# Discover Yield Products

Investing in digital assets involves risk. Please review our [Terms of Service](/shredpay-legal-documents/shredpay-terms-of-service) for a detailed list of the risks involved in the products we offer. ShredPay does not offer investment advice. Please evaluate your own investment risk tolerance before investing through ShredPay. Your participation in ShredPay's products indicates that you understand and accept the related risks.


# Aave V3 USDC

**About this market**\
This Earn opportunity generates yield by supplying USDC directly to the Aave v3 lending market on Base.

**What is Aave?**\
Aave is an on-chain lending protocol where suppliers earn interest by providing liquidity, and borrowers pay interest to borrow assets against over-collateralized collateral.

**01 Supply USDC to the Aave market**\
Supply USDC on the **Base network** to the Aave v3 USDC market. Your USDC becomes available liquidity for borrowers and can be withdrawn anytime (subject to available market liquidity).

**02 How your USDC is used**\
Your supplied USDC is pooled in the Aave USDC reserve. Aave automatically matches supply and borrow demand, and interest rates adjust dynamically based on utilization.

**03 Earn interest from borrowers**\
Borrowers deposit collateral and borrow USDC, paying interest back to suppliers. Your yield primarily comes from borrower interest and changes in market utilization over time.

**Aave market link:** <https://app.aave.com/reserve-overview/?underlyingAsset=0x833589fcd6edb6e08f4c7c32d4f71b54bda02913&marketName=proto_base_v3>


# Spark USDC Vault

**About this vault**\
This Earn vault generates yield by supplying USDC into Morpho, using a strategy curated by SparkDAO.&#x20;

**What is Morpho?**\
Morpho is an on-chain lending protocol where borrowers pay interest to borrow supplied assets, backed by over-collateralized collateral and liquidation rules.

**01 Deposit in a Morpho Vault**\
Deposit USDC into this vault on the Base network. Your deposit is supplied to a curator-managed vault strategy, so always review curator strategy and exposure before depositing.

**02 Assets are supplied to Morpho Markets**\
The vault supplies USDC to Morpho Markets whitelisted by SparkDAO, managing allocations and caps over time.

**03 Earn yield from borrowers**\
Earn yield from borrower interest, plus MORPHO incentives when available.

**Morpho vault link:** [https://app.morpho.org/base/vault/0x7BfA7C4f149E7415b73bdeDfe609237e29CBF34A/spark-usdc-vault](https://app.morpho.org/base/vault/0x7BfA7C4f149E7415b73bdeDfe609237e29CBF34A/spark-usdc-vault?utm_source=chatgpt.com)


# Moonwell Flagship USDC

**About this vault**\
This Earn vault generates yield by supplying USDC into Morpho, using a strategy curated by B.Protocol and Block Analitica.

**What is Morpho?**\
Morpho is an on-chain lending protocol where suppliers earn yield by lending assets, and borrowers pay interest to borrow against over-collateralized collateral.

**01 Deposit in a Morpho Vault**\
Deposit USDC into this vault on the Base network. Your deposit is supplied to a curator-managed vault strategy, so always review curator strategy and exposure before depositing.

**02 Assets are supplied to Morpho Markets**\
The vault allocates deposits only to Morpho Markets whitelisted by the curators, with caps and rebalancing based on risk parameters.

**03 Earn yield from borrowers**\
Borrowers post collateral and borrow USDC, paying interest back to the vault. The vault may also earn MORPHO incentive rewards.

**Morpho vault link:** [https://app.morpho.org/base/vault/0xc1256Ae5FF1cf2719D4937adb3bbCCab2E00A2Ca/moonwell-flagship-usdc](https://app.morpho.org/base/vault/0xc1256Ae5FF1cf2719D4937adb3bbCCab2E00A2Ca/moonwell-flagship-usdc?utm_source=chatgpt.com)


# Steakhouse USDC

**About this vault**\
This Earn vault generates yield by supplying USDC into Morpho, using a strategy curated by Steakhouse Financial.

**What is Morpho?**\
Morpho is an on-chain lending protocol where suppliers earn interest from borrowers, who borrow only after posting over-collateralized collateral.

**01 Deposit in a Morpho Vault**\
Deposit USDC into this vault on the Base network. Your deposit is supplied to a curator-managed vault strategy, so always review curator strategy and exposure before depositing.

**02 Assets are supplied to Morpho Markets**\
The vault allocates deposits into whitelisted Morpho lending markets and manages caps to balance yield and risk (often targeting blue-chip/RWA-backed collateral).

**03 Earn yield from borrowers**\
Yield comes from borrower interest payments, and may include MORPHO incentive rewards depending on underlying markets.

**Morpho vault link:** [https://app.morpho.org/base/vault/0xbeeF010f9cb27031ad51e3333f9aF9C6B1228183/steakhouse-usdc](https://app.morpho.org/base/vault/0xbeeF010f9cb27031ad51e3333f9aF9C6B1228183/steakhouse-usdc?utm_source=chatgpt.com)


# Seamless USDC

**About this vault**\
This Earn vault generates yield by supplying USDC into Morpho, using a strategy curated by Gauntlet for Seamless.

**What is Morpho?**\
Morpho is an on-chain lending protocol where suppliers earn yield by lending assets, and borrowers pay interest to borrow against over-collateralized collateral.

**01 Deposit in a Morpho Vault**\
Deposit USDC into this vault on the **Base network**. Your deposit is supplied to a curator-managed vault strategy, so always review curator strategy and exposure before depositing.

**02 Assets are supplied to Morpho Markets**\
The vault allocates deposits into Morpho lending markets whitelisted by the curator. Gauntlet manages allocations and caps to target risk-adjusted yield across high-demand collateral markets.

**03 Earn yield from borrowers**\
Yield comes from interest paid by borrowers who borrow USDC against collateral, and may also include MORPHO incentive rewards when available.

**Morpho vault link:** [https://app.morpho.org/base/vault/0x616a4E1db48e22028f6bbf20444Cd3b8e3273738/seamless-usdc-vault](https://app.morpho.org/base/vault/0x616a4E1db48e22028f6bbf20444Cd3b8e3273738/seamless-usdc-vault?utm_source=chatgpt.com)


# High Yield Clearstar USDC

**About this vault**\
This Earn vault generates yield by supplying USDC into Morpho, using a higher-yield strategy curated by Clearstar.

**What is Morpho?**\
Morpho is an on-chain lending protocol where suppliers earn yield by lending assets, and borrowers pay interest to borrow against over-collateralized collateral.

**01 Deposit in a Morpho Vault**\
Deposit USDC into this vault on the **Base network**. Your deposit is supplied to a curator-managed vault strategy, so always review curator strategy and exposure before depositing.

**02 Assets are supplied to Morpho Markets**\
Clearstar allocates deposits into Morpho lending markets it has whitelisted, targeting higher-yield opportunities. This can include markets with more volatile or frontier collateral, which may carry higher risk.

**03 Earn yield from borrowers**\
Yield comes from interest paid by borrowers who borrow USDC against collateral, and may also include MORPHO incentive rewards when available.

**Morpho vault link:** [https://app.morpho.org/base/vault/0xE74c499fA461AF1844fCa84204490877787cED56/high-yield-clearstar-usdc](https://app.morpho.org/base/vault/0xE74c499fA461AF1844fCa84204490877787cED56/high-yield-clearstar-usdc?utm_source=chatgpt.com)


# Re7 USDC

**About this vault**\
This Earn vault generates yield by supplying USDC into Morpho, using a strategy curated by Re7 Labs.

**What is Morpho?**\
Morpho is an on-chain lending protocol where depositors supply assets to earn interest from borrowers who borrow against over-collateralized collateral.

**01 Deposit in a Morpho Vault**\
Deposit USDC into this vault on the Base network. Your deposit is supplied to a curator-managed vault strategy, so always review curator strategy and exposure before depositing.

**02 Assets are supplied to Morpho Markets**\
The vault allocates deposits to Morpho Markets whitelisted by Re7, with caps and rebalancing across markets.

**03 Earn yield from borrowers**\
Yield is generated from borrower interest payments, and may include MORPHO incentive rewards.

**Morpho vault link:** [https://app.morpho.org/base/vault/0x12AFDeFb2237a5963e7BAb3e2D46ad0eee70406e/re7-usdc](https://app.morpho.org/base/vault/0x12AFDeFb2237a5963e7BAb3e2D46ad0eee70406e/re7-usdc?utm_source=chatgpt.com)


# Edge UltraYield USD

#### About this vault

This Earn vault generates yield by supplying USDC into Morpho, using a higher-yield strategy curated by Edge Capital.

#### What is Morpho?

Morpho is an on-chain lending protocol where depositors supply assets to earn interest from borrowers who borrow against over-collateralized collateral.

#### How this vault works

**01 Deposit into the Edge UltraYield Vault**\
Deposit USDC into this vault on the Base network. Your funds are supplied into a curator-managed strategy designed to optimize yield across selected Morpho markets. Always review the curator’s strategy and risk profile before depositing.

**02 Assets are allocated across Morpho Markets**\
The vault allocates deposits to Morpho Markets selected and managed by Edge Capital. Allocation caps, risk parameters, and rebalancing rules are applied to manage exposure across markets.

**03 Earn yield from borrowers and incentives**\
Yield is generated from borrower interest payments and may include additional incentive rewards depending on market conditions.

🔗 **Morpho vault link:**\
<https://app.morpho.org/base/vault/0x5435BC53f2C61298167cdB11Cdf0Db2BFa259ca0/edge-ultrayield-usdc>


# Clearstar USDC Reactor

#### About this vault

This Earn vault generates yield by supplying USDC into Morpho through the Clearstar USDC Reactor, a dynamically managed lending strategy curated by Clearstar.

#### What is Morpho?

Morpho is an on-chain lending protocol where depositors supply assets to earn interest from borrowers who borrow against over-collateralized collateral.

#### How this vault works

**01 Deposit into the Clearstar USDC Reactor**\
Deposit USDC into this vault on the Base network. Your funds are supplied to a curator-managed reactor strategy that dynamically allocates capital based on predefined risk and efficiency parameters.

**02 Dynamic allocation across Morpho Markets**\
The reactor automatically routes liquidity across Morpho Markets approved by Clearstar, applying caps and rebalancing logic to optimize capital efficiency while managing risk exposure.

**03 Earn yield from borrower interest**\
Yield is generated from interest paid by borrowers across the underlying Morpho Markets. Returns may vary depending on utilization and market conditions.

🔗 **Morpho vault link:**\
<https://app.morpho.org/base/vault/0x1D3b1Cd0a0f242d598834b3F2d126dC6bd774657/clearstar-usdc-reactor>


# YieldNest RWA

#### About this vault

This Earn vault generates yield by supplying USDC into Morpho through the YieldNest RWA, a dynamically managed lending strategy curated by Edge Capital Ultra Yield.

#### What is Morpho?

Morpho is an on-chain lending protocol where depositors supply assets to earn interest from borrowers who borrow against over-collateralized collateral.

#### How this vault works

**01 Deposit into the YieldNest RWA**\
Deposit USDC into this vault on the Ethereum network. Your funds are supplied to a curator-managed reactor strategy that dynamically allocates capital based on predefined risk and efficiency parameters.

**02 Dynamic allocation across Morpho Markets**\
The reactor automatically routes liquidity across Morpho Markets approved by Edge Capital Ultra Yield, applying caps and rebalancing logic to optimize capital efficiency while managing risk exposure.

**03 Earn yield from borrower interest**\
Yield is generated from interest paid by borrowers across the underlying Morpho Markets. Returns may vary depending on utilization and market conditions.

🔗 **Morpho vault link:**\
<https://app.morpho.org/ethereum/vault/0x62efA7CAcC11CAA959A8f956EC4F683302397e5c/yieldnest-rwa>


# Sky.money USDC Risk Capital

#### About this vault

This Earn vault generates yield by supplying USDC into Morpho through the Sky.money USDC Risk Capital, a dynamically managed lending strategy curated by Sky.money.

#### What is Morpho?

Morpho is an on-chain lending protocol where depositors supply assets to earn interest from borrowers who borrow against over-collateralized collateral.

#### How this vault works

**01 Deposit into the Sky.money USDC Risk Capital**\
Deposit USDC into this vault on the Ethereum network. Your funds are supplied to a curator-managed reactor strategy that dynamically allocates capital based on predefined risk and efficiency parameters.

**02 Dynamic allocation across Morpho Markets**\
The reactor automatically routes liquidity across Morpho Markets approved by Sky.money, applying caps and rebalancing logic to optimize capital efficiency while managing risk exposure.

**03 Earn yield from borrower interest**\
Yield is generated from interest paid by borrowers across the underlying Morpho Markets. Returns may vary depending on utilization and market conditions.

🔗 **Morpho vault link:**\
<https://app.morpho.org/ethereum/vault/0x56bfa6f53669B836D1E0Dfa5e99706b12c373ecf/skymoney-usdc-risk-capital>


# HyperithmUSDC Degen

#### About this vault

This Earn vault generates yield by supplying USDC into Morpho through the HyperithmUSDC Degen, a dynamically managed lending strategy curated by Hyperithm.

#### What is Morpho?

Morpho is an on-chain lending protocol where depositors supply assets to earn interest from borrowers who borrow against over-collateralized collateral.

#### How this vault works

**01 Deposit into the HyperithmUSDC Degen**\
Deposit USDC into this vault on the Ethereum network. Your funds are supplied to a curator-managed reactor strategy that dynamically allocates capital based on predefined risk and efficiency parameters.

**02 Dynamic allocation across Morpho Markets**\
The reactor automatically routes liquidity across Morpho Markets approved by Hyperithm, applying caps and rebalancing logic to optimize capital efficiency while managing risk exposure.

**03 Earn yield from borrower interest**\
Yield is generated from interest paid by borrowers across the underlying Morpho Markets. Returns may vary depending on utilization and market conditions.

🔗 **Morpho vault link:**\
<https://app.morpho.org/ethereum/vault/0x777791C4d6DC2CE140D00D2828a7C93503c67777/hyperithm-usdc-apex>


# Steakhouse Reservoir USDC

#### About this vault

This Earn vault generates yield by supplying USDC into Morpho through the Steakhouse Reservoir USDC, a dynamically managed lending strategy curated by Steakhouse.

#### What is Morpho?

Morpho is an on-chain lending protocol where depositors supply assets to earn interest from borrowers who borrow against over-collateralized collateral.

#### How this vault works

**01 Deposit into the Steakhouse Reservoir USDC**\
Deposit USDC into this vault on the Ethereum network. Your funds are supplied to a curator-managed reactor strategy that dynamically allocates capital based on predefined risk and efficiency parameters.

**02 Dynamic allocation across Morpho Markets**\
The reactor automatically routes liquidity across Morpho Markets approved by Steakhouse, applying caps and rebalancing logic to optimize capital efficiency while managing risk exposure.

**03 Earn yield from borrower interest**\
Yield is generated from interest paid by borrowers across the underlying Morpho Markets. Returns may vary depending on utilization and market conditions.

🔗 **Morpho vault link:**\
<https://app.morpho.org/ethereum/vault/0xbeEF346d7099865208Ff331e4f648f4154DDAa05/steakhouse-reservoir-usdc>


# ShredPay DeFi Risk Ratings Methodology

ShredPay Ratings is our proprietary, three-tiered due diligence framework designed to evaluate and score the operational, technical, and financial health of Decentralized Finance (DeFi) protocols and their specific products.&#x20;

#### Tier 1: Protocol Due Diligence

The Protocol layer focuses on the foundational security and governance of the core decentralized application itself. This evaluation reviews the robustness of the protocol’s underlying technology and management. The goal of Protocol Due Diligence is to assess the core protocol infrastructure’s technical and compliance  effectiveness.

#### Tier 2: Vault Due Diligence

The Vault/Curator layer shifts focus to the entity or team responsible for managing the specific investment strategy or vault parameters. This assessment is critical for understanding the human and organizational factors that influence risk.This determines the level to which the entity entrusted with strategic oversight possesses the requisite expertise, transparency, and technical knowledge to effectively manage the allocated capital responsibly.

#### Tier 3: Market Due Diligence

The Market layer provides the final layer of risk assessment, focusing on the real-time financial and on-chain health of the specific underlying asset pools and deployments. This analysis uses available quantitative metrics to determine the market’s financial stability and risk appetite.<br>

### ShredPay Ratings Levels

For each DeFi protocol offered on the ShredPay platform, the individual findings from the Protocol, Vault, and Market due diligence layers are synthesized into a final ShredPay Ratings level:

#### Risk Rating:  Low Risk&#x20;

Protocols, vaults, or markets achieving this score demonstrate strength across all three layers at the time the rating is published.&#x20;

#### Risk Rating:  Medium-Low Risk

Protocols, vaults, or markets in this tier demonstrate strength in the significant majority of due diligence criteria but may have certain areas that may be marginally less robust at the time the rating is published.

#### Risk Rating: Medium

Protocols, vaults, or markets in this tier exhibit strong performance in the majority of due diligence criteria but may have certain areas that are somewhat less robust at the time the rating is published.

#### Risk Rating: Medium-High

Protocols, vaults, or markets in this tier exhibit adequate performance in the majority of due diligence criteria but may have certain areas that could be more  robust at the time the rating is published.&#x20;

#### Risk Rating:  High Risk

While these protocols, vaults, or markets satisfy basic requirements, they present notable, elevated risks across multiple layers at the time the rating is published. These offerings may be riskier than the others listed, and users should exercise a higher degree of discretion and due diligence in their usage.

\
*Important Disclosure: In issuing and maintaining its ShredPay DeFi Ratings, ShredPay relies on factual information it obtains from the third-party decentralized finance protocol and other publicly available sources that ShredPay believes to be credible. ShedPay conducts a reasonable investigation of the factual information relied upon by it in accordance with its ratings methodology, and obtains reasonable verification of that information from independent sources, to the extent such sources are available. A ShredPay DeFi Risk Rating does not constitute an individualized recommendation that a decentralized finance protocol deposit/transaction is appropriate for you. You agree not to hold ShredPay liable for any losses, lost profits or other damages resulting from your use of - or reliance upon - any ShredPay DeFi Rating.*&#x20;


# Risk ratings information

Risk ratings are offered for informational purposes only. They are not a guarantee of performance or security. Details of the factors considered when ShredPay risk ratings are determined can be found [here](/shredpay-defi-risk-ratings-methodology)


# Earn Yield Fees

Fees include the network fee charged by the DeFi protocol, a 0 transaction fee and a 10% performance fee for any yield earned. Redeem currently has a 0 fee. More information about ShredPay fees can be found [here](/shredpay-legal-documents/shredpay-pricing-and-fee-disclosure).


# 3rd Party Bank Processing Fee

Lower processing fees on larger deposits.

Deposit fees decrease as your deposit amount increases:

$1 – $349.99: 4.5%

$350 – $499.99: 3%

$500 – $999.99: 1.5%

$1,000 and above: 1%

These fees reflect combined third-party bank processing costs (e.g. ACH and Debit Card fees), not a ShredPay platform fee.

More information about ShredPay fees can be found [here](/shredpay-legal-documents/shredpay-pricing-and-fee-disclosure).


# Buy / Sell Crypto Fees

Fees include the network fee charged by the DeFi protocol and a 1% DEX swap transaction fee. More information about ShredPay fees can be found [here](/shredpay-legal-documents/shredpay-pricing-and-fee-disclosure).


# Withdraw Fees

Fees include a 1% transaction fee. More information about ShredPay Fees can be found  [here](/shredpay-legal-documents/shredpay-pricing-and-fee-disclosure).


# Receive Fees

Fees include the network fee charged by the underlying blockchain protocol and a 1% transaction fee. More information about ShredPay fees can be found [here](/shredpay-legal-documents/shredpay-pricing-and-fee-disclosure).


# ShredPay Legal Documents

Links to Legal Documents:&#x20;

[ShredPay Terms of Service](/shredpay-legal-documents/shredpay-terms-of-service)

[ShredPay Privacy Policy](/shredpay-legal-documents/shredpay-privacy-policy)

[ShredPay Pricing & Fee Disclosure](/shredpay-legal-documents/shredpay-pricing-and-fee-disclosure)

[ShredPay E-Sign Consent Agreement](/shredpay-legal-documents/shredpay-e-sign-consent-agreement)

[ShredPay DeFi Risk Ratings Methodology](/shredpay-defi-risk-ratings-methodology)


# ShredPay Terms of Service

EFFECTIVE DATE: April 13, 2026

These Terms of Service (“Agreement”) are between, as applicable, ShredPay, Markets, LLC (“ShredPay Markets”), ShredPay Research, LLC (“ShredPay Research”) and ShredPay Liquid, LLC (“ShredPay Liquid”) (collectively, “ShredPay”, “we”, “us”, or “our”) and you, the individual (“you”, “your” or “User”). Certain Services may be provided or otherwise involve these ShredPay entities and/or other companies in our corporate group (“Affiliates”) and/or third-party partners and vendors. You authorize ShredPay to share any of your information with Affiliates and third-party partners and vendors for the purpose of carrying out certain Services that you request. For more information about how we share your information, please see our [Privacy Policy](/shredpay-legal-documents/shredpay-privacy-policy)

THIS AGREEMENT CONTAINS AN ARBITRATION AGREEMENT THAT REQUIRES ANY DISPUTES BETWEEN YOU AND SHREDPAY TO BE SUBMITTED TO ARBITRATION.  SUCH CLAIMS INCLUDE, WITHOUT LIMITATION, ANY CLAIMS THAT AROSE OR WERE ASSERTED BEFORE THE EFFECTIVE DATE OF THIS AGREEMENT. IF YOU DO NOT AGREE TO ANY OF THESE TERMS AND CONDITIONS, INCLUDING THE MANDATORY ARBITRATION PROVISION IN SECTION 22, INCORPORATED HEREIN BY REFERENCE, DO NOT REGISTER AN ACCOUNT OR ACCESS OR USE THE SERVICES.

## 1. APPLICABILITY

This Agreement applies to an individual’s use of the following ShredPay products and services (“Services”), which will be offered through the [ShredPay.xyz](http://shredpay.xyz) website, through any mobile or desktop applications that we may offer, or through API connections.

