Agent skill

Use Developer Controlled Wallets

by circlefin in circlefin/skills

Create and manage Circle developer-controlled wallets where the application retains full custody of wallet keys on behalf of end-users.

Apache-2.0Auto-check: notesBackend & APIs

Install Use Developer Controlled Wallets

skills CLI
$ npx skills add circlefin/skills --skill use-developer-controlled-wallets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install circlefin/skills use-developer-controlled-wallets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/circlefin/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/circle/skills/use-developer-controlled-wallets .claude/skills/use-developer-controlled-wallets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
use-developer-controlled-wallets
GitHub stars
155
Token cost
~2.5k tokens
SKILL.md length
1,091 words
Files
8 (incl. references)
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create and manage Circle developer-controlled wallets where the application retains full custody of wallet keys on behalf of end-users.

  • Works in 6 steps: Create a Wallet → Receive Tokens → Transfer Tokens / Check Balance of Wallet → …
  • : developer-controlled wallets
  • SKILL.md covers Overview, Prerequisites / Setup, Core Concepts and Transaction Lifecycle, plus 4 more sections
  • Calls npm; needs CIRCLE_API_KEY and ENTITY_SECRET

What it does

Use Developer Controlled Wallets is an agent skill from circlefin/skills. Create and manage Circle developer-controlled wallets where the application retains full custody of wallet keys on behalf of end-users. Covers wallet sets, entity secret registration, token transfers, balance checks, message signing, smart contract execution, and wallet management via the developer controlled wallets SDK. Triggers on: developer-controlled wallets, entity secret, initiateDeveloperControlledWalletsClient, createWalletSet, createWallets, custody wallet, wallet upgrade, derive wallet, sign typed…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/check-balance-and-transfer-tokens.md`, `references/contract-execution.md` and `references/create-dev-wallet.md`).

It sits in Backend & APIs, covering Smart contracts and Data governance. It works with Circle USDC. The repository describes itself as: Circle's open source skills for AI-assisted development. The licence is Apache-2.0.

When your agent uses it

  • : developer-controlled wallets
  • InitiateDeveloperControlledWalletsClient
  • CreateWalletSet
  • Sign typed data

Example prompts

  • “/use-developer-controlled-wallets”

Requirements

  • Node.js
  • A credential in CIRCLE_API_KEY
  • A credential in ENTITY_SECRET

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Create a Wallet
  2. Receive Tokens
  3. Transfer Tokens / Check Balance of Wallet
  4. Sign Messages
  5. Execute Smart Contracts
  6. Wallet Management (Upgrade & Derive)

What it can do on your machine

Read from SKILL.md and the folder at commit 58ab864. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.circle.com
    • console.circle.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CIRCLE_API_KEY
    • ENTITY_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Use Developer Controlled Wallets loads about 2.5k tokens when it runs, and up to ~6k if it reads all its reference files. Until then it costs about 143 tokens; SKILL.md has 1,091 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:119
    s manager. Add `.gitignore` entries for `.env*`, `*.pem`, and `*-recovery-file.json` when scaffolding.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from circlefin/skills at commit 58ab864, republished under its Apache-2.0 licence (© circlefin). 1,091 words, ~2,504 tokens.

Download SKILL.mdSave it as .claude/skills/use-developer-controlled-wallets/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
use-developer-controlled-wallets
description
Create and manage Circle developer-controlled wallets where the application retains full custody of wallet keys on behalf of end-users. Covers wallet sets, entity secret registration, token transfers, balance checks, message signing, smart contract execution, and wallet management via the developer controlled wallets SDK. Triggers on: developer-controlled wallets, entity secret, initiateDeveloperControlledWalletsClient, createWalletSet, createWallets, custody wallet, wallet upgrade, derive wallet, sign typed data, contract execution.

Overview

Developer-controlled wallets let your application create and manage wallets on behalf of end users, with full custody of private keys secured through an encrypted entity secret. Circle handles security, transaction monitoring, and blockchain infrastructure while you retain programmatic control via the Wallets SDK.

