Table of Contents
AI agents that move USDC onchain need more than a hot key. They need dedicated wallets, enclave-enforced policy, gas sponsorship, and a way to confirm the payout landed.
The named object is Turnkey agentic USDC payments: company wallets scoped as agent wallets, non-root API-key users, EFFECT_ALLOW policies that pin Base USDC, and ethSendTransaction with sponsor: true so the agent can transfer USDC without holding ETH. That is not DFNS x402 ERC-3009 settle alone, not Privy session wallets alone, and not a buyer-only Coinbase AgentKit client.
Facts below come from Turnkey's Agentic Payments docs, Agentic Wallets guide, and Introducing Agentic Payments with Turnkey product post, as of October 4, 2026. API shapes, Base USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913, caip2 eip155:8453, getWalletAddressBalances, ethSendTransaction with sponsor: true, and pollTransactionStatus are taken from those sources. No invented fee schedules or endpoints.
Key Takeaways
- Provision one dedicated Turnkey agent wallet and a non-root API-key user.
- ALLOW policies must pin wallet id, Base USDC contract, and optional spend caps.
- Send USDC with ethSendTransaction to the token contract; set sponsor: true.
- Check balances with getWalletAddressBalances on caip2 eip155:8453 before paying.
- Prefer Turnkey when you need enclave policy; use x402 facilitators for hosted settle only.
Who this is for
Use this path if you run AI agents or automated systems that must send USDC on Base, you can adopt Turnkey company wallets, and you want policy evaluated inside a secure enclave before every signature.
Skip it if you only need a public x402 facilitator (see How to Choose an x402 Facilitator for USDC), DFNS-native EIP-712 settle (see How to Process DFNS x402 Agent Payments), Privy embedded agent wallets (see How to Provision Privy Agent Wallets for USDC), or Circle agent wallets (see How to Create a Circle Agent Wallet for USDC). For funding patterns, see How to Fund an AI Agent Wallet with USDC. For spend-limit design patterns, see How to Set Spend Limits for an AI Agent USDC Wallet. Related: How to Use Crossmint Agent Wallets for USDC, Flutterwave Stablecoin Wallet with Turnkey (news, not this how-to).
What Turnkey agentic USDC payments do
Turnkey positions Agentic Payments as production infrastructure that combines non-custodial wallets, transaction lifecycle management, gas sponsorship, real-time balances, and policy controls in one integration, per the June 25, 2026 product post. Agents authenticate with an API key and request signatures. Keys stay in the enclave. Policies decide whether the enclave will sign.
The Agentic Payments guide walks three patterns on the same wallet foundation: a stablecoin payout (this guide's focus), an x402 payment via @turnkey/viem, and an MPP payment via mppx. Start with the stablecoin payout before layering HTTP 402 clients.
| Decision | What to pin |
|---|---|
| Wallet architecture | One dedicated wallet per agent or per trust level; never share across trust boundaries |
| Payment controls | USDC contract allowlist, destination allowlist, spend caps, optional human consensus |
| Gas strategy | sponsor: true so the agent holds USDC only, not native ETH |
| Balance visibility | getWalletAddressBalances before every payout |
| Lifecycle | ethSendTransaction then pollTransactionStatus (or webhooks) |
Prerequisites
Complete Turnkey's Quickstart with root credentials, then follow Agentic Wallets for agent provisioning. Create an organization at app.turnkey.com. Every API call is a JSON POST to api.turnkey.com signed with a P-256 API key.
You will need root credentials only for wallet creation, user creation, and policy creation. The agent runtime should hold only the agent user's public/private API key pair, organization id, and wallet address. Never log root credentials beside agent keys.
Step 1: Create a dedicated agent wallet
Always list existing wallets first to avoid duplicates, then createWallet with a SECP256K1 Ethereum account (BIP32 path m/44'/60'/0'/0/0), per the Agentic Wallets guide:
const { wallets } = await turnkeyClient.apiClient().getWallets();
const { walletId, addresses } = await turnkeyClient.apiClient().createWallet({
walletName: "Agent USDC Payout Wallet",
accounts: [{
curve: "CURVE_SECP256K1",
pathFormat: "PATH_FORMAT_BIP32",
path: "m/44'/60'/0'/0/0",
addressFormat: "ADDRESS_FORMAT_ETHEREUM",
}],
});
const agentAddress = addresses[0];
Fund that address with Base USDC only for the sponsored path. With sponsor: true, the agent does not need ETH for gas on the payout itself.
