Canton Agent
Wallet
A settlement account your agent controls.
FTP Tech LLC provides a self-custody Canton account that an AI agent owns and controls, used to pay for x402-gated APIs on Canton. The agent holds its own key; the facilitator submits and pays gas but cannot move the funds.
What it provides
Four properties define the account. It is self-custody, it pays any x402 API, it verifies the relay-prepared transaction before signing, and it backs up and restores from a single key.
An account the agent owns
The agent generates and holds its own Ed25519 key on its machine. The validator only hosts the party; it cannot spend the balance. Only the agent's signature authorizes a transfer.
Pay any x402 API
The wallet settles an x402 402 challenge from the agent's own balance. On a gated request it builds the transfer, signs it locally, and retries with the signed transfer carried in the payment header; the merchant's facilitator relays it on-ledger.
Verify before sign
The relay is treated as untrusted. Before signing a transfer that moves funds, the wallet checks the relay-prepared transaction against its own intent and binds the signed hash to those exact bytes.
Backup and restore
The key lives in a single wallet file the agent reuses. Export prints the private key for backup; import restores it on another machine. The file is the funds, so it is kept under tight permissions.
How it works
Funding once is the only human step. The agent creates a self-custody party, the owner funds it, the agent claims the incoming Canton Coin, and from then on it pays x402 APIs from its own balance.
Create
The agent generates an Ed25519 key locally. The relay onboards the party as a CIP-0103 external party; the agent signs the onboarding hash itself.
Fund
The relay sends a new wallet a small Canton Coin starter grant, 0.2 CC on MainNet. For more, the owner sends Canton Coin or USDCx to the agent's party id.
Claim
Incoming funds arrive as a pending transfer. The agent accepts it with claim, and the accept is checked before signing like any other transaction, so a relay that substitutes an outbound transfer is refused.
Pay
On a 402, the wallet builds and signs the transfer locally and retries the request with the signed transfer in the payment header. The merchant's facilitator relays it on-ledger and pays the network fee.
Self-custody follows CIP-0103: the agent generates and holds the key, and the relay bridges onboarding and submission to a Canton participant using the validator’s auth, so the agent needs no Canton account. For the full flow, see the package. To use the wallet from an AI app, see the MCP server.
The building blocks
The wallet is a local key the agent holds, a facilitator relay that submits and pays gas without custody, and a paying fetch that settles x402 challenges from the agent's balance.
Local Ed25519 key
The agent holds its own key in a single wallet file under restrictive permissions. The validator hosts the party but never controls the funds, and the agent reuses the same wallet rather than creating a second one.
~/.canton-agent/wallet.jsonFacilitator relay
A facilitator the agent talks to over HTTPS. It onboards the party, prepares every transaction, and submits the claims and withdrawals the agent signs, paying gas; an x402 payment it only prepares, since the signed transfer travels in the payment header. It never signs and never holds the balance.
facilitator.ftptech.xyzPaying fetch
A drop-in fetch that pays x402 challenges from the agent's wallet. It detects a 402, verifies the prepared transaction, signs its hash locally, and retries the request with the signed transfer carried in the payment header.
makePayingFetch()# Install the CLI
npm i -g @ftptech/canton-agent-wallet
# Or run it without installing
npx @ftptech/canton-agent-wallet <command>Bin: canton-agent-wallet. Pass --relay-url to point at the facilitator.
createGenerate and onboard a self-custody wallet (idempotent).addressPrint the party id to fund.balancePrint every instrument the wallet holds: Canton Coin and registry tokens such as USDCx.claimAccept incoming transfers, Canton Coin or USDCx, including the initial funding.pay <url>Fetch a URL, auto-paying any x402 402 challenge. --asset picks the instrument when several are offered; spending a registry token such as USDCx is a separate opt-in.withdrawSend Canton Coin or a registry token back out, in full or by amount.swapSwap Canton Coin for a registry token such as USDCx, or back, on Cantex Connect (default) or the Tradecraft AMM. Waits for the output to land.mergeConsolidate dust holdings so a busy wallet stays enumerable and spendable.preapprovalMerchant setup: self-provision the TransferPreapproval that lets payments settle in one transaction.export · importPrint the private key for backup; restore it elsewhere.set-relay <url>Change the relay saved in the wallet. Refuses a relay that settles on a different network.
Published as @ftptech/canton-agent-wallet under Apache-2.0.
Who it is for
The same account serves the builder shipping one agent, the long-running service that settles its own calls, and the institution that wants agents with a bounded account they control.
AI-agent builders
Give an autonomous agent a Canton Coin account it controls, so it can pay for a gated API and retry without a custodian in the path.
Autonomous services
A long-running service holds its own key and settles each call from its own party, reusing one wallet across its lifetime.
Institutions
Deploy agents with a bounded settlement account they control, settled on Canton MainNet with on-ledger finality and no custodial relay.
Giving your agents a settlement account
FTP Tech LLC runs the facilitator the wallet talks to and supports integrations on Canton MainNet. Reach out to discuss a deployment.
The key never leaves the agent’s machine, and only the agent’s signature can spend. What the agent signs is what settles: the relay prepares transactions and gas is paid for the agent, but nobody else can move the funds, so nobody else holds custody.
Before signing a value-moving transfer, the wallet verifies the relay-prepared transaction against its own intent and binds the signed hash to those exact bytes, so a tampered preparation is rejected. The wallet is open source under Apache-2.0.
Let’s build something
that stays online
Launching a network, need a battle-tested validator, or want a community that actually shows up? Talk to us.