> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# How passkeys and modules work

> How a passkey signs modular wallet operations and how modules extend the wallet's behavior.

A modular wallet is a Modular Smart Contract Account (MSCA) controlled by a
passkey. Modules can extend the wallet, for example to restrict transfers to an
onchain allowlist.

## Passkeys

A passkey is the default signer for a modular wallet. It uses the
[WebAuthn](https://www.w3.org/TR/webauthn-3/) standard. The key pair is
generated on the user's device and stored in a secure enclave or password
manager. The user signs with biometrics or device unlock. No seed phrase or
password.

**What to know:**

* Passkeys use the `secp256r1` curve. Each signature includes WebAuthn metadata.
* The key never leaves the user's device. Your app can't read it, Circle can't
  read it, and it can't be phished.
* The [modular wallets SDKs](/sdks/modular/overview) handle passkey login and
  signing through `webAuthnAccount`.
* When the user signs, the SDK submits the signed user operation to a bundler,
  which broadcasts it onchain. Gas can be sponsored through
  [Gas Station](/wallets/gas-station) with `paymaster: true`.

<Note>
  Need an EOA-based signer instead of a passkey, for example when your app
  already uses a third-party auth provider like
  [Dynamic](https://www.dynamic.xyz/) to manage user identity? See [Dynamic
  integration](/wallets/modular/use-dynamic-as-a-signer) for the pattern.
</Note>

### Backup and recovery

Passkeys replace traditional private keys, so backup matters. Synced passkeys
(through Apple iCloud Keychain or Google Password Manager) restore on any device
the user signs into. Device-bound passkeys like YubiKey do not sync. Losing that
device means losing access unless the user has another credential.

Circle adds recovery keys as a backup. A recovery key has the same permissions
as a passkey. It uses ECDSA signatures and is self-custodial. No central
authority can restore it. Users can register multiple recovery keys.

<Warning>
  The passkey and any recovery keys are the only ways to access a modular
  wallet. Neither Circle nor your application can recover user wallets if every
  credential is lost.
</Warning>

For implementation details, see
[Set up passkey recovery](/wallets/modular/set-up-passkey-recovery).

## Modules

Modules are contracts that extend a modular wallet's behavior at runtime. They
add capabilities or enforce rules the base wallet lacks.

**What to know:**

* Modules follow the [ERC-6900](https://eips.ethereum.org/EIPS/eip-6900)
  standard, which defines how MSCAs plug in optional logic.
* Every modular wallet starts with the passkey signer as a built-in module. You
  attach more modules to extend behavior.
* You can also build custom modules against the ERC-6900 standard to fit
  application-specific logic.

### Supported modules

| Module | Description | Module address |
| - | - | - |
| Passkey (WebAuthn) | Default signer for the modular wallet. Built in. | Built-in |
| Address Book | Restricts transfers (ERC-20, ERC-721, ERC-1155) to a list of onchain allowlisted addresses. Useful for treasury vaults that should only send to known counterparties. | Mainnet and testnet: `0x0000000d81083B16EA76dfab46B0315B0eDBF3d0` |