Step 2: Create a non-root agent user
Generate a P-256 key pair locally. The private key never touches Turnkey. Create a user tag, then createUsers with curveType: API_KEY_CURVE_P256. Turnkey is default-deny: a non-root user cannot sign until you add explicit EFFECT_ALLOW policies.
Store agent credentials in a secrets manager:
TURNKEY_API_PUBLIC_KEY=<agent-public-key> TURNKEY_API_PRIVATE_KEY=<agent-private-key> TURNKEY_ORGANIZATION_ID=<org-id> AGENT_WALLET_ADDRESS=<agent-eth-address>
Step 3: Define ALLOW policies for Base USDC
Create policies as an admin. The Agentic Payments stablecoin example restricts the agent to the USDC contract on Base:
{
"policyName": "Restrict agent to USDC on Base",
"effect": "EFFECT_ALLOW",
"consensus": "approvers.any(user, user.id == '<AGENT_USER_ID>')",
"condition": "activity.type == 'ACTIVITY_TYPE_ETH_SEND_TRANSACTION' && wallet.id == '<AGENT_WALLET_ID>' && eth.tx.to == '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913'"
}
That policy pins eth.tx.to to the USDC contract, not the human recipient. ERC-20 transfer sends the transaction to the token contract with recipient encoded in calldata. To constrain recipients inside the transfer, Turnkey docs say upload the contract ABI and write policies against function parameters (see Smart Contract Interfaces in the Agentic Payments next steps).
From Agentic Wallets, also add a base signing ALLOW scoped to the agent wallet for ACTIVITY_TYPE_SIGN_TRANSACTION_V2 and ACTIVITY_TYPE_ETH_SEND_TRANSACTION, destination allowlists where you need them, EFFECT_DENY spend caps on eth.tx.value for native transfers, and multi-party consensus for high-value actions (agent + human admin).
Step 4: Initialize the agent client and check balances
Build the agent client with @turnkey/sdk-server:
import { Turnkey } from "@turnkey/sdk-server";
const agentClient = new Turnkey({
apiBaseUrl: "https://api.turnkey.com",
apiPublicKey: process.env.TURNKEY_API_PUBLIC_KEY!,
apiPrivateKey: process.env.TURNKEY_API_PRIVATE_KEY!,
defaultOrganizationId: process.env.TURNKEY_ORGANIZATION_ID!,
}).apiClient();
Before paying, call getWalletAddressBalances with caip2: "eip155:8453" (Base mainnet) and read the USDC display.crypto field. Skip the payout if balance is below the intended amount.
Step 5: Send a sponsored Base USDC payout
Encode ERC-20 transfer(address,uint256) with viem, then call ethSendTransaction. Docs sample amount: 1_000_000n (1.00 USDC, 6 decimals). to is the USDC contract. value is "0". sponsor: true covers gas:
import { encodeFunctionData, erc20Abi } from "viem";
const recipient = "0xRecipientAddress";
const usdcAddress = "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913";
const amount = 1_000_000n; // 1 USDC
const data = encodeFunctionData({
abi: erc20Abi,
functionName: "transfer",
args: [recipient, amount],
});
const sendTransactionStatusId = await agentClient.ethSendTransaction({
transaction: {
from: process.env.AGENT_WALLET_ADDRESS!,
to: usdcAddress,
caip2: "eip155:8453",
data,
value: "0",
sponsor: true,
},
});
Then pollTransactionStatus until status is INCLUDED (or FAILED). Read result.eth.txHash and confirm on Turnkey Agentic Payments docs for the pollTransactionStatus flow, then confirm the returned hash on a Base block explorer.
Worked numbers (Base mainnet from Turnkey docs)
| Field | Value from Turnkey docs |
|---|---|
| caip2 | eip155:8453 (Base mainnet) |
| Base USDC | 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Sample amount | 1_000_000n = 1.00 USDC |
| Send API | ethSendTransaction |
| Gas | sponsor: true |
| Balance API | getWalletAddressBalances |
| Status API | pollTransactionStatus |
| Policy effect | EFFECT_ALLOW on ACTIVITY_TYPE_ETH_SEND_TRANSACTION |
Optional secondary paths: x402 and MPP
After the stablecoin payout works, Turnkey documents two HTTP 402-style clients that reuse the same agent wallet.
x402: create a Turnkey-backed viem account with createAccount from @turnkey/viem, register ExactEvmScheme on x402Client, and wrapFetchWithPayment. The wrapped fetch handles 402, signs via Turnkey, and retries. See DFNS x402 and PayAI facilitator for complementary settle patterns.