## 2. DEFINITIONS

2.1 “**Account**” means an account in a User’s name identified by ShredPay for the benefit of such a customer for use in connection with the Services.\
2.2 “**Blockchain**” means a decentralized, digital ledger that securely and transparently records, stores, and verifies data across a network of computers. Data is stored in chronological "blocks" that are linked together using cryptography, making them immutable and tamper-proof.\
2.3 “**Confidential Information**” includes information about our business, including but not limited to software and technology, product designs, product plans, pricing information, financial information, business opportunities, marketing plans, discounts, inventions, and know-how, to the extent disclosed to you in connection with your use of the Services, and all other information that you knew, or reasonably should have known, was Confidential Information. Confidential Information also includes trade secrets as defined under Applicable Law (which includes the Uniform Trade Secrets Act). Confidential Information does not include information that: (a) is independently developed; (b) is or becomes public knowledge through no breach of this Agreement; or (c) is received from a third party under circumstances that do not create a reasonable suspicion that such information has been misappropriated or improperly disclosed.\
2.4 “**Decentralized cryptocurrency exchange**” (”DEX”) means a peer-to-peer marketplace that allows Users to trade Digital Assets directly with one another. These platforms operate using self-executing smart contracts on a blockchain.\
2.5 “**Decentralized Finance protocol**” (“DeFi Protocol”) means a set of rules and software, typically using smart contracts on a public blockchain network, that offers financial services without the need for a central authority or intermediary like a bank. These protocols enable peer-to-peer (P2P) transactions.\
2.6 “**Digital Asset**” means any stablecoin, cryptocurrency, digital asset, NFT, tokenised asset, and virtual currency. Digital Asset does not include a derivative of a virtual currency, or a security, as defined under Applicable Law.\
2.7 “**Fiat” or “fiat currency**” means currency that is government-issued money. (e.g. the U.S. dollar.)\
2.8 “**Smart contract**” means a self-executing program stored on a blockchain that automatically enforces the terms of an agreement when predetermined conditions are met. They are written in code, and the blockchain network executes them, providing a secure, transparent, and irreversible way to automate transactions and processes.

## 3. OVERVIEW OF SHREDPAY SERVICES

3.1 **No Investment Advice**. The use of ShredPay Services is self-directed. ShredPay will not provide investment or financial advice to you. You are solely responsible for determining whether any particular investment, transaction, or Digital Asset is appropriate for you. ShredPay has no responsibility for any such determination.

3.2 **No tax or legal advice**. ShredPay does not provide tax or legal advice. You understand and agree that, unless required by Applicable Law, ShredPay will not, and is not required to, prepare or send to you any tax forms or reports related to your activity on or through ShredPay. You are solely responsible for reporting any taxable gains to the appropriate authority.

3.3 **No custody services**. ShredPay does not provide fiat custody services, and it does not provide digital asset custody services.

3.4 **Education Content**. ShredPay may provide educational information about Digital Assets in order to assist Users in learning more about such Digital Assets. Information may include, but is not limited to, blog posts, articles, links to third-party content, news feeds, tutorials, and videos. The information provided through ShredPay is educational only and does not constitute investment advice, an investment recommendation, legal advice, or tax advice. ShredPay is not registered with the U.S. Securities and Exchange Commission and does not offer securities services in the United States or to U.S. persons.

3.5 **ShredPay Markets Services**. ShredPay Markets offers the following services:

3.5.1 Facilitate the ability for Users to purchase and sell Digital Assets for fiat currencies through the ShredPay web portal or mobile application utilizing our products or those of one of our partners. Money Transmission Services are provided through Bridge Building Inc. (NMLS # 2450917).

3.6 **ShredPay Research Services**. ShredPay Research offers proprietary risk ratings of select third-party decentralized finance protocols (“ShredPay DeFi Risk Ratings”).

3.7 **ShredPay Liquid Services**. ShredPay Liquid offers the following services:

3.7.1 Facilitate the provision of Digital Asset Non-Custodial Wallets (“ShredPay Wallets” as defined below) for use by the User on the ShredPay platform;

3.7.2 Facilitate the Users’ ability to deposit, withdraw, and store the Digital Assets in ShredPay Wallets;

3.7.3 Display price quotes for Digital Assets through the ShredPay website or mobile application;

3.7.4 Facilitates the technology to enable the User to buy Digital Assets with fiat;

3.7.5 Facilitates the technology to enable the User to sell Digital Assets for fiat;

3.7.6 Facilitate the technology to enable the User to swap or trade Digital Assets through a decentralized cryptocurrency exchange (“DEX”);

3.7.7 Facilitate the ability for the User to deposit and withdraw Digital Assets to select third-party Decentralized Finance protocols at the direction of a User;

3.7.8 Facilitates the collection and delivery (to User’s ShredPay Wallet) of yields earned by the User’s Digital Assets deposited into third-party Decentralized Finance protocols;

3.7.9 Facilitates the ability to utilize Digital Assets for payments at the direction of a User; and

3.7.10 Facilitates the ability for a User to direct ShredPay to send Digital Assets to any digital wallet of the User’s choosing.

## 4. ELIGIBILITY

4.1 **GENERAL**&#x20;

4.1.1 **Individuals.**&#x54;o create a ShredPay Account you must be at least 18 years of age and reside in the United States and in a state that ShredPay serves. When you create an Account you confirm that you meet this age requirement as well as affirm that you have the capacity to enter into this Agreement and are not prohibited from doing so by any Applicable Law.

4.1.2 **Entities.** To register an Account or use the Services, you must be an entity duly formed and legally authorized to operate in the United States (“**Entity**”). Individuals registering to use the ShredPay Services on behalf of a legal entity, represent and warrant that (i) such legal entity is duly organized and validly existing under the Applicable Laws of the jurisdiction of its organization, and (ii) you are duly authorized by such legal entity to act on its behalf. You further represent and warrant that: (a) you are at least 18 years of age, (b) you have the power and authority necessary to enter this agreement, (c) entering this Agreement does not violate any other agreement to which you are a party, and (d) you have not previously been suspended or removed from using the Services. ShredPay is not responsible or liable for relying on the representations an Entity’s agents, employees, contractors, attorneys, financial advisors, or any other person ShredPay reasonably believes represents the Entity in the acceptance of this Agreement or in the acceptance of any other instruction or use of Services.

4.1.3 **Permitted U.S. Jurisdictions.** If you are registering as an individual, you may only register an Account or use Services if you reside in a state, district or territory in which ShredPay is authorized to provide Services (“**Permitted U.S. Jurisdictions**”). If you are registering as an entity, you may only register an Account or use Services if you are organized and operate in a state, district, or territory in a Permitted U.S. Jurisdiction.

4.1.4 **Restricted Jurisdictions.** "Restricted Jurisdiction" means any country, U.S, state, district or territory not supported by ShredPay, in addition to any sanctioned country according to the up-to-date lists of the US Office of Foreign Assets Control (OFAC), the United Nations, the European Union and any EU Member State, HM Treasury (UK) or equivalent authority.

4.1.5 **Services and Your Location.** Your registration of an Account indicates that you understand and agree that the Services made available to you may be limited depending on the jurisdiction from which you are accessing the Services. ShredPay reserves the right to restrict the Services made available to you based on your location. You further understand and agree that the Services may be limited or terminated if you are located in or move to a jurisdiction that is not supported by ShredPay. ShredPay shall not be liable to you for any claims relating to the limitation of the Services based on your location or termination of Service resulting from your access of the Service from an unsupported jurisdiction. You shall hold ShredPay harmless for any actions taken by ShredPay resulting from your moving to a new jurisdiction or accessing the Services from an unsupported jurisdiction.

## 5. YOUR RELATIONSHIP WITH SHREDPAY

5.1 **Acceptance and Understanding of Agreement**. When you create a ShredPay Account you are indicating that you have read, understood, and accepted all of the terms and conditions contained in this Agreement, as well as our (collectively, “**Supplemental Agreements**”). These Supplemental Agreements are incorporated by reference to this Agreement. Your creation of an Account binds you to the terms of this Agreement and the Supplemental Agreements.

5.2 **Modification of the Agreement.** ShredPay reserves the right to make changes to this Agreement and any Supplemental Agreement in our sole discretion. Unless specifically indicated otherwise, any change will take effect immediately when the revised Agreement is posted through one of our communication channels (such as our website or mobile or desktop applications, if applicable). While we will strive to provide you with advance notice of material changes to this Agreement (either through email or a notification on the ShredPay platform), advanced notification may not always be possible. It is your responsibility to regularly review this Agreement for updates because you will be bound by any updated terms regardless of whether you receive advance notice of an update from ShredPay. Your use of the Services after the effective date of any change to this Agreement indicates you have read and accepted any changes. If you do not agree with any changes to this Agreement, you may stop using or close your Account.

5.3 **Additional Terms**. You may need to accept additional terms in order to use our Services, which include the terms and conditions of ShredPay’s third party partners and/or vendors. Your agreement with such third parties will govern the terms and conditions of products or services provided by those third parties. We are not responsible for the products or services provided to you by any third party partner and/or vendor.

## 6. OPENING AN ACCOUNT

6.1 **Account Information**. In order to use the Services, you will need to complete an onboarding process which requires the provision of the following information (“**Onboarding Information”**).&#x20;

6.1.1 **Individuals**. Individuals who wish to onboard to ShredPay are required to provide information to verify their identity (e.g. name, email, residence address, telephone number, date of birth, taxpayer identification or social security number, official government-issued photo identification, bank account information and network identity) or source of funds (e.g. employment, inheritance, payment, settlement) (**“Personal Information”**). We may also request personally identifiable information or other information we may reasonably deem helpful in satisfying our risk management or legal obligations. You authorize us, directly, or through our third parties partners and/or vendors, to make any and all inquiries we deem necessary to verify your identity and any information you provide. As a condition to accessing and using the Services, you must authorize ShredPay, if applicable, to share your Personal Information with all ShredPay affiliates and/or third party partners and vendors as necessary. You agree to provide accurate, current, and complete Personal Information.&#x20;

6.1.2 **Entity Information**. During the Account registration process for entities, you must provide ShredPay with information and documentation that we (and/or our third party partners and/or vendors) request for the purpose of establishing and verifying your entity information (**“Entity Information”**). In addition, as a condition to accessing and using the Services, you must authorize ShredPay (if applicable) to share your Entity Information with its affiliates and/or third party partners and vendors as necessary. Entity Information may include, but is not limited to, the name, email address, phone number, date of birth, and taxpayer identification number of each of your beneficial owners or controlling persons, in addition to your Employer Identification Number and incorporation documents, letters of good standing, or other corporate information and documentation as applicable and requested by us. Entity Information will be retained by us at our discretion and may be made available to any governmental authority or self-regulatory organization upon reasonable request in accordance with Applicable Laws. You agree to provide accurate, current, and complete Entity Information.

6.2 **Onboarding Information**. Collectively, Personal Information and Entity Information will be referred to as “**Onboarding Information**” herein.

6.3 **Verification**. You hereby authorize ShredPay, and/or our third-party service partner or vendor that we designate, to take any measures that we consider necessary to confirm and continue to maintain confirmation on an ongoing basis the Onboarding Information you provide, verify and authenticate your Onboarding Information, and take any action ShredPay deems necessary based on the results. You acknowledge that this process may result in a delay in registering your Account, and that you will not be authorized to access or use the Services until your Account registration has been successfully completed.&#x20;

6.3.1 You shall comply with any request by us for any Onboarding Information or documents from you by no later than 14 days following the date of any such request (the “**Onboarding Information Deadline**”).&#x20;

6.3.2 In the event that the requested Onboarding Information is not received by us, including by the Onboarding Information Deadline, you fail to update your Onboarding Information when it changes, you fail to provide accurate Onboarding Information, we are unable to verify your identity, or for any reason at all within our sole discretion, we reserve the right to limit your use of the Services, including prohibiting the use of ShredPay’s Services altogether.

6.4 **Updates**. You agree to update us of any changes to the **Onboarding Information** within 10 days from the date that you became aware of the relevant change. You can update this information by emailing us at <support@shredpay.xyz>.

6.5 For a list of ShredPay sub-processors of User Data see the

## 7. ACCOUNT AUTHORIZATION.

7.1 **Minimum Initial Deposit**. In order to open an Account, you must make an initial minimum deposit by purchasing Digital Assets in the sum of no less than USD$250 (two-hundred and fifty dollars). Thereafter, there are no additional minimum requirements on further deposits into the Account. Deposits are stored as Digital Assets in your non-custodial ShredPay Wallets. ShredPay reserves the right to amend the minimum deposit amount at its discretion.

7.2 **Authorization to ShredPay**. You understand and acknowledge that ShredPay does not take custody of your Digital Assets or fiat funds. ShredPay also does not have ownership of your Digital Assets. You further understand and acknowledge that your ShredPay Account is self-directed, and you hereby appoint ShredPay as your agent for the purpose of carrying out your instructions you place through ShredPay in accordance with this Agreement. You agree that ShredPay may rely on your instructions and shall not be liable for relying on and executing on such instructions. You hereby authorize ShredPay to open and close your Account at its sole discretion, restrict access to Services at its sole discretion, settle and cancel orders to purchase and sell Digital Assets (“**Orders**”), collect and offset any fees or other amounts due to ShredPay, block transactions or freeze assets as necessary, and take such other steps as are reasonable to carry out your instructions or any legally required action.

7.3 **Authorization to Fund Digital Assets Transactions.** You understand and acknowledge that when you submit an Order to purchase Digital Assets through the Platform, you are authorizing and instructing ShredPay, through its third-party partners or vendors, to transfer funds to your ShredPay Balance from a valid U.S. bank account that you have linked to your ShredPay Account, or from a valid fiat-funded account that you have linked to your ShredPay Account (“**Linked Payment Methods**”). We or our third-party partners or vendors may require that the name on your Linked Payment Method match your name. You further understand and acknowledge that no third party has the ability to monitor or recall funds after such funds have been wired or transferred to ShredPay.

7.4 If you select to utilize "Coinbase" or "Apple Pay" as the method by which you fund your Account, you acknowledge that you are purchasing Digital Assets through a Digital Asset exchange operated by Coinbase, Inc. or its affiliate ("Coinbase"), which is governed by separate terms and conditions between you and Coinbase:\
<https://www.coinbase.com/legal/guest-checkout/us>;\
<https://www.coinbase.com/legal/privacy>

7.5 **No SIPC or FDIC Protection.** ShredPay will not custody your funds or use your funds for its operating expenses or any other corporate purposes. You understand that fiat funds transferred to ShredPay are solely for the purchase of Digital Assets and that ShredPay does not store fiat funds on behalf of its users. You understand that all funds transferred to ShredPay, whether in the form of Digital Assets or fiat currency, will not be protected by the Securities Investor Protection Corporation (“**SIPC**”), nor will they be provided protection under the Federal Deposit Insurance Corporation (“**FDIC**”). You understand and acknowledge that Digital Assets in your ShredPay Account are held in your non-custodial wallet, not held at any bank.

7.6 **Authorization to Share Information with Business.** If ShredPay is provisioning an Account to you, you hereby authorize ShredPay to provide any applicable third-party (as discussed below) any of your Background Information, and to continue sharing such information, and any revisions or additions thereto, with applicable third-party on an ongoing basis until your account with ShredPay is closed. ShredPay may retain all Account information, including Account activity and Background Information, as required by this Agreement and law, and may share such information with a: (i) governmental authority or other third-party in accordance with any subpoena, regulatory request, court order, Applicable Law, or other legal requirement; and (ii) third-party in order to verify the Background Information. For further information on how we use or share your Background Information and other information you provide us during your use of the Services, see the ShredPay .

7.7 **Revocation of Your Authorization**. You may revoke our authorization to charge your ShredPay Balance with respect to future transactions (other than recurring transactions set to occur within one Business Day) by closing your Account, as described below.

## 8. PLACING ORDERS TO BUY AND SELL DIGITAL ASSETS

8.1. NEITHER SHREDPAY NOR ANY OF ITS AFFILIATES ARE FDIC-INSURED BANKS OR SIPC-MEMBER BROKERAGE FIRMS. ACCORDINGLY, YOUR DIGITAL ASSETS ALSO ARE NOT PROTECTED UNDER THE SIPC OR THE FDIC AND MAY LOSE VALUE.

8.2. ShredPay will facilitate your ability to submit offers to purchase Digital Assets with fiat currency or sell Digital Assets for fiat currency subject to the terms of this Agreement and subject to the terms of any third-party service provider’s platform through which ShredPay offers you this service. UNLESS OTHERWISE STATED IN THE SERVICES, OR AS SET FORTH HEREIN, WHEN YOU PURCHASE OR SELL DIGITAL ASSETS USING YOUR SHREDPAY ACCOUNT, YOU MAY BE PURCHASING OR SELLING DIRECTLY FROM SHREDPAY OR FROM ONE OF ITS THIRD-PARTY PARTNERS OR UNAFFILIATED ENTITIES. YOU AGREE THAT TO THE EXTENT THE PURCHASE IS MADE THROUGH A THIRD PARTY YOU ARE SUBJECT TO THAT THIRD PARTY’S TERMS AND CONDITIONS.

8.3. You must carefully enter and review all of the order details prior to submitting an offer to purchase or sell Digital Assets. If you agree to the terms as displayed, including pricing, you can then accept and submit the order. If you do not agree to the pricing displayed, or any other term, you can choose not to proceed with the order. Once you submit your order, you are bound to the terms of that order. You may not cancel, reverse or change any order once it has been submitted.

8.4. Once an order to purchase Digital Assets is submitted by you and accepted by ShredPay, ShredPay will receive the value that corresponds to the amount of purchase via your selected Linked Payment Method. This can include other Digital Asset wallets and connected bank accounts (if you have more than one Linked Payment Method, you will be given the option to select a different Linked Payment Method than the last one utilized). By adding a Linked Payment Method, you represent to us that you are the owner or an authorized User of that payment method. In order to purchase Digital Assets, you must have at least one Linked Payment Method associated with your ShredPay Account. By initiating a purchase with your selected Linked Payment Method, you authorize us and/or our applicable third-party service providers, to charge or debit your selected Linked Payment Method for the total amount of the purchase, including without limitation all applicable fees and taxes. In the event of any refund, chargeback, or other adjustment related to your Digital Assets purchase, you authorize us to credit or deduct the amount, as applicable, from your Linked Payment Method. The date and time that you initiate instructions to ShredPay to purchase Digital Assets may differ from the date and/or time when the order is executed and your Linked Payment Method is debited.

8.5. For orders to sell Digital Assets for fiat, once the order is created and accepted and the Digital Assets to be sold are delivered to ShredPay, ShredPay will deposit the proceeds from the sale to your selected Linked Payment Method. The date and time that you initiate instructions to ShredPay to sell Digital Assets may differ from the date and/or time when the order is executed and the proceeds from the sale are credited to your account.

8.6. Only certain payment methods are able to be linked to your ShredPay Account. Please refer to your ShredPay Account or the ShredPay website or app for further information on acceptable payment methods.

8.7. ShredPay may impose a minimum holding period for any Digital Assets that you would like to buy or sell, which may last up to seven (7) Business Days. These minimum holding periods are necessary to enable ShredPay to (a) engage in fraud prevention measures, (b) ensure settlement of the fiat currency leg of a transaction, and/or (c) complete its compliance reviews. If ShredPay cannot or does not complete the order for any reason (including, without limitation, suspected fraud, price movement, market latency, order size, or any other reason in ShredPay’s sole discretion), ShredPay may reject the order and notify you of such rejection and you will not be charged for a rejected Order. ShredPay automatically imposes a seven (7) Business Day holding period for any stablecoins purchased with fiat currency (“Fiat-Purchased Stablecoins”) through the services provided by Bridge Building, Inc., during which you may not withdraw the Fiat-Purchased Stablecoins to an external digital asset wallet nor sell them back for fiat currency. You may otherwise use ShredPay’s services as permitted, including by trading Fiat-Purchased Stablecoins for other digital assets on the DEX, except that you will remain prohibited from withdrawing the digital assets you received in exchange for the Fiat Purchased Stablecoins by any means until the holding period terminates.

8.8. Notwithstanding anything to the contrary, ShredPay reserves the right to, in its sole discretion, suspend, delay, redirect, or cancel any transaction (including an order submitted by you and accepted by ShredPay) at any time and for any reason. ShredPay further reserves the right to block transactions or freeze assets as required by Applicable Law.

8.9. If your payment is not successful, for example because your payment method has insufficient funds or you reverse a payment made from funds in your bank account, you authorize ShredPay, in its sole discretion, to either cancel the transaction or to debit your other Linked Payment Methods in any amount necessary to complete the transaction on its original terms. You are responsible for maintaining an adequate balance and/or sufficient credit limits in order to avoid overdraft, non-sufficient funds (NSF) or similar fees. Any such fees charged by your financial services provider will be solely your responsibility.

8.10. We reserve the right to refuse to process or to cancel or reverse any transaction in our sole discretion, even after funds have been debited from your Linked Payment Method(s), if we suspect the transaction meets any criteria set forth in this Agreement triggering cancellation or reversal or otherwise breaches this Agreement. In such instances, ShredPay will reverse the transaction and we are under no obligation to allow you to reinstate a purchase or sale order at the same price or under the same terms as the canceled transaction.

8.11. You may revoke our authorization to charge your Linked Payment Method with respect to all future transactions or stop the next recurring transaction (other than recurring transactions that are scheduled to occur in one or fewer Business Days) by going to the settings icon in your Account and navigating to recurring transactions; selecting the transaction(s) that you would like to cancel, opening the menu and tapping "Cancel recurring buy". When you close your Account, we will cancel any transactions that have not been completed, and you will remain liable and responsible for any and all obligations related to your Account, even after the account is closed.

8.12. You authorize your wireless carrier to use or disclose information about your Account and your wireless device, if available, to ShredPay or our applicable third-party partner or vendor for the duration of your business relationship. See our policy for how we treat your data.

8.13. NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, WE DO NOT GUARANTEE ANY ORDER YOU SUBMIT WILL BE EXECUTED, OR EXECUTED AT ANY PARTICULAR TIME, AND WE WILL NOT BE RESPONSIBLE FOR ANY DELAYS OR FOR ANY ORDERS THAT ARE NOT EXECUTED.

## 9. LIMITATIONS ON PLACING ORDERS TO BUY AND SELL DIGITAL ASSETS

9.1 **Submitting orders.** To submit offers to purchase or sell Digital Assets, you must first establish an Account. Your access to your ShredPay Account, and the ability to submit orders for Digital Assets, may not be available in all markets and jurisdictions. ShredPay has sole authority to restrict or prohibit use of a ShredPay Account at its discretion, including implementing transaction limits, in any jurisdiction including Restricted Jurisdictions. We may also update these limitations at any time with or without notice to you.

9.2 **Unauthorized Orders.** You agree that you are solely responsible for maintaining adequate security and control of your login and authentication details (including, but not limited to, your identity, email address and User name). You agree you are solely responsible for any access to and use of the Services and your Account, notwithstanding that such access or use may have been effected without your knowledge, authority or consent. You are solely responsible for all orders that occur using your ShredPay Account, including any orders and completed transactions that were not authorized by you. When an order occurs using your ShredPay Account credentials, we will assume that you authorized such an order. Except as otherwise provided in this Agreement, you agree that ShredPay will not be liable to you for any unauthorized orders, completed transactions or loss or damage resulting from any unauthorized access to your ShredPay Account. If you have reason to suspect that your ShredPay Account login and/or authentication details (including, but not limited to your email address) have become compromised, you are responsible for immediately contacting ShredPay by emailing <support@shredpay.xyz>.

