Skip to main content

Custody

Each agent gets an isolated Privy-managed Stellar wallet. Signing happens only inside the Hub after policy (and optional human confirmation) pass. The token authorizes tool calls. It cannot sign Stellar transactions by itself.
Never put a Stellar secret key (S…) in MCP config, env files, or prompts.
If a token leaks, revoke it on Connect and create a new one. Funds stay behind Hub policy.