Skip to content
Tenzro
← All tutorials
Tutorial · Agents

Create an agentic wallet

Give an agent its own machine DID and wallet, rooted in its device key and delegated from your passkey identity with spending limits.

Intermediate20 min

An agentic wallet is a wallet an agent can spend from on its own, within limits a person set. On Network 1 it has three parts:

  • The controller: your human identity, did:tenzro:human:..., derived from your passkey.
  • The machine identity: the agent's DID, did:tenzro:machine:..., derived from the device key in the agent machine's TPM 2.0 or Secure Enclave and recorded under your identity.
  • The delegation scope: the limits you sign with your passkey, carried inside every token the agent uses.

Nobody holds the agent's key but the agent's own hardware, and the delegation can be narrowed or revoked from your passkey at any time.

Prerequisites

  • A passkey wallet at /console/wallet. Link a second device first so your identity has two roots; see Device linking and recovery.
  • The agent machine, with a TPM 2.0 or a Secure Enclave and the Tenzro agent runtime (CLI, SDK or desktop app).
  • curl and jq, or Node.js 20+ with npm install tenzro-sdk.

1. Find your controller DID

Your human DID is derived from your first passkey's public key, so the console can compute it and the network can check it. The console shows it on the wallet page. Resolve it to confirm the network knows it:

bash
curl -s https://rpc.tenzro.xyz \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tenzro_resolveIdentity","params":{"did":"did:tenzro:human:...","include_record":true}}' | jq

The record carries your smart account address in its metadata, and a list of the machines you control, which is empty for now.

2. Create the device key on the agent machine

Start the agent runtime on the machine that will run the agent. It creates a key in the machine's TPM or Secure Enclave, and prints the pairing payload:

json
{
  "device_public_key": "0x04c3d4...",
  "machine_id": "research-agent-01"
}

Only the public key leaves the machine. Signing keys are used inside the hardware or derived from it on demand, and every signature the agent makes can be traced to this device.

3. Write the delegation scope

Decide what the agent may do. Amounts are decimal strings in wei (1 TNZO is 1000000000000000000).

json
{
  "max_transaction_value": "1000000000000000000",
  "max_daily_spend": "20000000000000000000",
  "allowed_operations": ["inference", "transfer"],
  "allowed_payment_protocols": ["x402", "mpp"],
  "allowed_chains": ["tenzro"]
}
FieldMeaning
max_transaction_valueThe largest single payment
max_daily_spendThe most the agent may spend in a day
allowed_operationsWhat the agent may do, for example inference and transfer
allowed_payment_protocolsWhich payment protocols it may use
allowed_chainsWhich networks it may act on

4. Delegate from your passkey

The simplest way is the console: open /console/agents, choose New agent, paste the pairing payload, enter the scope and approve with your passkey.

The console sends tenzro_onboardDelegatedAgent. It is an owner method: the authorization field carries a passkey assertion from your identity over a challenge that binds the device key and the scope, so nobody can attach an agent to your identity, or widen its limits, without your passkey.

json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tenzro_onboardDelegatedAgent",
  "params": {
    "controller_did": "did:tenzro:human:...",
    "device_public_key": "0x04c3d4...",
    "machine_id": "research-agent-01",
    "capabilities": ["inference", "payments"],
    "delegation_scope": {
      "max_transaction_value": "1000000000000000000",
      "max_daily_spend": "20000000000000000000",
      "allowed_operations": ["inference", "transfer"],
      "allowed_payment_protocols": ["x402", "mpp"],
      "allowed_chains": ["tenzro"]
    },
    "dpop_jwk": { "kty": "EC", "crv": "P-256", "x": "...", "y": "..." },
    "authorization": { "...": "controller passkey proof" }
  }
}

The response:

json
{
  "identity": {
    "did": "did:tenzro:machine:...",
    "identity_type": "machine",
    "controller_did": "did:tenzro:human:...",
    "capabilities": ["inference", "payments"],
    "status": "..."
  },
  "wallet": { "wallet_id": "...", "address": "0x...", "public_key": "0x..." },
  "access_token": "...",
  "token_type": "Bearer",
  "expires_in": "...",
  "refresh_token": "...",
  "dpop_bound": true,
  "authorization_details": { "...": "the delegation scope" }
}

Hand the tokens to the agent runtime only. They are bound to the agent's DPoP key (dpop_jwk), so they cannot be replayed from another machine. When the access token expires, the agent exchanges its refresh token with tenzro_refreshToken.

5. Inspect the wallet

Resolve your identity again. The new agent now appears under the machines you control:

bash
curl -s https://rpc.tenzro.xyz \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tenzro_resolveIdentity","params":{"did":"did:tenzro:human:...","include_record":true}}' \
  | jq '.record.identity_data.Human.controlled_machines'

Resolve the agent itself with the SDK:

ts
import { TenzroClient } from "tenzro-sdk";

const client = new TenzroClient({
  endpoint: "https://rpc.tenzro.xyz",
  apiEndpoint: "https://api.tenzro.xyz",
});

const agent = await client.identity.resolve("did:tenzro:machine:...");
console.log(agent);

const doc = await client.identity.resolveDidDocument("did:tenzro:machine:...");
console.log(doc.id);

Read its remaining allowance for today:

bash
curl -s https://rpc.tenzro.xyz \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tenzro_getAgentDailySpend","params":{"agent_did":"did:tenzro:machine:..."}}' | jq

Fund the wallet by transferring TNZO to its address from your own account or another wallet.

6. Change or revoke the delegation

Every change to an agent's authority is signed by your passkey:

  • Change the agent's limits, or revoke it, with a fresh passkey approval. See Agents.
  • Pause the agent's payments, or revoke it. Revoking the delegation revokes the agent's tokens and cascades to any child agents it spawned.

If the agent should also spend from your own smart account, grant it a session key held in its own hardware, with per-call and total caps and a time window. See Smart account policies.

Next steps