Cloudflare and MetaMask have introduced separate wallet systems for AI agents that move automated software closer to holding and spending cryptocurrency under pre-set rules. Cloudflare Wallets, announced on Aug. 4, is built for agents paying for digital services such as APIs, data, content and computing. MetaMask’s Agent Wallet, released on Aug. 6, focuses on letting agents execute on-chain actions including swaps, perpetual futures trades, prediction-market positions and liquidity management.
Together, the products place wallets at the center of an emerging model in which users delegate limited financial authority to software. Rather than merely analyzing markets or retrieving information, an agent can receive a budget, monitor conditions and pay or transact when the conditions written into its policy are met.
Cloudflare’s product targets a machine-to-machine commerce flow that bypasses conventional account creation and checkout. A software agent could request a paid resource, receive a payment demand, make the payment and obtain access without registering for a subscription or using a human-operated card payment flow.
Cloudflare uses x402 for API payments
Cloudflare Wallets is tied to x402, a payment protocol based on HTTP 402, the long-standing “payment required” web status code. The status code has existed for decades but saw little practical use because web payments generally developed around accounts, cards and subscriptions rather than native payment requests.
Under the x402 model described by Cloudflare, a paid API responds to a request with details including the required payment amount, accepted asset and payment destination. The requesting agent can then submit payment and retry the request with proof of settlement. If the payment satisfies the seller’s conditions, the agent receives the API response or other digital resource.
Cloudflare said its wallet system supports stablecoins including USDC. Using a price-stable token gives an agent a defined spending unit when it is buying services repeatedly, rather than requiring the agent to manage the price fluctuations associated with more volatile cryptoassets.
The setup would support pricing based on individual use instead of monthly plans. A provider could charge for each API call, data query, compute unit or content page. In the example outlined in Cloudflare’s materials, a research agent operating with a 10 USDC budget could test several sources, pay a few cents for each query and stop using a service when its output is not useful.
That structure gives developers a way to monetize services that may be too inexpensive or too irregular for a traditional subscription. It also changes the purchasing logic for agent software: an agent does not need advance approval for a broad vendor relationship if its policy authorizes a narrowly defined payment for a particular request.
MetaMask brings delegated execution on-chain
MetaMask’s Agent Wallet approaches the issue from the trading and defi side. The product lets an agent connect to an on-chain wallet and act within limits chosen by the user. Those limits can include price triggers, gas-fee conditions and the types of protocols the agent may access.
A user could, for example, authorize an agent to buy 0.2 ETH if the asset trades near $3,000 while gas costs remain below their 24-hour average. The agent would monitor the market and network conditions, prepare the transaction and submit it if every condition in the instruction is met.
This design moves beyond the common AI assistant model in which software offers a recommendation but leaves execution to the user. The potential benefit is speed and persistence: an agent can watch conditions continuously and execute without requiring a user to be online at the precise moment a threshold is reached.
The trade-off is that the agent now controls assets, even if only in a limited capacity. On-chain transfers are generally irreversible, so a flawed instruction, bad data source, manipulated prompt or malicious tool request can produce an immediate financial loss rather than an incorrect answer on a screen.
Spending policies become the security boundary
The practical question for these wallet systems is less whether an agent can sign a transaction than whether its authority can be constrained tightly enough for routine use. Cloudflare and MetaMask both frame budgets and permissions as the controls that define an agent’s operating range.
The safeguards described for agent wallets include single-transaction and daily spending caps, protocol allowlists, automated pauses when activity appears abnormal and escalation to human confirmation through two-factor authentication when an action falls outside the established policy.
The imToken team has described a comparable design as “ui 3.0,” where the user shifts from direct operator to manager of an automated account. In its example, a command such as “send Frank 500 USDT” is translated into structured transaction details for review before it proceeds.
imToken’s proposed architecture assigns each authorized agent a separate account and uses a session key isolated in a trusted execution environment, or TEE. A TEE is a protected area of a device’s processor designed to keep sensitive operations and data separated from the rest of the system. The session key can be bound to policies covering recipient allowlists, single-spend limits, daily limits, action frequency and expiry dates.
Its permissions framework ranges from L0 observation, where an agent can only monitor activity, to L1 advice, L2 execution after user confirmation and L3 autonomous execution within defined strategy boundaries. Users retain the ability to change policies, pause an agent, revoke access and retrieve funds.
Wallet interfaces shift toward oversight
Agent-enabled wallets could make transaction history, permission controls and exception handling more prominent than the familiar send-and-receive interface. A user delegating routine payments or trading conditions needs to see what an automated account did, why it acted and whether it remained within its mandate.
That favors separating working balances from long-term holdings. An agent paying for data or executing a narrow trading strategy does not need unrestricted access to a primary wallet. Isolated balances, small budgets and narrowly scoped permissions limit the amount exposed if the agent makes an error or encounters a compromised service.
Frequent transactions also make network fees part of the agent’s policy rather than an afterthought. MetaMask’s use of gas thresholds reflects this issue: a strategy that is profitable under normal network conditions can become uneconomic when transaction fees rise sharply.
Cloudflare Wallets and MetaMask’s Agent Wallet point to the same operational change from different directions. One enables software to buy web services; the other enables it to transact across on-chain markets. In both cases, the wallet becomes an access-control system that determines how much financial authority software receives, where it can use that authority and when it must hand control back to a person.
Want AI agents to trade crypto for you? Explore policy-based automation with Agent TradeKit for secure, rule-driven execution.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

