> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# How-to: Generate and register your entity secret

> Generate an entity secret and register it with Circle.

An [entity secret](/wallets/dev-controlled/entity-secret-management) is a
cryptographic key. Circle uses it to authorize signing on your
developer-controlled wallets. You must generate and register an entity secret
before creating any developer-controlled wallets.

To create an entity secret, use one of the following methods:

* [Circle Console](https://console.circle.com/wallets/dev/configurator/entity-secret)
  (recommended)
* [Circle SDK](#create-an-entity-secret-using-the-sdk)

## Create an entity secret using the SDK

### Prerequisites

Before you begin, ensure that you've:

* Created an [API key](/api-reference/keys) in the
  [Circle Console](https://console.circle.com/) and added it to a `.env` file in
  your project:

  ```text .env theme={null}
  CIRCLE_API_KEY=YOUR_API_KEY
  ```

  <Tip>
    Open `.env` in your editor rather than writing values with shell commands, and
    add `.env` to your `.gitignore`. This prevents credentials from leaking into
    your shell history or version control.
  </Tip>

* Installed one of the following:
  * [Node.js v22.6 or later](https://nodejs.org/)
  * [Python 3.11 or later](https://www.python.org/)

* Installed the Developer-Controlled Wallets SDK:

  <CodeGroup>
    ```shell Node.js theme={null}
    npm pkg set type=module
    npm install @circle-fin/developer-controlled-wallets
    ```

    ```shell Python theme={null}
    pip install circle-developer-controlled-wallets python-dotenv
    ```
  </CodeGroup>

<Note>
  If you are not using the Circle SDK, you can generate and register your entity
  secret [manually](https://github.com/circlefin/w3s-entity-secret-sample-code)
  using standard libraries or command-line tools.
</Note>

### Generate and register an entity secret

Create your script file with `touch register-entity-secret.ts` (Node.js) or
`touch register_entity_secret.py` (Python), then add the following script,
which:

* Generates a 32-byte entity secret
* Registers it with Circle
* Saves the recovery file to `./recovery/` with a unique filename
* Adds `CIRCLE_ENTITY_SECRET` to your `.env` file for local development (use a
  secrets manager in production)

<Warning>
  Store your entity secret in a secrets manager or encrypted password manager.
  Save the recovery file to a separate, secure location. It is the only way to
  reset your entity secret if it is lost. Circle does not store your entity secret
  and cannot recover it for you. For more on storage and rotation best practices,
  see
  [How the entity secret works](/wallets/dev-controlled/entity-secret-management).
</Warning>

<CodeGroup>
  ```typescript Node.js expandable theme={null}
  import { randomBytes } from "node:crypto";
  import { appendFileSync, existsSync, mkdirSync, readFileSync } from "node:fs";
  import { registerEntitySecretCiphertext } from "@circle-fin/developer-controlled-wallets";

  const apiKey: string | undefined = process.env.CIRCLE_API_KEY;
  if (!apiKey) {
    throw new Error("CIRCLE_API_KEY is required. Set it in .env first.");
  }

  // Refuse to overwrite an existing entity secret in .env.
  const existingEnv: string = existsSync(".env")
    ? readFileSync(".env", "utf8")
    : "";
  if (/^CIRCLE_ENTITY_SECRET=/m.test(existingEnv)) {
    throw new Error(
      "CIRCLE_ENTITY_SECRET already exists in .env. Refusing to overwrite it.",
    );
  }

  // Generate a 32-byte entity secret. The SDK's generateEntitySecret() helper
  // prints to stdout but doesn't return the value, so use crypto directly.
  const entitySecret: string = randomBytes(32).toString("hex");
  const recoveryFilePath: string = "./recovery";

  mkdirSync(recoveryFilePath, { recursive: true });

  await registerEntitySecretCiphertext({
    apiKey,
    entitySecret,
    recoveryFileDownloadPath: recoveryFilePath,
  });

  // For production, prefer a secrets manager over .env.
  appendFileSync(".env", `\nCIRCLE_ENTITY_SECRET=${entitySecret}\n`);

  console.log("Entity secret registered.");
  console.log(`Recovery file saved to a new file in: ${recoveryFilePath}`);
  console.log("CIRCLE_ENTITY_SECRET added to .env");
  ```

  ```python Python expandable theme={null}
  import os
  import re

  from dotenv import load_dotenv
  from circle.web3 import utils

  load_dotenv()

  api_key = os.environ.get("CIRCLE_API_KEY")
  if not api_key:
      raise RuntimeError("CIRCLE_API_KEY is required. Set it in .env first.")

  existing_env = ""
  if os.path.exists(".env"):
      with open(".env", "r") as f:
          existing_env = f.read()

  if re.search(r"^CIRCLE_ENTITY_SECRET=", existing_env, re.MULTILINE):
      raise RuntimeError(
          "CIRCLE_ENTITY_SECRET already exists in .env. Refusing to overwrite it."
      )

  entity_secret = os.urandom(32).hex()
  recovery_file_path = "./recovery"

  os.makedirs(recovery_file_path, exist_ok=True)

  utils.register_entity_secret_ciphertext(
      api_key=api_key,
      entity_secret=entity_secret,
      recoveryFileDownloadPath=recovery_file_path,
  )

  with open(".env", "a") as f:
      f.write(f"\nCIRCLE_ENTITY_SECRET={entity_secret}\n")

  print("Entity secret registered.")
  print(f"Recovery file saved to a new file in: {recovery_file_path}")
  print("CIRCLE_ENTITY_SECRET added to .env")
  ```
</CodeGroup>

### Run the script

From the same directory, run:

<CodeGroup>
  ```shell Node.js theme={null}
  node --env-file=.env register-entity-secret.ts
  ```

  ```shell Python theme={null}
  python register_entity_secret.py
  ```
</CodeGroup>

You should see:

```text theme={null}
Entity secret registered.
Recovery file saved to a new file in: ./recovery
CIRCLE_ENTITY_SECRET added to .env
```

<Note>
  If you see `Cannot find module '@circle-fin/developer-controlled-wallets'`,
  run the script from the same directory where you ran `npm install` (or `pip
      install`). The SDK lives in that project's `node_modules` or `virtualenv` and
  isn't visible from other folders.
</Note>
