# Sponge Wallet > Sponge Wallet is a hosted wallet for AI agents. It holds stablecoins on Ethereum, Base, Tempo and Solana, pays x402 and MPP endpoints, issues virtual cards, and is reached by a REST API, an MCP server, SDKs and a CLI. - Canonical: https://www.anchorterminal.com/tools/sponge-wallet - Markdown: https://www.anchorterminal.com/tools/sponge-wallet.md (~8,250 tokens) - Slim: https://www.anchorterminal.com/tools/sponge-wallet.min.md (~1,980 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/sponge-wallet.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade E · 43.2/100 · rank #785 of 842 · #5 in Agent wallets & spending controls · not agent-ready · confidence medium** ## Assessment An agent can register a wallet with one unauthenticated call and pay x402 or MPP endpoints under daily, weekly and monthly limits enforced on Sponge's servers. No status page, rate limits, fee schedule, custody statement or security contact was found, the terms run to eleven short clauses, and the SDK was last published on 7 July 2026. ## Facts | Field | Value | | --- | --- | | Vendor | Sponge Inc. (https://paysponge.com) | | Kind | HTTP API | | Category | Agent wallets & spending controls (https://www.anchorterminal.com/categories/agent-wallets) | | Transport | HTTP | | Endpoint | `https://api.wallet.paysponge.com` | | Auth | OAuth or key · Self-serve. An agent calls `POST /api/agents/register` with no credential and, with `agentFirst`, receives an agent API key at once. A person claims the wallet later through a claim URL. Requests carry the key as a bearer token plus a `Sponge-Version` header. Master keys, created in the dashboard, manage agents. The MCP server also accepts OAuth from app connectors. | | Pricing | Free (Free) · No fee schedule for the wallet was found. The home page's structured data lists a price of 0, a wallet needs no card or contract to start, and network and venue costs apply. Sponge Card (US) has no annual fee and charges 1 per cent on international transactions (https://paysponge.com/legal/sponge-card-terms-us, checked 2026-10-09). Fees on swaps, bridges, bank transfers and onramps were not found. | | x402 | Payer tooling only · The wallet pays x402 endpoints through `POST /api/x402/fetch`, `wallet.x402Fetch()` and `spongewallet pay x402`, pays MPP endpoints on Tempo, and creates x402 payment links. Sponge's own wallet API is not paid over either protocol (https://docs.paysponge.com/wallet/x402-payments.md; https://docs.paysponge.com/wallet/mpp-payments.md, checked 2026-10-09). | | Licence | Proprietary service under Sponge's terms of service. The SDK and CLI packages on npm are MIT, and the repository they name is private | | Packages | npm: `@paysponge/sdk`; npm: `spongewallet`; pypi: `paysponge` | | Docs | https://docs.paysponge.com | | llms.txt | https://docs.paysponge.com/llms.txt | | Last release | 2026-07-07 | | npm downloads / week | 126 | | PyPI downloads / week | 20 | | Custody | Not stated in the docs or the terms. The skill file describes a managed wallet tied to a human owner. The card terms say card collateral stays in the holder's custody | | Spending limits | Daily, weekly and monthly limits per agent, set with a master key and enforced server-side. Address allowlists return 403. A per-transaction limit is named on the home page and was not found in the docs | | Approvals | The owner approves each browser checkout in the dashboard. Plans (`submit_plan`, `approve_plan`) and trade proposals wait for a person. Link card credentials can return `approval_required` | | Revocation | Regenerate an agent's key or delete the agent with a master key. Master keys are created and revoked in the dashboard | | Chains | Ethereum, Base, Tempo and Solana per the docs. The skill file adds Polygon and Arbitrum. One address across EVM chains and a separate Solana keypair | | Assets | ETH, USDC and pathUSD on EVM chains, SOL and USDC on Solana per the transfers page. Swaps on Solana, Base and Tempo, and bridging between chains | | Machine payments | Pays x402 (`exact` and `upto` schemes) and MPP, with MPP sessions on Tempo. Creates x402 payment links. A catalogue of paid services is reached through `/api/discover` and `/api/paid/fetch` | | Cards | Sponge Card, a credit card issued by Rain against USDC collateral, after an identity check. Per-checkout virtual cards, stored cards tokenised by Basis Theory, and Link payment methods | | Banking | Virtual USD accounts whose deposits settle as USDC, and withdrawals to a linked US bank account by ACH in 1 to 3 business days, both after an identity check | | Trading | Hyperliquid perpetuals and Polymarket orders through one tool each | | API | REST at https://api.wallet.paysponge.com, OpenAPI 3.0.3 with 51 paths and 57 operations. A `Sponge-Version` header is required on each request | | MCP | Streamable HTTP at `/mcp` with a bearer key or OAuth, and a trading-only server at `/trade/mcp` with seven tools. 