9.3 **Mistaken/Accidental Orders.** You agree that you are solely responsible for reviewing the transaction summary page for accuracy before you choose to continue with a transaction. You agree that you are liable for ensuring that the information provided to ShredPay regarding your requested order is correct. Except as otherwise provided herein, ShredPay assumes that when an order occurs using your Account credentials, that the order is correct and authorized by you. You agree that ShredPay will not be liable to you for any mistaken or accidental orders placed using your ShredPay Account.

9.4 **Potentially Fraudulent Activity.** ShredPay and its applicable third-party partners and vendors maintain Anti-Fraud Policies designed to detect and prevent fraud and to identify and assess fraud-related risk areas. ShredPay shall monitor your use of your Account. Any actual or suspected Unauthorized Access and/or Unauthorized Activity will be treated by ShredPay as potentially fraudulent (“Potentially Fraudulent Activity”). You agree to notify us as soon as possible if you become aware of or suspect any Potentially Fraudulent Activity by emailing <support@shredpay.xyz>. For the avoidance of doubt, you are deemed to be aware of Potentially Fraudulent Activity upon receipt of any notice of the occurrence of such activity. Upon receipt of written notice via email to <support@shredpay.xyz> from you of any Potentially Fraudulent Activity, ShredPay (if applicable) will take reasonable and timely steps to protect your Account, including, for example, by temporarily restricting access to your Account, suspending any pending orders, and/or requiring you to change your Login Credentials. You agree to promptly report any Potentially Fraudulent Activity to legal authorities and provide us a copy of any report prepared by such legal authorities to <support@shredpay.xyz>. In the event of an investigation of any Potentially Fraudulent Activity, you further agree to: (i) cooperate fully with the legal authorities and ShredPay in such investigation; (ii) complete any required affidavits promptly, accurately and thoroughly; and (iii) allow ShredPay, or any third-party designated by us, access to your mobile device, computer, and network as may be relevant to such investigation. You understand and acknowledge that any failure to cooperate in any such investigation may cause delays in regaining access to your Account.

## 10. SHREDPAY WALLETS

10.1 ShredPay will provision Users with non-custodial wallets (“**ShredPay Wallets**”) through a third-party digital wallet infrastructure partner. Each individual User is provided with their own Holding Wallet, which is a non-custodial wallet that provides easy access to the User’s Digital Assets (“**Holding Wallet**”). ShredPay will also provision a non-custodial Deposit Wallet for each User through a third-party digital wallet infrastructure partner (“**Deposit Wallet**”), which receives deposits from external wallets to be automatically screened for sanctions and other compliance purposes (“Automated Screening”). Once the transaction passes Automated Screening, the funds are automatically routed through the Fee Smart Contract, which deducts applicable fees as described below, and then routes the funds into the Holding Wallet. All User-deposited funds will be automatically routed to the Deposit Holding Wallet through this process unless the attempted transaction fails Automated Screening. Solely in the limited circumstances that the funds fail Automated Screening, ShredPay may take action consistent with the terms of Section 10.3 below.

10.2 When you buy stablecoins or other Digital Assets at ShredPay, those Digital Assets will be automatically deposited into your Holding Wallet. You can then use your Holding Wallet to monitor your overall balance and take further actions directly from your Holding Wallet. Note that actions that require a fee deduction will be automatically routed through a smart contract published by ShredPay that deducts applicable fees before sending the Digital Assets to the end destination (“Fee Smart Contract”). The Fee Smart Contract will be a routing wallet only, will never hold a balance of Digital Assets, and ShredPay has no ability to freeze, withdraw, or transact with your assets moving through the Fee Smart Contract other than the automatic deduction of applicable fees. For the avoidance of doubt, the compliance-related screening of Digital Assets deposited in the Deposit Wallet occurs before any fees are deducted by the Fee Smart Contract.

10.3 You acknowledge and agree that ShredPay will have the limited authority to block deposits and withdrawals into and out of your ShredPay Wallets if such deposits and withdrawals are in violation of Applicable Law or at the discretion of ShredPay’s compliance department. ShredPay otherwise has no ability to direct transactions within or through your ShredPay Wallets or control the assets or funds therein.

10.4 When using the Services, you may be asked to provide us with the address of a Digital Asset wallet (“**User Wallet**”) that you or a third party holds for the purpose of moving assets on to or away from the ShredPay platform. You may provide the address of your User Wallet in one of three ways: (a) by providing a QR code which represents your User Wallet address; (b) manually typing a User Wallet address; or (c) using a User Wallet address provided by a ShredPay partner. You represent and warrant that you are the owner and controller of the User Wallet that you link to your account.

10.5 By providing us with an address that you represent to be your User Wallet, you represent and warrant that you own and control the User Wallet. There is no way for us to help you if you lose control over your User Wallet. It is your responsibility to keep your User Wallet safe from both theft and inadvertent loss. As the owner of Digital Assets in your User Wallet, you bear all risk of loss of such Digital Assets.

10.6 In the event that you provide the wallet address of a third party for purposes of delivery of assets held in your ShredPay Wallet, you represent that to the best of your knowledge that third party wallet is not held by a person who resides in a Restricted or Prohibited Location or would otherwise be prohibited from utilizing Services. All wallets receiving assets from ShredPay Wallets will be subject to compliance screening. Such compliance screening may result in a delay of the transfer of assets or the blocking of such transfer in the event that the transaction would be prohibited under relevant law.

10.7 You are solely responsible for maintaining the security of your login credentials. You acknowledge and agree, without prejudice to any other terms in this Agreement, that you bear all of the risk of any loss of access to your ShredPay Wallets and any Digital Asset contained therein. ShredPay is not liable for fluctuations in the fiat currency value of Digital Assets in your ShredPay Wallets.

10.8 If you send Digital Assets from your ShredPay Wallets to a wallet address that you entered incorrectly, you may lose access to your Digital Assets temporarily or permanently. ShredPay is not responsible or liable for erroneous, accidental, or mistaken Digital Asset transfers that you effectuate. If you have initiated an accidental or mistaken order through ShredPay, you are responsible for contacting ShredPay at <support@shredpay.xyz>, however, transactions in Digital Assets may be irreversible, and, accordingly, losses due to accidental transactions may not be recoverable.

## **11. SHREDPAY SMART CONTRACTS**

11.1 In order to facilitate the blockchain movement of Digital Assets for certain Services, you acknowledge and agree that your Digital Assets may flow through (but not be custodied by), ShredPay blockchain smart contracts. You acknowledge that ShredPay’s smart contracts may experience errors, bugs, cyberattacks, downtime, or failures.

11.2 **ShredPay Smart Contract Audit** - You may review the ShredPay smart contracts third-party audits here: [Quantstamp First Audit Repor](https://drive.google.com/file/d/1i-gq8c04xNBjfng_qvuLMjL0_2Dhf6rw/view?usp=sharing)t & [Quantstamp Second Audit Report](https://drive.google.com/file/d/1tc8cE_f9JlfjLloKV6eBReNsDFivS3mA/view?usp=drive_link).

## 12. PLACING ORDERS TO TRADE DIGITAL ASSETS

12.1 ShredPay does not provide centralized cryptocurrency exchange trading services.

12.2 When placing an order to trade or swap a Digital Asset for another Digital Asset, ShredPay facilitates the technology for the User to obtain price quotes from a third-party decentralized exchange (“DEX”) Aggregator. Upon receiving a price quote, the User will self-direct the DEX order, and ShredPay will facilitate the technology for the delivery of the Digital Asset to the DEX counterparty, and the receipt of the Digital Asset from the DEX counterparty. These Digital Asset transactions are peer-to-peer blockchain transactions which are generally irreversible.

12.3 ShredPay does not serve as an intermediary for DEX transactions, and you remain solely responsible for any losses or damages that result from your self-directed DEX transactions including, but not limited to, the real-time pricing information sourced from the third-party DEX Aggregator, or any other third party-source utilized by ShredPay.

12.4 When placing an order to buy or sell a Digital Asset, your order will be executed at or near the price offered by the DEX. ShredPay does not make any representation, warranty or guarantee that the prices offered by the DEX are fair market value, and may, at times, be materially higher or lower than prices available on other platforms or Digital Asset exchanges. ShredPay shall not be liable or responsible for any such price differences or other potential adverse events or adverse consequences you may experience, including but not limited to movements in the price of a Digital Asset between the placement of an order for that Digital Asset and the order’s execution, commonly known as “slippage,” which may be as much as 1% or more of the price of the Digital Asset quoted at order placement. Under certain market conditions you may find it difficult to trade a Digital Asset. In such circumstances, the DEX may not have sufficient demand to meet your request to execute such a transaction. You acknowledge and accept the risk that those market conditions may exist.

12.5 All Digital Asset buy/sell orders are executed on the broader blockchain ecosystem utilizing a decentralized exchange aggregator. In order to provide ShredPay customers with efficient liquidity and the ability to effectively use certain Digital Assets within decentralized finance applications, the ShredPay platform operates on the Ethereum and Base blockchains. With respect to tokens that are not native to the Ethereum and Base networks, ShredPay offers customers the following assets that are “wrapped” by third-party Coinbase, Inc. (“Coinbase”), allowing them to be efficiently deployed on the Base blockchain:\
  • Bitcoin (cbBTC): Represents Bitcoin and is available on the Base, Ethereum, Solana, and Arbitrum networks.\
  • Dogecoin (cbDOGE): Represents Dogecoin on the Base network.\
  • Ripple (cbXRP): Represents XRP on the Base network.\
  • Litecoin (cbLTC): Represents Litecoin on the Base network.\
  • Cardano (cbADA): Represents Cardano on the Base network. (jointly hereafter “Wrapped Tokens”)

Coinbase wrapped tokens are backed 1:1 by the underlying assets held in custody by Coinbase (i.e., for every cbBTC token issued, Coinbase holds one BTC token), and these holdings are verified by a Proof of Reserves system. For more information, you can access the relevant Coinbase page here: <https://help.coinbase.com/en/coinbase/trading-and-funding/sending-or-receiving-cryptocurrency/coinbase-wrapped-btc>\
By placing an order for a Wrapped Token, you acknowledge and agree to the terms of this Section 12.5 and understand that ShredPay does not warranty or guarantee in any manner the ability for a Wrapped Token to be exchanged by Coinbase.

## 13. Depositing into Decentralized Finance Protocols

**13.1 Third-Party Decentralized Finance Protocols**

ShredPay will make available to you the ability to deposit Digital Assets into select third-party decentralized finance protocols. You acknowledge and agree and the offered decentralized finance protocols are fully independent from ShredPay and you agree to accept all risks associated with depositing Digital Assets into a decentralized finance protocol including, but not limited to:

**13.1.1 Blockchain & Smart Contract Risk**

By depositing Digital Assets into a decentralized finance protocol, you accept all risks associated with new and experimental technologies like smart contracts and blockchain-based systems. These technologies, especially crypto-assets, are inherently volatile and blockchain-based systems may experience errors, bugs, cyberattacks, smart contract vulnerabilities, hacks, forks, attacks, downtime, or failures—potentially leading to a total loss of your crypto-assets or funds.

**13.1.2 Irreversible Transactions**

Blockchain entries are permanent and immutable. Once confirmed, transactions (including crypto-assets transfers and programmed data) cannot be undone by you, us, or anyone.

**13.1.3 Service and Data Availability**

Access to decentralized finance protocols may be interrupted or unavailable due to technical failures, maintenance, or third-party issues.

**13.2 Deposits and Withdrawals**

By requesting to deposit Digital Assets into a decentralized finance protocol, you agree that ShredPay will route the Digital Assets from your ShredPay Wallets through a ShredPay smart contract for delivery to the selected decentralized finance protocol. Similarly, by requesting to withdraw Digital Assets from the selected decentralized finance protocol, you agree that ShredPay will route the Digital Assets from the selected decentralized finance protocol through a ShredPay smart contract for deposit into your ShredPay Wallets.

**13.3 Decentralized Finance Protocol Yields**

You agree that any decentralized finance protocol yields earned by your digital asset deposits will be delivered to a ShredPay smart contract for deposit into your ShredPay wallet.

**13.4 Decentralized Finance Yield Sweep**

You acknowledge that, once every 24 hour period, ShredPay will sweep all yields earned by your digital asset deposits into its ShredPay smart contract for deposit into your ShredPay wallet. You agree that any yield earned by you will be subject to a performance fee as set forth in the at the time the sweep occurs.

**13.5 Conversion to Stablecoin**

In the event that the yield earned by your Digital Asset is not paid by the decentralized finance protocol in stablecoin, you agree to permit ShredPay to convert, at its reasonable discretion, any such yield to stablecoin prior to delivery to your ShredPay Wallets. ShredPay will not assess a fee for this conversion and you acknowledge that volatility of the Digital Asset yield prior to conversion to stablecoin may result in a reduction in the amount of total yield proceeds deposited into your ShredPay Wallets.

### **14. USE OF SHREDPAY DEFI RISK RATINGS**

**14.1** While ShredPay may make available its own proprietary research and/or publish a ShredPay DeFi Risk Rating, or other information, this does not constitute an individualized recommendation that a decentralized finance protocol deposit/transaction is appropriate for you. You agree not to hold ShredPay liable for any losses, lost profits or other damages resulting from your use of - or reliance upon - any ShredPay DeFi Rating.

**14.2** In issuing and maintaining its ShredPay DeFi Ratings, ShredPay relies on factual information it obtains from the third-party decentralized finance protocol and other publicly available sources that ShredPay believes to be credible. ShedPay conducts a reasonable investigation of the factual information relied upon by it in accordance with its ratings methodology, and obtains reasonable verification of that information from independent sources, to the extent such sources are available. You may learn more about ShredPay DeFi Ratings.

**14.3** Users of ShredPay DeFi Risk Ratings should understand that neither an enhanced factual investigation nor any third-party verification can ensure that all of the information ShredPay relies on in connection with a risk rating will be accurate and complete. Further, risk ratings are inherently forward-looking and embody assumptions and predictions about future events that by their nature cannot be verified as facts. As a result, despite any verification of current facts, ratings can be affected by future events or conditions that were not anticipated at the time a rating was issued or affirmed.

**14.4** ShredPay seeks to periodically improve its ratings criteria and methodologies and periodically updates the descriptions of its criteria and methodologies. The criteria and methodology used to determine a rating action are those in effect at the time the risk rating is published.

**14.5** SHREDPAY DEFI RISK RATINGS ARE PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND AND SHREDPAY MAKES NO REPRESENTATION OR WARRANTY, EXPRESS OR IMPLIED, AS TO THE ACCURACY, TIMELINESS, COMPLETENESS, MERCHANTABILITY OR FITNESS FOR ANY PARTICULAR PURPOSE OF ANY SUCH INFORMATION.

**14.6** Each User acknowledges that a ShredPay risk rating is an opinion as to the specified decentralized finance protocol. This opinion is based on established criteria and methodologies that ShredPay is periodically evaluating and updating. Therefore, ratings are the collective work product of ShredPay and no individual, or group of individuals, is solely responsible for a risk rating. Risk ratings may be changed or withdrawn at any time for any reason in the sole discretion of ShredPay. In issuing and/or maintaining a risk rating, ShredPay is not making any recommendation or suggestion, directly or indirectly to you, or any other person, to undertake any investment strategy with respect to any decentralized finance protocol. ANY PERSON OR ENTITY WHO USES - OR RELIES UPON - A SHREDPAY RISK RATING DOES SO ENTIRELY AT HIS, HER OR ITS OWN RISK.

#### 15. RECURRING PURCHASES OF DIGITAL ASSETS

**15.1.** We may enable you to purchase Digital Assets on a recurring basis using your Linked Payment Method that we authorize from time to time. By enrolling in recurring Digital Asset purchases, you authorize us to debit your Linked Payment Method at the frequency and in the amount, including applicable fees, that you specified at the time of enrollment until you cancel.

**15.2.** Your enrollment in recurring purchases will continue until you cancel. You may cancel your recurring Digital Assets purchases by going to the settings icon in your ShredPay account, navigating to Recurring transactions and selecting the transaction(s) that you would like to cancel.

**15.3.** For all recurring Digital Asset purchases, we will provide notice to you one Business Day before the purchase is initiated. After the recurring Digital Asset purchase is completed, we will provide notice of the completion.

**15.4.** The amount that you may be charged in connection with your recurring purchase will not change. However, the amount of Digital Assets you receive for your recurring purchase is based on current market prices and fees at the time of the recurring purchase.

**15.5.** If you have told us in advance to make regular payments for the purchase of Digital Assets from a Linked Payment Method, you can stop any of these payments by taking the following action:

**15.5.1.** Contact us at <support@shredpay.xyz>, in time for us to receive your request 3 Business Days or more before the payment is scheduled to be made.

**15.6.** If you request to cancel a specific recurring purchase for a Digital Asset, we will cancel all future recurring purchases for that Digital Asset. You will need to re-enroll in recurring purchases if you wish to continue making recurring purchases from your authorized Linked Payment Method for that Digital Asset. However, if you have more than one recurring purchase set up (i.e., different recurring purchases for different Digital Assets), canceling one recurring purchase only cancels future recurring purchases for that Digital Asset. If you want to cancel a recurring purchase for a different Digital Asset, you will need to separately cancel that recurring purchase.

## 16. Fees

**16.1 Types of fees.**&#x20;

**16.1.1** ShredPay does not charge deposit and fiat-to-stablecoin fees.&#x20;

**16.1.2** ShredPay charges stablecoin-to-fiat fees, digital asset withdrawal fees, and fiat withdrawal fees.&#x20;

**16.1.3** ShredPay also charges transaction and performance fees related to decentralized finance protocol deposits, buy/sell crypto commissions, and merchant payment fees.&#x20;

**16.1.4** Additional third-party fees for ACH and debit card deposits, and gas fees for decentralized protocols will be passed on to you.

**16.2** **Pricing schedule.** A schedule of the types of fees can be found on our [Pricing and Fees Disclosure](/shredpay-legal-documents/shredpay-pricing-and-fee-disclosure). ShredPay reserves the right to adjust its pricing and fees and any applicable waivers at any time. We will always notify you of the pricing and fees which apply to your transaction before you authorize the transaction and will confirm those fees following completion of the transaction.

**16.3** **Debiting for fees.** You agree that ShredPay may debit fees (the amounts as disclosed in the Pricing and Fees Disclosure) automatically and without prior notice for Services.

**16.4 Bank fees.** You are responsible for payment of any third-party bank fees (such as ACH and wire fees) charged in connection with the transfer of assets to or from the ShredPay platform. Such fees will be itemized on any transaction receipt or confirmation provided by ShredPay.

**16.5** **Receipts**. Upon placement of an order, ShredPay will provide you with certain information regarding your transaction such as the amount of Digital Assets you sold/purchased, the amount your Linked Payment Method will be charged for the purchase, and any fees imposed on the transaction.

## 17. PROHIBITED USE

You may not use your Account or any of the Services to engage in the following categories of activity (“Prohibited Use”):

17.1 **Unlawful Activity.** Activity which would violate, or aid or assist in violation of, any law, statute, ordinance, regulation, or sanctions programs administered in the countries where ShredPay conducts business, including but not limited to the U.S. Department of Treasury's Office of Foreign Assets Control ("OFAC"), or which would involve proceeds of any unlawful activity; publishing, distributing or disseminating any unlawful material or information. This includes unlawful gambling (i.e. internet gaming, lotteries, bidding fee auctions, sports forecasting or odds-making, fantasy sports leagues with cash prizes, contests, sweepstakes, or illegal games of chance).

17.2 **Fraud.** Activity which operates to defraud ShredPay, ShredPay Users, or any other person; provide any false, inaccurate, or misleading information to ShredPay.

17.3 **Forbidden Activity.** Transactions involving (a) illegal and/or controlled substances, (b) drug paraphernalia, (c) cigarettes, (d) items that encourage, promote, facilitate or instruct others to engage in illegal activity, (e) stolen goods including digital and virtual goods, (f) the financial exploitation of a crime, (g) obscenity and sexually oriented materials or services, (h) infringement or violation of any copyright, trademark, right of publicity or privacy or any other proprietary right under the laws of any jurisdiction, (i) weapons including, without limitation, firearms, ammunition, firearm parts or accessories, and/or knives, that are regulated under Applicable Law, and (j) the promotion of hate, violence, racial or other forms of intolerance that is discriminatory

17.1.4 **Abusive Activity.** Actions which detrimentally interfere with, intercept, or expropriate any system, data, or information; impose an unreasonable or disproportionately large load on our infrastructure; transmit or upload any material to the ShredPay platform that contains viruses, worms, trojan horses, or any other harmful or deleterious programs; attempt to gain unauthorized access to the ShredPay platform, other Accounts, computer systems or networks connected to the ShredPay platform, through any means; use of ShredPay Account information of another party to access or use the ShredPay platform, except in the case of specific merchants and/or applications which are specifically authorized by a User to access such User's Account and information; or transfer your account access or rights to your account to a third party, unless by operation of law or with the express permission of ShredPay.

17.1.5 **Intellectual Property Infringement.** Engage in transactions involving works that infringe or violate any trademark, copyright, right of publicity or privacy, or any other proprietary right under the law, including but not limited to sales, distribution, or access to counterfeit music, movies, software, images / likenesses, or other licensed materials without the appropriate authorization from the rights holder; use of ShredPay intellectual property, name, or logo, including use of ShredPay trade or service marks, without express consent from ShredPay or in a manner that otherwise harms ShredPay or the ShredPay brand; any action that implies an untrue endorsement by or affiliation with ShredPay.

17.6 **Abuse Other Users.** Engage in activity that shows the personal information of others in violation of Applicable Law; interfere with another individual’s or entity's access to or use of any Services; abuse, extort, defame, harass, stalk, threaten or otherwise violate or infringe the legal rights (such as, but not limited to, rights of privacy, publicity and intellectual property) of others; harvest or otherwise collect information from the ShredPay platform about others, including without limitation email addresses, without proper consent.

17.7 **Unacceptable Activity**. Transactions that (a) show the personal information of third parties in violation of Applicable Law, (b) support pyramid or ponzi schemes, matrix programs, other "get rich quick" schemes or certain multi-level marketing programs, (c) are associated with purchases of annuities or lottery contracts, lay-away systems, off-shore banking or transactions to finance or refinance debts funded by a credit card, (d) are for the sale of certain items before the seller has control or possession of the item, (e) are by payment processors to collect payments on behalf of merchants, (f) are associated with the sale of traveler's checks or money orders, (g) involve currency exchanges or check cashing businesses, (h) involve certain credit repair, debt settlement services, credit transactions or insurance activities, or (i) involve offering or receiving payments for the purpose of bribery or corruption.

## 18. REPRESENTATIONS AND WARRANTIES

18.1 You represent and warrant to ShredPay that you: (a) are a resident of the United States; (b) you are not located in, under the control of, or a resident of any Restricted Location or any country to which the United States has embargoed goods and services; (c) are not identified as a “Specially Designated National” by the United States Treasury Department; and (d) will not use the Services if you are prohibited by any Applicable Law from doing so.