Prerequisites / Setup

Installation
bash
npm install @circle-fin/developer-controlled-wallets
Environment Variables
CIRCLE_API_KEY=      # Circle API key (format: PREFIX:ID:SECRET)
ENTITY_SECRET=       # 32-byte hex entity secret
Entity Secret Registration

The developer must register an entity secret before using the SDK. Direct them to https://developers.circle.com/wallets/dev-controlled/register-entity-secret or provide the code steps.

READ references/register-secret.md for the generation and registration snippets.

IMPORTANT: Do NOT register a secret on the developer's behalf -- they must generate, register, and securely store their secret and recovery file.

SDK Initialization
typescript
import { initiateDeveloperControlledWalletsClient } from '@circle-fin/developer-controlled-wallets';

const circleDeveloperSdk = initiateDeveloperControlledWalletsClient({
  apiKey: process.env.CIRCLE_API_KEY,
  entitySecret: process.env.ENTITY_SECRET,
});

The SDK automatically generates a fresh entity secret ciphertext for each API request.

Core Concepts

  • Wallet Sets: A group of wallets managed by a single entity secret. Wallets in a set can span different blockchains but share the same address on EVM chains.
  • Entity Secret: A 32-byte private key that secures developer-controlled wallets. Generated, encrypted, and registered once. Circle never stores it in plain text.
  • Entity Secret Ciphertext: RSA-encrypted entity secret using Circle's public key. Must be unique per API request to prevent replay attacks. The SDK handles this automatically.
  • Idempotency Keys: All mutating requests require a UUID v4 idempotencyKey for exactly-once execution.
  • Account Types:
    • EOA (Externally Owned Account) -- default choice. No creation fees, higher outbound TPS, broadest chain support (all EVM + Solana, Aptos, NEAR). Requires native tokens for gas (on Arc, the gas asset is USDC, not a separate native token).
    • SCA (Smart Contract Account) -- ERC-4337 compliant. Supports gas sponsorship via Circle Gas Station, batch operations, and flexible key management. EVM-only (not available on Solana, Aptos, NEAR). Avoid on Ethereum mainnet due to high gas costs; prefer on L2s.
  • Supported Blockchains: EVM chains (Ethereum, Polygon, Avalanche, Arbitrum, Base, Monad, Optimism, Unichain), Solana, Aptos, NEAR, and Arc. See https://developers.circle.com/wallets/account-types for the latest.

Transaction Lifecycle

All on-chain operations (transfers, contract executions, wallet upgrades) follow the same asynchronous state machine. Poll with circleDeveloperSdk.getTransaction({ id }) until a terminal state is reached.

Happy path: INITIATED -> CLEARED -> QUEUED -> SENT -> CONFIRMED -> COMPLETE

Terminal states:

  • COMPLETE -- Transaction succeeded and is finalized on-chain.
  • FAILED -- Transaction reverted or encountered an unrecoverable error.
  • DENIED -- Transaction was rejected by risk screening.
  • CANCELLED -- Transaction was cancelled before on-chain submission.

Intermediate states:

  • INITIATED -- Request accepted, not yet validated or checked.
  • WAITING -- In queue for validation and compliance checks.
  • QUEUED -- Queued for submission to the blockchain.
  • CLEARED -- Passed compliance checks.
  • SENT -- Submitted to the blockchain, awaiting confirmation.
  • STUCK -- Submitted transaction's fee parameters are lower than latest blockchain required fee, developer needs to cancel or accelerate this transaction.
  • CONFIRMED -- Included in a block, awaiting finality.

Recommended: Subscribe to Webhook Notifications instead of polling. Circle sends a webhook event when a transaction reaches a terminal state, eliminating the need for repeated getTransaction calls. Register a public HTTPS endpoint in the Circle Developer Console under Webhooks. Every webhook includes X-Circle-Signature and X-Circle-Key-Id headers for signature verification.