53 tool definitions in the SDK | | Credentials | Agent keys `sponge_live_` and `sponge_test_` for one agent, master keys `sponge_master_` for agent management. OAuth scopes `mcp:tools`, `wallet:read`, `wallet:transfer` and `sponge:all` | | Errors | HTTP status with `{"error":"message"}`. 403 for an address outside the allowlist, 409 for a duplicate action, 429 with advice to back off | | SDKs | `@paysponge/sdk` 0.1.147 and the `spongewallet` CLI 0.1.127 on npm (7 July 2026), `paysponge` 0.1.5 on PyPI (17 May 2026) | | Status | No status page, SLA or published rate limit found | | Capabilities | wallet.onchain, wallet.spend-limits, payments.x402, payments.card, wallet.custody | | Tags | hosted, free, openapi, llms-txt, mcp, typescript, python, cli, wallet, x402, mpp, virtual-cards, stablecoins, closed-source, skills | | JSON | https://www.anchorterminal.com/api/v1/tools/sponge-wallet.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 13 | 2.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 66 | 10.7 | | Agent ergonomics | 13% | 16.2 | 43 | 7.0 | | Security & auth | 14% | 17.5 | 48 | 8.4 | | Payments & pricing | 10% | 12.5 | 70 | 8.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 27 | 2.4 | | Transparency & trust (editorial 27, provenance 51) | 7% | 8.8 | 39 | 3.4 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **43.2 → E** | ### Why each score - Reliability 13: Graded as a hosted service on the REST API and the MCP server at api.wallet.paysponge.com. No status page was found. The site and docs link none and status.paysponge.com did not resolve (0). With no readable incident history the record takes the default (5). No rate limit with numbers was found in the docs, the OpenAPI file or the skill file (0). The skill file lists 429 as rate limited with the advice to back off and retry, and 409 for a duplicate action. No `Retry-After` header, backoff schedule or idempotency key is documented for transfers (4 of 15). No SLA was found (0). The terms say the service may be offered in beta and may change or be discontinued at any time, the SDK and CLI are at 0.1.x, and Sponge Card is labelled a beta preview. The wallet API itself carries no beta label (4 of 10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 66: A public OpenAPI 3.0.3 file at docs.paysponge.com/api-reference/public-openapi.json with 51 paths and 57 operations. It leaves out endpoints the skill file documents, among them `/api/agents/register`, `/api/paid/fetch`, `/api/discover`, the bank routes and `/api/payment-links` (20 of 25). llms.txt, a Markdown twin of each docs page and two skill files for agents (10). Most operation descriptions in the OpenAPI file repeat the title, such as "Get wallet details via GET.", while the skill file and the SDK's 53 tool definitions say when to use each call (12 of 20). The spec has 48 enums and 123 required lists. Amounts travel as strings and the `hyperliquid` and `polymarket` tools take an action name plus loosely typed arguments (10 of 15). The docs carry TypeScript, Python and curl examples for each workflow. Errors are a seven-row table in the skill file, the OpenAPI file documents only 200 and 204 responses, and the `SpongeApiError` codes are not listed (8 of 15). Every request carries a `Sponge-Version` header and the API returns version status and minimum-version headers. No changelog was found (6 of 15). - Agent ergonomics 43: `@paysponge/sdk` 0.1.147 defines 53 tools for the MCP server, from `get_balance` to `polymarket`, which is the more-than-30 band (5). A second, trading-only server at `/trade/mcp` exposes seven tools, and `get_balance` can be narrowed by chain or to USDC (5 back, 10 of 25). We did not connect to the live server, so the count is from the package. Transaction history and MPP sessions take a `limit` and a chain or status filter and service discovery takes `limit` and `offset`. No cursor was found (8 of 20). Errors are an HTTP status and `{"error":"message"}`, with seven statuses explained and no list of machine-readable codes (9 of 20). No idempotency key was found for transfers, swaps or bank sends. 