Security

MinAgent lets software hold and spend money, so security is the product, not a feature. Here is how we approach it, and how to tell us if you find a problem.

Last updated

How we protect agent wallets

The model never decides alone

We assume a model can be tricked by a web page, a tool result or a message. So every payment goes through a policy engine the model can't change. It checks, in order: is the wallet frozen, is the service on the owner's allow-list, is the amount under the per-payment cap, and does it fit the daily budget. The details are in Spending rules for AI agents.

Agents never hold the main key

Each client connection, such as a Claude Code session, gets a session key that is limited in scope, set to expire, and can only ask for signatures through the policy engine. Owners can revoke a session key at any time without moving funds.

Owners stay in control

How we build

Audits

The wallet contracts and the policy engine are being audited during the private beta. We will publish the results here before the public launch in 2027. Until then, please treat MinAgent as beta software and keep only small amounts in agent wallets.

Reporting a vulnerability

If you think you have found a security problem in minagent.xyz or in MinAgent, please email hello@minagent.xyz. Include:

What we ask

What we promise

A paid bug bounty programme will start with the public launch. Reports made before then will be considered for a reward when it opens.

Machine-readable contact details are in /.well-known/security.txt.