Bankr Dev - Safety & Access Control

v2026.09.24

This skill should be used when building secure Bankr integrations, implementing API key management, configuring access controls, setting up dedicated agent wallets, or handling rate limits and security best practices in Bankr API projects.

GitHub
安装命令
npx skhub add bankrbot/bankr-dev-safety-access-control
Markdown
SKILL.md

Safety & Access Control

Security patterns and best practices for Bankr API integrations.

API Key Capability Flags

Each API key has independent toggles managed at bankr.bot/api:

FlagControlsDefault
agentApiEnabled/agent/* endpointsfalse
llmGatewayEnabledLLM Gateway at llm.bankr.botfalse
readOnlyRestricts agent to read-only toolsfalse

Separate Agent & LLM Keys

ConfigAgent API KeyLLM Gateway Key
Env varBANKR_API_KEYBANKR_LLM_KEY (falls back to API key)
CLI configapiKeyllmKey (falls back to apiKey)

Read-Only Keys

When readOnly: true:

  • /agent/prompt works but only read tools are available
  • /agent/sign returns 403
  • /agent/submit returns 403
// Handle read-only 403 errors
const response = await fetch(`${API_URL}/agent/sign`, { ... });
if (response.status === 403) {
  const error = await response.json();
  // error.message: "This API key has read-only access..."
}

IP Whitelisting

// Requests from non-whitelisted IPs get 403
// Configure allowedIps at bankr.bot/api
const response = await fetch(`${API_URL}/agent/prompt`, { ... });
if (response.status === 403) {
  const error = await response.json();
  // error.message: "IP address not allowed for this API key"
}

Dedicated Agent Wallet

For autonomous agents, create a separate Bankr account:

  1. Sign up at bankr.bot/api with a different email
  2. Generate an API key with Agent API enabled
  3. Configure access controls (readOnly, allowedIps)
  4. Fund with limited amounts

Access Control Combinations

Use CasereadOnlyallowedIpsFunding
Monitoring botYesYes (server IP)None
Trading bot (server)NoYes (server IP)Limited
Development/testingNoNoMinimal
Research agentYesNoNone

Rate Limits

TierDaily Limit
Standard100 messages/day
Bankr Club1,000 messages/day
CustomSet per API key
// Handle 429 rate limit responses
const response = await fetch(`${API_URL}/agent/prompt`, { ... });
if (response.status === 429) {
  const error = await response.json();
  // error.resetAt: Unix timestamp when counter resets
  // error.limit: Daily limit
  // error.used: Messages used
  const retryAfter = error.resetAt - Date.now();
}

Key Management Patterns

// Always use environment variables
const API_KEY = process.env.BANKR_API_KEY;
const LLM_KEY = process.env.BANKR_LLM_KEY || API_KEY;

if (!API_KEY) {
  throw new Error("BANKR_API_KEY not set. Get one at https://bankr.bot/api");
}

Storage rules:

  • Environment variables for server-side agents and CI/CD
  • ~/.bankr/config.json for local development (CLI manages this)
  • Never commit keys to source control
  • Add ~/.bankr/, .env to .gitignore
  • Rotate periodically, revoke immediately if compromised

Transaction Safety

  • /agent/submit executes immediately with no confirmation prompt
  • Always use waitForConfirmation: true for important transactions
  • Test with small amounts on Base/Polygon first
  • Verify calldata source for arbitrary transactions

Related Skills

  • bankr-client-patterns - Client setup with error handling
  • bankr-api-basics - API fundamentals
  • bankr-sign-submit-api - Sync endpoints that need extra caution
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

bankr-agent-dev/skills/bankr-safety

默认分支

main

最新提交

67d33d4

Tree SHA

76943a8