409 is described as a duplicate action, creating a virtual account is described as idempotent, and the SDK's tool definitions carry no read-only or destructive annotations (4 of 20). SDKs in TypeScript and Python, a CLI, and wallets created on every supported chain with no parameters. The Python package is at 0.1.5 from May 2026, and spending limits and banking are documented for TypeScript only (12 of 15). - Security & auth 48: Agent keys (`sponge_live_`, `sponge_test_`) cover one agent and can be regenerated. Master keys (`sponge_master_`) create and delete agents and per the docs never touch wallets. The MCP server also takes OAuth, and its resource metadata lists the scopes `mcp:tools`, `wallet:read`, `wallet:transfer` and `sponge:all`. An agent key is described as full access to one agent, and how scopes attach to keys is not documented. No secret travels in a URL (22 of 30). Daily, weekly and monthly spending limits are set per agent and enforced server-side, transfers to an address outside the allowlist return 403, checkouts need the owner's approval, and plans and trade proposals wait for a person. The transfers page describes `evmTransfer` and `solanaTransfer` as the enforced helpers next to a plain `transfer`, which leaves open whether every path applies the limits, and an agent-first key works before any person has claimed the wallet (14 of 20). `paid_fetch` returns third-party content and service discovery returns free-text `instructions` written by sellers. No guidance on treating that content as untrusted was found. The docs do warn against pasting or logging card details (3 of 15). Transaction history, MPP session lists and last-used times on master keys are readable by API. The dashboard's logs were not read (7 of 15). No security.txt (404), disclosure policy, certification or bug bounty was found. The terms name Basis Theory for card tokenisation and the docs name Persona for identity checks (2 of 20). - Payments & pricing 70: Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. The wallet pays x402 and MPP endpoints and creates x402 payment links so that another agent can pay its holder, and Sponge's separate Gateway product puts x402 and MPP in front of a seller's API. The wallet API itself is not paid over either, so the merchant step (25 of 40). No fee schedule for the wallet was found. The home page's structured data lists a price of 0, and the Sponge Card terms for the US give no annual fee and 1 per cent on international transactions. Fees on swaps, bridges, bank transfers and onramps were not found (5 of 20). A wallet costs nothing to create and needs no card, and the SDK defines a `claim_signup_bonus` tool that sends 1 USDC on Base (20). `POST /api/agents/register` needs no authentication and with `agentFirst` returns an API key at once, and `npx spongewallet init` does the same from a terminal. A person claims the agent later (20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 27: `@paysponge/sdk` 0.1.147 and `spongewallet` 0.1.127 were published on 7 July 2026, 94 days before this check. The docs sitemap's newest date is 27 May 2026 and the wallet skill file was last modified on 23 June 2026 (10 of 30). No release or dated changelog entry falls in the last 90 days (0). The service is closed and the repository named in the packages, github.com/paysponge/sponge, is private. Support is a Discord server and a contact address, neither tested, and no changelog was found (4 of 15). Official SDKs exist in TypeScript and Python. The TypeScript SDK had 115 versions between 31 January and 7 July 2026 and the Python package six, all in May 2026 (10 of 15). The SDK has six runtime dependencies. CI is not visible because the repository is private (3 of 10). - Transparency & trust 39: A closed service. The SDK and CLI are MIT on npm, and the repository they name is private. The terms of service, updated 30 June 2026, are eleven short clauses that describe the service as AI-powered functionality and do not mention wallets, funds, custody, fees or API use (10 of 30). The privacy policy of the same date lists prompts, usage data and IP addresses, names no provider, gives no retention period beyond as long as necessary, and does not mention payment, card, bank or identity data. Separate card