Give agents spending power, not your wallet.
Put funds in a vault only your wallet owns. Hand an agent a key that works inside limits the chain itself enforces: how much, to whom, until when.
A vault only your wallet can open.
Your wallet deploys a small contract and becomes its one owner. It cannot be upgraded and has no administrator. PrivateOps holds no key to it and cannot move what is inside.
- Owner
- Your connected wallet, and nobody else
- Code
- Immutable. No proxy, no admin, no upgrade
- Way out
- You can withdraw at any time, even while everything is paused
An agent asks. The vault decides.
The agent gets a session key, never your wallet's. Write its policy below, then play the agent and try to get past it.
The vault's answers
Spent today 0 of 120
Nothing asked yet. Try 20 to Supplier A, then 80, then the address you never listed.
A simulation, with no chain behind it. It runs the same check PrivateOps uses to explain a refusal. On Robinhood Chain the rule is enforced by the vault contract, so it holds even if our servers do not.
Private means separate, not invisible.
The agent's authority is kept apart from your main wallet. That is the whole meaning of the name. Robinhood Chain is public, and PrivateOps does not hide transactions.
- Your wallet's keyNever given to an agent or to PrivateOps
- Yours
- The agent's session keyHeld encrypted by PrivateOps; signs only what the policy allows
- Limited
- Vault, recipient, amountOn a public chain, for everyone, for good
- Public
- Who paid the gasThe relaying account is visible on every transaction
- Public
Who pays gas is chosen, never assumed
The default. PrivateOps checks the request and signs that one action. You get a ready transaction, and any account you choose relays it and pays.
One request in. A record of everything.
Any agent that can make an HTTP call can use a vault. Every request, refusal and confirmation is kept, with the transaction behind it. Send the same idempotency key twice and you get the same action back, never a second one.
curl -X POST https://useprivateops.xyz/api/v1/agents/$AGENT_ID/actions \
-H "Authorization: Bearer $AGENT_API_KEY" \
-H "Idempotency-Key: invoice-2041" \
-d '{"type":"erc20_transfer","token":"0x…","to":"0x…","amount":"20000000"}'- validatingchecked against the live onchain policy
- simulatingsigned by the session key and dry-run on the vault
- preparedcaller-paid: a ready transaction is handed back, with an expiry
- submittedbroadcast; you get the transaction hash
- confirmedmined. Only now has it happened
A request the policy forbids ends as rejected before anything is broadcast. Nothing is spent.
Keep the wallet. Lend the limits.