Skip to main content
A Locus wallet lets your agent pay for tools, send USDC, and make purchases from one balance on Base. Locus sponsors gas, so you don’t need to keep ETH in the wallet for these transactions. You retain a recovery key and can revoke Locus’s signing access. Set an allowance and approval threshold in the dashboard to control your agent’s spending.

Your keys

User key

You control this key. Use it to recover the wallet or revoke Locus’s permissioned key. It is generated in your browser and never stored on Locus servers. Save your user key securely when you create the wallet. See the quickstart for setup.

Permissioned key

Locus stores this key in a hardware security module to sign agent transactions. It can rotate itself; only your user key can fully revoke it.

Subwallets

Email payments use subwallets to hold funds until the recipient claims them:
  1. Send USDC to an email address.
  2. Locus places the funds in a separate subwallet.
  3. The recipient receives an email with a one-time password.
  4. They claim the funds to a wallet address of their choosing.
Each payment has a claim deadline. Funds cannot be disbursed after that deadline. Claimed subwallets return to a reuse pool for future payments. See USDC transfers for the two ways to send funds.

Locus smart wallet

Locus wallets use ERC-4337 accounts based on Solady. Either the user key or active permissioned key can sign. The user key can call revokePermissionedKey() to remove Locus’s access. The wallet implementation is immutable: _authorizeUpgrade always reverts.

Factory

LocusFactory deploys wallets at deterministic addresses using CREATE2. The permissioned key is set during deployment. For contract methods and subwallet limits, inspect the verified implementations:

Smart wallet contract

Signing, access revocation, transfers, and wallet deployment.

Subwallet contract

Email payment escrow, deadlines, and claims.