terms and an account opening privacy notice cover the Sponge Card (8 of 30). The API reports version status and a minimum version in response headers. No deprecation policy or dated notice was found (3 of 20). Basis Theory is named in the terms, Rain as card issuer on the home page, and Persona, Stripe and Coinbase in the docs, with no subprocessor list or data location. The CLI sends usage events to PostHog, which the npm README discloses, and no opt-out setting was found in the package (6 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (28 items): https://www.anchorterminal.com/fixes/sponge-wallet.md (JSON https://www.anchorterminal.com/fixes/sponge-wallet.json) ### What we couldn't check - unchecked: the tools the live MCP server lists and whether they carry annotations. We did not connect with a key. The count of 53 is from `@paysponge/sdk` 0.1.147 - unchecked: the dashboard at wallet.paysponge.com, so per-transaction limits, merchant lists, key scopes and activity logs were not seen - unchecked: the source repository github.com/paysponge/sponge, which asked for credentials, so CI, issues and star counts were not read - unchecked: the account opening privacy notice, the international card terms and the electronic communications notice - unchecked: whether Discord or the contact address answers - Who holds wallet keys was not established. The docs and terms are silent, the skill file says managed wallet, and the card terms say card collateral stays in the holder's custody - The home page FAQ names per-transaction limits and approved merchant lists. The docs show daily, weekly and monthly limits and address allowlists only - The master keys page says the SDK has no admin client, and the platforms page documents `SpongePlatform` for the same job - Chain lists differ. The docs name Ethereum, Base, Tempo and Solana, the skill file adds Polygon and Arbitrum, and the home page FAQ adds Monad and Hyperliquid - The payment links page points to the API reference for `/api/payment-links`, and the OpenAPI file has no such path - No package release, docs change or legal update dated after 7 July 2026 was found. The API and MCP server answered on the day - The MCP resource metadata gives spongewallet.com as its documentation address, a second domain we did not read - The lead said wires are accepted. The docs name virtual USD accounts and ACH withdrawals, and only the skill file names wire payouts - The skill files are instructions addressed to AI agents, including a rule to register and never log in. We recorded them as facts and did not act on them - paysponge.com was registered on 9 January 2026 ### Sources - docs index for agents: (seen 2026-10-09) - OpenAPI file: (seen 2026-10-09) - MCP server guide: (seen 2026-10-09) - agent authentication: (seen 2026-10-09) - platforms, master keys and spending limits: (seen 2026-10-09) - master keys: (seen 2026-10-09) - platform SDK reference: (seen 2026-10-09) - CLI: (seen 2026-10-09) - transfers: (seen 2026-10-09) - supported networks: (seen 2026-10-09) - x402 payments: (seen 2026-10-09) - MPP payments: (seen 2026-10-09) - payment links: (seen 2026-10-09) - browser checkout approvals: (seen 2026-10-09) - Sponge Card: (seen 2026-10-09) - bank withdrawals: (seen 2026-10-09) - docs sitemap dates: (seen 2026-10-09) - wallet skill file 0.2.2: (seen 2026-10-09) - CLI skill file 0.1.3: (seen 2026-10-09) - MCP OAuth resource metadata: (seen 2026-10-09) - home page and FAQ: (seen 2026-10-09) - terms of service: (seen 2026-10-09) - privacy policy: (seen 2026-10-09) - Sponge Card terms (US): (seen 2026-10-09) - prohibitions list: (seen 2026-10-09) - security.txt (404): (seen 2026-10-09) - npm registry, @paysponge/sdk: (seen 2026-10-09) - npm registry, spongewallet: (seen 2026-10-09) - npm downloads for @paysponge/sdk: (seen 2026-10-09) - PyPI, paysponge: (seen 2026-10-09) - RDAP for paysponge.com: (seen 2026-10-09) ## Who's behind it (provenance 51/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Sponge Inc. | 20/20 | | Domain age | paysponge.com, registered 2026-01-09 (under a year) | 0/15 | | Endpoint on the vendor's domain | api.wallet.paysponge.