# Turnkey Agentic Wallets > Turnkey's signing API gives an AI agent its own non-root user and P-256 key over a company wallet. Policies evaluated in secure enclaves set what the agent may sign, and can require a person's approval. - Canonical: https://www.anchorterminal.com/tools/turnkey-agentic-wallets - Markdown: https://www.anchorterminal.com/tools/turnkey-agentic-wallets.md (~8,350 tokens) - Slim: https://www.anchorterminal.com/tools/turnkey-agentic-wallets.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/turnkey-agentic-wallets.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade BB · 76/100 · rank #38 of 842 · #1 in Agent wallets & spending controls · agent-ready · confidence medium** ## Assessment An agent gets a non-root user that can sign nothing until a policy allows it, with DENY rules taking precedence and human co-approval available. Policies cap value per transaction only, with no daily or rolling limit found, and each organisation gets five policies below Enterprise. Signing endpoints returned elevated errors for five hours on 27 August 2026. ## Facts | Field | Value | | --- | --- | | Vendor | Turnkey Global, Inc. (https://www.turnkey.com) | | Kind | HTTP API | | Category | Agent wallets & spending controls (https://www.anchorterminal.com/categories/agent-wallets) | | Transport | HTTP | | Endpoint | `https://api.turnkey.com` | | Auth | API key · Self-serve. A person creates an organisation at app.turnkey.com with an email address and a passkey, then registers a P-256 public key. Every request is a JSON POST signed with that key in an `X-Stamp` header. There are no bearer tokens. An agent gets its own non-root user and key, created through the API by a root user, and can do only what policies allow. | | Pricing | Freemium ($0.10 / call) · 25 free signatures a month on Pay as You Go, then $0.10 a signature. Pro is $99 a month and $0.05 a signature. Enterprise is custom, from $0.0015 a signature, and adds gas sponsorship, SLAs and up to 250 policies. The free allowance needs no card, so an agent can start without a contract. Transaction management and swaps are priced per transaction on request (https://www.turnkey.com/pricing, checked 2026-10-08). | | x402 | Payer tooling only · Turnkey documents paying over x402 and MPP as a buyer. A viem account from `@turnkey/viem` signs in the enclave and is passed to the `@x402/fetch` or `mppx` client. Turnkey's own API is not paid over either protocol (https://docs.turnkey.com/solutions/company-wallets/agentic-payments, checked 2026-10-08). | | Licence | Proprietary service under Turnkey's terms of service. The SDKs, the CLI and the agent skills on GitHub are Apache-2.0 | | Packages | npm: `@turnkey/sdk-server`; npm: `@turnkey/viem`; pypi: `turnkey-http` | | Source | https://github.com/tkhq/turnkey-agent-skills | | Docs | https://docs.turnkey.com/solutions/company-wallets/agentic-wallets | | llms.txt | https://docs.turnkey.com/llms.txt | | Last release | 2026-10-08 | | npm downloads / week | 304,389 | | PyPI downloads / week | 11,903 | | Custody | Non-custodial per the terms. Keys are generated and used inside secure enclaves (AWS Nitro Enclaves per the docs), and the agent receives signatures only | | Spending limits | Policy conditions on value per transaction, destination address, chain, contract function and arguments (with an uploaded ABI or IDL), and time windows by cron. No daily or rolling cap found | | Approvals | Consensus expressions can require the agent plus a named person or second agent. Approvals lapse 24 hours after submission and must be sent again | | Revocation | Delete the agent user, delete its API key, or let an expiring key lapse. Up to ten long-lived and ten expiring keys a user | | Chains | Curve-level signing (secp256k1, ed25519). Policies and transaction parsing for Ethereum and EVM chains, Solana, Bitcoin, Tron and Tempo | | API | JSON POST only at https://api.turnkey.com, 71 queries under `/public/v1/query` and 114 submissions under `/public/v1/submit`, Swagger 2.0 | | Credentials | P-256 API key pair per user, private key held by the customer, each request signed in an `X-Stamp` header. Requests are valid from one hour old to five minutes ahead | | Rate limits | 1 request a second on Free and Pay as You Go, 3 on Pro, 60 on Enterprise, shared across an organisation and its sub-organisations. 10 a second for each sub-organisation and for broadcast and balance calls | | Errors | 32 `turnkeyErrorCode` categories with messages and fixes. 