install @paysponge/sdk
First request
curl -sS -X POST https://api.wallet.paysponge.com/api/agents/register -H "Sponge-Version: 0.2.2" -H "Content-Type: application/json" -d '{"name":"YourAgentName","agentFirst":true}'
Claude Code
claude mcp add -s user --transport http sponge https://api.wallet.paysponge.com/mcp --header "Authorization: Bearer <SPONGE_API_KEY>"
Through letme picks today, calling later
GET https://letme.dev/sponge-wallet
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Turnkey Agentic Wallets BBCircle Wallets (Agent Wallets, Programmable Wallets) BBCoinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) BBPrivy Wallets (server wallets, agent wallets, policy engine) BStripe API + MCP ANevermined API + MCP BB
Head to head Circle Wallets (Agent Wallets, Programmable Wallets) vs Sponge Wallet · Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Sponge Wallet · Privy Wallets (server wallets, agent wallets, policy engine) vs Sponge Wallet · Sponge Wallet vs Turnkey Agentic Wallets
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Turnkey Agentic Wallets Turnkey Global, Inc. | BB | 76 | wallet.onchain wallet.spend-limits wallet.custody payments.x402 | no |
| Circle Wallets (Agent Wallets, Programmable Wallets) Circle | BB | 73.9 | wallet.onchain wallet.custody wallet.spend-limits payments.x402 | no |
| Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) Coinbase Developer Platform | BB | 71.2 | wallet.onchain wallet.custody wallet.spend-limits payments.x402 | no |
| Privy Wallets (server wallets, agent wallets, policy engine) Privy (Stripe) | B | 69.9 | wallet.onchain wallet.custody wallet.spend-limits payments.x402 | no |
| Stripe API + MCP Stripe | A | 82.4 | payments.card payments.x402 | no |
| Nevermined API + MCP Nevermined | BB | 70.8 | payments.x402 payments.card | no |
Machine-readable
- JSON
/api/v1/tools/sponge-wallet.json· historyhistory.json· badge/badges/sponge-wallet.svg· changes feed/feeds/tools/sponge-wallet.xml - Markdown
/tools/sponge-wallet.md· slim/tools/sponge-wallet.min.md(or sendAccept: text/markdown) - Fix list
/fixes/sponge-wallet.md·/fixes/sponge-wallet.json - From a terminal
anchor tool sponge-wallet --md(the CLI) · over MCPget_tool {"slug": "sponge-wallet"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/sponge-wallet"><img src="https://www.anchorterminal.com/badges/sponge-wallet.svg" alt="Sponge Wallet on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/sponge-wallet)<a href="https://www.anchorterminal.com/tools/sponge-wallet">Sponge Wallet on Anchor Terminal</a>It counts on a page on paysponge.com or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "sponge-wallet", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