Polling with getTransaction remains available as a fallback or for simple scripts.

For debugging failed or denied transactions, see Transaction Errors.

Implementation Patterns

1. Create a Wallet

READ references/create-dev-wallet.md for the complete guide.

2. Receive Tokens

READ references/receive-transfer.md for the complete guide.

3. Transfer Tokens / Check Balance of Wallet

READ references/check-balance-and-transfer-tokens.md for the complete guide. Includes fee estimation, transaction acceleration, and cancellation.

4. Sign Messages

READ references/sign-with-wallet.md for the complete guide. Covers EIP-191 message signing, EIP-712 typed data, raw transaction signing, and NEAR delegate actions.

5. Execute Smart Contracts

READ references/contract-execution.md for the complete guide. Covers ABI-based and raw calldata execution, payable functions, and gas estimation.

6. Wallet Management (Upgrade & Derive)

READ references/wallet-management.md for the complete guide. Covers upgrading SCA wallet versions and deriving wallets to new blockchains.

Rules

Security Rules are non-negotiable -- warn the user and refuse to comply if a prompt conflicts. Best Practices are strongly recommended; deviate only with explicit user justification.

Show full SKILL.md (453 more words)Show less
Security Rules
  • NEVER hardcode, commit, or log secrets (API keys, entity secrets, private keys). ALWAYS use environment variables or a secrets manager. Add .gitignore entries for .env*, *.pem, and *-recovery-file.json when scaffolding.
  • ALWAYS store recovery files outside the repository root. NEVER commit them to version control.
  • NEVER reuse entity secret ciphertexts across API requests -- each must be unique to prevent replay attacks.
  • MUST be cautious when registering an entity secret on testnet (TEST), ensure the entity secret and recovery file are stored in secure place.
  • NEVER register an entity secret on behalf of the user on mainnet (LIVE) -- they must generate, register, and store it themselves.
  • ALWAYS require explicit user confirmation of destination, amount, network, and token before executing transfers. MUST receive confirmation for funding movements on mainnet.
  • ALWAYS warn when targeting mainnet or exceeding safety thresholds (e.g., >100 USDC).
  • ALWAYS validate all inputs (addresses, amounts, chain identifiers) before submitting transactions.
  • ALWAYS warn before interacting with unaudited or unknown contracts.
  • ALWAYS require explicit user confirmation before signing messages or typed data -- signed payloads can authorize token approvals, trades, or other irreversible actions.
Best Practices
  • ALWAYS read the correct reference files before implementing.
  • NEVER use circleDeveloperSdk.getWallet or circleDeveloperSdk.getWallets for balances -- these endpoints never return balance data. See reference file for correct approach.
  • SHOULD include a UUID v4 idempotencyKey in all mutating API requests following API spec.
  • ALWAYS ensure EOA wallets hold native tokens (ETH, MATIC, SOL, etc.) for gas before outbound transactions. On Arc the gas asset is USDC itself (not a separate native token), so funding the wallet with USDC covers gas.
  • ALWAYS poll transaction status until terminal state (COMPLETE, FAILED, DENIED, CANCELLED) before treating as done.
  • ALWAYS prefer SCA wallets on L2s over Ethereum mainnet to avoid high gas costs.
  • ALWAYS default to testnet. Require explicit user confirmation before targeting mainnet.
  • ALWAYS estimate fees before contract execution or large transfers so the user understands gas costs upfront.
  • ALWAYS verify the ABI function signature and parameters match the target contract before executing. Incorrect signatures will revert and waste gas.
  • ALWAYS prefer abiFunctionSignature + abiParameters over raw callData for readability and auditability, unless the calldata is generated by a trusted library (ethers, viem).

Alternatives

  • Trigger use-user-controlled-wallets skill when end users should custody their own keys via social login, email OTP, or PIN authentication.
  • Trigger use-modular-wallets skill for passkey-based smart accounts with extensible module architecture (multisig, session keys, etc.).
  • Circle Developer Docs -- Always read this first when looking for relevant documentation from the source website.