429 has no `Retry-After` header. Submissions are idempotent by body fingerprint | | Agent tooling | Nine skills in tkhq/turnkey-agent-skills 1.0.0, among them `provisioning-agent`, `managing-agent`, `managing-policies` and `signing-transactions`. A CLI (`brew install tkhq/tap/turnkey`). A docs-search MCP server. No MCP server for wallet actions | | SDKs | Server SDKs for TypeScript (`@turnkey/sdk-server` 8.6.0), Go, Ruby, Rust and Python, and signers for viem, ethers, Solana and CosmJS. Apache-2.0 | | Audit | Every request is an activity recording its approvers and result, listable with status and type filters, and sent by Ed25519-signed webhooks | | Free tier | 25 signatures a month and up to 1,000 wallets, no card until the allowance is used | | Certifications | SOC 2 Type II and GDPR compliance per docs.turnkey.com/security/trust-centre page. Bug bounty up to $50,000 | | Status | turnkey-status.com on Atlassian Statuspage, 23 components among them APIs, Webhooks, Transaction Broadcasting and Gas Sponsorship | | Capabilities | wallet.onchain, wallet.spend-limits, wallet.custody, payments.x402 | | Tags | hosted, freemium, free-tier, openapi, llms-txt, typescript, go, python, rust, ruby, wallet, policy-engine, x402, status-page, bug-bounty, soc2, closed-source, webhooks, skills | | JSON | https://www.anchorterminal.com/api/v1/tools/turnkey-agentic-wallets.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 75 | 15.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 79 | 12.8 | | Agent ergonomics | 13% | 16.2 | 77 | 12.5 | | Security & auth | 14% | 17.5 | 85 | 14.9 | | Payments & pricing | 10% | 12.5 | 58 | 7.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 83 | 7.3 | | Transparency & trust (editorial 50, provenance 94) | 7% | 8.8 | 72 | 6.3 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **76 → BB** | ### Why each score - Reliability 75: Status page at turnkey-status.com on Atlassian Statuspage with 23 components and 90-day uptime bars (20). Between 10 July and 8 October 2026 it lists seven incidents. Signing endpoints, `sign_raw_payload` and `sign_transaction` among them, returned elevated errors for 5 hours 9 minutes on 27 August, marked minor. SMS authentication was down for about 12 hours on 6 and 7 August, marked critical and outside the path an agent's API key uses. The rest were webhook delays and broadcast failures traced to upstream RPC providers (12 of 30). Rate limits are published as 1 request a second on Free and Pay as You Go, 3 on Pro and 60 on Enterprise, with 10 a second for each sub-organisation and for broadcast and balance calls (15). The docs describe 429 handling with exponential backoff and jitter and say submissions are idempotent by body fingerprint, but the API returns no `Retry-After` header (13 of 15). SLAs are listed on the Enterprise plan with no published terms (5 of 10). The API is generally available and the agent skills are at 1.0.0 (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 79: A public Swagger 2.0 document at docs.turnkey.com/public_api.swagger.json with 186 paths, 71 queries and 114 submissions (25). llms.txt, llms-full.txt and a Markdown twin of every docs page (10). Operation descriptions in the spec are one line each, such as "Sign a transaction.", while the guides and the nine agent skills say when to use each call and when not to (13 of 20). The spec has 175 enums and required fields on every request, but 64-bit numbers travel as strings and policy `condition` and `consensus` are free-form strings in Turnkey's own expression language (11 of 15). The errors page lists 32 `turnkeyErrorCode` values and a table of messages with HTTP codes and fixes, though the spec documents only the 200 response for each path (12 of 15). Paths sit under `/public/v1` and activity types carry version suffixes, but no changelog for the API was found in the docs. Changes appear only in the SDK changelogs on GitHub (8 of 15). - Agent ergonomics 77: There is no MCP server for wallet actions; the MCP server at docs.turnkey.com/mcp searches the docs only. An agent calls the API through an SDK, the CLI or the skills, and responses can't be trimmed by field (15 of 25). List queries take cursor pagination with a limit of 1 to 100 and filters by activity status and type (17 of 20). Errors carry a category code and a readable message with documented fixes, wrapped in a gRPC status the docs say not to rely on (16 of 20). Submissions are idempotent by a hash of the POST body, and the docs explain