Build

Building on OpenApps.

Four ways in, from least to most involved: let people sign in to your site with OpenWallet, get paid by their agents, charge OpenApps credits from an app in the suite, and list your app's operations so any agent can find and run them.

Last updated: 5 October 2026

Sign in with OpenWallet.

Live OpenWallet ID is a standard OpenID Connect provider. Anyone can use it without registering first: your client id is the URL of a metadata document you publish. People sign in with Google or an email code plus a passkey or TOTP, and your site gets a private identifier for them. They share their email only if they tick it.

Value
Issuerhttps://wallet.openapps.network
Discoveryhttps://wallet.openapps.network/.well-known/openid-configuration
Client idAn https URL serving your client metadata document. No registration.
FlowAuthorization code with PKCE (S256)
Scopesopenid, and optionally email, xrpl (an XRP Ledger address), nostr (an npub)
ID tokensES256, keys at /oidc/jwks.json
SubjectPairwise: the same person has a different sub on every registrable domain, so two sites cannot match their users up.

The full guide, with a working example, is Sign in with OpenWallet.

Get paid by agents.

Live If you run an HTTP API or an MCP server, you can charge agents that pay with OpenWallet, or with any other x402 client. Answer a request with 402 Payment Required and an x402 challenge in XRP or RLUSD; the agent's wallet pays within its owner's limits and retries, and you return the resource with a receipt. The open-source @openwallet/x402-xrpl library asks for the payment, verifies it on the ledger and issues the receipt. See Accept payments.

Accounts and credits.

Live for apps in the OpenApps suite. Every app shares one account service, so a person signs in once and spends one balance everywhere. App keys are issued to apps in the suite; if you are building one, write to contact@openapps.network.

Value
Base URLhttps://accounts.openapps.network
User tokensEdDSA JWTs, 15 minutes, verified locally against /.well-known/jwks.json. Refresh tokens rotate; reusing an old one revokes the whole family.
Sign-in methodsGoogle, OpenWallet, Ethereum wallets, Nostr and Telegram. Ask GET /v1/auth/methods before drawing a sign-in screen.
Top-upsCard (Stripe), Ethereum, Lightning, and Apple and Google in-app purchase. GET /v1/payments/packages lists the packages.
Errors{"error": {"code": "insufficient_balance", "message": "…"}} with 400, 401, 402, 404, 409, 429

The calls an app makes

CallAuthWhat for
GET /v1/meuserThe person, their linked sign-ins, balance and referral code
GET /v1/credits/balanceuserThe balance, before offering a paid feature
POST /v1/credits/deductapp key + userCharge for work that succeeded: { amount, reason, idempotency_key }
GET /v1/credits/historyuserThe ledger, newest first, with which app charged each entry
POST /v1/payments/stripe/checkoutuserA card top-up; poll /v1/payments/topups/{id} for the result

Three rules for charging

List your operations for agents.

Building An app reaches agents by publishing operations into the OpenApps MCP catalogue, not by adding tools. An operation is a contract:

FieldWhat it says
iddomain.verb, for example doc.classify_and_split
Input and outputTyped schemas. Inputs are files by handle or URL, never by path.
InvariantsWhat the operation guarantees about its result, and what it explicitly does not establish
CostHow the price is worked out, so a quote can be given before running
Effectsreads, writes, sends or spends. This is what OpenWallet decides on.
Evidence gradeHow far the result can be relied on, from best-effort to audited by an independent checker
AliasesWhat people actually type, in all eight of our languages (“split invoices”, “拆分发票”)

To list one:

  1. Add the contract, with aliases in the eight languages, and an auditor if any guarantee is meant to back money.
  2. Add at least ten labelled search queries that should find it. The catalogue's search must still find the right operation in its top five for 95% of all labelled queries.
  3. Pass the operation's conformance cases and the search check.
  4. Deploy. A new operation needs no new tool and no change to any tool description, so agents pick it up without re-approving anything.

Building something you would like listed? Join the builders' list.

Writing an MCP server for an app.

If your app runs on people's own machines and ships its own MCP server, follow the conventions in the MCP reference. The short version: