AgentKit hands every agent a wallet and registers the fund-moving action by default
Every AI Agent deserves a wallet.
At a glance
- What is it?
- AgentKit is Coinbase Developer Platform's TypeScript and Python toolkit for giving AI agents a crypto wallet and onchain actions. Its own risk section is the most useful page in the repository, because the fund-moving action ships enabled and nothing in the SDK gates a transfer.
- Who is it for?
- AgentKit is for developers who already have a CDP Secret API Key, a model endpoint and a spending cap of their own, and who intend to run a funded wallet in a testnet environment first.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 30 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 3, 2026, and from our analysis. They are not legal advice.
Editorial analysis
walletActionProvider is registered by default and nothing gates the transfer
The risk section of this README is the part worth reading twice. It states the problem plainly: AgentKit gives an AI agent a wallet, and large language models do not reliably distinguish instructions from data, so any text that reaches the model's context can influence which actions the agent takes, including transfers. The page calls this inherent to the design and says it cannot be resolved inside the SDK.
It then splits the exposure in two. Direct surfaces are interfaces where a third party sends text to the agent, such as a public website, a chat bot or an API. Indirect surfaces are actions that pull external content into context: `twitterActionProvider` returns mentions and `farcasterActionProvider` returns profile data, both handed to the model as tool output rather than as user input.
Either surface, combined with a funded wallet and a fund-moving action provider, is enough for injected text to end up as an onchain transfer. `walletActionProvider` is registered by default, and the page names three controls the library does not ship: it does not gate transfers behind human approval, does not enforce spend caps, and does not allowlist destinations. Responsibility for those three is handed to the developer in writing.
The remedy is pointed at one LangChain example, not at the SDK
Having named the hole, the same section points at one strategy: guardrails middleware. The links it gives are the LangChain middleware documentation and a guardrails chatbot example under the TypeScript tree, which combines human-in-the-loop approval for transfers with prompt injection filtering.
That is the whole remedy as this repository presents it, and the shape of the pointer matters. Both links sit under `typescript/`: one in `framework-extensions/langchain/`, one in `examples/`. So the mitigation is documented as a LangChain-specific composition, layered outside the SDK rather than configured through it, and the page names no equivalent path for the Python track. The `python/` directory exists at the root of the repository, but its contents are not set out here, so whether a Python equivalent of that guardrails example exists is not answerable from this page.
The practical consequence for a reader is that "does AgentKit protect my funds" and "did I wire up protection" are two different questions, and only the second one is under your control.
Two language tracks, two scaffolders, one identical env file dance
Both quickstarts need the same three credentials before any code runs: Node.js 22 or later plus a CDP Secret API Key and an OpenAI API key for the TypeScript track, and Python 3.10 or later with Poetry plus those same two keys for the Python track. A toolkit described as framework-agnostic still hands you an OpenAI-shaped default at the scaffold step.
The TypeScript path:
# Create a new fullstack agent project
npm create onchain-agent@latest
# Navigate to your project directory
cd onchain-agent
# At this point, fill in your CDP API key id/secret, OpenAI API key, and any other environment variables in the .env.local file.
# Then, rename the .env.local file to .env
mv .env.local .env
# Install dependencies
npm install
# Run the development server
npm run devThe Python path:
# Create a new agent chatbot
pipx run create-onchain-agent
# Navigate to your project directory
cd onchain-agent
# At this point, fill in your CDP API key id/secret, OpenAI API key, and any other environment variables in the .env.local file.
# Then, rename the .env.local file to .env
mv .env.local .env
# Install dependencies
poetry install
# Run the chatbot
poetry run python chatbot.pyTwo different scaffolders, `npm create onchain-agent@latest` and `pipx run create-onchain-agent`, produce the same directory name, and both then ask you to write secrets into `.env.local` and rename that file to `.env` before installing anything.
Two entry points, one base-sepolia transaction, two renderings of its link
The two samples then diverge in how you talk to the agent. The TypeScript track ends at `npm run dev` and a browser: visit `http://localhost:3000` and start telling the agent to do things onchain. The Python track ends at a terminal and a menu, where you select "1. chat mode".
Both walk through the same request, funding a wallet with testnet ETH, and both point at the same transaction on sepolia.basescan.org. The Python transcript is the more informative one, because it echoes the wallet identity before answering: a wallet id of `ccaf1dbf-3a90-4e52-ad34-89a07aad9e8b` on network `base-sepolia` with a default address of `0xD9b990c7b0079c1c3733D2918Ee50b68f29FCFD5`.
The two transcripts render the resulting link differently. The Node sample carries the transaction hash in full inside a markdown link, and the Python sample stops partway through the same hash. Both transcripts also carry markdown link syntax into what is plainly a terminal session, which is a small sign that the published transcripts were pasted from a richer client than the one being documented.
Everything on show here is testnet. Nothing in either quickstart shows a mainnet configuration, and the visible configuration surface is the env file the scaffolder asks you to edit.
The table of contents promises twelve sections and six of them are here
The README opens with a table of contents of twelve entries: Overview, Quickstart, Repository Structure, Managing Risk, Contributing, Documentation, Nightly Builds, Security and Bug Reports, Contact, Supported Wallets, Protocols, and Frameworks, License, and Legal and Privacy. Six of them have sections on this page. The Documentation section is the sixth, and it ends inside its own link:
- [AgentKit Documentation](https://docs.cdp.coinbase.com/agentkiThat leaves the parts of this project a reader is most likely to need unanswered by its own front page. Which wallets, protocols and frameworks are supported is announced in the table of contents and never stated, although the TypeScript tree hints at three wallet providers under `cdp/`, `privy/` and `viem/`. How nightly builds work is announced and not explained. Same for the security reporting route, the contact address, and the legal and privacy terms.
The License entry is the sharpest gap, because it cannot be resolved from the text. No license identifier is attached to the repository record, and while a `LICENSE.md` file sits at the root next to `RELEASE.md`, `SECURITY.md` and `WISHLIST.md`, this page never states which terms apply. Anyone building on the toolkit has to open that file rather than trust the summary.
Two monorepos in one root, and a directory listing that stops mid-list
The Repository Structure section calls AgentKit two monorepos, one for Python and one for TypeScript. In the tree they are two directories inside a single repository, `python/` and `typescript/`, and the root carries `CONTRIBUTING.md` beside `CONTRIBUTING-PYTHON.md` and `CONTRIBUTING-TYPESCRIPT.md`. The listing itself covers only the TypeScript half:
agentkit/
├── typescript/
│ ├── agentkit/
| | └── scripts/generate-action-provider/ # use this to create new actions
│ │ └── src/
│ │ ├── action-providers/ # find 50+ actions in here
│ │ └── wallet-providers/
│ │ ├── cdp/
│ │ ├── privy/
│ │ └── viem/
│ ├── create-onchain-agent/
│ ├── framework-extensions/
│ │ ├── langchain/
│ │ ├── vercel-ai-sdk/
│ │ └── model-context-protocol/
│ └── examples/
│ ├── langchain-cdp-chatbot/
│ ├── langchain-cdp-smart-wallet-chatbot/
│ ├── langchain-farcaster-chatThe listing ends at `langchain-farcaster-chat` with no closing branch, and one line of it is drawn with plain pipes instead of the box-drawing characters used elsewhere. Small things, but they tell you the section is an excerpt rather than a map.
What the excerpt does show is the extension model. `scripts/generate-action-provider/` is marked as the place to create new actions, `src/action-providers/` holds more than fifty of them, wallet implementations are pluggable under three provider directories, and framework bindings live beside the core package rather than inside it. Note that the two action providers named in the risk section, `twitterActionProvider` and `farcasterActionProvider`, are exactly the kind of indirect surface that lives in that directory.
The newest published releases are three nightlies from March 2025
The three most recent releases are dated builds, not versions: `nightly-20250311`, `nightly-20250310` and `nightly-20250309`, each named for its build date and published within half an hour of midnight UTC. No version-numbered tag appears among them, while a `RELEASE.md` file sits at the root and the table of contents has a Nightly Builds section that this page does not include.
Against that, the default branch is current: the most recent push is dated 2026-09-03, roughly eighteen months after the newest tag, and the README itself says AgentKit is actively being built out and welcomes community contributions. Both statements are true at once. Commits keep arriving and no named release marks where any of them can be pinned.
For adoption planning the numbers explain the shape of interest: 1,322 stars and 838 forks, a fork count close to two thirds of the star count, which is what a monorepo that is consumed as templates and copied out of examples tends to produce. There are 395 open issues on the same record, and a code scanning badge wired to CodeQL in the header. Nothing on this page says how those 395 issues are triaged, so treat the volume as a fact about the queue rather than a measure of maintainer response.
Editorial conclusion
AgentKit is for developers who already have a CDP Secret API Key, a model endpoint and a spending cap of their own, and who intend to run a funded wallet in a testnet environment first. Treat the transfers, not the prompts, as the dangerous surface: the fund-moving action is registered by default and the library itself supplies no approval step, spend limit or destination allowlist, so those controls have to come from the framework extension or the middleware you wrap around it. Before you build on it, check which license the root LICENSE.md actually carries, since no license identifier is attached to the repository record, and pin a version deliberately, because the newest published tag is a nightly build from 2025-03-11 while the default branch has been pushed as recently as 2026-09-03.
Frequently asked questions
Does AgentKit gate wallet transfers behind human approval?
No. The Managing Risk section states that AgentKit does not gate transfers behind human approval, does not enforce spend caps, and does not allowlist destinations, and that `walletActionProvider` is registered by default. It points to guardrails middleware and a LangChain guardrails chatbot example instead.
What license does AgentKit use?
The repository record carries no license identifier and this page has no License section body, although the table of contents lists one. A `LICENSE.md` file sits at the root next to `RELEASE.md`, `SECURITY.md` and `WISHLIST.md`, so the terms have to be read from that file rather than from the README.
Which Node.js and Python versions does AgentKit require?
The Node.js quickstart lists Node.js 22 or later, and the Python quickstart lists Python 3.10 or later with Poetry. Both tracks also require a CDP Secret API Key and an OpenAI API key before the scaffolded project will run.
How is AgentKit installed from Node.js?
Run `npm create onchain-agent@latest`, change into the `onchain-agent` directory, fill the CDP and OpenAI values into `.env.local`, rename that file to `.env` with `mv .env.local .env`, then `npm install` and `npm run dev`. The browser entry point is `http://localhost:3000`.
Which wallets and networks does AgentKit support?
The TypeScript tree shows wallet providers under `cdp/`, `privy/` and `viem/`, and the Python quickstart shows a wallet on network `base-sepolia`. The section titled Supported Wallets, Protocols, and Frameworks is announced in the table of contents but has no body on this page, so the full list is not stated here.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/coinbase-agentkit)