Connect Bankr to Meta Muse
Give Meta Muse a crypto wallet it can check, trade from and automate with. The API key lives in Muse's secure credentials store, never in chat, and belongs to a dedicated low-privilege wallet so a leak stays contained.
What you get
Muse builds its own connector from the Bankr skill and CLI. Once your API key sits in Muse's secure credentials store, you can say things like:
- "What's my Bankr wallet balance?"
- "Quote swapping $25 of USDC to ETH on Base, don't execute yet."
- "Send 10 USDC to vitalik.eth."
- "Set up a DCA into ETH every Monday with Bankr."
Before you start
Create a separate Bankr account for Muse instead of using your main one, fund it with only what Muse needs, and give it a least-privilege key. If the key leaks or Muse misreads an instruction, only that wallet is affected.
| What Muse does for you | Key setup |
|---|---|
| Prices, balances, research, alerts | Read-only, no token launch, no funding needed |
| Swaps and transfers to known addresses | Read-write, no token launch, recipient allowlist, small balance |
| Automations, Polymarket, open-ended asks | Read-write, no token launch, leave recipient allowlist empty, small balance |
New keys are read-write with wallet, agent and token-launch access all on, which is more than Muse usually needs. Add an IP allowlist if Muse's VM has a stable egress IP. Every flag and what it blocks: API Keys.
Connect in Muse
Paste this into Muse to have it set everything up:
Connect Bankr to my account: read https://bankr.bot/skill.md and follow it. When you
need my API key, ask me to add it to your secure credentials store as BANKR_API_KEY —
never ask me to paste it into chat.
Per Meta's published Muse security model, the secure credentials store hands the agent a surrogate token and swaps in the real key at the network boundary, so Muse never sees the key itself. Anything pasted into chat becomes part of the conversation and should be treated as leaked. Neither path below has Muse read the key.
Create a key for Muse (recommended)
Give Muse its own key rather than sharing one. A key that lives in exactly one place is the one you can revoke without breaking anything else — so do not hand Muse a key another machine is already using.
- Create a key at bankr.bot/api-keys with the flags from the table above.
- When Muse shows its secure credentials card, add it as
BANKR_API_KEY. The Bankr CLI reads that variable, so no login command runs in the VM. - Ask Muse to run
bankr whoami. It should print the dedicated account's wallet address.
Create the key from inside Muse
Headless email login lets Muse mint a key without leaving the chat. The CLI saves that key to ~/.bankr/config.json on the VM, which is the wrong place for it to stay, so finish by rotating it: the store gets a fresh key Muse never read, and the on-disk copy dies with the rotation.
-
Ask Muse to run
bankr login email you@example.com. Bankr emails you a code. -
Give Muse the code to finish the login, with the same restrictions you would pick on the dashboard — flags are listed in the CLI reference. Completing a headless login accepts the Terms of Service on the account's behalf.
bankr login email you@example.com --code 123456 --accept-terms \
--key-name "Muse" --read-only --no-token-launch -
Open bankr.bot/api-keys, find the key named "Muse" and click Rotate Key. Add the new key to Muse's secure credentials card as
BANKR_API_KEY. -
Run
bankr logoutto delete the stale on-disk copy, thenbankr whoami. The CLI prefersBANKR_API_KEYover the file, so this check proves the secure store is wired up.
Muse may suggest minting a fresh key "with the same permissions" for the secure store. Decline. Rotate the key it just created instead. A second key doubles the surface you have to revoke later, and the original stays live on disk until someone remembers it.
How Muse should call Bankr
The skill covers this: typed CLI commands for anything deterministic, bankr agent "<prompt>" for asks that need judgement.
REST is equivalent if Muse would rather build its own connector. The base URL is https://api.bankr.bot and every call authenticates with the same key in an X-API-Key header — no OAuth, no token exchange. See the Agent API and Wallet API, the OpenAPI spec at https://docs.bankr.bot/openapi/api.yaml, or https://docs.bankr.bot/llms.txt.
Safety and approvals
Ask Muse to surface every trade and transfer for your approval, and to run swaps --quote-only first. Beyond that, the key's own limits are the real ceiling: a read-only key refuses swaps, transfers and signing whatever Muse is asked, and pausing the wallet at bankr.bot → Security halts outbound transactions immediately. See API Keys for read-only behaviour, allowlists and incident response.
Troubleshooting
- The key ended up in chat. Treat it as leaked: pause the wallet at bankr.bot → Security, rotate the key at bankr.bot/api-keys (the old one dies with it) and add the new key through the secure credentials card only.
bankr whoamiworks but Muse still asks for the key. The CLI is reading~/.bankr/config.json. Rotate the key, add the new one to the secure store, then runbankr logoutso only the stored variable remains.