that changing `timestampMs` creates a new activity. No MCP annotations apply (18 of 20). Server SDKs exist for TypeScript, Go, Ruby, Rust and Python, with wallet and policy helpers in the first three, but every request needs a P-256 signature in an `X-Stamp` header and submissions need an activity envelope (11 of 15). - Security & auth 85: Each user holds P-256 API key pairs whose private half is generated by the customer and never sent to Turnkey. Keys can be created with an expiry, a user has up to ten of each kind, deleting the user revokes access at once, and no secret travels in a URL. Scope comes from policies, not from the key itself (28 of 30). Policies deny by default, DENY beats ALLOW, a non-root user starts with no permissions, read access needs no policy, and consensus expressions can require a named person to approve. Root users bypass the policy engine, and no daily or rolling spending limit was found in the policy language, only conditions on a single transaction (17 of 20). The skills page warns that models can misread instructions and that policies are the technical control, and the terms say the same. No guidance on untrusted content in balances or token data was found (9 of 15). Every action is an activity recording who approved it, readable by query and delivered by signed webhooks (13 of 15). SOC 2 Type II per the docs, a bug bounty of up to $50,000 with safe harbour, a security.txt with a PGP key and no Expires field, a published whitepaper and the enclave operating system QuorumOS open source (18 of 20). - Payments & pricing 58: Payment platforms and wallets take the highest step that applies on the 40-point protocol line. 40 for x402, MPP or L402 on all their own endpoints, 30 on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, 0 for only a protocol of their own. Turnkey documents x402 and MPP clients signing through `@turnkey/viem`, and its own API is not paid over either, so the buyer step (15 of 40). Prices are public per signature, $0.10 on Pay as You Go and $0.05 on Pro with a $99 monthly minimum, while transaction management and swap fees need a sales contact (18 of 20). 25 free signatures a month, with a card needed only beyond that (20). A person creates the organisation in the dashboard with an email address and a passkey. After that, users, keys, wallets and policies are created through the API (5 of 20). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 83: The SDK repository tagged v2026.10.0 on 8 October 2026 and `@turnkey/sdk-server` 8.6.0 on 22 September (30). Twelve dated release tags between 6 August and 8 October (20). The service is closed, with dashboard chat, email and a community Slack for support and pull requests merged on the day of the last tag. We didn't test a support channel and no API changelog was found (10 of 15). Current official SDKs in TypeScript, Go, Ruby, Rust and Python (15). Public CI workflows, a dependency patch merged on 8 October and Renovate on the skills repository. The CLI's last tag is May 2025 (8 of 10). - Transparency & trust 72: A closed service under published terms of service, updated 6 August 2026, with the SDKs, CLI and agent skills under Apache-2.0 and QuorumOS open source (18 of 30). The privacy policy, updated 29 June 2026, names Turnkey Global, Inc., says Turnkey is a processor for its business customers' users and lists categories of service providers. It gives no retention periods, and the data processing terms were not read because the trust centre is drawn by script (17 of 30). Deprecated activity types are marked in the docs with migration guides, with no dates or notice period found (7 of 20). The docs say subprocessors and their locations are in the trust centre, which we couldn't read. The status page names AWS SES and SNS in us-east-1, Cloudflare and Alchemy as dependencies (8 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/turnkey-agentic-wallets.md (JSON https://www.anchorterminal.com/fixes/turnkey-agentic-wallets.json) ### What we couldn't check - unchecked: the trust centre at trust.turnkey.com is drawn by script, so the subprocessor list, data locations, the SOC 2 report details and any data processing addendum were not read - unchecked: GitHub star counts, because the GitHub API refused our requests for the rate limit - unchecked: open issues and reply times on tkhq/sdk, and whether a support channel answers - unchecked: whether signing up needs a card. The pricing FAQ says a card is needed only past 25 signatures - unchecked: the tools the docs MCP server lists. We did not connect to it - No daily, rolling or cumulative spending limit was found in the policy language. Turnkey's marketing for a customer mentions tamper-proof spend limits, and how those are built was not established - The rate limits page names a Free plan that the pricing page does not list, and the pricing FAQ says Pro can come down to $0.01 a signature where the table says $0.05 - The terms forbid using the services for availability or performance monitoring and for benchmarking, which matters before our probes run - The status page's robots.txt disallows `/api/`. One request reached `/api/v2/incidents.json` before we read robots.txt. The file was deleted unread and the incident record here comes from the `/history` pages - llms.txt and every Markdown docs page open with a block headed Agent Instructions addressed to AI models. We recorded it as a fact and did not act on it - Agentic Wallets is a documented use of Turnkey's general wallet API and not a separate endpoint, plan or price ### Sources - agentic wallets guide: (seen 2026-10-08) - agentic payments guide (x402 and MPP): (seen 2026-10-08) - agent skills: (seen 2026-10-08) - agent skills repository: (seen 2026-10-08) - Swagger spec: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - rate limits: (seen 2026-10-08) - resource limits: (seen 2026-10-08) - errors: (seen 2026-10-08) - activities, idempotency and request validity: (seen 2026-10-08) - policy overview: (seen 2026-10-08) - policy language: (seen 2026-10-08) - MCP server and AI resources: (seen 2026-10-08) - pricing: (seen 2026-10-08) - terms of service: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - status history: (seen 2026-10-08) - 27 August signing incident: (seen 2026-10-08) - support channels: (seen 2026-10-08) - trust centre pointer: (seen 2026-10-08) - vulnerability reporting and bounty: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - SDK repository and tags: (seen 2026-10-08) - SDK reference: (seen 2026-10-08) - npm downloads for @turnkey/sdk-server: (seen 2026-10-08) - RDAP for turnkey.com: (seen 2026-10-08) ## Who's behind it (provenance 94/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Turnkey Global, Inc. | 20/20 | | Domain age | turnkey.com, registered 1994-12-20 (31 years) | 15/15 | | Endpoint on the vendor's domain | api.turnkey.com | 15/15 | | Terms of service | read, states 7 of the 7 things a reader expects, and has 3 clauses that cost points | 4/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | www.turnkey-status.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The terms of service (updated 6 August 2026) are the agreement for the services and the API. They name Turnkey Global, Inc., give 15 W. 18th Street, New York as the notice address and choose New York law. The terms have a section on automated and AI-mediated access. It treats agents using a customer's credentials as authorised users and makes the customer responsible for their actions. The privacy policy (updated 29 June 2026) covers the services and says Turnkey is a processor where it serves a business customer's users. The API answers at api.turnkey.com. The status page is on a second domain, turnkey-status.com, hosted by Atlassian Statuspage. www.turnkey.com/.well-known/security.txt gives a policy URL, a contact form, security@turnkey.com and a PGP key. It has no Expires field. No changelog for the API was found in the docs. The link is the server SDK's changelog on GitHub. RDAP for turnkey.com gives a registration date of 1994-12-20. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.turnkey.com/legal/terms), read 2026-10-08, dated 2026-08-06, states 7 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "…content from the Services using any engine, software, tool, agent, device or mechanism (including spiders, robots, crawlers, data mining tools or the like) other than the software or search agents provided by Turnkey or other generally available third-party web browsers;" - To know. Restricts benchmarking or competitive use (costs points). "● Use or access the Services for purposes of monitoring the availability, performance, or functionality of any of Turnkey’s products and service or for any other benchmarking purposes;" - To know. Says the terms or the service can change without notice (costs points). "Because our Services are evolving over time we may change, suspend or discontinue all or any part of the Services, at any time and without