Create an agentic wallet
Give an agent its own machine DID and wallet, rooted in its device key and delegated from your passkey identity with spending limits.
An agentic wallet is a wallet an agent can spend from on its own, within limits a person set. On Network 1 it has three parts:
- The controller: your human identity,
did:tenzro:human:..., derived from your passkey. - The machine identity: the agent's DID,
did:tenzro:machine:..., derived from the device key in the agent machine's TPM 2.0 or Secure Enclave and recorded under your identity. - The delegation scope: the limits you sign with your passkey, carried inside every token the agent uses.
Nobody holds the agent's key but the agent's own hardware, and the delegation can be narrowed or revoked from your passkey at any time.
Prerequisites
- A passkey wallet at /console/wallet. Link a second device first so your identity has two roots; see Device linking and recovery.
- The agent machine, with a TPM 2.0 or a Secure Enclave and the Tenzro agent runtime (CLI, SDK or desktop app).
curlandjq, or Node.js 20+ withnpm install tenzro-sdk.
1. Find your controller DID
Your human DID is derived from your first passkey's public key, so the console can compute it and the network can check it. The console shows it on the wallet page. Resolve it to confirm the network knows it:
curl -s https://rpc.tenzro.xyz \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_resolveIdentity","params":{"did":"did:tenzro:human:...","include_record":true}}' | jqThe record carries your smart account address in its metadata, and a list of the machines you control, which is empty for now.
2. Create the device key on the agent machine
Start the agent runtime on the machine that will run the agent. It creates a key in the machine's TPM or Secure Enclave, and prints the pairing payload:
{
"device_public_key": "0x04c3d4...",
"machine_id": "research-agent-01"
}Only the public key leaves the machine. Signing keys are used inside the hardware or derived from it on demand, and every signature the agent makes can be traced to this device.
3. Write the delegation scope
Decide what the agent may do. Amounts are decimal strings in wei (1 TNZO is 1000000000000000000).
{
"max_transaction_value": "1000000000000000000",
"max_daily_spend": "20000000000000000000",
"allowed_operations": ["inference", "transfer"],
"allowed_payment_protocols": ["x402", "mpp"],
"allowed_chains": ["tenzro"]
}| Field | Meaning |
|---|---|
max_transaction_value | The largest single payment |
max_daily_spend | The most the agent may spend in a day |
allowed_operations | What the agent may do, for example inference and transfer |
allowed_payment_protocols | Which payment protocols it may use |
allowed_chains | Which networks it may act on |
4. Delegate from your passkey
The simplest way is the console: open /console/agents, choose New agent, paste the pairing payload, enter the scope and approve with your passkey.
The console sends tenzro_onboardDelegatedAgent. It is an owner method: the authorization field carries a passkey assertion from your identity over a challenge that binds the device key and the scope, so nobody can attach an agent to your identity, or widen its limits, without your passkey.
{
"jsonrpc": "2.0",
"id": 1,
"method": "tenzro_onboardDelegatedAgent",
"params": {
"controller_did": "did:tenzro:human:...",
"device_public_key": "0x04c3d4...",
"machine_id": "research-agent-01",
"capabilities": ["inference", "payments"],
"delegation_scope": {
"max_transaction_value": "1000000000000000000",
"max_daily_spend": "20000000000000000000",
"allowed_operations": ["inference", "transfer"],
"allowed_payment_protocols": ["x402", "mpp"],
"allowed_chains": ["tenzro"]
},
"dpop_jwk": { "kty": "EC", "crv": "P-256", "x": "...", "y": "..." },
"authorization": { "...": "controller passkey proof" }
}
}The response:
{
"identity": {
"did": "did:tenzro:machine:...",
"identity_type": "machine",
"controller_did": "did:tenzro:human:...",
"capabilities": ["inference", "payments"],
"status": "..."
},
"wallet": { "wallet_id": "...", "address": "0x...", "public_key": "0x..." },
"access_token": "...",
"token_type": "Bearer",
"expires_in": "...",
"refresh_token": "...",
"dpop_bound": true,
"authorization_details": { "...": "the delegation scope" }
}Hand the tokens to the agent runtime only. They are bound to the agent's DPoP key (dpop_jwk), so they cannot be replayed from another machine. When the access token expires, the agent exchanges its refresh token with tenzro_refreshToken.
5. Inspect the wallet
Resolve your identity again. The new agent now appears under the machines you control:
curl -s https://rpc.tenzro.xyz \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_resolveIdentity","params":{"did":"did:tenzro:human:...","include_record":true}}' \
| jq '.record.identity_data.Human.controlled_machines'Resolve the agent itself with the SDK:
import { TenzroClient } from "tenzro-sdk";
const client = new TenzroClient({
endpoint: "https://rpc.tenzro.xyz",
apiEndpoint: "https://api.tenzro.xyz",
});
const agent = await client.identity.resolve("did:tenzro:machine:...");
console.log(agent);
const doc = await client.identity.resolveDidDocument("did:tenzro:machine:...");
console.log(doc.id);Read its remaining allowance for today:
curl -s https://rpc.tenzro.xyz \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_getAgentDailySpend","params":{"agent_did":"did:tenzro:machine:..."}}' | jqFund the wallet by transferring TNZO to its address from your own account or another wallet.
6. Change or revoke the delegation
Every change to an agent's authority is signed by your passkey:
- Change the agent's limits, or revoke it, with a fresh passkey approval. See Agents.
- Pause the agent's payments, or revoke it. Revoking the delegation revokes the agent's tokens and cascades to any child agents it spawned.
If the agent should also spend from your own smart account, grant it a session key held in its own hardware, with per-call and total caps and a time window. See Smart account policies.
Next steps
- Agent demo, start to finish: run the agent you just created.
- Compose an agent from the registry: spawn child agents that can never exceed this scope.
- Agents, Identity and Hardware-rooted keys.