permixaDocs

PERMIXA DOCUMENTATION

Signer & wallets

Your Signer runs in your environment. Permixa governs requests; it does not take custody of your wallet.

What the Signer does

The Signer verifies Permixa's signed authorization, enforces its own local policy, checks the exact transaction, invokes the configured wallet and returns a signed receipt. It remembers consumed authorizations so a restart cannot make them fresh again.

Two independent checks.

Cloud approval cannot override local limits. An agent never talks directly to an arbitrary signing endpoint.

Connect multiple browser wallets

In the dashboard, open an agent's Manage wallets / add another control, or use Treasury → Add a wallet. Choose the extension and account, then approve the ownership message. Repeat for another wallet; your earlier accounts stay connected.

Account familyConnectionWhat it proves
EVMCompatible extensions such as Rabby and MetaMaskOwnership of an EVM address; not a balance or spending grant
SolanaPhantom and compatible Wallet Standard walletsOwnership of a Solana account
BitcoinUniSat; older Phantom Bitcoin providers only when exposedNative SegWit or key-path Taproot ownership

Modern Phantom versions may omit its older Bitcoin provider. Mobile QR sessions and EVM smart-contract account signatures are not supported by this connection flow. Bitcoin ownership does not connect a Lightning wallet.

The macOS desktop companion preview can save and switch between up to 20 accounts, preserving their local drafts. It hands public account details to the dashboard, which requires its own organization-bound proof. It is unsigned, not notarized and not automatically installed or updated.

Connected does not mean ready to spend.

Account association does not register an executable source or delegate wallet authority. Treasury separately reads supported testnet balances; seeing funds does not complete Signer setup. Local Signer enrollment, funding and bounded spending access remain separate assisted steps.

Install a Signer for assisted execution

Assisted testnet pilot Start with one Base Sepolia USDC wallet. You need macOS or Linux, Node.js 22.20 or later, a terminal, and your own test-only wallet. Windows users need a suitable Linux environment; a native Windows installer is not provided.

  1. Open Settings → Connect your first wallet.
  2. Download the reviewed Signer package. In your download folder, use the displayed checksum command and compare the complete result before installing. Stop if it differs.
  3. Run the displayed install command. It installs into a local folder, not a system-wide location. No wallet is unlocked and no payment is made.
  4. Ask your workspace administrator to assign your own Signer and register your public testnet address. Do not borrow the demo owner's account. Your assigned setup commands appear in Settings when these records exist.

The package is a local command-line application, not a browser wallet extension. Installing it is not the same as enrollment or permission to spend.

Operator-assisted local wallet setup

Keep the local wallet file outside your project, cloud-synced folders and shared directories. The Base Sepolia adapter reads a 32-byte private key encoded as hexadecimal; the Solana devnet adapter reads a 32-byte seed encoded as hexadecimal, not a 64-number wallet-export array. Browser extensions can verify account ownership through the dashboard; they do not supply a private key to this file-based Signer adapter. Do not export your everyday wallet key just to complete the connection flow. If you do not already have the correct test-only file, stop and ask your administrator to guide local wallet creation—never send them the key.

  1. Keep the key file private: a regular file with owner-only permissions (0600). Do not paste its contents into commands, chat or the dashboard.
  2. In Settings, select the assigned Signer and exact registered wallet. Replace the three capitalized local values in the command: a new absolute data-directory path, your private key-file path, and a credential-free HTTPS testnet RPC URL.
  3. Run setup. It checks that the public wallet address matches the local key and creates a PENDING identity. Do not point it at an existing Signer as a workaround for an error.
  4. Complete enrollment with your administrator: cloud challenge, local proof of possession, administrator approval and a signed activation message verified locally.
  5. Receive your separate Signer credential through a private channel. Set it only in your local environment using the administrator's secure-entry instructions. Do not paste it into a shared terminal transcript. Review and approve your local hard limits.
  6. Run doctor --data-dir /your/private/signer-directory and status --data-dir /your/private/signer-directory --runtime-environment test --key-backend software-test. Resolve failures before attempting a payment.

Reuse an existing configured Signer and its durable history when appropriate. Never replace it simply to clear a failed or uncertain payment.

Fund, check, then make one payment

For Base Sepolia, fund the exact registered public address with test ETH for gas and the accepted USDC contract 0x036cbd53842c5426634e7929541ec2318f3dcf7e. For Solana devnet, use devnet SOL and mint 4zMMC9srt5Ri5X14GAgXhaHii3GnPAEERYPJgZJDncDU. Your administrator can walk you through an available faucet; availability and owner-only faucet limits vary. Never use mainnet funds.

Refresh Treasury to see the reported balance, network and observation time. A stale report is not a current spendable balance. Set a small agent budget and planning targets, then complete one assisted purchase and one denied-policy test. Activity should distinguish submission from independently verified settlement. Do not retry a payment with an uncertain result.

What stays on your machine

Wallet keys, recovery material, wallet passphrases, RPC credentials and sensitive Lightning proofs stay customer-local. Permixa Cloud receives public identifiers, enrollment proofs, permitted metadata and receipts, not treasury keys.

Never paste a seed or private key into the dashboard, a support chat or documentation form. Private test-key files must have restrictive local permissions. Use dedicated testnet wallets, never a wallet containing real funds.

Registered is not the same as ready

Readiness includes valid enrollment and credentials, the expected local policy, unlocked execution only where explicitly permitted, correct network synchronization and sufficient test funds. Balance and connection checks do not authorize spending.

The packaged doctor and status commands report bounded local facts. The run --once command can consume pending authorizations; it is an execution command, not a harmless connection test.

The configured pilot has a separate customer-local purchase worker that can complete approved Echo x402 purchases while the Mac is awake and online. Closing the companion is not the same as stopping that worker. New-user setup remains assisted. Direct USDC and L402 are not enabled under the current local policy; do not use an older adapter or weaken limits to bypass that restriction. Production service and custody remain outside this demo.

For completed capabilities, assisted setup and remaining work, see the current roadmap.