PrivateOps

Give agents spending power, not your wallet.

Put funds in a vault only your wallet owns. Hand an agent a key that works inside limits the chain itself enforces: how much, to whom, until when.

A vault only your wallet can open.

Your wallet deploys a small contract and becomes its one owner. It cannot be upgraded and has no administrator. PrivateOps holds no key to it and cannot move what is inside.

Owner
Your connected wallet, and nobody else
Code
Immutable. No proxy, no admin, no upgrade
Way out
You can withdraw at any time, even while everything is paused

An agent asks. The vault decides.

The agent gets a session key, never your wallet's. Write its policy below, then play the agent and try to get past it.

The policy you write

May be paid

What the agent asks for

The vault's answers

Spent today 0 of 120

Nothing asked yet. Try 20 to Supplier A, then 80, then the address you never listed.

A simulation, with no chain behind it. It runs the same check PrivateOps uses to explain a refusal. On Robinhood Chain the rule is enforced by the vault contract, so it holds even if our servers do not.

Private means separate, not invisible.

The agent's authority is kept apart from your main wallet. That is the whole meaning of the name. Robinhood Chain is public, and PrivateOps does not hide transactions.

Your wallet's keyNever given to an agent or to PrivateOps
Yours
The agent's session keyHeld encrypted by PrivateOps; signs only what the policy allows
Limited
Vault, recipient, amountOn a public chain, for everyone, for good
Public
Who paid the gasThe relaying account is visible on every transaction
Public

Who pays gas is chosen, never assumed

The default. PrivateOps checks the request and signs that one action. You get a ready transaction, and any account you choose relays it and pays.

One request in. A record of everything.

Any agent that can make an HTTP call can use a vault. Every request, refusal and confirmation is kept, with the transaction behind it. Send the same idempotency key twice and you get the same action back, never a second one.

curl -X POST https://useprivateops.xyz/api/v1/agents/$AGENT_ID/actions \
  -H "Authorization: Bearer $AGENT_API_KEY" \
  -H "Idempotency-Key: invoice-2041" \
  -d '{"type":"erc20_transfer","token":"0x…","to":"0x…","amount":"20000000"}'
  1. validatingchecked against the live onchain policy
  2. simulatingsigned by the session key and dry-run on the vault
  3. preparedcaller-paid: a ready transaction is handed back, with an expiry
  4. submittedbroadcast; you get the transaction hash
  5. confirmedmined. Only now has it happened

A request the policy forbids ends as rejected before anything is broadcast. Nothing is spent.

Keep the wallet. Lend the limits.