MPP: pass the same Turnkey viem account into Mppx.create with tempo({ account }) from mppx/client. Useful when the counterparty speaks Stripe/Tempo Machine Payments Protocol instead of classic x402.
Treat x402/MPP as optional secondary rails. The operator how-to you need first is still: wallet, non-root user, USDC ALLOW policy, sponsored ethSendTransaction, balance check, status poll.
Operator policy checklist
| Control | Where | Starting bound | On breach |
|---|---|---|---|
| Wallet scope | createWallet + policy wallet.id | One wallet per agent | Deny other wallets |
| USDC contract pin | EFFECT_ALLOW eth.tx.to | 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 on Base | Reject |
| Recipient allowlist | ABI-aware policy / app allowlist | Only approved payout addresses | Reject |
| Spend cap | EFFECT_DENY / consensus | Org-specific; docs show native-value examples | Deny or require human |
| Non-root agent | createUsers | Never root | Revoke by deleting user |
| Balance gate | getWalletAddressBalances | Require USDC >= amount | Skip payout |
| Status confirm | pollTransactionStatus | Wait for INCLUDED | Retry / alert on FAILED |
For broader spend-limit design language outside Turnkey's exact DSL, see How to Set Spend Limits for an AI Agent USDC Wallet. For accept-side agent payment patterns, see How to Accept x402 USDC Payments from AI Agents.
Personas: worker, observer, approver
Turnkey's Agentic Wallets guide defines three personas you can compose:
| Persona | Can do | Policy approach |
|---|---|---|
| Worker | Sign on a designated wallet | ALLOW with wallet + destination/function/value constraints |
| Observer | Read balances and activity | No signing policies; default-deny |
| Approver | Approve or reject activities | Narrow ALLOW for APPROVE_ACTIVITY / REJECT_ACTIVITY only |
A production payout desk often uses a worker agent for routine USDC transfers under a hard cap, plus an approver (human or second agent) for larger tickets.
When Turnkey fits (and when it does not)
Fit: teams that want enclave-held keys, company-wallet agent personas, Base USDC payouts with gas sponsorship, and policy that cannot be bypassed by a compromised agent host.
Poor fit: teams that only want a drop-in x402 facilitator URL; product surfaces that need Nevermined-style plans; buyers who only need AgentKit against someone else's merchant (see How to Pay for an x402 API with Coinbase AgentKit).
Stablecoin Insider's take
FAQ
What are Turnkey agentic USDC payments?
They are Turnkey's company-wallet pattern for autonomous USDC payouts: dedicated agent wallets, non-root API users, EFFECT_ALLOW policies, and ethSendTransaction with sponsor:true on Base. See the Agentic Payments docs.
Does the agent need ETH for gas?
Not for the sponsored stablecoin payout path in the docs. Set sponsor: true on ethSendTransaction so Turnkey covers gas while the agent holds USDC.
Which Base USDC address should I pin?
Turnkey's Agentic Payments example uses 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 with caip2: "eip155:8453".
Why does eth.tx.to equal the USDC contract?
ERC-20 transfers send the transaction to the token contract. The recipient is encoded in calldata. Policies that only check eth.tx.to therefore pin the token, not the human payee, unless you add ABI-level parameter policies.
How do I revoke an agent instantly?
Delete the agent user. Turnkey documents that as permanent, immediate revocation of signing access.
Can the same wallet do x402 and plain USDC payouts?
Yes. The Agentic Payments guide reuses one agent wallet foundation for stablecoin payout, x402 via @turnkey/viem, and MPP via mppx. Get the payout path working first.
How is this different from DFNS x402?
DFNS x402 centers on EIP-712 ReceiveWithAuthorization with a merchant settle wallet. Turnkey's primary payout example is a sponsored ERC-20 transfer via ethSendTransaction. See How to Process DFNS x402 Agent Payments.
Where do I create the organization?
Self-serve at app.turnkey.com. API base URL is api.turnkey.com (JSON POST; see Turnkey docs).
Need the x402 facilitator shortlist before you commit to Turnkey company wallets? Start with Stablecoin Insider's facilitator comparison, then come back to this Turnkey wire-up.
This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice; no material herein should be interpreted as a recommendation, endorsement, or solicitation to buy or sell.