DOMAWALLET
Back
[17 JUN 2025]  PRODUCT

Clean rules are the cost of entry for agents holding your keys

TEAM DOMA, PRODUCT
One policy engine. Every transaction checked.
SHARE

Agents that trade, rebalance, or pay on your behalf are becoming normal. Giving one your actual keys is not something you should have to do to make that useful.

A session key is a scoped credential: it can do exactly what you've allowed and nothing else. The scope isn't a setting the agent reads and could ignore — it's enforced by your account the same way your daily limit and allowlist are.

What a scoped session key looks like

Send$100,000 / day
SwapAllowed
DestinationsAllowlist only
A session key issued to a treasury agent

Why the cap has to be on the account, not the agent

An agent is code, and code has bugs, gets compromised, or gets tricked by a malicious prompt. If the only thing standing between a bug and your entire balance is the agent's own good behavior, the cap doesn't really exist. Enforced on your account, the cap holds regardless of what the agent tries to do.

A spending cap and an allowlist for your agent — enforced by your account, not a database.

Revoking access is the same story: turn off the session key from your account, once, and every permission tied to it ends immediately — no dependency on the agent cooperating.

Never miss new content