# Account abstraction

> Native account abstraction on NeuroChain — sponsored gas pools, session keys that let apps and AI agents act within a scope, spend cap and expiry, .agent accounts, and the MCP server that connects AI assistants to the chain.

Source: https://docs.nro.world/ai/account-abstraction

On NeuroChain an account is an ML-DSA-65 key, not a contract, so account abstraction is built into the protocol instead of being emulated by wallet contracts. It covers three things: **someone else pays the gas**, **a limited key acts for you**, and **AI agents use both** safely.

## Sponsored gas

A **gas pool** is NRO set aside to pay transaction fees.

| Who pays a fee | When |
|----------------|------|
| The sender's own pool | Whenever it holds enough for the fee |
| The network's onboarding sponsor | The wallet can cover the transferred value but not the fee (new users with only the amount they were sent) |
| The sender's balance | Otherwise |

Rules:

- A sponsored fee is at most `NEUROCHAIN_MAX_SPONSORED_FEE` (100 000 uNRO) per transaction.
- Sponsored fees are burned and paid to the proposer like any other fee.
- The onboarding sponsor is `NEUROCHAIN_GAS_SPONSOR` (default `neuro:faucet.vault`); its pool is funded once at genesis with `NEUROCHAIN_GAS_SPONSOR_FUND` (1 000 000 NRO) and topped up later through deposits.

| Action | Endpoint | Signs for |
|--------|----------|-----------|
| Put NRO into your pool | `POST /api/v1/sponsor/deposit` (`address`, `amount`) | `neuro:system.sponsor` |
| Take it back | `POST /api/v1/sponsor/withdraw` (`address`, `amount`) | `neuro:system.sponsor` |
| Pool balance | `GET /api/v1/sponsor/:address` | — |

## Session keys

A **session key** is a separate ML-DSA-65 key that your master key authorises to act for your account — within limits you set:

| Limit | Field | Meaning |
|-------|-------|---------|
| Scope | `scope` | Comma-separated addresses the key may send to, or `*` for any |
| Spend cap | `cap` | Total uNRO the key may move over its life |
| Expiry | `expiry_block` | Last block height the key is valid; must be in the future |

```json
POST /api/v1/session/grant
{
  "account": "neuro:<15 hex>.human",
  "session_pk": "<session public key, hex>",
  "scope": "neuro:<10 hex>.app",
  "cap": 5000000,
  "expiry_block": 120000,
  "signature": "…", "public_key": "<master key>", "nonce": 1791200000000
}
```

A session key then signs ordinary transactions **as the account** (`from` = your address, `public_key` = the session key). Every validator checks, in consensus:

1. the signature is valid for the session key;
2. the account granted that key, and it is not revoked;
3. the current height is not past `expiry_block`;
4. the target is in `scope`;
5. what it has spent plus this value stays within `cap`.

Spending is recorded only when the transaction applies successfully. Revoke at any time with `POST /api/v1/session/revoke` (`account`, `session_pk`); list grants with `GET /api/v1/session/list/:account`.

**What a session key can never do:** manage the [Sentinel](./sentinel) trust list, or confirm or cancel a held transfer — those need the master key. So an agent can start a risky transfer, but only you can approve it.

**How it is tested:** a network test on several validators confirmed that the spend cap holds under concurrent transactions, a replayed transaction is refused, and revocation takes effect on every node.

## `.agent` accounts

A `.agent` address is a paid name for an AI agent's account — registered by your `.human` wallet, controlled by your key, and meant to hold the agent's gas pool and session keys. It is not a validator and holds no stake. Price by name length, as for custom names ([Addresses → Name prices](/learn/addresses#name-prices)).

`POST /api/v1/agents/register` (`name`, `owner`; signs for `neuro:system.agent`), `GET /api/v1/agents/:address`.

## AI agents through MCP

The `neurochain-mcp` server gives AI assistants (Claude Code, Claude Desktop, any MCP client) read access to the chain and, with a session key, `nc_transfer`, `nc_call_contract` and `nc_deploy` — never the master key. Setup, every tool and the limits: [AI agents (MCP)](/build/mcp).
