Skip to content

Guides

Coinbase CDP wallets and AgentKit

Coinbase’s server wallets have a policy engine but no outside approval call, so the agent asks Immiscible before it sends.

Coinbase Developer Platform server wallets (which AgentKit uses) have a policy engine: rules on a project or an account that accept or reject operations such as signEvmTransaction and sendEvmTransaction by criteria such as ethValue, evmAddress and evmNetwork. The first matching rule wins.

There is no outside approval call. The policies are evaluated inside Coinbase; nothing asks a service like Immiscible before signing. So the gate is the agent asking first.

#How to use them together

  • Have the agent ask POST /v1/actions/authorize before it sends, through the SDK’s decideThenSign (TypeScript) or decide_then_sign (Python), which signs only after an allow whose receipt covers the exact transfer. See Crypto payments.
  • For x402 resources, use x402Fetch or x402_request with the CDP wallet as the signer. See x402.
  • Keep a CDP policy as a backstop: an evmAddress allow list matching the addresses in the agent’s crypto rule, so a path that skips the wrapper still cannot pay anyone else.

Coinbase’s x402 client also has its own spend controls (a maximum per payment, a cumulative maximum, allowed networks). They are static limits in the client; Immiscible’s decision is per payment, with reasons and a person when it should be.