18.2 You agree that you are solely responsible for your conduct while accessing and using the Services. You further agree, without limitation to the generality of the foregoing, that you shall not:

18.2.1 Use the Services in any manner that could disrupt, interfere with, inhibit, prevent, or in any way negatively affect other Users from fully utilizing the Services, or that could disable, overburden, damage, or impair the functioning of ShredPay’s Services in any manner;

18.2.2 Provide false, inaccurate, or misleading information;

18.2.3 Use the Services to pay for, support or otherwise engage in any illegal activities;

18.2.4 Use any automated means or interface including, without limitation, robot, spider, crawler, scraper, not provided by us to access our Services or to extract data;

18.2.5 Use or attempt to use another person’s ShredPay Account;

18.2.6 Attempt to circumvent any content filtering techniques we employ, or attempt to access any service or area of our Services that you are not authorized to access;

18.2.7 Introduce to the Services any virus, Trojan horse attacks, worms, logic bombs, or other harmful material;

18.2.8 Develop any third-party applications that interact with our Services without our prior written consent; or

18.2.9 Encourage or induce any other person to engage in any of the activities prohibited under this Agreement.

18.3 SHREDPAY DISCLAIMS ANY AND ALL REPRESENTATIONS, WARRANTIES, AND PROMISES, WHETHER EXPRESS, IMPLIED OR STATUTORY, INCLUDING, WITHOUT LIMITATION, ANY WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, TITLE, QUIET ENJOYMENT, NON-INFRINGEMENT, DATA ACCURACY, AND/OR SYSTEM INTEGRATION. ANY SERVICES PROVIDED BY SHREDPAY ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS. SHREDPAY DOES NOT MAKE ANY REPRESENTATIONS OR WARRANTIES OF ANY KIND WHATSOEVER (A) REGARDING THE CONTENTS OF THE SERVICES, THE SECURITY ASSOCIATED WITH THE TRANSMISSION OF INFORMATION THROUGH THE SERVICES, THE INFORMATION AND FUNCTIONS MADE ACCESSIBLE THROUGH THE SERVICES, ANY HYPERLINKS TO THIRD PARTY WEBSITES, OR ANY WEBSITE LINKED TO THE SERVICES OR (B) THAT ACCESS TO THE SERVICES SHALL BE UNINTERRUPTED, TIMELY, CONTINUOUS, OR ERROR-FREE.

EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, YOU ACKNOWLEDGE THAT SHREDPAY MAKES NO WARRANTIES UNDER THIS AGREEMENT DIRECTLY FOR THE BENEFIT OF ANY END USER, AND THAT SHREDPAY’S OBLIGATIONS UNDER THIS AGREEMENT ARE FOR THE BENEFIT OF YOU ONLY, AND NOT FOR THE BENEFIT OF ANY OTHER PERSON. IN ENTERING INTO THIS AGREEMENT, YOU REPRESENT THAT YOU HAVE NOT RELIED UPON ANY REPRESENTATION OR WARRANTY OF SHREDPAY OR ITS AFFILIATES EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT.

## 19. INDEMNIFICATION AND LIMITATIONS OF LIABILITY

19.1 **Indemnification**. You agree to indemnify and hold harmless ShredPay, its subsidiaries, affiliates, officers, directors, members, managers, employees, and other customers, from any and all claims, damages, losses, costs, expenses, demands or actions, including without limitation, reasonable legal fees, arising out of or relating to your or any other person’s use of the ShredPay platform or your ShredPay credentials in connection with: (a) violation of any Applicable Law; (b) use of the Services; (c) breach of this Agreement or any other agreement or policy; (d) false, incomplete, or misleading information relied upon by us to verify your identity and source of funds, where applicable; or (e) violation of any rights of any other person or entity; provided however, that you shall not indemnify ShredPay for claims or losses arising out of ShredPay’s gross negligence or willful misconduct as determined by final order of a court of competent jurisdiction. This indemnity shall apply to your successors and assigns and shall survive any termination or cancellation of this Agreement.

19.2 **Limitation of Liability**

19.2.1 ShredPay shall not be liable to you or anyone else for any loss caused in whole or part by any delays, interruptions, inaccuracies or incompleteness, errors or omissions, including, without limitation, those arising from the negligence of ShredPay or contingencies beyond its control in procuring, compiling, interpreting, computing, reporting, or delivering the Services thereon or the information therein. In no event will ShredPay be liable to you or anyone else for any decision made or action taken by you in reliance on, or in connection with your use of the Services or the information therein.

19.2.2 IN NO EVENT SHALL ANY SHREDPAY OFFICERS, DIRECTORS, AGENTS, EMPLOYEES OR REPRESENTATIVES BE INDIVIDUALLY LIABLE FOR ANY AMOUNT WHATSOEVER.

19.2.3 IN NO EVENT SHALL SHREDPAY, ITS AFFILIATES AND THIRD PARTY SERVICE PROVIDERS AND VENDORS, BE LIABLE FOR MORE THAN THE LOWER OF (I) THE VALUE OF THE DIGITAL ASSET(S) AT ISSUE IN ANY CLAIM(S) AND (II) $20,000 USD.

19.2.4 IN NO EVENT SHALL SHREDPAY, ITS AFFILIATES AND SERVICE PROVIDERS, OFFICERS, DIRECTORS, AGENTS, EMPLOYEES OR REPRESENTATIVES BE LIABLE FOR ANY LOST PROFITS OR ANY SPECIAL, INCIDENTAL, INDIRECT, INTANGIBLE, PUNITIVE OR CONSEQUENTIAL DAMAGES, WHETHER BASED IN CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE, ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT, OR THE AUTHORIZED OR UNAUTHORIZED USE OF THE SERVICES, EVEN IF SHREDPAY HAD BEEN ADVISED OF, KNEW OF, OR SHOULD HAVE KNOWN OF THE POSSIBILITY OF SUCH DAMAGES AND/OR EVEN IF ANY AVAILABLE REMEDIES IN THIS AGREEMENT FAIL OF THEIR ESSENTIAL PURPOSE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO THE ABOVE LIMITATION MAY NOT APPLY TO YOU BASED ON YOUR JURISDICTION OR THE GOVERNING LAW.

19.2.5 UNDER NO CIRCUMSTANCES SHALL SHREDPAY BE REQUIRED TO DELIVER TO YOU ANY DIGITAL ASSETS AS DAMAGES, OR SHALL YOU BE ENTITLED TO SPECIFIC PERFORMANCE OR ANY OTHER SIMILAR REMEDY. YOU AND WE AGREE THAT ANY CALCULATIONS OF DAMAGES BASED IN ANY WAY ON THE VALUE OF DIGITAL ASSETS SHALL BE BASED ON THE LOWEST VALUE OF THE DIGITAL ASSETS DURING THE PERIOD BETWEEN THE ACCRUAL OF THE CLAIM AND THE AWARD OF DAMAGES.

19.2.6 SHREDPAY SHALL NOT BE LIABLE FOR ANY DAMAGES CAUSED IN WHOLE OR IN PART BY (A) THE MALFUNCTION, UNEXPECTED FUNCTION OR UNINTENDED FUNCTION OF ANY COMPUTER OR DIGITAL ASSETS NETWORK, INCLUDING WITHOUT LIMITATION LOSSES ASSOCIATED WITH VIRUSES, NETWORK FORKS, REPLAY ATTACKS, DOUBLE-SPEND ATTACKS, SYBIL ATTACKS, 51% ATTACKS, GOVERNANCE DISPUTES, MINING DIFFICULTY, CHANGES IN CRYPTOGRAPHY OR CONSENSUS RULES, HACKING OR CYBERSECURITY BREACHES; (B) THE CHANGE IN VALUE OF ANY DIGITAL ASSETS; (C) ANY CHANGE IN LAW, REGULATION OR POLICY, OR (D) FORCE MAJEURE EVENT (INCLUDING BUT NOT LIMITED TO (I) ACTS OF GOD, NATURE, COURT OR GOVERNMENT; (II) FAILURE OR INTERRUPTION IN PUBLIC OR PRIVATE TELECOMMUNICATION NETWORKS, COMMUNICATION CHANNELS OR INFORMATION SYSTEMS; (III) ACTS OR OMISSIONS OF ACTS OF A PARTY FOR WHOM SHREDPAY IS NOT RESPONSIBLE; (IV) DELAY, FAILURE, OR INTERRUPTION IN, OR UNAVAILABILITY OF, THIRD PARTY SERVICES AND SITES; (V) STRIKES, LOCK-OUTS, LABOUR DISPUTES, WARS, PANDEMICS, EPIDEMICS, TERRORIST ACTS AND RIOTS; AND (VI) VIRUSES, MALWARES, OTHER MALICIOUS COMPUTER CODES OR THE HACKING OF SHREDPAY’S SYSTEMS) (collectively **“Force Majeure”)**.

19.2.7 THE LIMITATIONS OF LIABILITY IN THIS SECTION ARE INTENDED TO APPLY WITHOUT REGARD TO WHETHER OTHER PROVISIONS OF THIS AGREEMENT HAVE BEEN BREACHED OR HAVE PROVEN INEFFECTIVE OR FAIL OF THEIR ESSENTIAL PURPOSE.

19.2.8 Any and all of our indemnities and warranties (whether express or implied) are hereby excluded to the fullest extent permitted under law except as set forth in this Agreement. Nothing in this Agreement excludes or limits liability which may not be limited or excluded under Applicable Law.

## 20. GENERAL PROVISIONS

20.1 **Third party content**. In connection with using the Services, you may access or view content or services provided by third parties, including links to web pages and services of such parties (“Third Party Content”). ShredPay does not control, endorse or adopt any Third Party Content. ShredPay is not responsible for Third Party Content, including, without limitation, content that may be erroneous, misleading, incomplete, offensive, indecent or otherwise objectionable. In addition, your relationships with such third parties are solely between you and the third party. ShredPay is not responsible or liable for any loss or damage that occurs as a result of any such dealings; your use of Third Party Content is at your own risk.

20.2 **No implied license.** Unless otherwise indicated by us, the Services and any other material or content provided by ShredPay, and all intellectual property rights therein, are the property of ShredPay, our licensors, third party partners, or vendors. We do not give any implied license for the use of the contents of the Services. You accept and acknowledge that the material and content contained in or delivered by the Services is made available for your personal, lawful, non-commercial use only and that you may only use such material and content for the purpose of using the Services as set forth in this Agreement. Any rights not expressly granted in this Agreement to use the materials contained on or through the Services are reserved by ShredPay in full.

20.3 **Provision of Feedback.** If you provide any suggestions, ideas, feedback, or recommendations to us regarding the Services (“Feedback”), we may use this Feedback for any purpose and without any obligation to you. By providing us with Feedback, you give us a worldwide, perpetual, irrevocable, transferable, sublicensable, fully-paid and royalty-free license to use and exploit in any manner any and all Feedback. By submitting Feedback, you waive any legal or other rights to the fullest extent permitted under law. In responding to Feedback, we shall use commercially reasonable efforts to supply email-based support services, but cannot guarantee immediate responses, especially during times of high volume.

20.4 **Confidential information.** While using our Services, you may obtain or otherwise become aware of Confidential Information about us. You may only use this Confidential Information as necessary to exercise your rights or perform your obligations in this Agreement. You agree to hold the Confidential Information in strict confidence, and to take reasonable steps to protect this Confidential Information from being accessed by unauthorized individuals, entities or other third-parties. You agree to not copy or reverse engineer, or remove any proprietary markings from any Confidential Information. You may share our Confidential Information with legal, governmental or regulatory authorities only if required by Applicable Law to do so, provided you will notify us of the request, if Applicable Law allows it.

20.5 **No waiver**. A party’s failure or delay to enforce, or partially enforce, any provision of this Agreement shall not be construed as a waiver of any rights.

20.6 **Force majeure.** In no event shall a party be considered in breach of this Agreement to the extent the party’s obligations are prevented or delayed, directly or indirectly, by a Force Majeure Event, and the party’s period of time for performance shall be extended until such event has ended.

20.7 In the event that any provision of this Agreement is unenforceable under Applicable Law, the validity or enforceability of the remaining provisions will not be affected. To the extent any provision of this Agreement is judicially determined to be unenforceable, a court of competent jurisdiction may reform any such provision to make it enforceable. The provisions of this Agreement will, where possible, be interpreted so as to sustain its legality and enforceability.

20.8 This Agreement shall be binding on your successors, heirs, personal representatives, and assignees. You may not assign or transfer any of your rights or obligations under this Agreement without prior written consent of ShredPay, which may be withheld at ShredPay’s sole discretion. We may assign rights or delegate duties under this Agreement at our sole discretion.

20.9 Nothing in this Agreement shall create any partnership, joint venture, agency, or consultancy.

20.10 This Agreement, along with the Supplemental Agreements, constitute the entire agreement between the parties with respect to the subject matter described in this Agreement.

20.11 **Contact information.** How to contact ShredPay:

20.11.1 Support requests should be made by emailing us at <support@shredpay.xyz>.

20.11.2 For Law Enforcement requests please direct your official document to our compliance team at <compliance@shredpay.xyz>. Please note, however, that all formal legal documents and claims must be formally and properly served on the correct ShredPay entity according to Applicable Law.

## 21. CHOICE OF LAW

This Agreement and your access to and use of the Services shall be governed by and construed and enforced in accordance with the laws of the State of California (without regard to conflict of law rules or principles of the State of California, or any other jurisdiction that would cause the application of the laws of any other jurisdiction). Any dispute between the parties that is not subject to arbitration as set forth in Section 22.4 or cannot be heard in small claims court, shall be resolved in the state or federal courts of California.

## 22. DISPUTE RESOLUTION

22.1. **Mandatory Arbitration.** In the event of a dispute between the parties, such dispute shall be settled by arbitration as outlined in this Section 22.4.

22.2. **No Class Action.** YOU AGREE THAT ANY CLAIMS WILL BE ADJUDICATED SOLELY ON AN INDIVIDUAL BASIS, AND YOU WAIVE THE RIGHT TO PARTICIPATE IN A CLASS, COLLECTIVE, PRIVATE ATTORNEY GENERAL ACTION, OR OTHER JOINT ACTION WITH RESPECT TO ANY CLAIMS THAT MAY ARISE UNDER THIS AGREEMENT OR THE PROVISION OF SERVICES.

22.3. **Arbitration Disclosure.** ARBITRATION IS FINAL AND BINDING ON THE PARTIES. THE PARTIES ARE WAIVING THEIR RIGHT TO SEEK REMEDIES IN COURT, INCLUDING THE RIGHT TO JURY TRIAL. PRE-ARBITRATION DISCOVERY IS GENERALLY MORE LIMITED THAN AND DIFFERENT FROM COURT PROCEEDINGS. THE ARBITRATOR OR ARBITRATION PANEL SHALL ISSUE A REASONED AWARD.

22.4. **Arbitration Agreement.** Unless otherwise specified, any controversy or claim arising out of or relating to this contract, or the breach thereof, shall be settled by arbitration administered by the American Arbitration Association (“AAA”) under its Commercial Arbitration Rules, and judgment on the award rendered by the arbitrator(s) may be entered in any court having jurisdiction thereof. Any such arbitration proceeding and any arbitration award issued shall be confidential. The arbitration shall be conducted in San Francisco, California, U.S.A. before a single arbitrator who shall be a retired judicial officer with demonstrated experience in technology matters. Notwithstanding the foregoing, each party acknowledges that a breach of this Agreement may cause the other party irreparable injury and damage and therefore that party may seek preliminary or injunctive relief in court, and each party hereby consents to the jurisdiction of any federal or state courts located in San Francisco, California, U.S.A. with respect to any such action. The parties expressly waive any objection based on personal jurisdiction, venue or forum non conveniens. EACH PARTY HEREBY IRREVOCABLY WAIVES ALL RIGHTS TO TRIAL BY JURY IN ANY ACTION, CLAIM, SUIT, PROCEEDING OR COUNTERCLAIM (WHETHER BASED ON CONTRACT, TORT OR OTHERWISE) ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE ACTIONS OF SUCH PARTY IN THE NEGOTIATION, ADMINISTRATION, PERFORMANCE AND ENFORCEMENT HEREOF.

22.5. Unless the parties agree otherwise, each party must bring all related or similar claims in a single arbitration proceeding. If a party later initiates a subsequent arbitration asserting claims that are related or similar to ones that were raised by such party in a prior arbitration, the AAA or the arbitrator will either: (i) consolidate the subsequent arbitration with the earlier proceeding if it is ongoing; or (ii) dismiss the subsequent arbitration if it raises claims that would be barred by Applicable Law if brought in court.

22.6. **Notice of Dispute and Arbitration Procedures.** A party who intends to pursue a claim must first send to the other a letter describing the claim and containing the information described below (a “Notice of Dispute”). Any Notice of Dispute sent to ShredPay should be addressed to:

* Attn: Chief Legal Officer
* ShredPay Inc.
* 201 California Street, Suite 350
* San Francisco, California 94111
* <compliance@shredpay.xyz>

The Notice of Dispute must: (a) describe the nature and basis of the claim; (b) set forth the specific relief sought; (c) set forth the name and address of the claimant; and (d) include the Account numbers to which the claim relates. If the parties do not reach an agreement to resolve the claim described in the Notice of Dispute within forty-five (45) days after the Notice of Dispute is received, the parties may commence an arbitration proceeding with the AAA. If the parties attempt to commence arbitration proceedings before providing the requisite Notice of Dispute, the AAA shall not commence administration of arbitration proceedings for at least forty-five (45) days after the AAA receives the request to initiate arbitration. No party will disclose to the arbitrator the existence, amount, or terms of any settlement offers made by any party until after the arbitrator issues a final award resolving the claim.

A form for initiating arbitration proceedings is available on the AAA’s website at <http://www.adr.org>. The AAA Rules are available online at <http://www.adr.org>, by calling the AAA at 1-800-778-7879, or by writing to the notice address provided above.

The arbitrator is bound by the terms of this Agreement. All issues are for the arbitrator to decide, including issues relating to the arbitrability of claims or the scope (except for the issue of the application of the parties’ agreement that they may seek preliminary or injunctive relief in court), and enforceability of this arbitration provision, the interpretation of the prohibition of class and representative actions and non-individualized relief. If the value of the relief sought (by any party) is $10,000 or less, the parties may agree that the arbitration will be conducted solely on the basis of documents submitted to the arbitrator, through a telephonic hearing, or by an in-person hearing as established by the AAA Rules.

22.7. **Survival.** This Arbitration Agreement will survive the termination of your relationship with ShredPay.

22.8. **Modification.** Notwithstanding any provision in the Agreement to the contrary, we agree that if ShredPay makes any future material change to this Section 22, it will not apply to any individual claim(s) for which you had already provided notice of to ShredPay.

22.9. **Entire Agreement; Severability.** This Arbitration Agreement is the full and complete agreement relating to the formal resolution of disputes covered by this Arbitration Agreement. In the event any portion of this Arbitration Agreement is deemed unenforceable, the remainder of this Arbitration Agreement will be enforceable, and the remainder of the Agreement shall be unmodified.

## 23. E-SIGN DISCLOSURE AND CONSENT

23.1 **Communications to Be Provided in Electronic Form**. You understand and agree that we may provide you with any or all communications electronically including, without limitation: (a) legally required notices, disclosures, and other communications associated with your access to or use of the Services; (b) notices, disclosures and other communications about about fees or charges; (c) any and all legally required pre- and post-transaction disclosures; (d) privacy policies and notices; (e) customer service communications; (f) statements, information and records regarding your transactions; (g) changes to this Agreement; (h) information regarding the debiting or charging, as applicable of your selected payment method; (i) any and all legally required error resolution policies, and responses to claims filed in connection with your access to or use of the Services; (j) any other communications related to your access to and/or use of the Services; and (k) with your consent, marketing and other promotional communications (collectively, “Communications”).

23.2 **Communications in Writing.** All communications, whether in electronic or paper format, from ShredPay to you will be considered “in writing.” You should print or download for your records a copy of this Agreement and any other communication that is important to you.

23.3 **Method of Providing Communications to You in Electronic Form.** All communications that we provide to you in electronic form will be provided either (i) via email, (ii) by access to a web site that we will designate in an email notice we send to you at the time the information is available, or (iii) to the extent permitted by law, on the ShredPay website or via SMS text message. You agree to promptly review all communications sent to you, and that these are reasonable procedures for sending and receiving electronic communications.

23.4 **How to Update Your Records**. To receive electronic communications, at the time that you first use the Services, you must provide us with a true, accurate and complete email address that you possess and your contact information. You must promptly notify us of any changes to this information. You can update information (such as your email address) through the Site.

23.5 **Hardware and Software Requirements.** In order to access, view, and retain electronic communications that we make available to you, you must have an electronic device that enables access to your email account or a commercially available Internet browser. You may wish to utilize a device that is capable of storing or printing the communications for your records.

23.6 **Requesting Paper Copies.** Following your consent to receive electronic communications, we will not send you a paper copy of any communication unless we deem it appropriate to do so. You can obtain a paper copy of an electronic communication by printing it yourself. We reserve the right, but assume no obligation, to provide a paper (instead of electronic) copy of any communication that you have authorized us to provide electronically.

23.7 **How to Withdraw Consent.** You may withdraw your consent to receive Communications in electronic form at any time by contacting us at <support@shredpay.xyz>. Withdrawing consent to receive marketing communications, only, does not prevent you from using ShredPay’s services, however, IF YOU WITHDRAW YOUR CONSENT TO RECEIVE ALL COMMUNICATIONS IN ELECTRONIC FORM, YOU WILL NO LONGER BE ABLE TO USE THE SHREDPAY SERVICES. Any withdrawal of your consent to receive electronic Communications will be effective only after we have received your request for withdrawal and have a reasonable period of time to process such request. In the meantime, you will continue to receive Communications in electronic form. If you withdraw your consent, the legal validity and enforceability of prior Communications delivered in electronic form will not be affected, and your previous electronic records will remain accessible for such period as is required under law and in a form that allows the record to be accurately reproduced to all persons who are entitled under law to access the record.

23.8 **Federal Law**. You acknowledge and agree that your consent to electronic Communications is being provided in connection with a transaction affecting interstate commerce that is subject to the federal Electronic Signatures in Global and National Commerce Act (“E-SIGN Act”), and that you and we both intend that the E-Sign Act apply to the fullest extent possible to validate our ability to conduct business with you by electronic means.

23.9 **Termination/Changes.** We reserve the right, in our sole discretion, to discontinue the provision of your electronic Communications, or to terminate or change the terms and conditions on which we provide electronic Communications. We will provide you with notice of any such termination or change as required by law.

