Skip to content
Human Choice

Systems / Agency

Wallet Kernel

Can people delegate useful work to AI without taking on unacceptable financial risk or constant supervision?

This customer-hosted Wallet Kernel explores a specific part of that question: spending within explicit budgets, seller rules, and exact human approvals, through a customer-owned wallet.

From principle to behavior

Authority you can inspect.

The initial product is for AI platform and gateway teams. Its effects on human understanding and effort remain research questions.

Set limits

Decide what may proceed.

Specify a budget, permitted sellers, and when a request needs a person's approval.

Approve precisely

Keep an agreement specific.

An approval is bound to one request. A changed seller, amount, or resource needs a new decision.

Inspect outcomes

Keep the record honest.

Distinguish permission, payment, useful work, and an unresolved result. Preserve what happened across recovery.

Offline spend-control sandbox

Walk a Spend Intent through the Wallet Kernel.

Illustrative sampleNo account, wallet key, network call, payment, or saved data.
  1. 01PolicyDefault deny
  2. 02Auto-payBelow ceiling
  3. 03DenyUnknown seller
  4. 04EscalateExact mismatch
  5. 05ApproveStill no signature
  6. 06RetryWielder repeats

Sandbox ready. Load the fictional customer policy to begin.

Wallet + policy · sampleReady to load

Customer-hosted Wallet Kernel

Northstar Pi spend session

Ordinary Agent requests in; policy-bound x402 authority out.

Agent
pi-coding-agentLocal adapter · fictional session
Customer-owned wallet
0x71d371d371d371d371d371d371d371d371d371d3Customer-owned CDP wallet
Network
Base Sepoliaeip155:84532 · test USDC
Default
Denysha256:74db8f3e74db8f3e74db8f3e74db8f3e74db8f3e74db8f3e74db8f3e74db8f3e
Allowed seller: https://api.northstar.example. The Agent cannot access credentials, change policy, approve, or sign.
Spend journal · local preview0/3 intents

No Spend Intents yet.

Load policy, then run three deterministic Spend Intents. Nothing leaves this browser tab.

Next action

Creates a local default-deny policy. No wallet is contacted.

Evidence and limits

What has been demonstrated.

Different kinds of evidence answer different questions. These states should remain visible together.

This browser

A simulation.

The demonstration creates an unsigned projection that is not broadcast. Its sample people, wallet, requests, and outcomes are fictional.

Installed engineering checks

43 of 43 checks passed.

The archived run at 3ef2dbc tested installed offline behavior on Ubuntu 24.04 with Node 24.18.1. Wallet, seller, and chain adapters were synthetic.

Read the original evidence

Live use and human outcomes

Still to establish.

Live CDP payment and live testnet settlement evidence remain not run. Effects on comprehension, supervision, demand, and people's lives need separate studies.

Wallet Kernel is not released for live use.

The demonstration and archived engineering checks do not establish production readiness. Read the design for the remaining implementation and release requirements.

Explore the human research question