The safest way to let an AI agent build crypto transactions without giving it a private key is to use policy-controlled signing with unsigned transaction proposals. This approach ensures the agent can prepare and broadcast transactions while a human or hardware device retains final signing authority. This guide covers policy-controlled signing, hardware wallet integration, unsigned transaction construction, session keys, smart account policies, and MPC wallets. It explains how BuildAWallet enables secure agent operations on mainnets like Base and Solana.
Policy Controlled Signing
Policy controlled signing is a security model where transaction execution is governed by predefined rules rather than direct key access. In this model, an AI agent can propose actions, but the system validates them against a policy engine before allowing a signature. This prevents agents from executing arbitrary or malicious transactions. BuildAWallet supports this by separating balance reads and local signing from spending authority. The agent can query live data via the API explorer but cannot sign without explicit authorization. This separation ensures that even if an agent is compromised, the attacker cannot move funds without passing the policy checks.
Defining the Policy Engine
A policy engine is a software component that evaluates transaction parameters against a set of constraints. These constraints can include maximum transaction amounts, allowed recipient addresses, and specific network restrictions. By defining these rules, users create a safety net that limits the agent's operational scope. The engine acts as a gatekeeper, ensuring that only compliant transactions proceed to the signing stage.
Hardware Wallet Integration
Hardware wallet integration provides a physical layer of security for crypto assets. When an AI agent interacts with a hardware wallet, it typically requests an unsigned transaction that the user must manually approve on the device. This ensures that the private key never leaves the secure element of the hardware wallet. BuildAWallet allows users to connect hardware devices for signing, ensuring that the agent's role is limited to preparation and broadcasting. This setup is ideal for users who want to automate routine tasks while maintaining strict control over fund movement.
Benefits of Physical Isolation
Physical isolation means the private key is stored on a device that is not connected to the internet during signing. This eliminates the risk of remote key extraction. The agent can prepare the transaction data, but the final cryptographic signature requires physical interaction with the hardware device. This method is widely considered the gold standard for securing large amounts of crypto assets.

Unsigned Transaction Proposal
Reviewing Transaction Details
Users should review the recipient address, amount, and network fees in the unsigned proposal. This step is critical for preventing errors or malicious redirections. The agent can provide a human-readable summary of the transaction, making it easier for users to verify the intent. By reviewing the proposal, users ensure that the agent is acting within the expected parameters.
Unsigned Transaction Construction
Unsigned transaction construction is the process of assembling the raw data required for a blockchain transaction. This involves encoding the transaction parameters into a format that the network can understand. The AI agent performs this construction using the data retrieved from the machine API. The agent calculates the necessary gas limits and nonce values to ensure the transaction is valid. Once constructed, the transaction is ready for signing by the user or a designated signer.
Network Specific Considerations
Session Keys
Session keys are temporary cryptographic keys that grant limited access to a wallet for a specific duration or purpose. Instead of giving the agent the master private key, users can generate a session key that allows the agent to sign transactions within a defined scope. This key expires after a set time or after a certain number of transactions. This approach minimizes the risk of key compromise. If a session key is leaked, the damage is limited to the scope and duration of that session.
Managing Session Lifecycle
Users should monitor the lifecycle of session keys to ensure they are revoked when no longer needed. The agent can request a new session key for each task, ensuring that no single key has long-term access. This practice enhances security by reducing the window of opportunity for attackers. BuildAWallet's machine API supports session-based authentication, allowing agents to manage these keys programmatically.
Smart Account Policies
Smart account policies are rules embedded in smart contract wallets that dictate how transactions can be executed. These policies can require multi-signature approvals, time-locks, or specific conditions to be met before a transaction is finalized. By using smart accounts, users can enforce complex security rules that are difficult to implement with standard wallets. The AI agent interacts with the smart account by submitting transactions that comply with the embedded policies. This ensures that the agent cannot bypass the security controls.
