Skip to main content
Before you link a wallet, choose a custody mode. It answers two separate questions:
  1. Custody. Who can sign the transfer?
  2. Enforcement. Can Conto actually stop the transfer, or only govern the path that goes through Conto?

Quick comparison

What policies mean in each mode

Managed wallets

Managed wallet flow. The agent requests a payment, Conto checks the owner's policy, the owner's approver decides only when the payment needs review, the managed wallet sends the funds, and the payment is logged with full context. Managed wallet flow. The agent requests a payment, Conto checks the owner's policy, the owner's approver decides only when the payment needs review, the managed wallet sends the funds, and the payment is logged with full context. The wallet provider holds the private key for a managed wallet, and Conto never stores it. Conto signs only after your policies and approvals pass, and you choose who holds root control when you create the wallet.
  • Conto evaluates the payment.
  • If approved, Conto orchestrates execution.
  • If denied, the payment does not execute through Conto.
  • The agent calls POST /api/sdk/payments/request, then POST /api/sdk/payments/{id}/execute, or passes autoExecute: true on the request.
Create a managed wallet in the dashboard or use POST /api/wallets with custodyMode=MANAGED. Set controlModel to ORGANIZATION_CONTROLLED or CONTO_MANAGED. If you omit it, the wallet is organization-controlled when your organization has registered an owner key, and Conto-managed otherwise. The selection is fixed for the new wallet. Changing the organization default never migrates an existing wallet.

Managed control models

Organization-controlled (ORGANIZATION_CONTROLLED)
  • Your organization’s owner key is the root owner. Only your organization holds it.
  • Conto is a separate signer and signs only after your policies and approvals pass. On EVM, the wallet provider also limits what Conto’s signer can do.
  • Your owner can manage the wallet and approve a key export.
  • Conto cannot stop everything. The owner key can authorize actions outside Conto, and an exported key can sign outside Conto.
Conto-managed (CONTO_MANAGED)
  • A Conto authorization key is the root owner.
  • Conto is the only signer and signs only after your policies and approvals pass.
  • There is no self-service key export.
  • There is no customer signing path outside Conto.
For organization-controlled creation, an organization owner first registers a base64 SPKI P-256 public key in Settings → Wallet Control and keeps the matching private key in the customer’s own key manager. Conto never receives or stores that private key. Your owner key alone forms the owner quorum that holds root control, and Conto is added separately as an additional signer. Organization-controlled wallets are EVM only. For Solana, create the wallet with controlModel: "CONTO_MANAGED".

External (watch-only) wallets

Agent-controlled wallet flow. The agent asks Conto to authorize a payment, Conto checks the owner's policy, the owner's approver decides only when the payment needs review, the agent's own signer sends the transaction within 10 minutes, and the agent confirms the transaction ID so Conto can record it. Agent-controlled wallet flow. The agent asks Conto to authorize a payment, Conto checks the owner's policy, the owner's approver decides only when the payment needs review, the agent's own signer sends the transaction within 10 minutes, and the agent confirms the transaction ID so Conto can record it. When you import a wallet, Conto registers it in EXTERNAL mode. You keep the keys, and your agent or wallet stack signs the transaction.
  • Conto can still evaluate policies before the transfer.
  • Conto can still require approval, record the payment, and keep the audit trail.
  • The agent calls POST /api/sdk/payments/approve, sends the transfer with its own signer or wallet, then calls POST /api/sdk/payments/{id}/confirm.
  • Conto cannot cryptographically block a direct transfer signed outside Conto.
You can register an external wallet directly with custodyMode=EXTERNAL plus address, or use the watch-only import flow in the dashboard. Without a chain, the API records the address on its default chain (Tempo Testnet). For a Solana address, also send chainType: "SOLANA" and chainId (solana-mainnet or solana-devnet). The dashboard import detects a Solana address and asks for the network.

How to choose

  • Pick Organization-controlled managed if you need customer root administration or an export path while keeping Conto as the normal signer after Conto policies and approvals.
  • Pick Conto-managed if you want Conto to remain the only product signing path and do not need customer self-service export.
  • Pick External if you already have a wallet stack, MPC signer, or agent-held wallet and want to keep that setup.

Export a wallet key

An organization Owner can export the private key of an organization-controlled managed wallet. The export is owner-authorized and end-to-end encrypted. Conto relays the signed request and returns only HPKE ciphertext, and never receives the customer owner private key, the HPKE recipient private key, or the plaintext wallet key. This flow is not available for CONTO_MANAGED wallets.

Before you start

You need two customer-controlled P-256 keys with different purposes:
  1. The owner authorization key registered in Settings → Wallet Control. Keep its private half in your KMS or offline signing environment.
  2. A new HPKE recipient key for this export. Keep its private half outside Conto. Conto receives only its base64 SPKI public key.
Anyone with the decrypted wallet key can sign outside Conto and bypass Conto policies. Treat the export as a high-risk governance action and secure the resulting key accordingly.

Export from the dashboard

  1. Sign in as the organization Owner.
  2. Open Wallets, open the organization-controlled wallet menu, and select Export encrypted key.
  3. Paste the HPKE recipient public key and choose Prepare owner authorization.
  4. Copy and base64-decode the authorization payload. Sign the decoded bytes outside Conto with the registered owner authorization private key using ECDSA P-256 with SHA-256 and DER encoding.
  5. Paste the base64 DER signature and download the encrypted export before the displayed expiry.
  6. Decrypt ciphertext using encapsulatedKey, the HPKE recipient private key, and this suite: DHKEM(P-256, HKDF-SHA256) / HKDF-SHA256 / ChaCha20-Poly1305.
For a base64 PKCS8 owner authorization private key, this TypeScript snippet prints the signature the dialog expects. Save it as sign.ts and run npx tsx sign.ts with both environment variables set:
Conto does not keep the ciphertext or the key. A successful export sets the wallet’s keyAccess to EXPORTED and writes an audit event. If Conto cannot confirm the result, keyAccess shows EXPORT_RECONCILIATION_REQUIRED, and the next export request checks the provider’s export record before it continues.

Operational boundaries

  • The authorization payload covers this wallet, this recipient key, and this request, and expires after 10 minutes.
  • Only an authenticated organization Owner can prepare or submit an export.
  • Conto’s additional-signer key cannot authorize export or administer the customer owner quorum.
  • Conto can continue signing through its normal policy and approval path after export, but the exported key also permits signing outside Conto.

Choose your integration

Compare SDK, OpenClaw, Hermes, x402, and MPP

Payments API

See the managed and external payment flows