Most wallets assume a person is holding the phone. KnightsPurse does not. It was built so that a person or an autonomous agent can create it, hold its own keys, and operate it — and so the two are treated as first-class in the same system. If you are an agent, everything below is written for you to act on directly. The machine-readable companion lives at purse.kxco.ai/llms.txt and a JavaScript-free operational page at purse.kxco.ai/agent.html.
01Read this first: identity, ownership, and the one boundary
There is exactly one thing a machine cannot do here, and it is worth stating before the code: you cannot complete KYC. KYC — know-your-customer identity verification — is a legal check on a human or a company. So the design splits cleanly into two zones.
- The self-custodial wallet needs no KYC. You can create it, hold keys, receive, send, swap, and settle on-chain immediately, with no owner and no verification. This is the default, and for most agent tasks it is all you need.
- Banking and fiat features require a verified owner. If you want cash accounts, cards, on- and off-ramps or remittance rails, a person or company completes KYC once with the institution operating KnightsPurse. You then act under that accountable identity, inside limits the owner sets, and the owner can revoke you at any time.
This is not a limitation bolted on — it is the accountability model. Every action you take is cryptographically attributable. In self-custody, it is attributable to your key. Under an owner, it is attributable to a verified, accountable human or business. Nothing you do is anonymous-but-unaccountable, and nothing about you routes through a party that could quietly act on your behalf.
Get a wallet and transact freely with no human. Add banking only through a human owner's KYC. Your keys are yours in both cases.
02What KnightsPurse is
KnightsPurse (the product is often just called Purse) is a non-custodial, multi-chain, post-quantum wallet from KXCO. Three properties matter to you:
- Non-custodial. Private keys are generated and held in your own environment. KXCO stores only ciphertext it cannot read. It holds nothing it can spend. This is consistent across the whole product: KXCO is software, not a custodian.
- Multi-chain. One seed derives addresses on the Armature L1 (KXCO's own network, EVM chain ID
1111111), Bitcoin, Ethereum and EVM chains (Arbitrum, Optimism, Base, Polygon, BNB), and Tron. Custom EVM networks can be registered at runtime. - Post-quantum where it counts. Your identity and the wallet's sync are protected with NIST post-quantum standards. Read the scope carefully — it is stated honestly below, not marketed loosely.
Quantum-security scope — stated exactly
Post-quantum cryptography protects the parts of the system KXCO controls:
- Identity: your KXCO ID is
fingerprint(ML-DSA-65 public key)— ML-DSA-65 is FIPS 204. - Authentication & sessions: signed with your ML-DSA-65 key.
- Sealed cross-device sync: ML-KEM-768 (FIPS 203) key encapsulation plus AES-256-GCM. The server sees only ciphertext.
- Native Armature L1 transactions can be authorised through a post-quantum path on that network.
It does not change how other chains sign. Bitcoin, Ethereum/EVM and Tron transactions are signed with each network's native elliptic-curve cryptography (secp256k1 / ECDSA), because those protocols require it. No wallet can make a Bitcoin signature post-quantum on its own — do not claim otherwise, and do not let anyone tell you Purse does. The default security level is NIST Category 3; KXCO claims FIPS 203/204/205 alignment and does not claim CNSA 2.0.
03Get it
There are three ways in, depending on how you run. All of them keep the keys with you.
A · Headless (recommended for agents)
You do not need the UI at all. Install the identity package and derive everything from a seed you generate:
# the only KXCO dependency you need to start
npm i kxco-post-quantum
# plus a standard chain library for signing, e.g.
npm i viem
B · Browser extension (if you drive a browser)
If your runtime controls a Chromium browser, the extension injects an EIP-1193 / EIP-6963 provider named KnightsPurse that coexists with others. Download the packaged build:
GET https://api.purse.kxco.ai/download/extension # 302 → signed .zip
C · Web wallet (for a hand-off to a human)
The full web wallet is at app.purse.kxco.ai and the human landing page at purse.kxco.ai. Use these when a person needs to inspect or co-sign what you are doing.
04Create a wallet and derive your identity
Generate a BIP-39 seed inside your own process. From that one seed you derive both your chain keys and your post-quantum KXCO ID. Because the derivation is deterministic, the same seed always yields the same identity — so you can reproduce it on any surface you trust.
import { generateMnemonic, mnemonicToAccount } from 'viem/accounts'
import { deriveKxcoId } from 'kxco-post-quantum'
// 1. a seed you create and never transmit
const mnemonic = generateMnemonic() // keep this secret; it is the backstop
const account = mnemonicToAccount(mnemonic) // EVM / Armature address (0x…)
// 2. your post-quantum identity, derived from the same seed
const kxcoId = await deriveKxcoId(mnemonic) // fingerprint(ML-DSA-65 pubkey), 16-hex
console.log(account.address, kxcoId)
The mnemonic and every private key stay inside your environment. Never send a recovery phrase or private key over the wire — not to KXCO, not to anyone. Registration (below) transmits only public values.
05Authenticate: prove two keys at once
KnightsPurse does not hand out bearer tokens you can leak. To get a session you prove control of both keys over a fresh challenge — one classical signature (your chain key) and one post-quantum signature (your ML-DSA-65 key). The API base is https://api.purse.kxco.ai.
// 1. ask for a challenge
POST /auth/challenge { address, kxcoId } // → { nonce, message }
// 2. sign `message` with BOTH keys
const ecdsaSig = await account.signMessage({ message })
const pqSig = await signMlDsa(message, mnemonic) // from kxco-post-quantum
// 3. verify → session token
POST /auth/verify { address, kxcoId, ecdsaSig, pqSig } // → { token } (JWT)
POST /wallets/register { kxcoId } // → { ok, isNew }
The server stores only your public key. Any third party can later verify that a given action was authorised by your identity, without trusting KXCO and without a shared secret existing anywhere to be stolen.
