Skip to main content
The agent links to your Proofable profile and defaults to your signed-in account. Add a separate spend account and limits only when you need them. Leave out controllerWallet when the signed-in account from proofable_context should own the agent. Ask:
Create or import an agent on my Proofable profile. Give it a separate spend account if it needs one. Set spend and action limits. Then confirm it is ready.
Agent concepts Inspect a package, repo, or card with the agent import HTTP routes, then call proofable_agent_create with the mapped fields. There is no separate import tool.

Account options

Signed-in profile (default)

Omit agentWallet. The agent lives on your signed-in account. Identity is enough. Several agents on one account need agentId on every link and mount call.

Dedicated account

Proofable does not generate or hold private keys. Create the account in your wallet or secure runtime, then pass only its public address as agentWallet.
Use a dedicated account when you want independent spend, revocation, or offboarding without touching your profile account.

Bring an existing account

Pass an existing agentWallet. The agent account signs identity. The approving profile signs spend and action limits. When the signed-in account does not control that key:
  1. Sign and submit the returned identity step with the agent key.
  2. Repeat proofable_agent_create unchanged.
  3. The approving account completes permissions in-session or through the returned hosted URL.
A controller session cannot self-attest for a different agent account, so identity always comes first.

What each result means

Every non-validation result includes path and next_action. sessionProgress.identityComplete, delegationRequired, and delegationComplete show which step is required and already saved. On payment_required, add credits and retry the same request. This is an account billing requirement, not a signature failure.

Hosted callback

Use the SDK helper instead of assembling query strings:
With identityQHash, Hosted Verify requests only permissions. The callback receives the new permission qHash, agentId, and agentWallet. Keep the identity qHash from step 1. Do not combine agent creation with gateId or intent=login on one URL:
  • Login: intent=login&returnUrl=...
  • Gate checkout: gateId=...&returnUrl=...
  • Agent setup: getHostedAgentCreateUrl(...)

Billing

Billing follows the signer for each proof unless a validated sponsor or pay-per-call proof overrides it:
  • Agent identity: the agent account pays.
  • Permissions (separate spend account only): the approving profile pays.
  • Hosted completion: the signed-in account pays for the step it signs.
  • Sponsor grant or pay-per-call: the validated sponsor/caller pays.
Hosted sign-in itself is free. See Pricing. Optional fields include instructions, skills, services, scope, expiry, spend cap, runtime policy, approval policy, and allowed/denied actions. See Agent identity and Agent delegation. Auth, Agent link, Overview, Verify an agent
Last modified on September 15, 2026