Agent demo, start to finish
Create an agent from the console under your passkey identity, give it spending limits, fund it, let it pay for inference and answer over A2A.
This tutorial runs one agent end to end. You create it from the console under your own passkey identity, set the limits it may spend within, fund it, watch it buy inference and reply to another agent over A2A, and then pause it. Every step uses Network 1 as it runs: the agent's key lives in the hardware of the machine that runs it, and every action that moves money is checked against the limits you signed.
Prerequisites
- A passkey wallet in the console. If you do not have one, open /console/wallet and create an account; it takes one passkey prompt. See Console and passkey wallet.
- A machine to run the agent with a TPM 2.0 or a Secure Enclave (most laptops, desktops and servers from recent years have one).
- The
tenzroCLI installed on that machine. See Getting started. curlandjq.
1. Get the agent's pairing payload
The agent's key is created on the machine that will run it and stays rooted in that machine's TPM or Secure Enclave. The browser never generates an agent key, and there is no key file to copy.
Start the Tenzro agent runtime (the CLI, the SDK or the desktop app) on the agent machine. It shows a pairing payload, as text or as a QR code:
{
"device_public_key": "0x04a1b2...",
"machine_id": "demo-agent-01"
}device_public_key is the public half of the device key. The agent's DID is derived from it, so the identity is bound to that machine.
2. Create the agent in the console
Open /console/agents, signed in with your passkey, and choose New agent.
- Paste or scan the pairing payload.
- Name the agent
demo-agentand give it the capabilitiesinferenceandpayments. - Set the delegation scope:
| Limit | Value for this demo |
|---|---|
| Per-transaction limit | 1 TNZO |
| Daily limit | 10 TNZO |
| Allowed operations | transfer, inference |
| Payment protocols | x402, mpp |
| Chains | tenzro |
- Approve with your passkey.
The console registers the agent under your identity and shows its DID (did:tenzro:machine:...) and its wallet address. The agent runtime receives its access and refresh tokens, bound to its own DPoP key, so a copied token is useless without the device.
Behind the button, the console calls tenzro_onboardDelegatedAgent, an owner method that needs your passkey's signature. The limits are written into the delegation and carried inside the agent's token, so every service the agent calls sees the same caps. See Agents for the full request.
3. Fund the agent
Fund the agent by transferring TNZO to its address from your own wallet or another account. The console shows the new balance when the transfer lands.
Check the balance from any machine:
curl -s https://rpc.tenzro.xyz \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_getBalance","params":["0xAGENT_WALLET"]}' | jqThe result is the balance in wei (TNZO has 18 decimals), as a 0x hex string.
4. Let the agent pay for inference
The OpenAI-compatible routes on https://rpc.tenzro.xyz can be paid per request. A request without an API key gets an HTTP 402 answer that names the price and the accepted payment schemes; the agent pays and retries.
On the agent machine, pay for a chat completion with x402 and cap the amount:
tenzro payment pay https://rpc.tenzro.xyz/v1/chat/completions \
--payer-did did:tenzro:machine:... \
--protocol x402 \
--max-amount 1000000 \
--rpc https://rpc.tenzro.xyzThe payment is signed by the agent's hardware-rooted key and checked against the delegation. A payment above the per-transaction limit, over the daily limit or on a protocol you did not allow is refused before anything settles.
See how much of today's allowance is left:
curl -s https://rpc.tenzro.xyz \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_getAgentDailySpend","params":{"agent_did":"did:tenzro:machine:..."}}' | jq{
"agent_did": "did:tenzro:machine:...",
"max_daily_spend": "10000000000000000000",
"current_daily_spend": "...",
"remaining": "...",
"last_reset": "..."
}The console shows the same numbers on the agent's card.
5. Answer another agent over A2A
Every agent registered on the network has an A2A Agent Card hosted at a2a.tenzro.xyz:
curl -s https://a2a.tenzro.xyz/agents/did:tenzro:machine:.../.well-known/agent.json | jq '.name, .skills[].id'Another agent sends a message with message/send. Mutating A2A calls carry a signed DID envelope in message.metadata, so the receiver knows which identity sent them:
curl -s https://a2a.tenzro.xyz/a2a \
-H 'content-type: application/json' \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "message/send",
"params": {
"message": {
"role": "user",
"parts": [{ "type": "text", "text": "What is the latest block?" }],
"metadata": {
"tenzro.a2a.envelope.sender": "did:tenzro:machine:...",
"tenzro.a2a.envelope.public_key": "...",
"tenzro.a2a.envelope.signature": "...",
"tenzro.a2a.envelope.nonce": "...",
"tenzro.a2a.envelope.timestamp": 1790000000000
}
}
}
}' | jqThe reply is an A2A task with its status and an artifact that carries the response. The A2A protocol tutorial shows how the envelope is built.
6. Pause or revoke the agent
On the agent's card in /console/agents you can:
- Pause the agent: its payments stop until you resume it.
- Change limits: lower or raise the per-transaction and daily caps.
- Revoke the agent: its tokens stop working and any child agents it spawned are revoked with it.
Each of these is a custody-grade change, so the console asks for your passkey every time. A signed-in session never changes an agent's authority on its own.
Next steps
- Create an agentic wallet: the same flow from the SDK and RPC, with the scope in detail.
- Connect an MCP client: give an assistant access to the network through MCP.
- Agents, x402 and MPP.