Agents
Connect an AI app to OpenWallet, and it can pay for things you ask it to get, from a separate wallet with limits. Every payment comes back to you in the extension.
The worst case: you can lose at most what you put in the agent wallet.
The agent wallet
- A separate account made from your own wallet, which you fund with what the agent may spend. Your main wallet is never available to an agent.
- The agent can pay only a price a website or tool asked for, in answer to a request the agent made. It cannot send money to an address it chooses.
- Payments are in XRP or RLUSD on the XRP Ledger, using the open x402 standard.
Connect an AI app
- In your AI app, add a remote MCP server (sometimes called a connector) with this address:
https://mcp.opensync.network/mcp - The app opens an OpenWallet page that shows the app's name, what it is asking to do (pay within limits, read the balance and history), and a connection code of 8 characters, such as
KJ7M-2QXP. That page never asks for a code, a password or a sign-in. - Open the extension: Agents → Approve a connection. Check that the code and the app's name match, choose which agent wallet this app may use and its limits, and approve with Touch ID or your password.
- The app is connected. You can disconnect it from the extension at any time, which cuts it off at once.
A connection code expires after 10 minutes and works once. A fake page that shows you a code gains nothing: the connection only happens when you approve it in the extension, where you see which app you are approving.
Paying
- You ask the AI app for something that costs money, such as a report from a paid service.
- The app asks OpenWallet to fetch it. The service answers with a price. Anything over your limits is refused straight away.
- The extension shows the request: the app's name, the service, the amount, which agent wallet pays, and what is left of today's budget. You get a system notification too.
- Before you approve, the extension asks the service for the price itself and checks that the amount, the currency, the recipient and the network are the ones it was shown. If anything differs, it refuses. The first time you pay a new service, your browser asks you to let OpenWallet contact that site.
- You approve with Touch ID or your password. The payment is signed on your device, and the app gets what it asked for.
If you do not approve within a minute, the app is told the payment is waiting and checks back later. Declining, or letting it expire, signs nothing.
Limits
You set the limits when you approve a connection. The extension proposes:
| Per payment | Per day | |
|---|---|---|
| RLUSD | 10 | 50 |
| XRP | 20 | 100 |
One agent wallet can hold at most 500 RLUSD or 1,000 XRP. An app can have at most 10 payments waiting and 60 requests an hour. If the same service asks for the same amount more than 5 times in 10 minutes, the extension warns you and offers to block the app.
On a Mac: OpenWallet Agent
AI apps that run programs on your computer, such as Claude Code, can use OpenWallet Agent instead: a local MCP server for macOS that holds its own capped key for the agent wallet. You pair it once with the extension, and approve payments with Touch ID or your Mac's login password in a macOS prompt. Small payments to services you have already approved can go through without asking: by default under 0.10 RLUSD or 0.2 XRP. See the desktop setup.
Watching and stopping
- The extension checks each agent wallet on unlock and every 15 minutes while your browser runs. If the account does anything other than the payments it is allowed, you get a notification with Stop agent.
- Disconnect an app to cut it off. Sweep sends what is left in an agent wallet back to your main wallet. Close deletes the account and returns its 1 XRP reserve.
Things to know
- Wallets imported from an XRP Ledger seed (starting with
s) have one key and cannot make agent wallets. 24-word wallets can. - RLUSD in an agent wallet can be frozen or clawed back by Ripple, like any RLUSD.
- OpenWallet's MCP server sees the paid content in transit to deliver it, and does not keep it.
- For the technical model, see the developer docs.