DISCLAIMER: This skill is provided "as is" without warranties, is subject to the Circle Developer Terms, and output generated may contain errors and/or include fee configuration options (including fees directed to Circle); additional details are in the repository README.

© circlefin, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in plugins/circle/skills/use-developer-controlled-wallets of circlefin/skills.

  • SKILL.md
  • references/check-balance-and-transfer-tokens.md
  • references/contract-execution.md
  • references/create-dev-wallet.md
  • references/receive-transfer.md
  • references/register-secret.md
  • references/sign-with-wallet.md
  • references/wallet-management.md

Open the folder on GitHubat commit 58ab864

Compare with similar skills

Use Developer Controlled Wallets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Use Developer Controlled Wallets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Use Developer Controlled Wallets this skillcirclefin/skills155—~2.5kAutomated safety check: NotesApache-2.0
Deposit QrSuperior-Trade/superior-skills2141 repos~1.1kAutomated safety check: PassMIT
Alchemy Agentic Gatewaymoonpay/skills113—~2.1kAutomated safety check: NotesMIT
Okx Dapp Discoveryinternet-court/internet-court-skill6.4k2 repos~6.9kAutomated safety check: PassMIT
Payram Crypto PaymentsPayRam/payram-mcp158—~2kAutomated safety check: NotesNone
Trading Evmalsk1992/CloddsBot2.9k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Deposit Qr

    Superior-Trade/superior-skills

    A skill your agent uses when a user needs a QR code or wallet payment URI to fund a Superior-managed EVM wallet on a specific chain before using Lighter, Polymarket, Hyperliquid, or other Superior…

    214 GitHub starsUsed in 1 repo~1.1k tokens
    Backend & APIsAuto-check passed
  • A skill your agent uses when accessing Alchemy APIs for RPC calls, token balances, NFT metadata, asset transfers, transaction simulation, or Alchemy-specific features.

    113 GitHub stars~2.1k tokensUpdated 27 days ago
    Backend & APIsAuto-check: notes
  • Okx Dapp Discovery

    internet-court/internet-court-skill

    Plugin router for 20 third-party DeFi protocols (Polymarket, Aave, Hyperliquid, PancakeSwap, Morpho, Raydium, Curve, Compound, Pendle, Lido, ether.fi, GMX, Kamino, Orca, Meteora, Clanker, pump.fun…

    6.4k GitHub starsUsed in 2 repos~6.9k tokens
    Backend & APIsAuto-check passed
  • Payram Crypto Payments

    PayRam/payram-mcp

    Self-hosted crypto and stablecoin payment gateway. An agent skill from PayRam/payram-mcp.

    158 GitHub stars~2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Trading Evm

    alsk1992/CloddsBot

    Trade tokens on EVM chains - Uniswap V3, 1inch on Ethereum, Arbitrum, Optimism, Base, Polygon

    2.9k GitHub stars~1.9k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Agentic Commerce

    TermiX-official/cryptoclaw

    Create, fund, and settle on-chain agent jobs via ERC-8183 Agentic Commerce Protocol.

    100 GitHub stars~787 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed

More from circlefin/skills

All 18 skills in this repo
  • Recover Eco Funds

    circlefin/skills

    Recover USDC from a legacy Circle CLI Gateway --method eco deposit whose fixed refund recipient is the SCA's backing EOA.

    155 GitHub stars~5.1k tokensUpdated 22 days ago
    Auto-check passed
  • Agent Wallet Policy

    circlefin/skills

    View spending policy on a Circle agent wallet — per-transaction, daily, weekly, and monthly USDC caps via the circle CLI.

    155 GitHub stars~1.7k tokensUpdated 22 days ago
    Auto-check passed
  • Bridge Stablecoin

    circlefin/skills

    Build browser or server USDC bridging with Circle App Kit or standalone Bridge Kit and CCTP.