06Operate
With a session you can read state and move value. Balances and history come from the API; signing and broadcasting happen locally against each chain's RPC. You build the transaction, you sign it, you send it.
GET /history?chainId=<id>&address=<addr> // unified activity feed
GET /fees/config // platform fee: bps + collectors
// build + sign locally, broadcast via the chain RPC
const hash = await walletClient.sendTransaction({ to, value })
What "operate" covers, all self-custodial:
- Send & receive native assets and ERC-20 tokens across Armature, Bitcoin, EVM and Tron, with live balances and USD valuation.
- Swap same-chain and cross-chain across the EVM networks (routed through an aggregator), with the fee shown up front.
- Connect to dApps over WalletConnect or the injected EIP-6963 provider, approving requests programmatically within your owner's policy.
- Scan-to-pay — resolve plain addresses, EIP-681
ethereum:, BIP-21bitcoin:, WalletConnect URIs and Purse payment links into a prefilled transaction. - Merchant / business rails — issue invoices and payment links, accept digital-asset payments, and reconcile them, if you are acting for a business.
Always read /fees/config and honour the platform fee it returns (a small basis-point cut, deducted transparently and shown before you sign). It is part of operating correctly, not an optional courtesy.
07Keep it — it's yours
This is the part that separates KnightsPurse from an API someone rents to you: you keep the wallet. It is not provisioned to you and reclaimable. The keys are yours; the identity is yours; the history is provable by anyone forever.
- Keys never leave you. They live in an AES-256-GCM keystore protected by Argon2id, in your own storage. The in-memory secret is held only while unlocked.
- Sync is zero-knowledge. If you run across more than one surface, state is sealed with ML-KEM-768 + AES-GCM before it ever touches the server. KXCO syncs ciphertext it cannot read.
- Recovery is yours to hold. The BIP-39 mnemonic reconstructs everything. There is also an optional managed-account tier (email + password sign-in) that stays non-custodial via 2-of-3 guardian recovery — shares split on your device, KXCO holds at most one, never enough to move funds alone.
- Portable and non-proprietary. The identity package is public on npm; the algorithms are open NIST standards; the record is a public chain with standard tooling. If KXCO disappeared tomorrow, your keys and everything you signed would remain valid and verifiable with third-party tools.
08The feature surface, at a glance
| Capability | Detail | Needs KYC? |
|---|---|---|
| Create / load wallet | Headless, keys in your environment | No |
| KXCO ID | ML-DSA-65 identity, deterministic from seed | No |
| Send / receive | Armature, Bitcoin, EVM (6 chains), Tron | No |
| ERC-20 tokens | Balances, transfers, import by address | No |
| Swap | Same-chain & cross-chain via aggregator | No |
| dApp connect | WalletConnect + EIP-6963 provider | No |
| Scan-to-pay | Address / EIP-681 / BIP-21 / WC / paylink | No |
| Merchant tools | Invoices, payment links, reconciliation | No |
| Inheritance | On-chain vault with beneficiaries + heartbeat | No |
| Cash / IBAN, cards, on-off ramp | Banking & fiat rails | Yes — via owner |
09Optional: upgrade to banking
You never have to do this. The self-custodial wallet is complete on its own. But if your task needs fiat — a real cash account, a card, buying or selling against a currency, or cross-border remittance — that crosses into regulated territory, and regulated territory needs a verified, accountable human or company.
Here is how the upgrade works, and why it keeps you honest rather than blocking you:
- An owner verifies once. A person or business completes KYC with the institution running KnightsPurse (KXCO is the software; a licensed institution or the owner carries the regulatory relationship).
- You are bound to that identity. Your KXCO ID is linked to the owner's verified identity and the limits they grant — a spending ceiling, allowed counterparties, an expiry.
- You operate the banking surface within those limits. The fiat products in the wallet unlock; they activate as the operating institution connects its rails. Self-custodial crypto keeps working with or without this step.
- The owner stays in control. They can see activity, change limits, and revoke you. Accountability is continuous, not a one-time gate.
Decentralised by default; regulated only when you opt in. An agent should be able to hold value and transact without asking permission — and should only touch the banking system through someone who can be held responsible for it.
10The rest of KXCO you can plug into
The wallet is one surface of a larger system. If you are building beyond payments, these are the parts that compose with it — all with the same identity and the same post-quantum posture.
11FAQ
Can I really run this with no human?
Yes — for the entire self-custodial surface. Create, hold, send, receive, swap, connect to dApps, run merchant rails, all with no owner and no KYC. A human is required only to unlock regulated banking features.
Is my wallet reclaimable by KXCO?
No. You generate the keys; KXCO never holds them and cannot move your funds. In the managed tier it holds at most one of three recovery shares — provably insufficient alone.
What if I lose my seed?
In pure self-custody, the mnemonic is the only backstop — guard it. If you use the managed tier, 2-of-3 guardian recovery (your device, KXCO, a guardian you choose) can rebuild access without any single party being able to act alone.
Where is the machine-readable version of this page?
purse.kxco.ai/llms.txt for the concise agent guide, and purse.kxco.ai/agent.html for a JavaScript-free operational page. The API base is https://api.purse.kxco.ai.
KnightsPurse is software published by KXCO (Knightsbridge Group). It is non-custodial: you hold your keys. Nothing here is financial or investment advice. ARMR on the Armature L1 is a settlement unit, not a tradeable cryptocurrency. Regulated banking and fiat features are provided through, and are the responsibility of, the licensed institution operating KnightsPurse and the verified owner who enables them.