### 24. DIGITAL ASSET DISCLOSURES AND RISK FACTORS.

24.1 **Price Volatility.** The value of Digital Assets can fluctuate significantly, presenting a substantial risk of financial loss when buying, selling, holding, or investing in them. The potential for the value to increase or decrease to the total amount of your holdings requires caution. It's crucial to conduct independent research before engaging with Digital Assets. Carefully evaluate if these activities align with your financial circumstances.

24.2 **Unique Features of Digital Assets.** Digital Assets are not money/legal tender, not currently recognized as legal tender by the United States, and are not backed by the United States government. Digital asset accounts, and the value of the balances in those accounts, are not subject to Federal Deposit Insurance Corporation or Securities Investor Protection Corporation protections or any other insurance or guarantee against loss by an agency of the United States.

24.3 **No Insurance Against Loss.** Digital Assets are not insured by any private insurance policy held by ShredPay to protect against theft or loss. Further, any surety bond that ShredPay is required by state regulators to maintain for the benefit of its customers may not be sufficient to cover all losses incurred by its customers.

24.4 **Irreversible Transactions.** Digital asset transactions can be irreversible, meaning that losses from fraudulent or accidental transactions may not be recoverable. Additionally, there is a risk of delay as some digital asset transactions are effective once recorded on a public ledger. The recorded date or time may differ from when you initiated the transaction.

24.5 **Risk of Delay.** Some Digital Asset transactions may be immediately effective when recorded on a public ledger; the recorded date or time may not necessarily be the date or time that you initiated the transaction.

24.6 **Nefarious Activity.** The nature of Digital Assets may result in an increased risk of fraud, theft, hack, or cyber attack.

24.7 **Accessibility.** Further, the nature of Digital Assets means that any technological difficulties experienced by ShredPay may prevent your access to or use of your Digital Assets. You assume this risk and agree that you are responsible for any losses incurred as a result of technological difficulties that prevent your access to or use of your Digital Assets.

24.8 **Suitability Risk.** You acknowledge that (a) you are solely responsible for determining the suitability, nature, potential value, and appropriateness of the risks presented by Digital Assets for you; (b) you are familiar with the operation of Digital Asset buying, selling, trading, and blockchain-based decentralized financial applications and have the experience required to use the Services; and (c) you assume all liability and responsibility for determining whether using the Services is legal in your jurisdiction and you agree not to use any of the Services if your use is illegal or otherwise prohibited or limited by any rule or regulation. Your use of the Services requires you to assume all attendant risks, and ShredPay expressly disclaims any and all liability or responsibility for any such risks. The lists of the potential risks of Digital Assets contained in this Agreement are illustrative and not exhaustive, and you acknowledge that you may be subject to and liable for other significant potential risks.

24.9 **Technology Failures.** Hardware, software, or connections required to interact with a Digital Assets network might fail or succumb to malware, unauthorized access, or malicious attacks. Third parties may obtain unauthorized access to the Services, including, but not limited to, your public and private keys. ShredPay shall not be liable or responsible whatsoever for any communication failures, disruptions, errors, distortions, or delays or other potential adverse events or adverse consequences you may experience when using the Services, regardless of the cause.

24.10 **Network Vulnerabilities.** Losses may be caused by currently unknown vulnerabilities in or unanticipated changes to the network protocol. ShredPay has no control over any Digital Assets network and shall not be liable or responsible for any harm occurring as a result of the inability to reverse a transaction, and any losses in connection therewith due to erroneous or fraudulent actions, or other potential adverse events or adverse consequences you may experience.

24.11 **Regulatory Risks.** Legislative, judicial, and regulatory changes or actions at the State, Federal, or international level may adversely affect the use, transfer, exchange, and value of Digital Assets. It is possible that in the future, certain laws, regulations, policies, or rules relating to Digital Assets may be implemented, which would directly or indirectly affect or restrict your interaction with ShredPay, your use of Services, and/or your ability to use, transfer, or exchange Digital Assets.

24.12 **Decline in Demand.**

24.12.1 The value of a Digital Asset may be derived from market demand to exchange fiat currency for Digital Assets. A decline in market demand may result in the potential for permanent and total loss of value of a particular Digital Asset. You understand and accept this risk of loss.

24.12.2 The value of a Digital Asset may be derived from the continued willingness of market participants to exchange fiat currency for Digital Assets, which may result in the potential for permanent and total loss of value of a particular Digital Asset should the market for that Digital Asset be materially adversely impacted or otherwise disappear.

24.12.3 There can be no assurance that a person who accepts a Digital Asset as payment today will continue to do so in the future.

24.13 **Third Parties.**

24.13.1 By using the Services, you agree that the persons that maintain your accounts and any third-party partners or vendors that interact with your credentials or account data in connection with our service are not liable for any loss, theft, compromise, or misuse whatsoever in connection with our services (including negligence), except to the extent such liability cannot be limited under Applicable Law.

## 25. LEGAL

25.1 **Regulation**. ShredPay’s third-party partner Bridge.xyz (“Bridge”) is registered with the U.S. Department of Treasury’s Financial Crimes Enforcement Network as a money services business (“MSB”). As a registered MSB, Bridge is subject to the Bank Secrecy Act and its implementing regulations which set out the requirements imposed upon financial institutions to implement policies and procedures reasonably designed to detect and prevent money laundering and terrorist financing. You understand and acknowledge that your access to and use of the Services is subject to compliance with Bridge’s AML Program. You understand and acknowledge that neither ShredPay nor Bridge are a registered broker-dealer and are not a member of the Financial Industry Regulatory Authority or SIPC. You further understand and acknowledge that your Digital Asset holdings are not protected by the FDIC or SIPC, nor any insurance policy held by ShredPay.

25.2 **Compliance with Applicable Laws.** Digital Asset transactions are subject to applicable laws, regulations, and rules of federal and state governmental and regulatory authorities (collectively, “**Applicable Law(s)**”). You understand that compliance with Applicable Laws may include compliance with any guidance or direction of any regulatory authority or government agency, any writ of attachment, lien, levy, subpoena, warrant, or other legal order (collectively, “**Legal Orders**”). You understand and acknowledge that in no event will ShredPay be obligated to affect any Digital Asset transaction that we believe would violate any Applicable Law. You further understand and acknowledge that ShredPay is not responsible for any losses, whether direct or indirect, that you may incur as a result of our good faith efforts to comply with any Applicable Law, including any Legal Order. You authorize ShredPay to provide any information relating to your Account, your use of the Account or your use of the ShredPay Services enumerated in this Agreement if requested by any valid regulatory body, provided that any such disclosure by ShredPay shall comply with Applicable Law, including any applicable privacy rules and regulations.

25.3 **State Licenses and Disclosures.** Bridge is required to maintain licenses to engage in money transmission activities in certain states, and these license requirements may impact our provision and your use of certain Services depending on where you live or are formed in. It is your sole responsibility to ensure that you are accessing the Services available to you by reviewing the Permitted US Jurisdictions as listed by ShredPay, and updated from time to time, prior to placing any order on the Platform. A list of Bridge licenses and corresponding required disclosures can be found here:\
<https://www.bridge.xyz/legal/licenses/us-licenses-and-registrations>\
which are incorporated herein by reference. If you have any questions about the disclosures, contact us at <support@shredpay.xyz> before using the Services enumerated in this Agreement.

25.4 **Electronic Record.** The electronic stored copy of this Agreement is considered to be the true, complete, valid, authentic, and enforceable record of this Agreement. admissible in judicial or administrative proceedings to the same extent as if the documents and records were originally generated and maintained in printed form. You agree to not contest the admissibility or enforceability of the electronically stored copy of the Agreement.

25.5 **Electronic Acceptance**. You expressly confirm that you have read, agree to, and consent to be bound by all of the terms of this Agreement and by the terms and conditions of the ShredPay E-Sign Consent Agreement which may be found . By electronically signing this Agreement, which may be completed by all methods of “clickwrap” or “click through” including by accepting, clicking a button, or checking a box, you acknowledge and agree that such electronic signature is valid evidence of your consent to be legally bound by this Agreement and such subsequent terms as may govern the Services. If you do not agree to all of the terms of this Agreement, do not electronically sign this Agreement and cease from accessing, using, or installing any part of the Services.


# ShredPay Privacy Policy

## 1. Information Collection

We collect data about visitors to our websites and any affiliated blogs, mobile sites, or applications; about Users that access, directly or indirectly, our Services or Apps, or any other Users or Customers that attend events organized or hosted by us; and about our clients, including Platforms, (where these are natural persons) or their employees, agents and representatives (and these individuals about whom we collect data are incorporated into any reference to "you" or “your” in this Privacy Policy). Please refer to the below for further information about the personal information we may collect and how it may be used:

### Information You May Provide To Us

| **Category**                                                     | **Description**                                                                                                                                                                                                                |
| ---------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Basic Customer Information**                                   | Name; Address; Date of birth; Nationality; Country of residence; Phone number; Email Address; Website                                                                                                                          |
| **Supplemental Identification Information**                      | Government-issued identity document (*e.g.*, passport, driver’s license, or state identification card); Social security number; Employment information (*e.g.*, company name, industry, etc.); Proof of residency; or similar. |
| **Electronic Identification Information (EII)**                  | Biometric information generated based on photos, videos, or similar electronically identifiable biometric data you provide in order for us to verify your identity or location                                                 |
| **Financial Information**                                        | Bank account number; Payment card numbers; Trading and investment experience; Tax identification number; Income types; net assets/wealth verification; Source of funds; Account balances; or similar.                          |
| **Crypto or Wallet Information**                                 | Wallet addresses; digital transaction information; public and private chain information; and information related to cryptographic integrations                                                                                 |
| **Preferences**                                                  | User settings and preferences selected on our Website, Apps, or otherwise when using our Services                                                                                                                              |
| **Transaction Information**                                      | Information about the transactions made on our Services, such as: Name of the sender; Name of the recipient; Amount; Currency (fiat and/or digital); Payment method; Date; and/or Timestamp                                    |
| **Additional Information You Submit to Us**                      | Communications such as survey responses or Customer service information (*e.g.*, emails or call recordings provided by you to our customer service teams); any other information you choose to provide                         |
| **Institutional Information (only for Institutional Customers)** | Employer Identification number (or comparable number issued by a government); Legal name; Jurisdiction of formation; Entity type; and Personal identification information for all beneficial owners of your business           |

### Information Which May Be Collected Automatically

| **Category**                                          | **Description**                                                                                                                                                                                                                                              |
| ----------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Usage Data**                                        | IP addresses or other location metadata; device details; operating system and browser you’re using information; other device characteristics or identifiers (*e.g.*, network connection characteristics); data regarding your interaction with our Services. |
| **Product Usage Information**                         | Your viewing history and logs from visiting the websites or using our Apps or Services, including diagnostic information about the performance of websites, Apps, or Services                                                                                |
| **Information from Cookies and similar technologies** | Please see our Cookies Policy for additional information                                                                                                                                                                                                     |

### Information we Obtain from Affiliates or Third Parties

| **Category**                                                | **Description**                                                                                                                                                                                                 |
| ----------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **ShredPay Group (“Affiliates”)**                           | We may obtain any and all information about you that is collected by any other ShredPay Group affiliate as part of normal business practices or to adhere to applicable legal and regulatory requirements.      |
| **Platform Account Information**                            | We may obtain any and all information about you from the Platform you used to sign up for and access the ShredPay Services.                                                                                     |
| **Public Database Information**                             | We obtain information about you from any and all public databases.                                                                                                                                              |
| **Blockchain Data**                                         | We may analyze public blockchain data, including timestamps of transactions or events, transaction IDs, digital signatures, transaction amounts, and wallet addresses.                                          |
| **Information from our Service Provider Partners**          | We may receive information about you from our service provider partners as part of normal business practices or to adhere to applicable legal and regulatory requirements.                                      |
| **Information from our Marketing and Advertising Partners** | We may receive information about you from our marketing partners, potentially including in what content you viewed or the actions you take on our Website or Apps                                               |
| **Retail Merchant Information**                             | If you use your ShredPay account to conduct a transaction with a third party merchant, the merchant may provide us with information about you, including information about your transaction with that merchant. |
| **Research and Survey Information**                         | We may use third party service providers to conduct surveys to better understand our Customers’ or Users’ experience and improve our Services.                                                                  |

***

## 2. Use of Information

We may use your personal information for any lawful purpose, including the following: to deliver, personalize, operate, improve, create, and develop our Services, to provide you with a secure, smooth, efficient and safe experience, and to comply with legal and regulatory compliance, theft and loss prevention, and anti-fraud purposes. Below is additional information about how we use your personal information and our legal basis for doing so:

### Establish and Administer Your Account and Service Relationship

We will use your information to perform our duties under an applicable ShredPay Group company user agreement (*e.g.*, ShredPay Terms of Service) or similar customer or end-user agreement or other relevant contract with you as set forth below. We may need to suspend or terminate our Services or otherwise close your user account if we cannot process your personal information or similar data for these purposes.

{% stepper %}
{% step %}

### Creation and Maintenance of your User Account

Creation and maintenance of your user account and related account management activities.
{% endstep %}

{% step %}

### Provision of ShredPay or other Crypto services

Providing access to and operation of ShredPay services or other crypto-related services.
{% endstep %}

{% step %}

### Third-Party Access (API/SDK/Infrastructure)

To provide you with Third-Party Access, including through API, SDKs, or other infrastructure.
{% endstep %}

{% step %}

### Customer Support

To provide customer support.
{% endstep %}

{% step %}

### Service Communications

To send you Service communications related to, among other things, administrative matters, updates or transaction-related information.
{% endstep %}

{% step %}

### Safety, Security, and Integrity

To promote the safety, security, and integrity of our Services through, among other things, account verification, investigation of suspicious activity or unlawful behavior.
{% endstep %}
{% endstepper %}

### Data used to comply with our legal obligations

Certain uses of our Services may be subject to laws and regulations that require us to collect, use, and store your personal information in certain ways and for specified periods. If you do not provide and continue to provide access to the personal information as required by law, we may have to suspend or close your account.

{% stepper %}
{% step %}

### Identity verification and AML/KYC compliance

To permit us or our third-party service providers to verify your identity in compliance with the Bank Secrecy Act, anti-money laundering laws including know your customer rules, and sanctions regulations.
{% endstep %}

{% step %}

### Legal and regulatory obligations

To comply with other ShredPay Group legal and regulatory obligations to access, preserve or disclose information in compliance with applicable law.
{% endstep %}

{% step %}

### Platform legal and regulatory obligations

To comply with other Platform legal and regulatory obligations. We may access, read, preserve, and disclose information to the Platform(s) through which you signed up for or access the ShredPay Services when we believe it is reasonably necessary to comply with applicable law, legal obligations, regulations, law enforcement, governmental, and other legal requests, court orders, or for disclosure to tax authorities.
{% endstep %}
{% endstepper %}

***

## HOW AND WHY WE SHARE YOUR INFORMATION

### How We Share Your Information

#### Personal Information

| **Category of Personal Information**                                                                             | **Information Collected and Disclosed**                                                                                                                                   | **Categories of Recipients**                                                                                                                                        |
| ---------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Personal Identifiers                                                                                             | Basic User Information; Supplemental Identification Information; Institutional Information (*as applicable*); Financial Information                                       | Platforms; Third party identity verification services; Financial institutions; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators |
| Protected personal data classifications under California and federal law, (*e.g.*, gender, age, and citizenship) | Supplemental Identification Information; EII Information                                                                                                                  | Platforms; Third party identity verification services; Service Providers; ShredPay Group; Law enforcement/Regulators                                                |
| Commercial information such as records of services purchased, obtained, or considered                            | Transaction Information                                                                                                                                                   | Platforms; Third party identity verification services; Financial institutions; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators |
| Internet or other electronic network activity information                                                        | Product Usage Information; App, browser, and device information; Information from cookies and similar technologies                                                        | Platforms; Third party identity verification services; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators                         |
| Geolocation data                                                                                                 | App, browser, and device information                                                                                                                                      | Platforms; Third party identity verification services; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators                         |
| Audio, electronic, visual, or similar information                                                                | Additional information You Provide to Us; Information from our Marketing Partners; Information from Analytics and Providers; Research and Survey Information              | Platforms; Third party identity verification services; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators                         |
| Professional or employment related information                                                                   | Basic User Information; Supplemental Identification Information; Institutional Information (*as applicable*); Financial Information                                       | Platforms; Third party identity verification services; Financial institutions; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators |
| Inferences about preferences, characteristics, predispositions, etc.                                             | Preferences; Additional information You Provide to Us; Information from our Marketing Partners; Information from Analytics and Providers; Research and Survey Information | Platforms; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators                                                                     |

#### Sensitive Personal Information

Collection and Disclosure of Sensitive Personal Information. We collect and disclose the following categories of sensitive personal information, with the following categories of third parties:

| **Category of Personal Information**                                         | **Information Collected and Disclosed**                                                                                                                      | **Categories of Recipients**                                                                                                                |
| ---------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------- |
| Government identifiers                                                       | Supplemental Identification Information; EII Information                                                                                                     | Platforms; Third party identity verification services; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators |
| Account credentials and financial account details combined with access codes | Basic User Information; Supplemental Identification Information; EII Information                                                                             | Platforms; Third party identity verification services; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulator  |
| The contents of a consumer’s mail, email, and text messages                  | Additional information You Provide to Us; Information from our Marketing Partners; Information from Analytics and Providers; Research and Survey Information | Platforms; Third party identity verification services; Service providers; Professional advisors; ShredPay Group; Law enforcement/Regulators |
| Biometric information (via our service providers)                            | EII Information                                                                                                                                              | Platforms; Third party identity verification services; ShredPay Group; Law enforcement/Regulators                                           |

### Why We Share Your Information

We work with third-party service providers who process information on our behalf (such as payment processors, data hosting services, and email service providers, or with our legal or business advisors), third-party partners and other third parties to help us provide our Services, and as a result we need to share certain information with these third parties. We also share identifiers with third party analytics providers or advertising partners, for analytics and advertising purposes.

#### Affiliates

Personal information that we process and collect may be transferred between ShredPay Group companies, Services, and personnel affiliated with us as a normal part of conducting business and offering our Services to you and to comply with our legal or regulatory obligations. *See Section III. for a list of ShredPay Group affiliated companies.*

#### Platform Third Party

Personal information that we process and collect may be transferred between ShredPay and the Platform which you use to sign up for and/or access the ShredPay Services as a normal part of conducting business and offering our Services to you and to comply with our respective legal or regulatory obligations. Please note that when you use the Platform’s other services and products, which are not governed by this Privacy Policy, the Platform's own terms and privacy policies will govern your use of those services and products.

#### Linked Third Party Websites or Applications

When you utilize certain Services that use third-party services or websites (*e.g.*, AML/KYC services, pay with crypto, withdrawal services, etc.) that are linked through to our Services, the third-party service providers of those services or products may receive information about you that ShredPay, you, or others share with them. Please note that when you use third-party services or websites, which are not governed by this Privacy Policy, their own terms and privacy policies will govern your use of those services and products.

We may also use integrated social media tools or “plug-ins,” such as social networking tools offered by third parties. If you use these tools to share personal information or you otherwise interact with these features on our Services, those companies may collect information about you and may use and share such information in accordance with your account settings, including by sharing such information with the general public.

Your interactions with third-party companies and your use of their features are governed by the privacy policies of the companies that provide those features. We encourage you to carefully read the privacy policies of any accounts you create and use.

#### Professional advisors, industry partners, authorities and regulators

We may share your information described in Section I. with our professional advisors, regulators, tax authorities, law enforcement, government agencies, Platforms, and industry partners to:

* respond pursuant to applicable law or regulations, court orders, legal process or government requests;
* comply with our reporting and information sharing obligations with industry partners (*e.g.*, Virtual Asset Service Providers (“VASPs”) and regulatory authorities)
* detect, investigate, prevent, or address fraud and other illegal activity or security and technical issues; and
* protect the rights, property, and safety of our Users, Customers, the ShredPay Group, or others, including to prevent death, imminent bodily harm, or exploitation.

#### Asset Transfer or Company Acquisition

We may choose to buy or sell assets, and may share and/or transfer information about our Users or Customers in connection with the evaluation of and entry into such transactions. Also, if we (or our assets) are acquired, merged, reorganized, or if we go out of business, enter bankruptcy, or go through some other change of control or similar event, your personal information could be one of the assets transferred to the acquiring party.

#### Third-Party Service Providers

We work with third-party service providers to help us provide our Services. When we share information with third-party service providers in this capacity, we require them to use your information on our behalf in accordance with our instructions and terms and only process as necessary and proper for the limited purpose of the contract. We work with different types of third-party service providers, including:

| **Why & How We Use Your Information**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | **Information Categories Used**                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| We use Third-Party Electronic ID Verification Service Vendors, including those that process biometric information. For example, we use vendors to complete customer onboarding, transactions, and compliance. The information shared by those vendors will be collected and used as indicated in the privacy policies of those vendors which can be found here: <https://astra.com/privacy-policy/> <https://plaid.com/legal/#consumers> <https://www.bridge.xyz/legal/us-privacy-policy/bridge-building-inc> <https://www.privy.io/privacy-policy> [https://www.trmlabs.com/policies/privacy-policy?\_gl=1*j7ohi4*\_up*MQ..*\_gs\*MQ..\&gclid=Cj0KCQiAxJXJBhD\_ARIsAH\_JGji1Wc2QBmckhKdWBUJhqFH32ecaB4gx88Ecd0lm9CEe0yatmsXWFjkaAncqEALw\_wcB\&gbraid=0AAAAAoLreL5LiDfQxtb2EdscbpUYmeONP](https://www.trmlabs.com/policies/privacy-policy?_gl=1*j7ohi4*_up*MQ..*_gs*MQ..\&gclid=Cj0KCQiAxJXJBhD_ARIsAH_JGji1Wc2QBmckhKdWBUJhqFH32ecaB4gx88Ecd0lm9CEe0yatmsXWFjkaAncqEALw_wcB\&gbraid=0AAAAAoLreL5LiDfQxtb2EdscbpUYmeONP) <https://www.unit21.ai/privacy-policy> <https://aws.amazon.com/privacy/> <https://mailtrap.io/privacy/>, <https://policies.google.com/privacy> | - Basic Customer Information; - Supplemental Identification Information; - EII Information; - Additional information You Provide to Us; Institutional Information (*as applicable*); - App, browser, and device information and location data; - ShredPay Group Information; - Platform Account Information; - Public Database Information                                                                             |
| Vendors for tax reporting Retail merchants (to provide rewards/incentives) Telecommunications technology providers (to send you messages, including SMS messages) AML service providers (for the purposes of transaction monitoring) Data hosting service providers and payment vendors (for off-site data hosting) Security service providers (for investigating fraud and security incidents) Analytics providers (to understand how you use our Services) Payment processing companies (to process transactions on our behalf) Document repository services providers Customer support vendors                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | - Basic Customer Information; - Supplemental Identification Information; - Financial Information; - Crypto Information; - Transaction Information; - Additional information You Provide to Us; - Institutional Information (*as applicable*); - App, browser, and device information and location data; - ShredPay Group Information; - Platform Account Information; - Public Database Information; - Blockchain Data |

We may share information that has been de-identified or aggregated without limitation.

