# Coinbase CDP wallets and AgentKit

> Coinbase's server wallets have a policy engine but no outside approval call, so the agent asks Immiscible before it sends.

Source: https://immiscible.fly.dev/docs/guides/coinbase-cdp

Coinbase Developer Platform server wallets (which AgentKit uses) have a [policy engine](https://docs.cdp.coinbase.com/server-wallets/v2/using-the-wallet-api/policies/overview): rules on a project or an account that accept or reject operations such as `signEvmTransaction` and `sendEvmTransaction` by criteria such as `ethValue`, `evmAddress` and `evmNetwork`. The first matching rule wins.

**There is no outside approval call.** The policies are evaluated inside Coinbase; nothing asks a service like Immiscible before signing. So the gate is the agent asking first.

## How to use them together

- Have the agent ask `POST /v1/actions/authorize` before it sends, through the SDK's `decideThenSign` (TypeScript) or `decide_then_sign` (Python), which signs only after an allow whose receipt covers the exact transfer. See [Crypto payments](https://immiscible.fly.dev/docs/guides/crypto-payments.md).
- For x402 resources, use `x402Fetch` or `x402_request` with the CDP wallet as the signer. See [x402](https://immiscible.fly.dev/docs/guides/x402.md).
- Keep a CDP policy as a backstop: an `evmAddress` allow list matching the addresses in the agent's crypto rule, so a path that skips the wrapper still cannot pay anyone else.

Coinbase's x402 client also has its own spend controls (a maximum per payment, a cumulative maximum, allowed networks). They are static limits in the client; Immiscible's decision is per payment, with reasons and a person when it should be.
