Skip to main content
Policies let you govern wallet behavior by defining rules that accept or reject operations based on transaction parameters like destination address, value, and network.

Policy fields

Evaluation

Within a policy, any matching reject rule for an operation rejects the request, even if an accept rule also matches. Otherwise, any matching accept rule accepts it. This precedence does not depend on rule order. Among matching rules with the same action, the first in the policy applies. For API key auth wallets, the project-level policy takes precedence when any of its rules match, so an account-level reject rule does not override a matching project-level accept rule. Otherwise, the account-level policy is evaluated. If neither policy has a matching rule, the request is rejected when either policy has rules targeting the operation and accepted when neither does. For example, this policy accepts signEvmTransaction requests of up to 1 ETH unless the destination address is on the denylist. A request for 1 ETH or less to the listed address matches both rules and is rejected.

API key configuration

To manage policies via SDK or API, your API key must have the Non-custodial > Manage (modify policies) scope enabled under API restrictions > API-specific restrictions.

Create a policy

Policies can be created from the CDP Portal or via the SDK.

CDP Portal

In the Portal, navigate to Non-custodial Wallet > Security and click Create project policy to open the JSON editor.

SDK

User authentication wallets support project-scope policies only.

Supported operations

User authentication

API key authentication