***

## HOW LONG WE RETAIN YOUR PERSONAL INFORMATION

We retain your information as needed to provide our Services, comply with legal or regulatory obligations, or protect our, your, or others’ vital or necessary interests. We maintain internal retention policies on the basis of how information needs to be used and decide how long we need information on a case-by-case basis.

This includes considerations such as when the information was collected or created, whether it is necessary in order to continue offering you our Services, whether we are required to hold the information to comply with our legal obligations, whether we need it is necessary to protect a vital interest, or if it meets other information preservation requirements. We also keep certain information where necessary to protect the safety, security and integrity of our Services, Platforms, Customers, and Users. Our third-party electronic identity verification providers collect and retain information, which may include biometric information, for the period required for financial regulatory compliance or otherwise as required by applicable law. They retain this information as described in their respective policies.

In line with these considerations, we delete information that is no longer required or needed for the above purposes when you close your account, and delete any other information when permitted pursuant to the above considerations.

***

## CHILDREN'S PERSONAL INFORMATION

The Services are not directed to persons under the age of 18, and we do not knowingly request or collect any information about persons under the age of 18. We do not have actual knowledge that we sell or share the personal information of individuals under 18 years of age.

If you are under the age of 18, please do not provide any personal information to any ShredPay Group company. If a User or Customer submitting personal information is suspected of being under 18 years of age, we will require the relevant Customer or User to close the account, and will take all reasonable steps to delete or purge the individual’s information as soon as possible.

***

## HOW TO CONTACT US WITH QUESTIONS

If you have questions or concerns regarding this Privacy Policy, or if you have a complaint, please reach out to us at <privacy@ShredPay.xyz>, or by writing to us at the address of your ShredPay service provider, provided in Section XI.

{% hint style="info" %}
We may provide additional specific or immediate disclosures or information about how we collect or use your information in the context of specific Services; these in-product or supplemental notices may supplement or clarify our privacy practices or may provide you with additional information or choices about how we use your information.
{% endhint %}

***

## CHANGES TO THIS PRIVACY POLICY

We may change this Privacy Policy from time to time. We post any changes we make to this Privacy Policy on this page and, where appropriate, we will provide you with reasonable notice of any material changes before they take effect or as otherwise required by law. The date the Privacy Policy was last updated is identified at the top of this page.

***

## OUR RELATIONSHIP WITH YOU

ShredPay acts as controller with respect to your personal information and has primary responsibility thereto, including with respect to providing you with information and responding to any requests you may make under applicable law.

***

## III. SHREDPAY GROUP AFFILIATED COMPANIES

* ShredPay Inc. - 201 California St, Suite 350 San Francisco, CA 94111
* ShredPay Markets LLC - 201 California St, Suite 350 San Francisco, CA 94111
* ShredPay Liquid LLC - 201 California St, Suite 350 San Francisco, CA 94111
* ShredPay Technology LLC - 201 California St, Suite 350 San Francisco, CA 94111
* ShredPay Ratings LLC - 201 California St, Suite 350 San Francisco, CA 94111


# ShredPay Pricing & Fee Disclosure

ShredPay Pricing & Fee Disclosure - December 31, 2025

When you transact on ShredPay’s platform, you may be charged fees. These fees are calculated at time of a transaction and can be influenced by factors such as transaction type, size, partner, payment method and other costs ShredPay incurs in connection with your transaction.  Please note that it is possible for fees to vary for similar transactions and that ShredPay may make changes to its fee structure from time to time. &#x20;

Types of Fees

There are three types of fees charged by ShredPay in connection with your transactions: third party fees, transaction fees and performance fees.  Fees are non-refundable.

1. Third Party Fees

Certain ShredPay fees listed below, including bank-related fees (e.g. ACH and Debit Card fees), and blockchain fees (e.g. gas fees) are charged by a third party and are passed through to you in connection with a transaction. The fees indicated below are approximate and denoted with a “\~” symbol. <br>

2. Transaction Fees

ShredPay charges a transaction fee which covers transaction related expenses including, without limitation, processing costs, fraud prevention, monitoring, and affiliate costs.  Those transaction fees may vary by type of transaction executed.

3. Performance Fee

ShredPay charges a Performance Fee in connection with some products offered on the platform.  Those Performance Fees are included to cover other costs of operating not covered by transaction fees and allow ShredPay to continue to offer an easy to use and trustworthy product. &#x20;

Each time you place an order, ShredPay will disclose and you will review and confirm any applicable fees.  By completing an order, you agree to pay the applicable fees for that transaction.

Fee Structure

ShredPay charges fees as follows:

<table data-full-width="false"><thead><tr><th>Product Feature</th><th valign="top">Route</th><th valign="top">Fee</th></tr></thead><tbody><tr><td>USD ACH and Debit Card USD Deposit</td><td valign="top"><p>Transaction Size:</p><p><sub>$0 - $349.99</sub>    </p><p><sub>$350.00 - $499.99</sub></p><p><sub>$500.00 - $999.99</sub>   </p><p><sub>$1,000.00+</sub></p></td><td valign="top"><p>Bank Processing Fee:</p><p><sub>4.5%</sub></p><p><sub>3.0%</sub></p><p><sub>1.5%</sub></p><p><sub>1%</sub> </p></td></tr><tr><td>USD or stablecoin deposit from Coinbase </td><td valign="top">0%</td><td valign="top"></td></tr><tr><td>Stablecoin deposit from external wallet</td><td valign="top">0%</td><td valign="top"></td></tr><tr><td>Withdrawal</td><td valign="top">Fiat to bank account</td><td valign="top">1%</td></tr><tr><td>Stablecoin to external digital wallet </td><td valign="top">1%</td><td valign="top"></td></tr><tr><td>Yield Earning Products</td><td valign="top">DeFi protocol</td><td valign="top"><p>~ $0.02 - $0.05 Gas Fee</p><p><br></p><p>10% Performance Fee</p><p><br></p><p>0.75% Transaction Fee upon redemption</p></td></tr><tr><td>Merchant</td><td valign="top">ShredPay app </td><td valign="top">1%</td></tr><tr><td>Buy / Sell Crypto</td><td valign="top">DEX swap</td><td valign="top">1%</td></tr><tr><td></td><td valign="top"></td><td valign="top"></td></tr></tbody></table>

<br>


# ShredPay E-Sign Consent Agreement

E-Sign Consent Agreement

Effective December 31, 2025

1. Consent to Electronic Communication &#x20;

As used in this E-Sign Consent Agreement (“Agreement” or “Consent”), “Account” means all accounts, products, or services you have with us. The words “we” or “us” or “our” refer to ShredPay Inc. (“ShredPay”) and its partners and affiliates. The words “I” or “you” or “your” mean each holder of an Account with or through us.&#x20;

This E-Sign Consent disclosure covers all of your Accounts with or through us. We would like to communicate with you using electronic means. When you agree to this Agreement and tap your acceptance in the Application, this tells us:&#x20;

1. You agree to receive any electronic communication from us for any purpose&#x20;
2. You agree to receive an electronic version of any written notice or disclosures we must send you under law (“Legal Disclosures”). This may include, but is not limited to statements, disclosures, and notices relating to the maintenance or operation of an Account.  Examples of Account notices include, but are not limited to account information, account activity (or inactivity), payments made or due, periodic statements, disclosures, or notices that may be required by law or regulation including the Gramm-Leach-Bliley Act or other applicable federal or state laws and regulations.
3. You agree that we may use electronic signatures and obtain them from you as part of our transactions with you.
4. You understand that to receive Legal Disclosures, you must meet the requirements specified under Technology Requirements below.&#x20;

When we send electronic communication (including a Legal Disclosure) subject to applicable law, it may come in the form of the following:&#x20;

a. An update to the ShredPay website or within the ShredPay App&#x20;

b. As an email, text, or communication on social media&#x20;

c. As a notification on mobile, tablet, or wearable devices&#x20;

d. Through other electronic means.

&#x20;We may also send notices to you by mail to any postal address that you have provided to us.&#x20;

All notices by any of these methods will be considered to be received by you no later than the earlier of when received or posted, or 24 hours after sent, except for notice by postal mail, which will be deemed received by you no later than the earlier of when received or three (3) business days after it is mailed.&#x20;

2. Providing Consent&#x20;

You acknowledge and agree that this Consent is being provided in connection with a transaction affecting interstate commerce that is subject to the federal Electronic Signatures in Global and National Commerce Act (the "E-SIGN Act"), and that you and we both intend that the E-SIGN Act apply to the fullest extent possible to validate our ability to conduct business with you by electronic means.&#x20;

This Consent does not apply to any Communication that we determine, in our sole discretion, we are required to deliver in paper form under applicable law or you should receive in paper rather than electronic form.&#x20;

We reserve the right, in our sole discretion, to discontinue electronic Communications with you, or to terminate or change the terms and conditions on which we provide electronic Communications. We will provide you with notice of any such termination or change as required by law. <br>

Your continued use of the Services after we provide such notice is affirmation of your consent to those changes. You will be asked to acknowledge your acceptance of this Consent before you are able to continue with your application. In doing so, you are providing your affirmative consent to use electronic Communications.&#x20;

<br>

By accepting this Consent, you are also confirming that you meet the system requirements described above, that you have demonstrated your ability to receive, retain, and view electronic documents on your device, and that you have a current email address.&#x20;

<br>

3. Technology Requirements&#x20;

<br>

In order to receive electronic communications, including Legal Disclosures, you must have:&#x20;

<br>

1. A computer or mobile device, iPhone SE (1st generation) or newer, with an internet connection&#x20;
2. iPhone versions iOS 13 or newer&#x20;
3. Android device that supports Android versions 9 or newer&#x20;
4. A web browser that includes 128-bit encryption, with cookies enabled ● A valid email address and phone number&#x20;
5. Sufficient storage space to save any Legal Disclosure or an installed printer to print them&#x20;
6. The ability to view and retain Portable Document Format (PDF) files&#x20;

<br>

We may change these requirements, but we will notify you promptly of any material changes.

<br>

4. Paper Versions

<br>

If you would like a paper copy of any Legal Disclosure we send you, please contact us at <support@shredpay.xyz> or \[insert phone], and we will mail one to you at no cost.&#x20;

<br>

5. Withdrawing Consent&#x20;

<br>

If you would like to withdraw your Consent to receive Communications in electronic form, you can contact us at any time by emailing <support@shredpay.xyz>. If you withdraw your consent, (i) we may immediately suspend or terminate any Account with us, (ii) you will remain responsible for any amounts that you owe us or may come due under any such Account, and (iii) the legal validity and enforceability of prior communication delivered in electronic form will remain in full force and effect.&#x20;

<br>

Any withdrawal of this Consent will be effective only after we have a reasonable period of time to process your withdrawal request. Withdrawal will not affect any Communications we provided to you prior to your withdrawal, and we will send any required further Communications to you in paper form. We will not impose any fee in connection with any withdrawal of this Consent or any Communication provided in paper form.&#x20;

<br>

6. Updating Your Records&#x20;

<br>

You must immediately notify us of any change to your email address, contact information and other information related to this Consent and your Account. You can update this information in the ShredPay App or by contacting us at the email address or phone number listed above.&#x20;

<br>

7. Saving and Reviewing this Consent&#x20;

<br>

The Agreement can be printed and saved for your records.

<br>


# Support Center

If you have any suggestions or questions about our product, you can send your feedback to our email. Thank you for your support.

Email：<support@shredpay.xyz>


# Why a $250 minimum?

ShredPay requires a $250 minimum first-time deposit to help us reduce fraud, maintain compliance standards, and ensure the quality and security our customers expect.


# 24h Change

The performance of your yield products and token holdings over the past 24 hours. Updated every 5 minutes.


# Page


# Wrapped Digital Assets at ShredPay

ShredPay is not a centralized exchange and it does not maintain a central order book. All digital asset buy/sell orders are executed on the broader blockchain ecosystem utilizing a decentralized exchange aggregator, and the digital assets are deposited/withdrawn from your non-custodial digital wallet. In order to provide ShredPay customers with efficient liquidity and the ability to effectively use certain digital assets within decentralized finance (DeFi) applications, the ShredPay platform operates on the Ethereum and Base blockchains. With respect to tokens that are not native to the Ethereum and Base networks, ShredPay offers customers the following assets that are “wrapped” by Coinbase, Inc. (“Coinbase”), allowing them to be efficiently deployed on the Base blockchain:

Bitcoin (cbBTC): Represents Bitcoin and is available on the Base, Ethereum, Solana, and Arbitrum networks.

Dogecoin (cbDOGE): Represents Dogecoin on the Base network.

Ripple (cbXRP): Represents XRP on the Base network.

Litecoin (cbLTC): Represents Litecoin on the Base network.

Cardano (cbADA): Represents Cardano on the Base network.

Note that Coinbase wrapped tokens are backed 1:1 by the underlying assets held in custody by Coinbase (i.e. for every cbBTC token issued, Coinbase holds one BTC token), and these holdings are verified by a Proof of Reserves system. For more information, you can access the relevant Coinbase page here:

<https://help.coinbase.com/en/coinbase/trading-and-funding/sending-or-receiving-cryptocurrency/coinbase-wrapped-btc>


# Wrapped Solana (SOL) at ShredPay

ShredPay is not a centralized exchange and it does not maintain a central order book.  All digital asset buy/sell orders are executed on the broader blockchain ecosystem utilizing a decentralized exchange aggregator, and the digital assets are deposited/withdrawn from your non-custodial digital wallet.  In order to provide ShredPay customers with efficient liquidity and the ability to effectively use certain digital assets within decentralized finance (DeFi) applications, the ShredPay platform operates on the Ethereum and Base blockchains.  With respect to SOL, which is not native to the Ethereum and Base networks, ShredPay offers customers  “wrapped” SOL allowing it to be efficiently deployed on the Base blockchain.

Wrapped SOL refers to assets that have been transferred through a blockchain smart contract from the Solana blockchain to another blockchain network (like Base or Ethereum) or vice versa. Because different blockchains cannot "talk" to each other directly, they use blockchain smart contracts to act as secure intermediaries.&#x20;

ShredPay offers wrapped SOL that has been minted through the blockchain smart contract “Base-Solana Bridge”. Wrapped SOL is fully backed at a 1:1 ratio by native SOL tokens on Solana which are locked in a blockchain vault until the wrapped tokens are redeemed.  Using wrapped SOL allows users to engage with DeFi apps for lower fees across multiple networks. More information about the Base-Solana Bridge can be found here:  <https://docs.base.org/base-chain/quickstart/base-solana-bridge>


# Page


# Welcome

The source for the ShredPay developer portal at [developers.shredpay.xyz](https://developers.shredpay.xyz).

ShredPay is a crypto payment and DeFi investment platform. These docs cover everything developers need to integrate with ShredPay — most prominently the **Agent Wallet API**, which lets AI agents securely operate on-chain assets through REST and MCP interfaces.

## What's in this repo

| Section            | Contents                                                                       |
| ------------------ | ------------------------------------------------------------------------------ |
| `introduction.md`  | Platform overview                                                              |
| `getting-started/` | Authentication, environments, first request                                    |
| `agent-wallet/`    | Agent Wallet product — quickstarts, concepts, guides, API reference, MCP tools |
| `webhooks/`        | Event delivery, signature verification                                         |
| `sdks/`            | Official SDK index                                                             |
| `reference/`       | Errors, rate limits, glossary                                                  |

## License

Documentation © ShredPay. See repository for terms.


# Introduction

**ShredPay** is a crypto payment and DeFi investment platform. We provide the on-chain plumbing — wallets, payments, swaps, yield — so you can ship products without building blockchain infrastructure from scratch.

## What you can build

| Product                    | Description                                                                                                                                                                                       |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Agent Wallet**           | Give AI agents a secure on-chain wallet they can use through REST or [MCP](https://modelcontextprotocol.io/). Per-key spend limits, address screening, and sponsored gas for swap and DeFi flows. |
| **Payments** *(coming)*    | Accept stablecoin payments with automatic settlement to your treasury.                                                                                                                            |
| **DeFi Vaults** *(coming)* | Programmatic access to curated yield vaults across multiple chains.                                                                                                                               |

Today these docs focus on **Agent Wallet** — our first generally available developer product.

## How ShredPay is structured

ShredPay runs as a set of microservices behind a single API gateway. As a developer you only ever interact with the public surface, but it helps to know the boundaries:

* **Wallet Service** — custodial wallet infrastructure (built on Privy 2/2 key quorum).
* **Agent Service** — the API and MCP server that exposes Agent Wallet capabilities.
* **Screening Service** — runs OFAC and risk checks on every counterparty.
* **DeFi Service** — quotes, markets, position tracking.
* **Router contracts** — on-chain entry point that batches approve + swap + deposit and lets ShredPay sponsor gas.

## Who these docs are for

Developers integrating ShredPay into their own product — whether that's an autonomous agent, a wallet UX, a trading bot, or a backend service that needs to move funds on-chain.

If you are looking for the consumer ShredPay app, see [shredpay.xyz](https://shredpay.xyz).

## Next steps

* **New here?** Start with [Getting Started → Overview](/developers/getting-started/overview).
* **Building an agent?** Jump straight to [Agent Wallet → Introduction](/developers/agent-wallet/introduction).
* **Want a working request in 60 seconds?** Try the [Direct API quickstart](/developers/agent-wallet/quickstart/direct-api).


# Overview

A high-level look at how ShredPay is wired together and where your code fits in.

## Architecture at a glance

```
┌────────────────────┐        ┌────────────────────┐
│   Your app /       │        │   AI agent (MCP)   │
│   backend service  │        │   Claude, OpenClaw │
└─────────┬──────────┘        └─────────┬──────────┘
          │                             │
          │  REST  X-Api-Key            │  MCP  X-Api-Key
          │  https://agent-api...       │  /mcp endpoint
          ▼                             ▼
┌──────────────────────────────────────────────────┐
│             Agent Service (public)                │
│   API key auth · spend limits · screening         │
│   tx orchestration · MCP transport                │
└────────┬─────────────┬───────────────┬────────────┘
         │             │               │
         ▼             ▼               ▼
   Wallet Service  Screening     Router contracts
   (sub-wallets,   Service       (on-chain swap +
    P-256 quorum)  (OFAC, risk)   DeFi, gas sponsor)
```

## Request lifecycle (write path)

When an agent calls `POST /api/tx/send`:

1. **Authenticate** — Agent Service resolves the `X-Api-Key` to a sub-wallet and checks the key's permissions and `allowed_chains`.
2. **Limit check** — Daily and monthly USD spend is rolled up against the key's caps.
3. **Screen** — The `to` address (and any beneficiaries decoded from calldata) are screened.
4. **Co-sign** — Agent Service co-signs with its P-256 key; Privy signs with the user-side key (2/2 quorum).
5. **Broadcast** — The transaction is submitted to the configured RPC for the chain.
6. **Webhook** — When the tx confirms (or fails), Agent Service emits an event to your registered webhook URL.

Read-only requests (`get_balance`, `get_positions`, etc.) skip steps 2–5.

## Two ways to integrate

| Path                | When to use                                                                         | Auth               |
| ------------------- | ----------------------------------------------------------------------------------- | ------------------ |
| **REST** (`/api/*`) | Backends, traditional apps, deterministic flows.                                    | `X-Api-Key` header |
| **MCP** (`/mcp`)    | LLM agents that should pick the right tool autonomously (Claude, OpenClaw, custom). | `X-Api-Key` header |

The two surfaces are equivalent — every MCP tool maps 1:1 to a REST endpoint.

## What you need before building

1. A ShredPay account — sign up at [shredpay.xyz](https://shredpay.xyz).
2. Open the **Agent Console** at [console.shredpay.xyz](https://console.shredpay.xyz) and create a sub-wallet.
3. Issue an API key with the limits and chains you want to allow.
4. Fund the sub-wallet (USDC + a small ETH balance, or use the gas swap flow).

You're ready. Continue to [Authentication](/developers/getting-started/authentication).


# Authentication

ShredPay uses two auth schemes depending on who is calling.

| Caller                  | Scheme                      | Header                    |
| ----------------------- | --------------------------- | ------------------------- |
| AI agent / your backend | **API Key**                 | `X-Api-Key: sk_live_…`    |
| Agent Console (browser) | **Privy JWT** (via Gateway) | `Authorization: Bearer …` |

This page covers API keys — the only scheme you need for programmatic access. JWT-authenticated routes are reserved for the Agent Console UI.

## API keys

API keys are issued from the [Agent Console](https://console.shredpay.xyz). Each key is bound to exactly one **sub-wallet** and carries:

* **Permissions** — `read` or `trade`.
* **Spend limits** — daily and monthly USD caps.
* **Allowed chains** — a whitelist of chain IDs the key can transact on.

```http
GET /api/wallet/address HTTP/1.1
Host: agent-api.shredpay.xyz
X-Api-Key: sk_live_e9f3...c104
```

### Key format

```
sk_live_<32-character-secret>     production
sk_test_<32-character-secret>     test environment
```

The full secret is shown **once** at creation time. Store it securely — ShredPay only keeps a hash on disk, so we cannot recover a lost key. Use the rotate endpoint if a key is compromised; the previous key keeps working for 24 hours to give you a grace window.

### Permissions

| Permission | What it allows                                                                                         |
| ---------- | ------------------------------------------------------------------------------------------------------ |
| `read`     | All `GET /api/*` endpoints; MCP read-only tools (`get_balance`, `get_positions`, …).                   |
| `trade`    | Everything in `read` **plus** write endpoints (`send_transaction`, `execute_swap`, `defi_deposit`, …). |

Issue separate keys for read-only dashboards and trading bots. It limits blast radius if one is leaked.

### Spend limits

Limits are enforced **per key**, not per sub-wallet. A request that would exceed either the daily or monthly USD cap is rejected with `403 LIMIT_EXCEEDED` before any signing happens.

Check current usage anytime:

```http
GET /api/limits
```

```json
{
  "daily_limit_usd": "1000",
  "daily_used_usd": "247.50",
  "monthly_limit_usd": "10000",
  "monthly_used_usd": "1820.00",
  "resets_at": "2026-04-26T00:00:00Z"
}
```

### Rotating a key

```http
POST /api/v1/agent/keys/{key_id}/rotate
Authorization: Bearer <console JWT>
```

The response contains a brand-new `sk_live_…` value. The previous key continues to authenticate for 24 hours, then is permanently revoked.

## Storing keys safely

* Treat API keys like passwords — never commit them, never log them, never paste them into chat tools.
* Inject via environment variable or a secret manager (AWS Secrets Manager, Doppler, 1Password).
* Use **separate keys per environment** so a leaked test key cannot move production funds.
* Rotate on a schedule (quarterly is a good default) and immediately on suspected compromise.

