Select Page

Cloudflare Wallets

Cloudflare Wallets

https://cloudflare.com/agents

Free to create wallets; spending funded by stablecoin balance in Account Wallet

Account Wallets — Human-controlled, holds stablecoin funds, creates and configures Virtual Wallets, sets spending rules
Virtual Wallets — API-key-driven agent spending accounts with enforced controls: allowance, seller allow list, per-transaction max
x402 Protocol — Open HTTP micropayment standard, stablecoin settlement, sub-cent per-request fees, sub-second finality
cloudflare.pay Identity — Optional human-readable handles for agents (e.g. research.example.cloudflare.pay) built on Web Bot Auth keypairs
Monetization Gateway Integration — Seamless payment to any x402-compatible endpoint from Cloudflare or third parties
Spending Policy Enforcement — Account Wallet owners set policies; anomalous spending triggers human review; caps adjustable on demand
20+ Early Adopters — More than 20 companies participating in agent-initiated payment flows at launch
Two-Wallet Architecture — Custody (Account Wallet) separated from spending (Virtual Wallet) — right abstraction for organizational agent budgets
Agent-Native Identity — Raw keypair identity made human-readable via DNS-like handle system; optional disclosure; merchant选择性
API Key Authentication — Virtual Wallets authenticate via API key, matching how agents already interact with services

Solves a real, unresolved problem: every production agent hits the API payment wall — first serious infrastructure-layer answer
Sound architecture: two-wallet model (custody/spending), x402 stablecoin rails, infrastructure-enforced limits
Limits enable autonomy: spending caps give agents defined budgets to explore within without unbounded exposure
Identity layer is thoughtful: cloudflare.pay handles solve agent identity without forcing disclosure
Built on live rails: x402 had processed $41M+ before launch — proven protocol before managed wallet product
Complements existing stack: works with Cloudflare Agents SDK, Monetization Gateway, and any x402-compatible endpoint
Address the prompt-injection risk: Virtual Wallet caps are a financial backstop against compromised agent spending
Early traction: 20+ companies already participating in agent-initiated payment flows at launch

Not GA yet: wallet funding, Virtual Wallets, and programmable spending still rolling out over coming months
No hands-on testing possible: cannot verify actual UX, API design, or limit enforcement until rollout
Stablecoin-only settlement: requires crypto on/off ramps — not accessible to organizations without that infrastructure
Geographic restrictions: on/off ramp options are geography-dependent
Agentic identity standards still immature: cloudflare.pay is a proposal, not a settled standard
Sequence limits not yet defined: individual payment caps exist but multi-step drain attack prevention not yet documented