# Sponge Wallet (slim) > Sponge Wallet is a hosted wallet for AI agents. It holds stablecoins on Ethereum, Base, Tempo and Solana, pays x402 and MPP endpoints, issues virtual cards, and is reached by a REST API, an MCP server, SDKs and a CLI. - Full: https://www.anchorterminal.com/tools/sponge-wallet.md (~8,250 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/sponge-wallet.json · canonical https://www.anchorterminal.com/tools/sponge-wallet - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **E · 43.2/100 · rank #785 of 842 · #5 in Agent wallets & spending controls · not agent-ready · confidence medium** Assessment: An agent can register a wallet with one unauthenticated call and pay x402 or MPP endpoints under daily, weekly and monthly limits enforced on Sponge's servers. No status page, rate limits, fee schedule, custody statement or security contact was found, the terms run to eleven short clauses, and the SDK was last published on 7 July 2026. ## Facts - Kind: HTTP API · vendor: Sponge Inc. · category: Agent wallets & spending controls · legal entity: Sponge Inc. · provenance 51/100 - Endpoint: `https://api.wallet.paysponge.com` (HTTP) - Auth: OAuth or key · pricing: Free · x402: payer tooling only · licence: Proprietary service under Sponge's terms of service. The SDK and CLI packages on npm are MIT, and the repository they name is private - Probe metrics: not measured yet (probes haven't run) - Custody: Not stated in the docs or the terms. The skill file describes a managed wallet tied to a human owner. The card terms say card collateral stays in the holder's custody - Spending limits: Daily, weekly and monthly limits per agent, set with a master key and enforced server-side. Address allowlists return 403. A per-transaction limit is named on the home page and was not found in the docs - Approvals: The owner approves each browser checkout in the dashboard. Plans (`submit_plan`, `approve_plan`) and trade proposals wait for a person. Link card credentials can return `approval_required` - Revocation: Regenerate an agent's key or delete the agent with a master key. Master keys are created and revoked in the dashboard - Chains: Ethereum, Base, Tempo and Solana per the docs. The skill file adds Polygon and Arbitrum. One address across EVM chains and a separate Solana keypair - Assets: ETH, USDC and pathUSD on EVM chains, SOL and USDC on Solana per the transfers page. Swaps on Solana, Base and Tempo, and bridging between chains - Machine payments: Pays x402 (`exact` and `upto` schemes) and MPP, with MPP sessions on Tempo. Creates x402 payment links. A catalogue of paid services is reached through `/api/discover` and `/api/paid/fetch` - Cards: Sponge Card, a credit card issued by Rain against USDC collateral, after an identity check. Per-checkout virtual cards, stored cards tokenised by Basis Theory, and Link payment methods - Banking: Virtual USD accounts whose deposits settle as USDC, and withdrawals to a linked US bank account by ACH in 1 to 3 business days, both after an identity check - Trading: Hyperliquid perpetuals and Polymarket orders through one tool each - API: REST at https://api.wallet.paysponge.com, OpenAPI 3.0.3 with 51 paths and 57 operations. A `Sponge-Version` header is required on each request - MCP: Streamable HTTP at `/mcp` with a bearer key or OAuth, and a trading-only server at `/trade/mcp` with seven tools. 53 tool definitions in the SDK - Credentials: Agent keys `sponge_live_` and `sponge_test_` for one agent, master keys `sponge_master_` for agent management. OAuth scopes `mcp:tools`, `wallet:read`, `wallet:transfer` and `sponge:all` - Errors: HTTP status with `{"error":"message"}`. 403 for an address outside the allowlist, 409 for a duplicate action, 429 with advice to back off - SDKs: `@paysponge/sdk` 0.1.147 and the `spongewallet` CLI 0.1.127 on npm (7 July 2026), `paysponge` 0.1.5 on PyPI (17 May 2026) - Status: No status page, SLA or published rate limit found - Prices: Sponge Card international transaction (US terms) 1% percentage fee - Scores: Reliability 13, Performance pending, Schema & documentation 66, Agent ergonomics 43, Security & auth 48, Payments & pricing 70, Task success pending, Maintenance & community 27, Transparency & trust 39 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service on the REST API and the MCP server at api.wallet.paysponge.com. · Schema & documentation, A public OpenAPI 3.0.3 file at docs.paysponge.com/api-reference/public-openapi.json with 51 paths and 57 operations. · Agent ergonomics, `@paysponge/sdk` 0.1.147 defines 53 tools for the MCP server, from `get_balance` to `polymarket`, which is the more-than-30 band (5). · Security & auth, Agent keys (`sponge_live_`, `sponge_test_`) cover one agent and can be regenerated. · Payments & pricing, Payment platforms and wallets take the highest step that applies on the 40-point protocol line. · Maintenance & community, `@paysponge/sdk` 0.1.147 and `spongewallet` 0.1.127 were published on 7 July 2026, 94 days before this check. · Transparency & trust, A closed service. - Sources: 31, open questions: 15, both in the full twin - Capabilities: wallet.onchain, wallet.spend-limits, payments.x402, payments.card, wallet.custody - JSON: https://www.anchorterminal.com/api/v1/tools/sponge-wallet.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/sponge-wallet.svg` or a link to https://www.anchorterminal.com/tools/sponge-wallet from a page on paysponge.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Sponge-Version` on every REST request. The skill file marks it required and the API answers with version status headers 2. Use `evmTransfer` and `solanaTransfer`, the helpers the docs describe as enforcing allowlists and spending limits, not plain `transfer` 3. Store the `apiKey` from registration at once. It is returned a single time, and losing it means registering again 4. Call `GET /api/discover/{serviceId}` before `POST /api/paid/fetch`. The skill file says direct service URLs fail with auth errors 5. Treat `card details` output as secret. It returns an encrypted card number and CVC with a one-time `secret_key` ## Connect ```bash npm install @paysponge/sdk ``` ```bash curl -sS -X POST https://api.wallet.paysponge.com/api/agents/register -H "Sponge-Version: 0.2.2" -H "Content-Type: application/json" -d '{"name":"YourAgentName","agentFirst":true}' ``` ```bash claude mcp add -s user --transport http sponge https://api.wallet.paysponge.com/mcp --header "Authorization: Bearer " ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/sponge-wallet ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Turnkey Agentic Wallets | BB | 76 | wallet.onchain, wallet.spend-limits, wallet.custody, payments.x402 | https://www.anchorterminal.com/tools/turnkey-agentic-wallets.min.md | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 73.9 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/circle-wallets.min.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.2 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.min.md | | Privy Wallets (server wallets, agent wallets, policy engine) | B | 69.9 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/privy.min.md | | Stripe API + MCP | A | 82.4 | payments.card, payments.x402 | https://www.anchorterminal.com/tools/stripe-mcp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)