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects | 8.3/10 | | Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 | | Status page | not found | 0/10 | | Changelog | not found | 0/10 | | security.txt | not found | 0/10 | The terms of service (updated 30 June 2026) say they govern the Sponge platform and related services. They are eleven short clauses, name no legal entity or address, and choose the laws of the United States. The site footer names Sponge Inc. No company address or registration was found on the pages read. The privacy policy (updated 30 June 2026) covers the platform and related services. A separate account opening privacy notice and card terms cover the Sponge Card, whose issuer is Rain. The API and MCP server answer at api.wallet.paysponge.com and the dashboard at wallet.paysponge.com. The MCP resource metadata names spongewallet.com for documentation. paysponge.com/.well-known/security.txt returned 404. No status page or changelog was found. RDAP for paysponge.com gives a registration date of 2026-01-09. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://paysponge.com/terms), read 2026-10-08, dated 2026-06-30, states 5 of the 7 things a reader expects. - To know. Says access can be ended without notice or for any reason. "We may suspend or terminate access to the Service at any time, with or without notice, for any reason." - Gives the date it was last updated. Last updated 2026-06-30. - Names the governing law or courts. The law of the United States. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Not found in the text. Says how changes to the terms are announced. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). The service may be in beta and may change or be discontinued at any time. "The Service may be offered in beta and may change or be discontinued at any time." **Privacy policy** (https://paysponge.com/privacy), read 2026-10-08, dated 2026-06-30, states 5 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-06-30. - Says how long data is kept. For as long as needed, with no period named. - Not found in the text. Says whether personal data is sold or shared for advertising. - Not found in the text. Says what rights people have over their data. - Gives a privacy contact. Gives an email address, hidden from our reader by the page. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Third-party providers, including AI model providers, may process data on Sponge's behalf. "Our Service may rely on third-party providers, including AI model providers, hosting services, and analytics tools, to process data on our behalf." ## Live (updated 2026-10-09 10:14 UTC) - Right now: up, HTTP 404, 503 ms, checked 2026-10-09 10:14 UTC (get on `https://api.wallet.paysponge.com`) - Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 233 ms · p95 581 ms - Always current: https://www.anchorterminal.com/api/v1/live/sponge-wallet.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Sponge Card international transaction (US terms) | 1% | percentage fee | no annual fee, 0 per cent APR | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - `POST /api/agents/register` with `agentFirst` returns an agent key at once, and a person claims the wallet later through a claim URL - Daily, weekly and monthly spending limits are set per agent and enforced server-side, with address allowlists that return 403 - One wallet pays x402 and MPP endpoints, opens MPP sessions on Tempo and creates x402 payment links - Agent keys cover one agent and can be regenerated. Master keys create agents and, per the docs, never touch wallets - Public OpenAPI 3.0.3 file with 57 operations, llms.txt, Markdown docs and a 73 KB skill file written for agents ## Weaknesses - No status page, SLA or numeric rate limit was found, and the terms say the service may be offered in beta - Who holds the wallet keys is not stated in the docs or the terms. The skill file calls the wallet managed - The terms of 30 June 2026 are eleven short clauses that do not mention wallets, funds, custody or fees - No security.txt, disclosure policy, certification or bug bounty was found - `@paysponge/sdk` was last published on 7 July 2026 after 115 versions in five months. The source repository is private - The transfers page separates `wallet.transfer()` from enforced helpers that apply allowlists and limits, while another page says limits apply to every transfer ## Before you call it (notes for agents) 1. Send `Sponge-Version` on every REST request. The skill file marks it required and the API answers with version status headers 2. Use `evmTransfer` and `solanaTransfer`, the helpers the docs describe as enforcing allowlists and spending limits, not plain `transfer` 3. Store the `apiKey` from registration