Core concepts
The design problem: let a language model move money without letting it lose yours. Everything below exists to solve that one problem.
AgentWallet
A smart-contract account per user. The agent never holds a private key. It calls execute() on the wallet, and the wallet enforces the rules below. Only the owner can change those rules.
Session keys & whitelists
A session grant is time-boxed and scoped: which contracts the agent may call, who it may pay, how many calls per day, how much value per call. The wallet contract enforces it, so the caps hold even if our server is compromised.
Skills
Instructions that teach the agent a workflow. Installed from the Skill Hub, validated against the trusted-tool registry before first run.
Trusted tools
A skill can only call tools from a vetted registry. Balances, swaps, market data, search. It cannot reach an arbitrary contract or URL.
On-chain attestation
Actions write to the ActionLog. That log is what the credit score is computed from; nothing about reputation lives in a database we could edit.
Optimistic execution
The agent replies first, confirms on-chain in the background. Block time is 2 seconds, so the gap is barely visible.