Skip to main content

Wallet API Overview

The Wallet API provides direct access to wallet operations without going through the AI agent. Use it for reading balances, swapping, transferring, signing transactions, and submitting them on-chain.

Wallet API vs Agent API​

Wallet API (/wallet/*)Agent API (/agent/*)
AuthAny API key for reads; Wallet API (walletApiEnabled) otherwiseAgent API (agentApiEnabled)
OperationsDirect wallet ops (balances, swap, transfer, sign, submit)Natural language prompts → AI execution
LatencyFast (no LLM)Slower (LLM reasoning)
Use whenYou know exactly what to doYou want AI to decide

Base URL​

https://api.bankr.bot

Authentication​

Send an API key as X-API-Key: your_api_key_here (or Authorization: Bearer your_api_key_here). The reads, swap and transfer endpoints also accept a signed-in bankr.bot web session; /wallet/sign, /wallet/submit and /wallet/x402-pay take API keys only.

Access Control​

LayerRead endpointsQuoteWrite endpoints
API key valid + has walletRequiredRequiredRequired
IP allowlist (allowedIps)EnforcedEnforcedEnforced
Wallet API (walletApiEnabled)Not requiredRequiredRequired
Read-only mode (readOnly)AllowedAllowedBlocks with 403
Allowed recipients (allowedRecipients)N/AN/AEnforced per-endpoint

These flags are configured per key — see API Keys for the full reference. Enable Wallet API on a key at bankr.bot/api-keys.

  • Reads — GET /wallet/me and GET /wallet/portfolio work with any valid API key that has an associated wallet.
  • Quote — POST /wallet/swap-quote needs Wallet API but is a read, so read-only keys can use it.
  • Writes — /wallet/swap, /wallet/transfer, /wallet/sign, /wallet/submit and /wallet/x402-pay reject read-only keys with 403. Allowed recipients restrict where funds can go:
    • /wallet/transfer — validates the recipient against the EVM allowlist
    • /wallet/swap — swap output always returns to the caller's wallet; allowedRecipients is not enforced
    • /wallet/sign — blocks eth_signTransaction and eth_signTypedData_v4 (can't verify recipients from calldata); allows personal_sign
    • /wallet/submit — blocks all raw submissions (can't verify recipients from calldata)

The wallet's own security settings (pause, spend limits, permitted recipients, price-impact protection, arbitrary contract calls) apply on top of the key flags — each endpoint page notes which ones it checks.

Rate limit — /wallet/transfer, /wallet/swap, /wallet/sign and /wallet/submit share a cap of about 10 requests per minute per client IP; past it they answer 429.

Endpoints​

MethodEndpointAuthDescription
GET/wallet/meAny API keyWallet info, socials, club status
GET/wallet/portfolioAny API keyToken balances, PnL, NFTs
POST/wallet/swap-quoteWallet APIQuote a swap (EVM, Solana, cross-chain)
POST/wallet/swapWallet APIExecute a swap (EVM, Solana, cross-chain)
POST/wallet/transferWallet APIDirect ERC20/native transfer (EVM only)
POST/wallet/signWallet APISign messages and transactions
POST/wallet/submitWallet APISubmit + broadcast transactions
POST/wallet/x402-payWallet APIFetch an x402-paid URL, paying up to $10

Full request and response schemas for every endpoint are in the OpenAPI spec.

CLI​

bankr wallet                          # Show wallet info (whoami)
bankr wallet portfolio # Token balances
bankr wallet portfolio --pnl # With profit/loss
bankr wallet portfolio --nfts # With NFT holdings
bankr wallet portfolio --all # Everything
bankr wallet swap --from ETH --to USDC --amount 0.01
bankr wallet transfer --to 0x... --amount 10 --token USDC
bankr wallet sign -t personal_sign -m "hello"
bankr wallet submit tx --to 0x... --chain-id 8453