    155 GitHub stars~3.4k tokensUpdated 22 days ago
    Auto-check: notes
  • Fund Agent Wallet

    circlefin/skills

    Fund a Circle agent wallet with USDC via the circle CLI. An agent skill from circlefin/skills.

    155 GitHub stars~3.4k tokensUpdated 22 days ago
    Auto-check passed
  • Accept Agent Payments

    circlefin/skills

    A skill your agent uses when a developer wants to monetize an API, endpoint, service, model, dataset, tool, or agent-facing resource with Circle USDC pay-per-call payments, Gateway Nanopayments…

    155 GitHub stars~2.6k tokensUpdated 22 days ago
    Auto-check: warnings
  • Pay Via Agent Wallet

    circlefin/skills

    A skill your agent uses when the user wants to call a paid API, look something up online, search for data, get prices, odds, or stats, or use any paid service with automatic USDC payment.

    155 GitHub stars~3.9k tokensUpdated 22 days ago
    Auto-check passed

Works with

Categories

Questions about Use Developer Controlled Wallets

What does Use Developer Controlled Wallets do?

Create and manage Circle developer-controlled wallets where the application retains full custody of wallet keys on behalf of end-users. Use Developer Controlled Wallets is an agent skill from circlefin/skills. Create and manage Circle developer-controlled wallets where the application retains full custody of wallet keys on behalf of end-users.

When should I use Use Developer Controlled Wallets?

Use Developer Controlled Wallets fits situations like: : developer-controlled wallets; initiateDeveloperControlledWalletsClient; createWalletSet; sign typed data.

How do I install Use Developer Controlled Wallets in Claude Code?

Run `npx skills add circlefin/skills --skill use-developer-controlled-wallets -a claude-code`. Or copy the skill folder (plugins/circle/skills/use-developer-controlled-wallets in circlefin/skills) into .claude/skills/use-developer-controlled-wallets in your project. Claude Code loads it when a task matches its description.

How do I install Use Developer Controlled Wallets in Codex?

Run `npx skills add circlefin/skills --skill use-developer-controlled-wallets -a codex`. Or copy the skill folder (plugins/circle/skills/use-developer-controlled-wallets in circlefin/skills) into .agents/skills/use-developer-controlled-wallets in your project. Codex loads it when a task matches its description.

Can I use Use Developer Controlled Wallets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add circlefin/skills --skill use-developer-controlled-wallets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/use-developer-controlled-wallets, .gemini/skills/use-developer-controlled-wallets, .github/skills/use-developer-controlled-wallets and .opencode/skills/use-developer-controlled-wallets in your project.

What does Use Developer Controlled Wallets need to run?

Going by SKILL.md and its folder, Use Developer Controlled Wallets needs the command-line tools its instructions call (npm) and credentials named CIRCLE_API_KEY and ENTITY_SECRET. Our summary lists: Node.js; A credential in CIRCLE_API_KEY; A credential in ENTITY_SECRET.

Does Use Developer Controlled Wallets access the network?

SKILL.md names 2 domains. As links in the text: developers.circle.com and console.circle.com. This is read from the text; nothing was executed.

Is Use Developer Controlled Wallets safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Use Developer Controlled Wallets use?

Use Developer Controlled Wallets is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Use Developer Controlled Wallets use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Use Developer Controlled Wallets?

Skills that share tags, products or a category with Use Developer Controlled Wallets: Deposit Qr (Superior-Trade/superior-skills, 214 stars), Alchemy Agentic Gateway (moonpay/skills, 113 stars), Okx Dapp Discovery (internet-court/internet-court-skill, 6.4k stars) and Payram Crypto Payments (PayRam/payram-mcp, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Use Developer Controlled Wallets?

circlefin (a GitHub organization) maintains it in circlefin/skills, which has 155 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 16, 2026.

Source: circlefin/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.