# Turnkey Agentic Wallets (slim) > Turnkey's signing API gives an AI agent its own non-root user and P-256 key over a company wallet. Policies evaluated in secure enclaves set what the agent may sign, and can require a person's approval. - Full: https://www.anchorterminal.com/tools/turnkey-agentic-wallets.md (~8,350 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/turnkey-agentic-wallets.json · canonical https://www.anchorterminal.com/tools/turnkey-agentic-wallets - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **BB · 76/100 · rank #38 of 842 · #1 in Agent wallets & spending controls · agent-ready · confidence medium** Assessment: An agent gets a non-root user that can sign nothing until a policy allows it, with DENY rules taking precedence and human co-approval available. Policies cap value per transaction only, with no daily or rolling limit found, and each organisation gets five policies below Enterprise. Signing endpoints returned elevated errors for five hours on 27 August 2026. ## Facts - Kind: HTTP API · vendor: Turnkey Global, Inc. · category: Agent wallets & spending controls · legal entity: Turnkey Global, Inc. · provenance 94/100 - Endpoint: `https://api.turnkey.com` (HTTP) - Auth: API key · pricing: Freemium · x402: payer tooling only · licence: Proprietary service under Turnkey's terms of service. The SDKs, the CLI and the agent skills on GitHub are Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Custody: Non-custodial per the terms. Keys are generated and used inside secure enclaves (AWS Nitro Enclaves per the docs), and the agent receives signatures only - Spending limits: Policy conditions on value per transaction, destination address, chain, contract function and arguments (with an uploaded ABI or IDL), and time windows by cron. No daily or rolling cap found - Approvals: Consensus expressions can require the agent plus a named person or second agent. Approvals lapse 24 hours after submission and must be sent again - Revocation: Delete the agent user, delete its API key, or let an expiring key lapse. Up to ten long-lived and ten expiring keys a user - Chains: Curve-level signing (secp256k1, ed25519). Policies and transaction parsing for Ethereum and EVM chains, Solana, Bitcoin, Tron and Tempo - API: JSON POST only at https://api.turnkey.com, 71 queries under `/public/v1/query` and 114 submissions under `/public/v1/submit`, Swagger 2.0 - Credentials: P-256 API key pair per user, private key held by the customer, each request signed in an `X-Stamp` header. Requests are valid from one hour old to five minutes ahead - Rate limits: 1 request a second on Free and Pay as You Go, 3 on Pro, 60 on Enterprise, shared across an organisation and its sub-organisations. 10 a second for each sub-organisation and for broadcast and balance calls - Errors: 32 `turnkeyErrorCode` categories with messages and fixes. 429 has no `Retry-After` header. Submissions are idempotent by body fingerprint - Agent tooling: Nine skills in tkhq/turnkey-agent-skills 1.0.0, among them `provisioning-agent`, `managing-agent`, `managing-policies` and `signing-transactions`. A CLI (`brew install tkhq/tap/turnkey`). A docs-search MCP server. No MCP server for wallet actions - SDKs: Server SDKs for TypeScript (`@turnkey/sdk-server` 8.6.0), Go, Ruby, Rust and Python, and signers for viem, ethers, Solana and CosmJS. Apache-2.0 - Audit: Every request is an activity recording its approvers and result, listable with status and type filters, and sent by Ed25519-signed webhooks - Free tier: 25 signatures a month and up to 1,000 wallets, no card until the allowance is used - Certifications: SOC 2 Type II and GDPR compliance per docs.turnkey.com/security/trust-centre page. Bug bounty up to $50,000 - Status: turnkey-status.com on Atlassian Statuspage, 23 components among them APIs, Webhooks, Transaction Broadcasting and Gas Sponsorship - Prices: Signature, Pay as You Go $0.10 per call; Pro plan $99 per month (plan); Signature, Pro $0.05 per call - Scores: Reliability 75, Performance pending, Schema & documentation 79, Agent ergonomics 77, Security & auth 85, Payments & pricing 58, Task success pending, Maintenance & community 83, Transparency & trust 72 · total over the 7 assessed categories - Why: Reliability, Status page at turnkey-status.com on Atlassian Statuspage with 23 components and 90-day uptime bars (20). · Schema & documentation, A public Swagger 2.0 document at docs.turnkey.com/public_api.swagger.json with 186 paths, 71 queries and 114 submissions (25). · Agent ergonomics, There is no MCP server for wallet actions; the MCP server at docs.turnkey.com/mcp searches the docs only. · Security & auth, Each user holds P-256 API key pairs whose private half is generated by the customer and never sent to Turnkey. · Payments & pricing, Payment platforms and wallets take the highest step that applies on the 40-point protocol line. · Maintenance & community, The SDK repository tagged v2026.10.0 on 8 October 2026 and `@turnkey/sdk-server` 8.6.0 on 22 September (30). · Transparency & trust, A closed service under published terms of service, updated 6 August 2026, with the SDKs, CLI and agent skills under Apache-2.0 and QuorumOS… - Sources: 26, open questions: 11, both in the full twin - Capabilities: wallet.onchain, wallet.spend-limits, wallet.custody, payments.x402 - JSON: https://www.anchorterminal.com/api/v1/tools/turnkey-agentic-wallets.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/turnkey-agentic-wallets.svg` or a link to https://www.anchorterminal.com/tools/turnkey-agentic-wallets from a page on turnkey.com or one of its subdomains, or the README of github.com/tkhq/turnkey-agent-skills, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use a non-root user's key. Refuse root credentials for unattended work, because root bypasses every policy 2. Scope every signing ALLOW policy by `wallet.id` or `wallet_account.address`, or it covers every key the user can reach 3. Check the activity status on each response. `ACTIVITY_STATUS_CONSENSUS_NEEDED` means a person must approve within 24 hours 4. Retry with the identical body to stay idempotent. Changing `timestampMs` creates a new activity 5. Back off with jitter on 429 and poll `get_activity` sparingly, since polling counts against the same 1 to 3 requests a second ## Connect ```bash npm install @turnkey/sdk-server ``` ```bash claude mcp add --transport http turnkey https://docs.turnkey.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/turnkey-agentic-wallets ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Circle Wallets (Agent Wallets, Programmable Wallets) | BB | 73.9 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/circle-wallets.min.md | | Coinbase Developer Platform (Agentic Wallet, AgentKit, CDP MCP) | BB | 71.2 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/coinbase-cdp-agentkit.min.md | | Privy Wallets (server wallets, agent wallets, policy engine) | B | 69.9 | wallet.onchain, wallet.custody, wallet.spend-limits, payments.x402 | https://www.anchorterminal.com/tools/privy.min.md | | Sponge Wallet | E | 43.2 | wallet.onchain, wallet.spend-limits, payments.x402, wallet.custody | https://www.anchorterminal.com/tools/sponge-wallet.min.md | | Stripe API + MCP | A | 82.4 | payments.x402 | https://www.anchorterminal.com/tools/stripe-mcp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)