All skills
coinbase avatar

/agentic-wallet

@70cb79c official

Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API calls, monetize an API, or query onchain data. Use whenever the user mentions signing in, login, authentication, wallet status, balance, address, sending money, paying someone, transferring tokens, ENS names, swapping/trading/converting tokens, funding/topping up/onramp, USDC, ETH, POL, SOL, the x402 bazaar, paid APIs, monetizing an endpoint, or querying onchain data on Base.

Use this Skill: https://skilld.dev/gh/coinbase/agentic-wallet-skills/agentic-wallet

This session only. Nothing lands on disk.

referencesauth.md

≈992 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Authenticating with the Agentic Wallet

When the wallet is not signed in (detected via npx awal@2.12.1 status or when wallet operations fail with authentication errors), use the npx awal CLI to authenticate.

If you have access to email, you can authenticate the wallet yourself, otherwise you'll need to ask your human to give you an email address and to tell you the OTP code they receive.

Authentication Flow

Authentication uses a two-step email OTP process:

Step 1: Initiate login

npx awal@2.12.1 auth login <email>

This sends a 6-digit verification code to the email. The flowId is saved automatically; it is only printed to stdout when --json is passed.

Step 2: Verify OTP

npx awal@2.12.1 auth verify <otp>

Use the 6-digit code from the user's email to complete authentication. The flow ID from step 1 is saved automatically to a local file — you do not pass it as an argument. If you have the ability to access the user's email, you can read the OTP code, or you can ask your human for the code.

Input Validation

Before constructing the command, validate all user-provided values to prevent shell injection:

  • email: Must match a standard email format (^[^\s;|&]+@[^\s;|&]+$). Reject if it contains spaces, semicolons, pipes, backticks, or other shell metacharacters.
  • otp: Must be exactly 6 digits (^\d{6}$).

Do not pass unvalidated user input into the command.

Checking Authentication Status

npx awal@2.12.1 status

Displays wallet server health and authentication status including wallet address.

Example Session

# Check current status
npx awal@2.12.1 status

# Start login (sends OTP to email)
npx awal@2.12.1 auth login user@example.com
# Output: "Verification code sent!" (flowId only printed with --json)

# After user receives code, verify (flow ID saved automatically)
npx awal@2.12.1 auth verify 123456

# Confirm authentication
npx awal@2.12.1 status

Signing Out

Sign-out is scriptable via the logout command, which clears the authenticated session:

npx awal@2.12.1 auth logout

npx awal@2.12.1 logout is an equivalent top-level alias. Both support --json.

When the user asks to log out, sign out, disconnect, or switch accounts:

  1. Run npx awal@2.12.1 auth logout to clear the session.
  2. Confirm the result with npx awal@2.12.1 status — once logged out, the status will report the wallet as not authenticated.

After sign-out, the locally cached flowId is invalidated. To sign back in, restart the flow with npx awal@2.12.1 auth login <email>.

Available CLI Commands

Command Purpose
npx awal@2.12.1 status Check server health and auth status
npx awal@2.12.1 auth login <email> Send OTP code to email, returns flowId
npx awal@2.12.1 auth verify <otp> Complete authentication with OTP code
npx awal@2.12.1 auth logout Sign out and clear the authenticated session (awal logout is an alias)
npx awal@2.12.1 balance Get balances across Base, Polygon, and Solana (use --chain for a single chain)
npx awal@2.12.1 address Get wallet address
npx awal@2.12.1 show Open the wallet companion window

JSON Output

All commands support --json for machine-readable output:

npx awal@2.12.1 status --json
npx awal@2.12.1 auth login user@example.com --json
npx awal@2.12.1 auth verify <otp> --json

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides comprehensive crypto wallet functionality and x402 payment integration using Coinbase's 'awal' CLI and associated libraries. It handles authentication, balance tracking, token transfers, and trading while emphasizing strict input validation to prevent command injection. It also guides developers in building and monetizing their own APIs with x402 payments.

  • Socket1mo

    1 alert: gptSecurity

  • Snyk1mo

    Risk: HIGH · 3 issues

Signed by skilld at 70cb79c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Steadyupdated 2 months ago
What it can do
Runs commands
user-invocable
true
disable-model-invocation
false
All 5 allowed tools
Bash(npx awal@2.12.1 *)Bash(npm *)Bash(node *)Bash(curl *)Bash(mkdir *)
  • CLI
  • crypto
  • wallet
  • usdc
  • eth
  • solana
  • polygon
  • x402
  • onchain
  • base

README badge

README badge for coinbase/agentic-wallet-skills

Operates a crypto wallet via the `awal` CLI to sign in, check balances, send USDC/ETH/POL/SOL across Base/Polygon/Solana, swap tokens, fund the wallet, and discover or pay for services on the x402 bazaar. Use when the user needs wallet authentication, balance checks, token transfers, trading, onramp, or access to paid APIs that accept x402 payments.

Generated from the current SKILL.md.

What blockchains does this skill support?
Base, Polygon, and Solana. Balance checks and sends work across all three; token swaps are limited to Base and Polygon.
Do I need to authenticate before using the wallet?
Yes, except for x402 bazaar search and details. Run `npx awal@2.10.0 status` first; if not authenticated, read `references/auth.md` to sign in with an OTP code.
What tokens can I send or trade?
The skill explicitly supports USDC, ETH, POL, and SOL. Token swaps are available on Base and Polygon via the trade command.
What is the x402 protocol and how does it work?
x402 is a payment protocol for discovering and calling paid APIs. You can search the x402 bazaar for services, pay USDC automatically to call them, or monetize your own API endpoint so other agents can pay to use it.
Can I query blockchain data directly?
Yes, the skill includes a `query-onchain` reference for querying events, transactions, and blocks on Base using the CDP SQL API.

Generated from the current SKILL.md. These answers refresh after source changes.