Policy fields
Evaluation
Within a policy, any matchingreject rule for an operation rejects the request, even if an accept rule also matches. Otherwise, any matching accept rule accepts it. This precedence does not depend on rule order. Among matching rules with the same action, the first in the policy applies.
For API key auth wallets, the project-level policy takes precedence when any of its rules match, so an account-level reject rule does not override a matching project-level accept rule. Otherwise, the account-level policy is evaluated. If neither policy has a matching rule, the request is rejected when either policy has rules targeting the operation and accepted when neither does.
For example, this policy accepts signEvmTransaction requests of up to 1 ETH unless the destination address is on the denylist. A request for 1 ETH or less to the listed address matches both rules and is rejected.
API key configuration
To manage policies via SDK or API, your API key must have the Non-custodial > Manage (modify policies) scope enabled under API restrictions > API-specific restrictions.Create a policy
Policies can be created from the CDP Portal or via the SDK.CDP Portal
In the Portal, navigate to Non-custodial Wallet > Security and click Create project policy to open the JSON editor.SDK
- User Authentication
- API Key Authentication
User authentication wallets support project-scope policies only.
- Node (TypeScript)
- Python