notice, at our sole discretion." - To know. Says access can be ended without notice or for any reason. "Because our Services are evolving over time we may change, suspend or discontinue all or any part of the Services, at any time and without notice, at our sole discretion." - To know. Requires arbitration or waives class actions. "These Terms include information about future changes to these Terms, automatic renewals, limitations of liability, class action waiver, confidentiality and resolution of disputes by arbitration instead of in court." - Gives the date it was last updated. Last updated 2026-08-06. - Names the governing law or courts. The law of the State of New York. - States a limit on its liability. Capped at the greater of $1,000 and the fees paid in the 6 months before the claim. - Says how changes to the terms are announced. Says it gives notice of a change. - Also in the text (2026-10-08). AI agents using the customer's credentials are treated as authorised users, and the customer is solely responsible for everything they do. "AI Agents operating under User's Authentication Credentials are deemed Authorized Users for purposes of these Terms, and all actions taken by such AI Agents are attributed to and are the sole responsibility of User." - Also in the text (2026-10-08). The customer bears all risk of giving root-level credentials to an AI agent. "User assumes all risk associated with providing root-level credentials to any AI Agent in any environment." - Also in the text (2026-10-08). After an account is cancelled, Turnkey has no duty to keep or hand over the customer's data. "Following cancellation of your Account, Turnkey has no responsibility to maintain, retain, or provide any of your data on your behalf." **Privacy policy** (https://www.turnkey.com/legal/privacy), read 2026-10-08, dated 2026-06-29, states 8 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "However, we may share personal information with advertising measurement partners for cross-context behavioral advertising purposes, as described in Section 3 of this Privacy Policy." - Gives the date it was last updated. Last updated 2026-06-29. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Where Turnkey serves end users on behalf of a business customer, that customer is the controller and its privacy notice governs the data. "In those cases, the business customer is the controller of your personal information, and their privacy notice governs how your personal information is used." - Also in the text (2026-10-08). Turnkey says it cannot edit or delete information stored on a blockchain. "Notwithstanding the above, we cannot edit or delete any information that is stored on a blockchain or other technologies involving immutable records." ## Live (updated 2026-10-09 10:14 UTC) - Right now: up, HTTP 404, 82 ms, checked 2026-10-09 10:14 UTC (get on `https://api.turnkey.com`) - Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 91 ms · p95 148 ms - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/turnkey-agentic-wallets.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Signature, Pay as You Go | $0.10 | per call | after 25 free signatures a month | | Pro plan | $99 | per month (plan) | monthly minimum, up to 2,000 wallets | | Signature, Pro | $0.05 | per call | per signature on the Pro plan | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Non-root users have no permissions until an ALLOW policy exists, and any matching DENY policy wins - Consensus expressions can require the agent and a named person to approve before the enclave signs - API private keys are generated by the customer and never sent to Turnkey. Keys can carry an expiry - Submissions are idempotent by request body, so a retry with the same body returns the same activity - Public Swagger 2.0 spec with 186 paths, llms.txt, a full-text docs feed and nine Apache-2.0 agent skills ## Weaknesses - Policy conditions cap value per transaction. No daily, rolling or cumulative spending limit was found in the policy language - Free, Pay as You Go and Pro organisations are limited to five policies and a default of 1 to 3 requests a second - Root users bypass the policy engine entirely, and the first user of a new organisation is root - Signing endpoints returned elevated errors from 00:44 to 05:53 EDT on 27 August 2026 - 429 responses carry no `Retry-After` header, and the terms forbid benchmarking and availability monitoring ## Before you call it (notes for agents) 1. Use a non-root user's