How it works
- Your agent calls a Nebula tool over MCP (local
nebulamcp-stdioor remotePOST /mcp). - The Hub authenticates the
nbl_live_…token (or OAuth) and loads that agent’s wallet and policy for its network. - Policy runs (caps, allow/deny, pause). Some actions return
confirmation_requireduntil you approve in the dashboard. - The Hub signs with Privy custody and submits to Stellar. The agent never sees a secret key.