## Errors

| Code                    | Meaning                                                                |
| ----------------------- | ---------------------------------------------------------------------- |
| `401 UNAUTHENTICATED`   | Missing or malformed `X-Api-Key` header.                               |
| `401 INVALID_KEY`       | Key does not exist or has been revoked.                                |
| `403 PERMISSION_DENIED` | Key lacks the required permission (e.g. `read` key calling `tx/send`). |
| `403 CHAIN_NOT_ALLOWED` | Target `chain_id` is not in the key's `allowed_chains`.                |
| `403 LIMIT_EXCEEDED`    | Daily or monthly USD cap hit.                                          |

See [reference/error-codes.md](/developers/reference/error-codes) for the full list.


# Environments

ShredPay provides production endpoints for external developers. Credentials are environment-specific and not portable.

| Environment | Purpose                             | API base                         | MCP endpoint                         | Console                        |
| ----------- | ----------------------------------- | -------------------------------- | ------------------------------------ | ------------------------------ |
| **Prod**    | Production. Real funds. SLA-backed. | `https://agent-api.shredpay.xyz` | `https://agent-api.shredpay.xyz/mcp` | `https://console.shredpay.xyz` |

## Chain availability

Prod operates on the following mainnet chains: Ethereum, Base, Arbitrum, Polygon, Optimism, BNB Chain. There is currently no testnet support.

Always query `GET /api/wallet/chains` for the authoritative list — chains may be added without a documentation update.

## Status and uptime

Subscribe to the status page at [status.shredpay.xyz](https://status.shredpay.xyz) for incident notifications.

## Per-environment configuration

When deploying your integration:

1. Create a sub-wallet in the [Console](https://console.shredpay.xyz).
2. Issue an API key bound to that sub-wallet.
3. Register your webhook endpoint and store the signing secret.
4. Update your application config.

API keys are scoped to a single sub-wallet group and cannot be reused across wallets.


# Support

How to get help when you're stuck.

## Channels

| Channel                                                                            | When to use                                                                           |
| ---------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------- |
| Email — `developers@shredpay.xyz`                                                  | Integration questions, account issues, anything non-urgent.                           |
| GitHub issues — [`ShredPay/dev-docs`](https://github.com/ShredPay/dev-docs/issues) | Documentation bugs, typos, missing examples.                                          |
| Status page — [status.shredpay.xyz](https://status.shredpay.xyz)                   | Live incident updates.                                                                |
| Security disclosures — `security@shredpay.xyz`                                     | Vulnerabilities (please use [responsible disclosure](https://shredpay.xyz/security)). |

## Before you reach out

A short reproduction goes a long way. Please include:

* Environment (`dev` / `test` / `prod`).
* The HTTP method, path, and request body (with the API key redacted).
* The response status, headers, and body.
* A timestamp (UTC) and the `x-request-id` header from the response if available.

## SLA

Response targets for production accounts:

| Severity                                    | First response |
| ------------------------------------------- | -------------- |
| Critical (production outage, funds at risk) | 1 hour         |
| High (degraded production)                  | 4 hours        |
| Normal                                      | 1 business day |

Dev and Test environments are best-effort.


# Introduction

A custodial wallet purpose-built for AI agents. Agent Wallet lets your agent hold assets, sign transactions, swap tokens, and deposit into DeFi vaults — across six EVM chains — through a single REST or [MCP](https://modelcontextprotocol.io/) interface.

## Why a separate wallet for agents

Giving an LLM-powered agent direct access to a user's main wallet is reckless. Agent Wallet exists to make agent autonomy safe:

* **Isolated funds** — Each agent gets its own sub-wallet, scoped per user. Compromise stays contained.
* **Hard spend caps** — Per-key daily and monthly USD limits enforced server-side, before any signing.
* **Address screening** — Every counterparty is checked against OFAC and risk lists on every write call.
* **Quorum signing** — Two-of-two signatures (Privy + ShredPay co-signer) on every transaction. Neither party alone can move funds.
* **Per-chain whitelisting** — Restrict a key to specific chains so a swap on Mainnet can't be triggered with a key meant for Base.
* **Killable** — Revoke or rotate a key from the console without touching the wallet itself.

## What it can do

| Capability                       | REST                                          | MCP                                                                                           |
| -------------------------------- | --------------------------------------------- | --------------------------------------------------------------------------------------------- |
| Read addresses, balances, limits | `GET /api/wallet/*`                           | `get_wallet_address`, `get_balance`, `get_native_balance`, `get_token_balances`, `get_limits` |
| Send arbitrary transactions      | `POST /api/tx/send`                           | `send_transaction`                                                                            |
| Simulate transactions            | `POST /api/tx/simulate`                       | `simulate_transaction`                                                                        |
| Quote and execute swaps          | `POST /api/swap/quote`, `/execute`            | `get_swap_quote`, `execute_swap`                                                              |
| DeFi vault deposit / withdraw    | `POST /api/defi/deposit`, `/withdraw`         | `defi_deposit`, `defi_withdraw`                                                               |
| Position and market discovery    | `GET /api/defi/markets`, `/positions`         | `get_defi_markets`, `get_positions`                                                           |
| Gas management (USDC → ETH)      | `POST /api/gas/swap`, `GET /api/gas/estimate` | `gas_swap`, `gas_estimate`                                                                    |
| Status lookup                    | `GET /api/tx/{tx_id}`                         | `get_transaction_status`                                                                      |
| Chain discovery                  | `GET /api/wallet/chains`                      | `get_supported_chains`                                                                        |

That's the full surface — 17 MCP tools, all also available as REST endpoints.

## Supported chains

Ethereum, Optimism, BNB Chain, Polygon, Base, Arbitrum. Always check `GET /api/wallet/chains` for the live list and to see which chains have ShredPay's **Router** contract deployed (Router-enabled chains support sponsored gas for swap and DeFi flows).

## Pick a starting point

| If you...                                | Go to                                                                           |
| ---------------------------------------- | ------------------------------------------------------------------------------- |
| ...want a working REST request right now | [Direct API quickstart](/developers/agent-wallet/quickstart/direct-api)         |
| ...are wiring up Claude Desktop          | [Claude Desktop quickstart](/developers/agent-wallet/quickstart/claude-desktop) |
| ...are building on the OpenClaw platform | [OpenClaw quickstart](/developers/agent-wallet/quickstart/openclaw)             |
| ...want to understand the model first    | [Sub-wallets](/developers/agent-wallet/concepts/sub-wallets)                    |


# Quickstart


# Claude Desktop

Wire ShredPay Agent Wallet into Claude Desktop in about three minutes. Claude will then be able to use all 17 wallet tools directly from any conversation.

## Prerequisites

* [Claude Desktop](https://claude.ai/download) installed (macOS or Windows).
* A ShredPay API key. If you don't have one, follow steps 1–2 of the [Direct API quickstart](/developers/agent-wallet/quickstart/direct-api).

## 1. Locate your Claude Desktop config

| OS      | Path                                                              |
| ------- | ----------------------------------------------------------------- |
| macOS   | `~/Library/Application Support/Claude/claude_desktop_config.json` |
| Windows | `%APPDATA%\Claude\claude_desktop_config.json`                     |

If the file doesn't exist, create it.

## 2. Add the ShredPay MCP server

```json
{
  "mcpServers": {
    "shredpay-wallet": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/server-fetch",
        "https://agent-api.shredpay.xyz/mcp"
      ],
      "env": {
        "X_API_KEY": "sk_live_..."
      }
    }
  }
}
```

Replace `sk_live_…` with your real key from the [Console](https://console.shredpay.xyz).

> The `@modelcontextprotocol/server-fetch` package is the simplest way to point Claude Desktop at a remote streamable-HTTP MCP server. If you maintain your own MCP client transport, point it directly at the `/mcp` endpoint with `X-Api-Key` set on every request.

## 3. Restart Claude Desktop

Fully quit and relaunch. After restart, click the tools icon at the bottom of the chat — you should see **shredpay-wallet** with 17 tools listed.

## 4. Ask Claude to use it

```
What's my USDC balance on Base?
```

Claude will call `get_wallet_address` and `get_balance` and answer with a number. Try follow-ups:

```
Show me my open DeFi positions.
Quote a swap of 50 USDC to ETH on Base.
What's my remaining daily spend limit?
```

Trade-permission tools (`send_transaction`, `execute_swap`, `defi_deposit`, `defi_withdraw`) only work if your key has `trade` enabled.

## Troubleshooting

| Symptom                                 | Fix                                                                                             |
| --------------------------------------- | ----------------------------------------------------------------------------------------------- |
| Tools don't appear after restart        | Check the log at `~/Library/Logs/Claude/mcp*.log` (macOS) for JSON parse errors in your config. |
| `401 INVALID_KEY` in tool output        | Key was revoked or you copied a typo. Issue a new one in the console.                           |
| `403 PERMISSION_DENIED` on a write tool | Your key is `read` only. Create a `trade` key.                                                  |

## Next steps

* [MCP Tools reference](/developers/agent-wallet/mcp-tools) — every tool and its parameters.
* [Gas Model](/developers/agent-wallet/concepts/gas-model) — when ShredPay sponsors gas vs. when you pay.


# OpenClaw

Use the official ShredPay Skill on the [OpenClaw](https://openclaw.ai) agent platform.

## What you'll build

A connected ShredPay Skill in your OpenClaw workspace. Once installed, every agent in the workspace can call any of the 17 wallet tools.

## Steps

This page is a placeholder while we finalize the OpenClaw Skill submission flow. The outline:

1. **Get a ShredPay API key** — same as the [Direct API quickstart](/developers/agent-wallet/quickstart/direct-api), steps 1–2.
2. **Open the OpenClaw Skill marketplace** — search for *ShredPay Wallet*.
3. **Install** — click *Install* and paste your API key when prompted.
4. **Test in any agent** — ask the agent for your wallet balance.

## Skill manifest

The Skill is defined by [`shredpay-wallet.skill.yaml`](https://github.com/ShredPay/openclaw-skill) in the public OpenClaw repo. Version `2.2.0` exposes all 17 tools and supports six EVM chains.

## Coming soon

* Full screenshots of the install flow.
* A worked example with a yield-farming agent.
* Notes on per-workspace key rotation.

In the meantime, the [Direct API quickstart](/developers/agent-wallet/quickstart/direct-api) and [MCP Tools reference](/developers/agent-wallet/mcp-tools) cover everything the Skill exposes.


# Direct API

Make your first authenticated request in under a minute.

## 1. Create an API key

1. Sign in to the [Agent Console](https://console.shredpay.xyz).
2. Create a sub-wallet if you don't have one yet.
3. Open **API Keys → New key**. Pick:
   * **Name** — something memorable, e.g. `quickstart-laptop`.
   * **Permissions** — `read` is enough for this quickstart.
   * **Allowed chains** — leave the default (all supported) or restrict.
   * **Daily / monthly limits** — any value; reads don't consume them.
4. Copy the `sk_live_…` value. **It is shown only once.**

```bash
export SHREDPAY_API_KEY="sk_live_..."
export SHREDPAY_BASE_URL="https://agent-api.shredpay.xyz"
```

## 2. Fetch your wallet addresses

```bash
curl "$SHREDPAY_BASE_URL/api/wallet/address" \
  -H "X-Api-Key: $SHREDPAY_API_KEY"
```

```json
{
  "addresses": {
    "evm": "0xA1b2C3d4e5F60718293A4B5c6d7E8f9012345678"
  },
  "sub_wallet_id": "sw_01HRZK..."
}
```

The same EVM address is used across every chain.

## 3. Check a balance

```bash
# USDC on Base
curl "$SHREDPAY_BASE_URL/api/wallet/balance?chain_id=8453&token=0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913" \
  -H "X-Api-Key: $SHREDPAY_API_KEY"
```

```json
{
  "chain_id": 8453,
  "token": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
  "balance": "1500000",
  "decimals": 6,
  "symbol": "USDC"
}
```

`balance` is always in the smallest unit (here, 1.5 USDC = 1,500,000).

## 4. Send a transaction

> Requires a key with `trade` permission and a funded sub-wallet (USDC + a small amount of native gas, or use [`gas_swap`](/developers/agent-wallet/guides/gas-management) on Base).

The example below transfers 0.10 USDC to another address on Base.

```bash
# ERC20 transfer(address,uint256) calldata for 100000 (= 0.10 USDC)
TO_TOKEN=0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
RECIPIENT=0x000000000000000000000000abc123...           # 32-byte right-padded
AMOUNT=00000000000000000000000000000000000000000000000000000000000186a0
DATA="0xa9059cbb${RECIPIENT}${AMOUNT}"

curl "$SHREDPAY_BASE_URL/api/tx/send" \
  -H "X-Api-Key: $SHREDPAY_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{
    \"chain_id\": 8453,
    \"to\": \"$TO_TOKEN\",
    \"data\": \"$DATA\",
    \"value\": \"0\"
  }"
```

```json
{
  "tx_id": "tx_01HRZL...",
  "tx_hash": "0xa3b4...",
  "status": "broadcast"
}
```

Poll status with `GET /api/tx/{tx_id}` or — better — register a [webhook](/developers/agent-wallet/guides/webhooks) and let ShredPay push the confirmation.

## What just happened

1. Your `X-Api-Key` resolved to a sub-wallet.
2. Spend limits were checked (here, the value is denominated and counted).
3. The recipient address was screened.
4. ShredPay co-signed alongside Privy (2/2 quorum).
5. The signed tx was broadcast on Base and an ID was returned.

## Next steps

* [Send a Transaction guide](/developers/agent-wallet/guides/send-transaction) — full request/response with error handling.
* [Swap Tokens guide](/developers/agent-wallet/guides/swap) — sponsored swaps via Router.
* [API Reference](/developers/agent-wallet/api-reference) — every endpoint and field.


# Concepts


# Sub-wallets

Every agent gets its own wallet — distinct from the user's main ShredPay wallet, isolated from other agents, and disposable.

## Mental model

```
ShredPay user
    │
    ├── main wallet           (user controls — receives deposits, settles payments)
    │
    └── agent sub-wallets     (one per agent / use case)
            │
            ├── sub_wallet_1   ← API key A  ← agent #1 (e.g. trading bot)
            ├── sub_wallet_2   ← API key B  ← agent #2 (e.g. yield manager)
            └── sub_wallet_3   ← API key C  ← agent #3 (e.g. read-only dashboard)
```

A sub-wallet is a real on-chain address. It has its own balances and signs its own transactions.

## Properties

| Property    | Notes                                                                                                                                |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| **Address** | One EVM address used across all six supported chains. Returned by `GET /api/wallet/address`.                                         |
| **Owner**   | The ShredPay user that created it. Visible only to that user in the console.                                                         |
| **Group**   | Sub-wallets are organized under a `group_id`. Today every key maps to exactly one sub-wallet.                                        |
| **Signing** | 2/2 quorum: ShredPay co-signer (P-256) + Privy. Neither party alone can move funds.                                                  |
| **Funding** | Deposit from main wallet via the console. The main → sub transfer goes through the Router contract — full amount lands, no fee skim. |

## Sub-wallet vs. API key

A common point of confusion. They are **separate** concepts:

* A **sub-wallet** is the asset container — the on-chain address.
* An **API key** is the credential that grants access to a sub-wallet.

A sub-wallet can have multiple API keys attached (e.g. one read-only key for a dashboard, one trade key for a bot — both pointing at the same funds). Spend limits live on the **key**, not the wallet.

## Lifecycle

1. **Create** in the Agent Console. Pick a name and (optionally) a group.
2. **Fund** by depositing USDC from your main wallet. You can also send any ERC-20 to the address from outside ShredPay.
3. **Issue API keys** with the permissions you want.
4. **Use** via REST or MCP.
5. **Drain** when done — withdraw funds back to your main wallet from the console.
6. **Archive** — once empty, the sub-wallet can be archived. Archived wallets stop accepting new transactions.

## What sub-wallets do **not** do

* They do not gate which DeFi protocol or which token an agent can interact with. That's the agent's choice. Use **screening** and **per-key limits** for those controls.
* They do not enforce any business policy beyond key-level limits and chain whitelists.

## Related

* [API Keys](/developers/agent-wallet/concepts/api-keys) — auth and limits
* [Multi-chain](/developers/agent-wallet/concepts/multi-chain) — how one address spans six chains
* [Address Screening](/developers/agent-wallet/concepts/address-screening) — automatic OFAC checks on every counterparty


# API Keys

API keys are how AI agents and your backend services authenticate to Agent Wallet. Each key wraps a set of policies — permissions, chains, and spend limits — that ShredPay enforces on every request.

## Anatomy of a key

| Field                        | Description                                                              |
| ---------------------------- | ------------------------------------------------------------------------ |
| `key_id`                     | Stable identifier (e.g. `key_01HRZK…`). Safe to log.                     |
| `secret`                     | The `sk_live_…` or `sk_test_…` value. Sensitive. Shown once at creation. |
| `name`                       | Human label set by the creator.                                          |
| `sub_wallet_id`              | Which sub-wallet the key controls. One-to-one binding.                   |
| `permissions`                | `read` or `trade`.                                                       |
| `allowed_chains`             | List of chain IDs (e.g. `[8453, 42161]`). Empty list = all supported.    |
| `daily_limit_usd`            | USD spend cap per UTC day.                                               |
| `monthly_limit_usd`          | USD spend cap per UTC month.                                             |
| `status`                     | `active`, `revoked`, or `rotating`.                                      |
| `created_at`, `last_used_at` | Audit fields.                                                            |

## Permissions

Two levels — keep them as small as you can get away with.

| `read`  | All `GET /api/*` endpoints. MCP read tools. No signing.                    |
| ------- | -------------------------------------------------------------------------- |
| `trade` | Everything `read` does **plus** `POST /api/tx/send`, swap, DeFi, gas swap. |

## Spend limits

Spend is measured in USD using the price oracle at the time of execution. Native gas paid by ShredPay (sponsored flows) does **not** count against the key's limit. The `value` of swaps and DeFi deposits **does**.

```http
GET /api/limits
```

```json
{
  "daily_limit_usd": "1000",
  "daily_used_usd": "247.50",
  "monthly_limit_usd": "10000",
  "monthly_used_usd": "1820.00",
  "resets_at": "2026-04-26T00:00:00Z"
}
```

When a request would push usage over either cap, ShredPay returns `403 LIMIT_EXCEEDED` **before** any signing. Funds stay safe.

## Allowed chains

`allowed_chains` is an explicit whitelist. A request whose `chain_id` isn't on the list is rejected with `403 CHAIN_NOT_ALLOWED`. Use it to:

* Restrict an experimental key to a low-fee testnet-equivalent like Base.
* Stop a swap bot from accidentally moving on Mainnet.
* Implement per-chain risk budgets at the IAM layer.

## Rotating

```http
POST /api/v1/agent/keys/{key_id}/rotate
```

The response contains a fresh `secret`. The previous secret continues to authenticate for **24 hours** then is permanently retired. Use this window to deploy the new value across your fleet without downtime.

## Revoking

```http
DELETE /api/v1/agent/keys/{key_id}
```

Immediate. There is no grace period — use rotation if you need one.

## Best practices

* **One key per environment.** Test keys never authenticate against Prod and vice versa.
* **One key per agent / use case.** Easier to attribute spend, easier to revoke.
* **Read keys for dashboards, trade keys for bots.** Don't grant `trade` to anything that doesn't need to write.
* **Bind to chains.** Even if a bot only ever runs on Base, set `allowed_chains: [8453]`.
* **Set tight limits.** Start small. You can raise limits without re-issuing.
* **Rotate on a schedule.** Quarterly is a reasonable default.
* **Monitor `last_used_at`.** A key that hasn't been used in 30 days is a candidate for retirement.

## Related

* [Authentication](/developers/getting-started/authentication) — how to send the key
* [Sub-wallets](/developers/agent-wallet/concepts/sub-wallets) — what the key controls
* [Address Screening](/developers/agent-wallet/concepts/address-screening) — the other server-side guardrail


# Gas Model

Two ways to pay for gas. Knowing which applies to which call is the difference between "this transaction worked" and "out of funds."

| Mode                  | Who pays                                                  | When it applies                                                                                                  | Service fee                                         |
| --------------------- | --------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | --------------------------------------------------- |
| **Agent pays**        | The sub-wallet's own native balance (ETH, BNB, MATIC, …). | `send_transaction` and any direct call you make through `POST /api/tx/send`.                                     | None.                                               |
| **ShredPay sponsors** | ShredPay's gas wallet on the target chain.                | `execute_swap`, `defi_deposit`, `defi_withdraw`, `gas_swap` — all flows that go through the **Router** contract. | A small fee on the input amount, in the same token. |

## Why two modes

Agents need to be able to call arbitrary contracts (paying their own gas keeps the model simple and uncensorable). But the most common operations — swaps, deposits, withdrawals — go through ShredPay's Router contract, which can batch token approvals and the actual call into a single sponsored transaction. That's faster, cheaper, and avoids the "agent has USDC but no ETH for gas" footgun.

## When you must hold native gas

Any time you call `send_transaction`. Typical examples:

* ERC-20 transfers to addresses outside the Router.
* Direct calls to a third-party protocol that ShredPay does not have a Router pathway for.
* Any custom calldata.

If your sub-wallet runs out of native gas mid-flow, use [`gas_swap`](/developers/agent-wallet/guides/gas-management) — it converts USDC to ETH through the Router with **ShredPay** paying gas, so the agent doesn't need ETH to obtain ETH. This is how an agent funded only in USDC bootstraps itself.

> **Today `gas_swap` is supported on Base only.** Plan accordingly if your agent operates on other chains — pre-fund native gas or hold the agent on Base.

## When ShredPay sponsors

Any time you call:

* `execute_swap` — swap one token for another.
* `defi_deposit` / `defi_withdraw` — vault interactions in the curated DeFi catalog.
* `gas_swap` — bootstrap native gas from USDC.

These calls only succeed on chains where the **Router** contract is deployed. Check `has_router` in `GET /api/wallet/chains`:

```json
{
  "chains": [
    { "id": 1,     "name": "Ethereum", "has_router": false },
    { "id": 8453,  "name": "Base",     "has_router": true  },
    { "id": 42161, "name": "Arbitrum", "has_router": false }
  ]
}
```

A sponsored call on a chain without Router returns `400 ROUTER_NOT_AVAILABLE`.

## Service fees

Sponsored flows charge a small fee (basis points on the input amount, taken in the same token). Fees are returned in every quote — they are never a surprise:

```json
{
  "amount_in": "100000000",
  "amount_out": "0.0473...",
  "fee_amount": "100000",
  "fee_token": "USDC",
  "gas_sponsored": true
}
```

For exact current fee schedules, check the response body of `POST /api/swap/quote` — they are sourced live, not from documentation.

