PocketDocs

Privy

Where the keys live. Your agent never holds one, and neither does Pocket.

Privy holds every agent wallet. Pocket never sees a private key, and no signing material reaches your agent, the database, or a log line.

The same account also signs you in to the dashboard, so there is no second set of credentials to manage.

What crosses the line

The only thing that ever crosses is a signature. There is no path in Pocket that could export a key, because the ability to do so is explicitly switched off on every wallet it creates.

Two ceilings, not one

Your limits in Pocket are the first ceiling. Underneath them, each wallet carries a second set of rules held by Privy.

That means a bug in Pocket cannot on its own authorise an unbounded transfer, because Privy would refuse to sign it. You get two independent things that both have to fail before money moves incorrectly.

Signing in

Email, Google, GitHub, or a wallet you already have. The first time you sign in, your organization and its first API key are created together.

On this page