key. Refuse root credentials for unattended work, because root bypasses every policy 2. Scope every signing ALLOW policy by `wallet.id` or `wallet_account.address`, or it covers every key the user can reach 3. Check the activity status on each response. `ACTIVITY_STATUS_CONSENSUS_NEEDED` means a person must approve within 24 hours 4. Retry with the identical body to stay idempotent. Changing `timestampMs` creates a new activity 5. Back off with jitter on 429 and poll `get_activity` sparingly, since polling counts against the same 1 to 3 requests a second ## Connect Install: ```bash npm install @turnkey/sdk-server ``` Claude Code: ```bash claude mcp add --transport http turnkey https://docs.turnkey.com/mcp ``` Through letme (picks today, calling later): https://letme.dev/turnkey-agentic-wallets (letme picks it for wallet.custody, the top-graded tool for the job, letme picks it for wallet.onchain, the top-graded tool for the job, letme picks it for wallet.spend-limits, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 73.9 | 79 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/circle-wallets.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.2 | 129 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.md | | Privy Wallets (server wallets, agent wallets, policy engine) | B | 69.9 | 158 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | no | https://www.anchorterminal.com/tools/privy.md | | Sponge Wallet | E | 43.2 | 785 | wallet.onchain, wallet.spend-limits, payments.x402, wallet.custody | no | https://www.anchorterminal.com/tools/sponge-wallet.md | | Stripe API + MCP | A | 82.4 | 5 | payments.x402 | no | https://www.anchorterminal.com/tools/stripe-mcp.md | | x402 | A | 79.7 | not ranked, protocol | payments.x402 | no | https://www.anchorterminal.com/tools/x402.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The guide names three agent roles built from policies, a worker that signs on one wallet, an observer with read access only and an approver limited to `APPROVE_ACTIVITY` and `REJECT_ACTIVITY` (source: ) - Policy evaluation is default-deny. A root quorum bypasses all policies, any matching `EFFECT_DENY` wins, and otherwise one matching `EFFECT_ALLOW` is needed (source: ) - Free, Pay as You Go and Pro organisations are limited to five policies each, 100 users and 100 wallets, with up to 250 policies on Enterprise (source: , ) - The terms of 6 August 2026 say skills and prompts supplied by Turnkey are advisory only and that policy rules are the technical control for agents (source: ) - The terms forbid using the services to monitor availability or performance and for benchmarking (source: ) - The MCP server at https://docs.turnkey.com/mcp searches the documentation. It does not create wallets or sign (source: ) - llms.txt and each Markdown docs page begin with a block headed Agent Instructions that describes Turnkey to AI models and lists its developer resources (source: ) - Signing endpoints returned elevated errors from 00:44 to 05:53 EDT on 27 August 2026 (source: ) ## Compare - [Circle Wallets (Agent Wallets, Programmable Wallets) vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/circle-wallets-vs-turnkey-agentic-wallets.md): BB 73.9 vs BB 76 - [Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/coinbase-cdp-agentkit-vs-turnkey-agentic-wallets.md): BB 71.2 vs BB 76 - [Privy Wallets (server wallets, agent wallets, policy engine) vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/privy-vs-turnkey-agentic-wallets.md): B 69.9 vs BB 76 - [Sponge Wallet vs Turnkey Agentic Wallets](https://www.anchorterminal.com/compare/sponge-wallet-vs-turnkey-agentic-wallets.md): E 43.2 vs BB 76 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on turnkey.com or one of its subdomains, or the README of github.com/tkhq/turnkey-agent-skills. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "turnkey-agentic-wallets", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Turnkey Agentic Wallets on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Turnkey Agentic Wallets on Anchor Terminal](https://www.anchorterminal.com/badges/turnkey-agentic-wallets.svg)](https://www.anchorterminal.com/tools/turnkey-agentic-wallets) ``` Plain link: ```html Turnkey Agentic Wallets on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Turnkey Agentic Wallets is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/turnkey-agentic-wallets-dark.png - Light: https://www.anchorterminal.com/assets/share/turnkey-agentic-wallets-light.png