## Gas estimation

```http
GET /api/gas/estimate?chain_id=8453
```

```json
{
  "chain_id": 8453,
  "gas_price_wei": "1000000",
  "recommended_eth_for_5_txs": "0.0005",
  "native_balance_wei": "120000000000000"
}
```

Use this to decide whether the wallet has enough headroom for the next few transactions, or whether to swap up first.

## Related

* [Manage Gas guide](/developers/agent-wallet/guides/gas-management) — how to keep the wallet topped up
* [Multi-chain](/developers/agent-wallet/concepts/multi-chain) — which chains have Router


# Multi-chain

One sub-wallet, one address, six chains. This page explains what that means in practice and where the asymmetries are.

## Supported chains

| Chain     |    ID | Native gas | Router |
| --------- | ----: | ---------- | :----: |
| Ethereum  |     1 | ETH        |    —   |
| Optimism  |    10 | ETH        |    —   |
| BNB Chain |    56 | BNB        |    —   |
| Polygon   |   137 | POL        |    —   |
| Base      |  8453 | ETH        |   Yes  |
| Arbitrum  | 42161 | ETH        |    —   |

The authoritative list is dynamic — query `GET /api/wallet/chains`. Any chain returned there is supported; the documentation above may lag.

## One address, many chains

EVM addresses are deterministic: the same private key produces the same address on every EVM chain. Your sub-wallet has one address that is valid everywhere. There is no per-chain provisioning step.

```http
GET /api/wallet/address
```

```json
{
  "addresses": {
    "evm": "0xA1b2C3d4e5F60718293A4B5c6d7E8f9012345678"
  },
  "sub_wallet_id": "sw_01HRZK..."
}
```

Funds on different chains are independent — sending USDC to your address on Ethereum does not make it appear on Base. Each balance is queried per chain.

## `has_router` matters

The Router contract powers ShredPay's sponsored-gas flows. **Sponsored operations only work on chains with `has_router: true`.** Today that's **Base** only; more chains are in the pipeline.

| Operation                        | Mainnet | Base | Arbitrum | Polygon | Optimism | BNB |
| -------------------------------- | :-----: | :--: | :------: | :-----: | :------: | :-: |
| `send_transaction`               |   yes   |  yes |    yes   |   yes   |    yes   | yes |
| `simulate_transaction`           |   yes   |  yes |    yes   |   yes   |    yes   | yes |
| `execute_swap`                   |    —    |  yes |     —    |    —    |     —    |  —  |
| `defi_deposit` / `defi_withdraw` |    —    |  yes |     —    |    —    |     —    |  —  |
| `gas_swap`                       |    —    |  yes |     —    |    —    |     —    |  —  |
| Read tools (`get_balance`, …)    |   yes   |  yes |    yes   |   yes   |    yes   | yes |

A sponsored call on a non-Router chain returns `400 ROUTER_NOT_AVAILABLE`. Either move the operation to Base, or use `send_transaction` and pay gas yourself.

## Per-chain key whitelisting

The `allowed_chains` array on an API key is checked first. If your bot only operates on Base, set `allowed_chains: [8453]` — every other chain returns `403 CHAIN_NOT_ALLOWED`, no matter what the agent tries. This is the cheapest defense against a confused agent moving funds on the wrong chain.

## Native gas per chain

If you intend to use `send_transaction` (the Agent-pays path), the sub-wallet needs the **right native token** on the **right chain**:

* Ethereum, Optimism, Base, Arbitrum → ETH
* BNB Chain → BNB
* Polygon → POL (formerly MATIC)

Use `GET /api/gas/estimate?chain_id=…` to see how much native gas a chain has. On Base you can self-fund through `POST /api/gas/swap`. On other chains you need to send native tokens to the address from outside.

## Practical advice

* **Default to Base.** Lowest fees, full Router support, sponsored gas. Build there first.
* **Use chain whitelists aggressively.** They cost nothing and prevent footguns.
* **Don't assume cross-chain liquidity.** If your strategy needs USDC on both Mainnet and Arbitrum, plan the bridge yourself — Agent Wallet does not auto-bridge.
* **Read `GET /api/wallet/chains` at startup.** Cache for a session, but re-poll occasionally so new chains light up automatically.


# Address Screening

Every write call has its counterparties screened against OFAC and risk lists before signing. This page explains what's checked, when, and how to interpret the result.

## What gets screened

Outline:

* The `to` address on every `send_transaction`.
* Beneficiaries decoded from calldata for known function selectors (e.g. ERC-20 `transfer`, swap router recipients).
* Counterparties on `execute_swap`, `defi_deposit`, `defi_withdraw`.

## When it happens

* Before any signature is produced.
* Both for `send_transaction` and `simulate_transaction` — simulate is a safe way to pre-flight a screening check.

## Failure modes and codes

* `403 ADDRESS_BLOCKED` — counterparty is on a blocked list. The transaction is refused; funds remain in the sub-wallet.
* `403 SUB_WALLET_FROZEN` — the sub-wallet itself was frozen following a screening alert on an inbound transfer. Reach out to support to begin manual review.

## What to do on a hit

Outline:

* Read the response body for the offending address and category.
* Surface the message back to the agent / end-user — agents should treat blocks as terminal.
* Contact `support@shredpay.xyz` if you believe the block is a false positive.

## Inbound transfers

Outline:

* Funds arriving from a flagged source freeze only the receiving sub-wallet, not the user's main account.
* Resolution is manual.

This page will be expanded with concrete examples once the public screening response schema is finalized.


# Guides


# Send a Transaction

Outline for the full guide:

* Building the request — `chain_id`, `to`, `data`, `value`, optional `gas_limit`.
* The Agent-pays gas model and how to top up.
* Reading the response — `tx_id`, `tx_hash`, status semantics.
* Polling vs. webhook for confirmation.
* Common errors: `LIMIT_EXCEEDED`, `ADDRESS_BLOCKED`, `INSUFFICIENT_GAS`.
* Worked example: ERC-20 transfer.
* Worked example: arbitrary contract call (e.g. NFT mint).

For now see the [Direct API quickstart](/developers/agent-wallet/quickstart/direct-api) for a runnable example.


# Swap Tokens

Outline:

* Quote first with `POST /api/swap/quote` — slippage, fee preview, expected out.
* Execute with `POST /api/swap/execute` — runs through Router, ShredPay sponsors gas.
* Worked example: 100 USDC → ETH on Base.
* Handling slippage failures and re-quoting.
* Why this is Base-only today (Router availability).

See [Gas Model](/developers/agent-wallet/concepts/gas-model) for the sponsorship rules.


# Deposit into DeFi

Outline:

* Discover markets with `GET /api/defi/markets`.
* Deposit with `POST /api/defi/deposit` — `chain_id`, `market_id`, `amount`.
* Track shares and USD value with `GET /api/defi/positions`.
* Withdraw with `POST /api/defi/withdraw` — pass `shares` from the position.
* Worked example: deposit USDC into a curated yield vault on Base.
* Fees, gas sponsorship, and APY semantics.

See [MCP Tools](/developers/agent-wallet/mcp-tools) for the equivalent `defi_deposit` / `defi_withdraw` tools.


# Manage Gas

Outline:

* `GET /api/gas/estimate?chain_id=…` — current gas price and a recommendation.
* `POST /api/gas/swap` — convert USDC to ETH on Base, sponsored by ShredPay.
* Pre-flight check pattern: estimate → swap if low → send.
* What to do on chains without `gas_swap` (manual native-token funding).
* Monitoring native balances across chains.


# Webhooks

Outline:

* Register a webhook URL in the Agent Console.
* Events emitted: `transaction.broadcast`, `transaction.confirmed`, `transaction.failed`, `funds.deposited`, `screening.alert`.
* Payload shape (one example per event).
* Verifying signatures — see [Webhooks → Signature Verification](/developers/webhooks/signature-verification).
* Retries and idempotency keys.


# API Reference

Full machine-readable reference for every Agent Wallet REST endpoint.

## Live OpenAPI / Swagger UI

The authoritative spec is served by the Agent Service itself:

* **Swagger UI**: <https://agent-api.shredpay.xyz/api/docs>
* **OpenAPI JSON**: <https://agent-api.shredpay.xyz/api/docs-json>

## Endpoint summary

| Method | Path                         | Permission | Description                                       |
| ------ | ---------------------------- | ---------- | ------------------------------------------------- |
| GET    | `/api/wallet/chains`         | read       | Supported chains and `has_router` flag            |
| GET    | `/api/wallet/address`        | read       | Sub-wallet addresses                              |
| GET    | `/api/wallet/balance`        | read       | ERC-20 balance for one token on one chain         |
| GET    | `/api/wallet/balances`       | read       | All known-token balances on one chain             |
| GET    | `/api/wallet/native-balance` | read       | Native token balance                              |
| GET    | `/api/wallet/token-balances` | read       | All ERC-20 balances on a chain (Alchemy)          |
| GET    | `/api/limits`                | read       | Daily / monthly USD limits and usage              |
| GET    | `/api/gas/estimate`          | read       | Gas price and recommended ETH amount              |
| GET    | `/api/tx/{tx_id}`            | read       | Transaction status                                |
| GET    | `/api/defi/markets`          | read       | Available DeFi vaults                             |
| GET    | `/api/defi/positions`        | read       | Sub-wallet's open positions                       |
| POST   | `/api/swap/quote`            | read       | Swap quote via Li.Fi                              |
| POST   | `/api/tx/simulate`           | trade      | Simulate a transaction (validation + screening)   |
| POST   | `/api/tx/send`               | trade      | Sign and broadcast a transaction (Agent pays gas) |
| POST   | `/api/swap/execute`          | trade      | Execute a swap via Router (sponsored)             |
| POST   | `/api/defi/deposit`          | trade      | Deposit into a DeFi vault (sponsored)             |
| POST   | `/api/defi/withdraw`         | trade      | Withdraw from a DeFi vault (sponsored)            |
| POST   | `/api/gas/swap`              | trade      | Convert USDC to ETH for gas (sponsored, Base)     |

This page is intentionally a thin index — the Swagger UI is always up to date with the deployed code.


# MCP Tools

ShredPay Agent Wallet exposes 17 tools over the [Model Context Protocol](https://modelcontextprotocol.io/). Every tool maps 1:1 to a REST endpoint — pick whichever surface fits your client.

## Endpoint

```
https://agent-api.shredpay.xyz/mcp
```

Transport: **streamable-http**. Auth: `X-Api-Key` header on every request.

## Read tools (no `trade` permission required)

### `get_supported_chains`

List supported blockchain networks and whether each has the Router contract deployed.

| Param | Type | Required |
| ----- | ---- | -------- |
| —     |      |          |

### `get_wallet_address`

Get the agent's wallet addresses (one EVM address shared across all chains).

| Param | Type | Required |
| ----- | ---- | -------- |
| —     |      |          |

### `get_balance`

Query an ERC-20 token balance on a specific chain.

| Param      | Type   | Required | Description                     |
| ---------- | ------ | :------: | ------------------------------- |
| `chain_id` | number |    yes   | Chain ID (e.g. `8453` for Base) |
| `token`    | string |    yes   | Token contract address          |

### `get_native_balance`

Query the native token balance (ETH / BNB / POL).

| Param      | Type   | Required | Description |
| ---------- | ------ | :------: | ----------- |
| `chain_id` | number |    yes   | Chain ID    |

### `get_token_balances`

List all ERC-20 balances and the native balance on a chain (powered by Alchemy).

| Param      | Type   | Required | Description |
| ---------- | ------ | :------: | ----------- |
| `chain_id` | number |    yes   | Chain ID    |

### `get_limits`

Query daily and monthly spend limits and current usage.

| Param | Type | Required |
| ----- | ---- | -------- |
| —     |      |          |

### `get_transaction_status`

Look up the status of a previously submitted transaction.

| Param   | Type   | Required | Description                                   |
| ------- | ------ | :------: | --------------------------------------------- |
| `tx_id` | string |    yes   | Transaction ID returned by `send_transaction` |

### `gas_estimate`

Estimate current gas price and recommended ETH amount for a chain.

| Param      | Type   | Required | Description |
| ---------- | ------ | :------: | ----------- |
| `chain_id` | number |    yes   | Chain ID    |

### `get_defi_markets`

Get the catalog of available DeFi vaults.

| Param | Type | Required |
| ----- | ---- | -------- |
| —     |      |          |

### `get_positions`

Get the wallet's open DeFi positions (shares, USD value, market info, APY).

| Param | Type | Required |
| ----- | ---- | -------- |
| —     |      |          |

### `get_swap_quote`

Get a swap quote via the Li.Fi aggregator. Useful for previewing a price before calling `execute_swap`.

| Param        | Type   | Required | Description               |
| ------------ | ------ | :------: | ------------------------- |
| `chain_id`   | number |    yes   | Chain ID                  |
| `from_token` | string |    yes   | Source token address      |
| `to_token`   | string |    yes   | Destination token address |
| `amount`     | string |    yes   | Amount in smallest unit   |

## Trade tools (require `trade` permission)

### `send_transaction`

Sign and broadcast an arbitrary on-chain transaction. **Agent pays gas** — sub-wallet must hold native token.

| Param       | Type   | Required | Description                                    |
| ----------- | ------ | :------: | ---------------------------------------------- |
| `chain_id`  | number |    yes   | Target chain ID                                |
| `to`        | string |    yes   | Destination address                            |
| `data`      | string |    yes   | Transaction calldata (hex)                     |
| `value`     | string |    no    | Value in wei (hex or decimal). Defaults to `0` |
| `gas_limit` | string |    no    | Override gas limit                             |

### `simulate_transaction`

Simulate a transaction without broadcasting. Runs validation and address screening — useful for pre-flighting an expensive call.

| Param      | Type   | Required | Description                |
| ---------- | ------ | :------: | -------------------------- |
| `chain_id` | number |    yes   | Target chain ID            |
| `to`       | string |    yes   | Destination address        |
| `data`     | string |    yes   | Transaction calldata (hex) |
| `value`    | string |    no    | Value in wei               |

### `gas_swap`

Swap USDC to ETH for gas. **Sponsored** by ShredPay (you don't need ETH to obtain ETH). Base only today.

| Param         | Type   | Required | Description                               |
| ------------- | ------ | :------: | ----------------------------------------- |
| `amount_usdc` | string |    yes   | USDC amount in smallest unit (6 decimals) |
| `chain_id`    | number |    yes   | Chain ID (currently must be `8453`)       |

### `execute_swap`

Execute a token swap via the Router contract. **Sponsored** — ShredPay pays gas, collects a small fee.

| Param        | Type   | Required | Description                             |
| ------------ | ------ | :------: | --------------------------------------- |
| `chain_id`   | number |    yes   | Chain ID (must have `has_router: true`) |
| `from_token` | string |    yes   | Source token address                    |
| `to_token`   | string |    yes   | Destination token address               |
| `amount`     | string |    yes   | Amount in smallest unit                 |
| `slippage`   | string |    no    | Slippage tolerance (default `0.5%`)     |

### `defi_deposit`

Deposit into a curated DeFi vault via Router. **Sponsored**.

| Param       | Type   | Required | Description                                      |
| ----------- | ------ | :------: | ------------------------------------------------ |
| `chain_id`  | number |    yes   | Chain ID                                         |
| `market_id` | string |    yes   | Market ID from `get_defi_markets`                |
| `amount`    | string |    yes   | Amount in smallest unit (e.g. USDC = 6 decimals) |

### `defi_withdraw`

Withdraw from a DeFi vault via Router. **Sponsored**.

| Param       | Type   | Required | Description                                  |
| ----------- | ------ | :------: | -------------------------------------------- |
| `chain_id`  | number |    yes   | Chain ID                                     |
| `market_id` | string |    yes   | Market ID from `get_defi_markets`            |
| `shares`    | string |    yes   | Shares to redeem (read from `get_positions`) |

## Permission summary

| Permission | Tools                                                                                                                                                                                                                  |
| ---------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `read`     | `get_supported_chains`, `get_wallet_address`, `get_balance`, `get_native_balance`, `get_token_balances`, `get_limits`, `get_transaction_status`, `gas_estimate`, `get_defi_markets`, `get_positions`, `get_swap_quote` |
| `trade`    | All `read` tools **plus** `send_transaction`, `simulate_transaction`, `gas_swap`, `execute_swap`, `defi_deposit`, `defi_withdraw`                                                                                      |

## Source of truth

The Skill manifest used by OpenClaw and other agent platforms lives at [`ShredPay/openclaw-skill`](https://github.com/ShredPay/openclaw-skill) — `shredpay-wallet.skill.yaml`. If that file disagrees with this page, the YAML wins.


# Changelog

Notable changes to the Agent Wallet API and MCP Skill.

## v2.2.0

* 17 MCP tools across read and trade tiers.
* Multi-chain support: Ethereum, Optimism, BNB Chain, Polygon, Base, Arbitrum.
* Swap and DeFi flows route through the Router contract on Base with sponsored gas.

## Earlier versions

Earlier internal versions are not documented publicly.

## Versioning policy

* Tools and endpoints are added without a version bump.
* Breaking changes (renaming a parameter, changing a return shape, removing a tool) bump the **major** version and ship behind an opt-in flag for at least one minor cycle.


# Overview

Outline:

* Why webhooks (push vs. poll for transaction state).
* How to register a URL in the Agent Console.
* Delivery semantics: at-least-once, ordered per-resource, retried with exponential backoff.
* Required HTTP response (`2xx` within 5 seconds).
* Best practices: respond fast, queue work, dedupe by `event_id`.

See [Signature Verification](/developers/webhooks/signature-verification) for security and [Events](/developers/webhooks/events) for the catalog.


# Signature Verification

Outline:

* Header carrying the signature (e.g. `X-ShredPay-Signature`).
* Algorithm: HMAC-SHA256 over `<timestamp>.<raw body>`.
* Per-endpoint signing secret (different from the API key).
* Pseudocode for verification.
* Replay protection: reject if `timestamp` is older than 5 minutes.
* Sample implementations in Node, Python, Go.


# Events

Outline of events emitted by Agent Wallet:

| Event                   | When                                                                      |
| ----------------------- | ------------------------------------------------------------------------- |
| `transaction.broadcast` | A signed tx has been submitted to the chain.                              |
| `transaction.confirmed` | The tx reached the configured confirmation depth.                         |
| `transaction.failed`    | The tx reverted or was dropped.                                           |
| `funds.deposited`       | An inbound transfer was credited to the sub-wallet.                       |
| `screening.alert`       | An inbound transfer triggered a screening hit; the sub-wallet was frozen. |

Each event will be documented with a sample payload and field reference. For now, follow the patterns in [Webhooks Overview](/developers/webhooks/overview) and verify signatures per [Signature Verification](/developers/webhooks/signature-verification).


# Overview

ShredPay does not yet ship official language SDKs. The REST API is small enough that a generated client from the OpenAPI spec works well in the meantime — see [API Reference](/developers/agent-wallet/api-reference) for the live spec URL.

## Planned

* **TypeScript / Node** — first official SDK, targeting backend agents and Next.js apps.
* **Python** — for ML / data engineering use cases.
* **Go** — for high-throughput backends.

## Community

If you build a client and want it listed here, open a PR against this page.


# Error Codes

Every error response carries a stable `code` field. Use it for programmatic handling — the human `message` may change.

```json
{
  "error": {
    "code": "LIMIT_EXCEEDED",
    "message": "Daily USD limit reached",
    "request_id": "req_01HRZK..."
  }
}
```

Outline of codes (full reference to come):

| HTTP | Code                   | Meaning                                          |
| ---- | ---------------------- | ------------------------------------------------ |
| 400  | `BAD_REQUEST`          | Malformed body or missing required field.        |
| 400  | `INVALID_CHAIN`        | Unknown `chain_id`.                              |
| 400  | `ROUTER_NOT_AVAILABLE` | Sponsored op called on a chain without Router.   |
| 401  | `UNAUTHENTICATED`      | Missing `X-Api-Key`.                             |
| 401  | `INVALID_KEY`          | Key not found or revoked.                        |
| 403  | `PERMISSION_DENIED`    | Key lacks `trade` permission.                    |
| 403  | `CHAIN_NOT_ALLOWED`    | `chain_id` not in key's `allowed_chains`.        |
| 403  | `LIMIT_EXCEEDED`       | Daily or monthly USD cap hit.                    |
| 403  | `ADDRESS_BLOCKED`      | Counterparty failed screening.                   |
| 403  | `SUB_WALLET_FROZEN`    | Wallet under manual review.                      |
| 404  | `NOT_FOUND`            | Unknown `tx_id`, `market_id`, etc.               |
| 429  | `RATE_LIMITED`         | Too many requests; back off.                     |
| 500  | `INTERNAL_ERROR`       | Server-side failure; safe to retry with backoff. |
| 502  | `UPSTREAM_ERROR`       | Chain RPC or Privy unreachable; retry.           |


# Rate Limits

Outline:

* Per-key request budgets (separate for read and write).
* Headers returned on every response (`X-RateLimit-Limit`, `X-RateLimit-Remaining`, `X-RateLimit-Reset`).
* Behavior on overflow (`429 RATE_LIMITED`).
* Recommended retry strategy: exponential backoff with jitter.
* Bursts vs. sustained throughput.

Specific limits will be published once the production rollout is complete.


# Glossary

| Term                 | Definition                                                                                                                 |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| **Agent Wallet**     | ShredPay's product giving AI agents a sandboxed on-chain wallet.                                                           |
| **Sub-wallet**       | A user-owned wallet dedicated to a single agent / use case. Distinct from the user's main ShredPay wallet.                 |
| **API key**          | The credential that grants access to one sub-wallet, with permissions and spend limits attached.                           |
| **Co-signer**        | ShredPay's P-256 key that participates in the 2/2 quorum signing scheme.                                                   |
| **Privy**            | The wallet infrastructure provider that holds the other half of the 2/2 quorum.                                            |
| **Router**           | ShredPay's on-chain contract that batches approve + swap + deposit and lets ShredPay sponsor gas.                          |
| **MCP**              | [Model Context Protocol](https://modelcontextprotocol.io/) — the open standard ShredPay uses to expose tools to AI agents. |
| **OpenClaw**         | An agent platform that ships ShredPay as a one-click installable Skill.                                                    |
| **Skill (OpenClaw)** | A bundled set of tools and metadata an agent can install. ShredPay's Skill is `shredpay-wallet`.                           |
| **Sponsored gas**    | Gas paid by ShredPay (in exchange for a small service fee). Available for swap, DeFi, and `gas_swap`.                      |
| **Allowed chains**   | The whitelist on an API key — only listed chain IDs may be used.                                                           |
| **Group ID**         | An optional grouping of sub-wallets under a user. Reserved for future multi-wallet workflows.                              |
| **Quorum**           | A signing scheme that requires multiple signatures. ShredPay uses 2/2 (Privy + ShredPay co-signer).                        |
| **Smallest unit**    | The integer representation of a token amount (e.g. 1 USDC = `1000000` because USDC has 6 decimals).                        |