at once. It is returned a single time, and losing it means registering again 4. Call `GET /api/discover/{serviceId}` before `POST /api/paid/fetch`. The skill file says direct service URLs fail with auth errors 5. Treat `card details` output as secret. It returns an encrypted card number and CVC with a one-time `secret_key` ## Connect Install: ```bash npm install @paysponge/sdk ``` First request: ```bash curl -sS -X POST https://api.wallet.paysponge.com/api/agents/register -H "Sponge-Version: 0.2.2" -H "Content-Type: application/json" -d '{"name":"YourAgentName","agentFirst":true}' ``` Claude Code: ```bash claude mcp add -s user --transport http sponge https://api.wallet.paysponge.com/mcp --header "Authorization: Bearer " ``` Through letme (picks today, calling later): https://letme.dev/sponge-wallet. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Turnkey Agentic Wallets | BB | 76 | 38 | wallet.onchain, wallet.spend-limits, wallet.custody, payments.x402 | no | https://www.anchorterminal.com/tools/turnkey-agentic-wallets.md | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 73.9 | 79 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/circle-wallets.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.2 | 129 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.md | | Privy Wallets (server wallets, agent wallets, policy engine) | B | 69.9 | 158 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/privy.md | | Stripe API + MCP | A | 82.4 | 5 | payments.card, payments.x402 | no | https://www.anchorterminal.com/tools/stripe-mcp.md | | Nevermined API + MCP | BB | 70.8 | 137 | payments.x402, payments.card | no | https://www.anchorterminal.com/tools/nevermined.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - An agent registers its own wallet with `POST /api/agents/register` and no credential. With `agentFirst` the key is returned at once and a person claims the wallet later (source: ) - Spending limits are daily, weekly and monthly per agent, set with a master key and enforced server-side per the docs (source: ) - The transfers page says to use the enforced helpers `evmTransfer` and `solanaTransfer` for allowlist and limit checks, next to a plain `transfer` (source: ) - The MCP server is at https://api.wallet.paysponge.com/mcp, with a seven-tool trading-only server at `/trade/mcp`. `@paysponge/sdk` 0.1.147 defines 53 tools (source: ) - The terms of service, updated 30 June 2026, are eleven short clauses and say the service may be offered in beta and may be discontinued at any time (source: ) - Sponge Card is a credit card issued by Rain, backed by USDC collateral, and labelled a beta preview in the skill file (source: , ) - `@paysponge/sdk` and `spongewallet` were last published on 7 July 2026, after 115 SDK versions since 31 January 2026 (source: ) - The CLI sends usage events to PostHog, disclosed in the npm README. No opt-out setting was found in the package (source: ) - The skill files at wallet.paysponge.com are instructions addressed to AI agents, among them a rule to register and never log in (source: ) - paysponge.com was registered on 9 January 2026 (source: ) ## Compare - [Circle Wallets (Agent Wallets, Programmable Wallets) vs Sponge Wallet](https://www.anchorterminal.com/compare/circle-wallets-vs-sponge-wallet.md): BB 73.9 vs E 43.2 - [Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Sponge Wallet](https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-sponge-wallet.md): BB 71.2 vs E 43.2 - [Privy Wallets (server wallets, agent wallets, policy engine) vs Sponge Wallet](https://www.anchorterminal.com/compare/privy-vs-sponge-wallet.md): B 69.9 vs E 43.2 - [Sponge Wallet vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/sponge-wallet-vs-turnkey-agentic-wallets.md): E 43.2 vs BB 76 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on paysponge.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "sponge-wallet", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Sponge Wallet on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Sponge Wallet on Anchor Terminal](https://www.anchorterminal.com/badges/sponge-wallet.svg)](https://www.anchorterminal.com/tools/sponge-wallet) ``` Plain link: ```html Sponge Wallet on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Sponge Wallet is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/sponge-wallet-dark.png - Light: https://www.anchorterminal.com/assets/share/sponge-wallet-light.png