PluginBench
Skill
Official
Fail
Audit score 45

authenticate-wallet

coinbase/agentic-wallet-skills

Sign in to your wallet via email OTP before sending, trading, or funding.

What is authenticate-wallet?

Authenticates to the Agentic Wallet using a two-step email verification process. Use this skill when you need to log in, connect the wallet, or when wallet operations fail with authentication errors. It is a prerequisite for all other wallet operations.

  • Initiate login by sending a 6-digit OTP code to a provided email address
  • Verify authentication by submitting the OTP code received via email
  • Check current wallet authentication status and server health
  • Retrieve wallet address and balance information across multiple blockchains
  • Validate user input to prevent shell injection attacks

How to install authenticate-wallet

npx skills add https://github.com/coinbase/agentic-wallet-skills --skill authenticate-wallet
Prerequisites
  • Node.js and npm installed to run npx commands
  • Access to the email address associated with the wallet account
  • Ability to receive and retrieve OTP codes from email
Claude Code
Cursor
Windsurf
Cline

How to use authenticate-wallet

  1. 1.Run `npx awal@2.10.0 status` to check current authentication status
  2. 2.If not authenticated, run `npx awal@2.10.0 auth login <email>` with a valid email address
  3. 3.Wait for the 6-digit OTP code to arrive in the email inbox
  4. 4.Run `npx awal@2.10.0 auth verify <otp>` with the 6-digit code
  5. 5.Confirm successful authentication by running `npx awal@2.10.0 status` again

Use cases

Good for
  • User wants to connect their wallet for the first time
  • Wallet operation fails with 'not signed in' or authentication error
  • Agent needs to verify current authentication status before proceeding with transactions
  • User needs to retrieve their wallet address or check balances after signing in
  • Setting up wallet access for trading or funding operations
Who it's for
  • Users setting up wallet access for the first time
  • Agents performing wallet operations that require prior authentication
  • Users who need to reconnect after session expiration
  • Anyone integrating Agentic Wallet into an agent workflow

authenticate-wallet FAQ

What if I don't have access to the user's email?

Ask the user to provide their email address and to share the 6-digit OTP code they receive. You can then use that code to complete the verification step.

How long is the OTP code valid?

The SKILL.md does not specify an expiration time for OTP codes. Check the email for any time limits mentioned in the verification message.

Can I use the same email for multiple wallets?

The SKILL.md does not specify whether one email can be associated with multiple wallets. Refer to Coinbase Agentic Wallet documentation for multi-wallet account details.

What happens if I enter the wrong OTP code?

The verification will fail. You can initiate a new login with `npx awal@2.10.0 auth login <email>` to request a new OTP code.

Which blockchains does the wallet support?

The wallet supports Base, Polygon, and Solana. You can check balances across all chains or use the `--chain` flag to query a single chain.

Full instructions (SKILL.md)

Source of truth, from coinbase/agentic-wallet-skills.


name: authenticate-wallet description: Sign in to the wallet. Use when you or the user want to log in, sign in, connect, or set up the wallet, or when any wallet operation fails with authentication or "not signed in" errors. This skill is a prerequisite before sending, trading, or funding. user-invocable: true disable-model-invocation: false allowed-tools: ["Bash(npx awal@2.10.0 status*)", "Bash(npx awal@2.10.0 auth )", "Bash(npx awal@2.10.0 balance)", "Bash(npx awal@2.10.0 address*)", "Bash(npx awal@2.10.0 show*)"]

Authenticating with the Agentic Wallet

When the wallet is not signed in (detected via npx awal status or when wallet operations fail with authentication errors), use the npx awal CLI to authenticate.

If you have access to email, you can authenticate the wallet yourself, otherwise you'll need to ask your human to give you an email address and to tell you the OTP code they receive.

Authentication Flow

Authentication uses a two-step email OTP process:

Step 1: Initiate login

npx awal@2.10.0 auth login <email>

This sends a 6-digit verification code to the email and outputs a flowId.

Step 2: Verify OTP

npx awal@2.10.0 auth verify <otp>

Use the 6-digit code from the user's email to complete authentication. The flow ID from step 1 is saved automatically to a local file — you do not pass it as an argument. If you have the ability to access the user's email, you can read the OTP code, or you can ask your human for the code.

Input Validation

Before constructing the command, validate all user-provided values to prevent shell injection:

  • email: Must match a standard email format (^[^\s;|&]+@[^\s;|&]+$). Reject if it contains spaces, semicolons, pipes, backticks, or other shell metacharacters.
  • otp: Must be exactly 6 digits (^\d{6}$).

Do not pass unvalidated user input into the command.

Checking Authentication Status

npx awal@2.10.0 status

Displays wallet server health and authentication status including wallet address.

Example Session

# Check current status
npx awal@2.10.0 status

# Start login (sends OTP to email)
npx awal@2.10.0 auth login user@example.com
# Output: flowId: abc123...

# After user receives code, verify (flow ID saved automatically)
npx awal@2.10.0 auth verify 123456

# Confirm authentication
npx awal@2.10.0 status

Available CLI Commands

CommandPurpose
npx awal@2.10.0 statusCheck server health and auth status
npx awal@2.10.0 auth login <email>Send OTP code to email, returns flowId
npx awal@2.10.0 auth verify <otp>Complete authentication with OTP code
npx awal@2.10.0 balanceGet balances across Base, Polygon, and Solana (use --chain for a single chain)
npx awal@2.10.0 addressGet wallet address
npx awal@2.10.0 showOpen the wallet companion window

JSON Output

All commands support --json for machine-readable output:

npx awal@2.10.0 status --json
npx awal@2.10.0 auth login user@example.com --json
npx awal@2.10.0 auth verify <otp> --json