Implementing Multi-Sig Requirements
Multi-signature requirements mandate that multiple parties must sign a transaction before it is executed. This is a powerful security measure for high-value transactions. The agent can prepare the transaction, but it will not be broadcast until all required signatures are collected. This ensures that no single entity, including the agent, has unilateral control over the funds.
Hardware Wallet Signing
Hardware wallet signing is the process of using a physical device to sign a transaction. The user connects the hardware wallet to their computer or mobile device and approves the transaction on the device's screen. This ensures that the private key remains secure within the hardware wallet. The AI agent can prompt the user to sign the transaction, but the actual signing process is handled by the hardware device. This method provides a high level of security and is recommended for users who hold significant amounts of crypto assets.
Choosing the Right Hardware Wallet
MPC Wallets
MPC wallets, or Multi-Party Computation wallets, use cryptographic techniques to split the private key into multiple shares. No single party holds the complete key, and a threshold of shares is required to sign a transaction. This approach provides a high level of security without the need for a physical hardware device. The AI agent can hold one share of the key, while the user holds another. This ensures that the agent cannot sign transactions without the user's participation. MPC wallets are a flexible solution for users who want to balance security and convenience.
Key Share Management
Users should store their key shares securely and ensure that the agent's share is protected. If the agent's share is compromised, the attacker still needs the user's share to sign a transaction. This provides an additional layer of security. BuildAWallet supports MPC wallet configurations, allowing users to set up secure agent operations.
Comparison of Security Methods
| Method | Security Level | Convenience | Best For |
|---|---|---|---|
| Policy Controlled Signing | High | Medium | Automated routine tasks |
| Hardware Wallet Integration | Very High | Low | High-value assets |
| Session Keys | Medium | High | Short-term agent tasks |
| Smart Account Policies | High | Medium | Complex security rules |
| MPC Wallets | High | Medium | Flexible key management |
Key Takeaways
- Policy controlled signing ensures that AI agents can only execute transactions that comply with predefined rules.
- Hardware wallet integration provides a physical layer of security, keeping private keys offline.
- Unsigned transaction proposals allow users to review transaction details before authorizing them.
- Session keys limit the agent's access to a specific scope and duration, reducing the risk of key compromise.
- Smart account policies enable complex security rules, such as multi-signature requirements.
- MPC wallets split the private key into multiple shares, ensuring that no single party has full control.
- BuildAWallet supports these methods, allowing users to secure their assets while leveraging AI agents.
- Users should always review transaction details and monitor session key lifecycles.
Frequently Asked Questions
What is policy controlled signing?
Policy controlled signing is a security model where transaction execution is governed by predefined rules. The AI agent can propose transactions, but they must pass policy checks before being signed.
How does hardware wallet integration work with AI agents?
The AI agent prepares an unsigned transaction, and the user approves it on their hardware wallet. The private key never leaves the hardware device.
What is an unsigned transaction proposal?
An unsigned transaction proposal is a data structure that contains all the details for a blockchain transfer but lacks the cryptographic signature required for execution.
How do session keys enhance security?
Session keys are temporary keys that grant limited access to a wallet. They expire after a set time or number of transactions, reducing the risk of key compromise.
What are smart account policies?
Smart account policies are rules embedded in smart contract wallets that dictate how transactions can be executed, such as requiring multi-signature approvals.
How do MPC wallets work?
MPC wallets split the private key into multiple shares. A threshold of shares is required to sign a transaction, ensuring that no single party has full control.
Can I use BuildAWallet for both human and agent wallets?
Yes, BuildAWallet is designed for both humans and autonomous agents. Humans can design their own wallets, while agents can use the paid API for mainnet data and transaction preparation.
Where can I find the BuildAWallet API documentation?
You can find the API documentation at the API explorer page on the BuildAWallet website.
Conclusion
Securing AI agent operations in crypto requires a multi-layered approach. By combining policy controlled signing, hardware wallet integration, and MPC wallets, users can create a robust security framework. BuildAWallet provides the tools to implement these methods, allowing users to leverage the benefits of AI agents while maintaining control over their assets. To get started, visit the BuildAWallet homepage and explore the options for both human and agent wallets.

