Co-signing for AI agent wallets

Your agent spends only what your policy signs off on.

Countersign makes each agent wallet a 2-of-3 multisig shared by the agent, its owner and a rotating committee of staked nodes, and the nodes sign only what the owner's published spend policy allows.

Signers
Agent, owner, committee
Needed
Any two of three
Rules checked
Five, in order

Co-sign ledger

Epoch 0
Committee

reading ledger

checking rule 1 of 5

Last 40 requests: 0 signed, 0 refused Open the full ledger
The problem

One vendor key stands behind every agent wallet

Agent platforms give their agents spending power through one embedded-wallet provider. That provider holds delegated signing rights over thousands of user wallets, and it signs whatever the platform's agent sends it.

So one bug, one leaked key or one prompt-injected agent can drain every wallet at once. The owners have no independent check. The only limits are the ones the platform and its vendor choose to enforce.

delegated signing rights Vendor key signs for all wallet 9fQe…2KdLvendor-signed wallet Hx3P…bW7mvendor-signed wallet 4tNa…Qe8svendor-signed wallet Lm2R…v9Tyvendor-signed wallet C8wD…pZ4k drained wallet Ru6J…n3Xavendor-signed thousands more wallets behind the same key
Today: one key, one company, every wallet. Nothing between the agent and the funds checks the owner's limits.
How it works

Every payment needs two of three signatures

The agent, the owner and a committee of Countersign nodes each hold one key. The agent can start a payment. It can never finish one alone.

  1. The agent proposes

    The agent builds a transaction and signs it with its own key. That is one signature of the three.

  2. Nodes check the owner's policy

    This epoch's three committee nodes run five rules in order: per-transaction cap, allowed programs, allowed tokens, slippage against the oracle price, and the daily spending limit.

  3. Two of three sign

    If every rule passes, the committee adds its signature and the payment goes out. If one fails, the nodes refuse and record the rule that decided it.

The policy belongs to the owner

The owner publishes the policy. Each version gets a hash, and the nodes check every transaction against that exact version.

The owner can tighten the limits or revoke the agent from any wallet, without asking the platform. Platforms plug in through an SDK that replaces their signer-delegation call with one line.

See the SDK swap on Platforms

Published policy

v0

reading policy

verifying policy hash

Live view

Send three requests as Atlas Trader's agent

Each button runs the same policy check the app uses. Watch the rules resolve, then find the verdict in the co-sign ledger at the top of this page and on the Wallets page.

Wallet

Active

reading wallet

loading policy

Agent request

Committee verdict

reading Atlas Trader policy

checking rule 1 of 5

Signed payments lower the balance and add to today's spend. Refusals change nothing but the ledger. Open Atlas Trader in the app
The CSIGN token

Stake is the collateral behind every signature

Node operators stake CSIGN to join signing committees. Each epoch, three staked nodes hold the seats and earn a fee for every signature, paid by the platform.

If a node signs a transaction that broke the published policy, the policy hash and the transaction prove it on-chain. The network slashes 20% of that node's stake and repays the owner from it.

A plain payment can't do this. A permissionless network needs collateral it can seize.

Staked across all nodes
0 CSIGN
Nodes able to take a seat
0 of 0
Committee this epoch
Minimum stake for a seat
CSIGN

Stake by node

Stake as a node

reading stake ledger

ranking nodes

Sign past a published policy and lose of your stake. The owner is repaid from it. Run the slash on Nodes

Compared

Single-vendor delegation next to Countersign

What changes for an agent app that swaps its vendor signer for a co-signing committee. Open a row for the mechanism behind it.

Single-vendor delegation compared with Countersign on agent apps
Question Single-vendor delegation Countersign on agent apps
Who can sign for the agent One custodial key at the wallet vendor signs for every agent on the platform. Any two of three keys: the agent, the owner, and this epoch's committee of three staked nodes.
What a leaked platform key can do Sign anything from every wallet until someone notices. Propose transactions. The committee refuses each one that breaks the owner's policy.
Who can change the limits The platform and its vendor, in their own dashboards. Only the owner. Every change is a new policy version with its own hash.
Stopping a rogue agent File a request with the platform and wait. The owner revokes the agent from any wallet. The committee stops signing at once.
Moving the agent to another app Start over with the new app's vendor and the new app's limits. The policy stays with the wallet. Same version, same limits, no re-approval.
When a signer breaks the rules The owner's word against the vendor's logs. The breach is provable on-chain. The node loses 20% of its stake and the owner is repaid.

Set a limit, then try to break it

The app opens on six agent wallets you own. Tighten a policy, send a payment as the agent, and watch the committee sign or refuse.

Reset the sample data?

Wallets, policies, ledger rows, stakes and platform moves go back to their starting state.