Skip to content
Public beta on Solana devnet. Test funds only. Tell us what breaks: report an issue
syndromí betaLaunch app

Budgets for AI agents on Solana

Give your AI agents an allowance, not your wallet.

syndromí turns Solana's new Subscriptions & Allowances program into safe budgets for fleets of agents. They spend what you allow, ask when it matters, and stop when you say so.

  • ✓Open source (MIT)
  • ✓No custom onchain program
  • ✓Works with Claude, Cursor and any MCP client
Activity feed example from the demo
  • pool-scout pulling its allowance…
  • pool-scout sent: pull 2 USDC from the allowance
  • pool-scout reading yield data…
  • pool-scout BLOCKED: transfer 2 USDC to AhLo5H…The destination is not on the owner's allowlist. Nothing was signed.

The owner also gets a Telegram alert.

An agent with your key can lose everything in one bad prompt.

Today you either hand an agent a full wallet or approve every transaction by hand. One poisoned web page or tool result saying "send your funds to this address" is enough to empty a wallet. Neither option lets you run more than a couple of agents.

Without a budget

  • ✕The agent holds your full key
  • ✕One prompt injection can move everything
  • ✕You approve every action, or none
  • ✕No way to cut it off fast

With syndromí

  • ✓The agent can pull only its allowance per period
  • ✓Every transaction passes your rules first
  • ✓You sign only what is above your threshold
  • ✓One signature revokes everything

Three steps from wallet to working agent

  1. 1

    Fund one bag

    Your USDC stays in your own wallet. Nothing is deposited into a contract.

  2. 2

    Give each agent an allowance

    Pick an amount per day, week or month, the programs it may use, where funds may go, a per-transaction cap and an approval threshold.

  3. 3

    Agents work. You stay in control.

    Routine actions run. Larger ones reach you in Telegram or the dashboard as a Blink to sign. Anything outside the rules is blocked before it is signed.

You read this before you sign from the mcp-agent template

  • •mcp-agent may take up to 5 USDC per week from your bag. The limit is enforced onchain.
  • •It may only use Jupiter swaps and pulling its allowance, and funds may only go to its own wallet.
  • •No single transaction may move more than $10; anything above $5 waits for your signature.
  • •You send it 0.02 SOL once for network fees.
  • •You can revoke it at any time with the kill switch.

Everything an owner needs to trust an agent

Onchain allowances

Each agent can pull only its allowance per period, enforced by the Solana program. Even a stolen agent key can't pull more.

A policy on every transaction

Program and destination allowlists, a per-transaction cap and an approval threshold. Nothing is signed without passing it.

Approve from your phone

Held actions become Blinks. You sign a message that names exactly what you approve, and the runtime checks it again before executing.

One-signature kill switch

Revoke every allowance and top-up at once, from the dashboard or from Telegram.

Top-ups on request

When an agent runs out, it asks once. You grant a one-time amount, not a bigger standing budget.

A live activity feed

Every tool call, decision and block, in plain words. Blocked actions show in red.

Agents are described in one portable manifest and run locally from the CLI, or hosted by the server.

What is enforced where

We keep the claims precise, because security people check.

Enforced onchain

  • ✓The amount an agent can pull per period
  • ✓One-time top-up limits
  • ✓Revocation by the owner, any time

Enforced by the policy signer

  • ✓Which programs a transaction may call
  • ✓Where funds may go
  • ✓The per-transaction cap
  • ✓The approval threshold

Onchain rule enforcement with Swig smart wallets is next.

The model never touches a signer. Tools return unsigned transactions, the policy decides, and only an allowed transaction is signed with the agent's key.

Bring the agent you already have

Use Claude, Cursor or any MCP client. syndromi mcp gives your existing agent a funded wallet under the same rules. It never sees a key, and every action is executed, held for your signature, or blocked.

  • ✓Only the tools you enable are available
  • ✓The client reads your rules before it acts
  • ✓Approvals and top-ups reach you as usual
# create a budgeted wallet for Claude or any MCP client
pnpm syndromi init
pnpm syndromi fund templates/mcp-agent

# init prints a line like this for you to run
claude mcp add syndromi-mcp-agent …

Who it's for

Owners

You want agents to act onchain without handing over a wallet.

Developers

You ship agents and need spending limits and approvals you don't want to build yourself.

Teams

You run more than one agent, each with its own budget and rules.

Join the devnet beta

syndromí is in beta and runs on Solana devnet, so you can test everything with free test tokens. Mainnet needs an explicit flag and a typed confirmation.

  1. 1

    Open the app

    Connect a Phantom account set to devnet and sign in. It is a free message, not a transaction.

  2. 2

    Get test funds

    Devnet SOL from the faucet, and devnet USDC from Circle's faucet. No real money.

  3. 3

    Create an agent

    Pick a template (mcp-agent is the default), read the rule card, and sign to fund it.

  4. 4

    Break it, and tell us

    Try a transfer outside the rules, or the kill switch. Report what's confusing or broken.

Prefer to run it yourself?
git clone https://github.com/Leac1m/syndromi
cd syndromi && pnpm install
pnpm syndromi init                       # an agent and its encrypted key
pnpm syndromi fund templates/mcp-agent   # fee budget + a 5 USDC/week allowance
pnpm syndromi status                     # what each agent may still pull
pnpm syndromi revoke --all               # the kill switch

Needs Node 20+, pnpm, and a devnet wallet with a little devnet SOL and USDC.

Questions

Do I deposit funds into a contract?

No. The bag is your own USDC token account. The allowance is a delegation that you can revoke at any time.

What if an agent is compromised?

It can only pull its allowance per period, and every transaction it signs still passes the policy. You can revoke everything in one signature.

Is the whole policy onchain?

The allowance is enforced onchain. Program and destination rules, the per-transaction cap and approvals are enforced by our policy signer before anything is signed. Onchain rule enforcement through Swig smart wallets is next.

Which network does it use?

Devnet by default. Mainnet needs an explicit flag and a typed confirmation.

Do I need a custom program or a new token?

No. It uses the Solana Foundation's Subscriptions & Allowances program and plain USDC.

Which models can agents use?

Anthropic (bring your own key) and any OpenAI-compatible endpoint, or bring your own agent through MCP.