Live on Coston2 testnet

An XRP account that only does what you allow.

The key is generated inside a secure enclave and never leaves. It can only ever sign what your on-chain rules permit — so steal the key, hijack the app, poison the address, and it still can’t be drained.

No extension. No custodian. Built on Flare + the XRP Ledger.

keyless.app/account
Exchange savings
Exchange-only🔒 locked
Deposit addressBalance
rw15KUmE…wVDMC50,000 XRP
What this account can & can’t do
✓Pay your exchange✕Send anywhere else✓Up to 5,000 XRP each✕Be drained — even if your key is stolen
Try to break it — someone with the key sends it elsewhere
rF3x9…Att4cker
5,000
Pay
✗Refused — recipient not allowed. The enclave was never asked to sign. Nothing left the account.
Built onFlare Confidential ComputeThe XRP LedgerNo bridge. No wrapped token. Real XRP.

One account, many jobs

Pick the rule your account obeys.

Every account is an XRP wallet whose key can only sign what its rule permits. Choose one when you create it — change it anytime, or lock it forever.

Exchange & allowlist

Pay only the addresses you approve.

Protects against: A stolen key can't send anywhere you didn't approve.

Spending limit

Cap how much can leave — per window or as a fixed budget.

Protects against: Nothing can exceed the cap — not a hijacked bot, not a stolen key.

Scheduled payments

A fixed amount, to a fixed payee, on a fixed date. Nothing early, nothing extra.

Protects against: Whoever triggers it can only run your schedule on time — never early, never more.

Conditional

Pay only once something in the real world is proven true.

Protects against: Funds stay locked until the world proves it — no early release, no wrong payee.

FXRP on Flare

Move XRP to Flare, earn yield, and bring it home — locked to your account.

Protects against: Every step lands in your own account — never a thief's.

How it works

Live in three steps.

1

Create an account

One click. The XRP key is generated inside a secure enclave — no seed phrase, no extension, and no human ever sees it.

2

Pick a rule

Exchange-only, an agent allowance, a standing order, a payout that waits on a proven fact. The rule is the account's entire security surface.

3

It can't be drained

The key can only ever sign what the rule allows. Lock the rule and not even your own control key can change it.

Conditional payments

…and it can wait on the real world.

Lock a payment to something that has to be true first — a shipment marked delivered, a milestone closed, a price reached. Flare’s Data Connector proves it on-chain, and only then can the money move. XRP’s own escrow can do timeouts and hashlocks; it can’t do this.

Neither side can jump the queue: the payee can’t be paid before it’s proven, and the payer can’t pull the funds back before the deadline. If it never happens, they return.

Supplier paymentwaiting on proof
PayrSupplier…8fK2 · up to 100 XRP
Only whenthe courier API says delivered
✕Pay the supplier now — refused, condition not proven yet.
✕Take it back early— refused, the deadline hasn’t passed.

enclave holds the key · Flare’s validators prove the world · XRPL settles

Don’t take our word for it.

Try to make a live rule pay a thief. The verdict comes straight from the real contract on Coston2 — no wallet, no signup.

Why it can't be drained

The security isn't a promise. It's the architecture.

The key never leaves the enclave

It's generated inside a TEE on Flare and can't be exported — so there's nothing to phish, leak, or steal. You receive to it like any XRP account; you spend only through the rule.

The rules live on-chain

Every payment runs the rule first, enforced by a contract, not a server. If the rule says no, the enclave is never even asked to sign.

Lock it and it's final

Freeze an account's rule forever. After that, not even your own control key can repoint it or widen it — a thief who steals everything still can't move your funds.

05Where this goes

Three things XRP couldn't do yesterday.

A new capability is one new rule contract — the key, the enclave, and the account never change. Because the rules live on Flare, they can depend on things the XRP Ledger cannot see. Same wallet, new brain.

Payments that react to the world

XRPL escrow does time-locks and hash-locks — nothing else. A rule on Flare can gate a payment on an FTSO price or an FDC-attested real-world event: pay the supplier when delivery is proven, release when a price is hit.

Wallets for AI agents

Give an autonomous agent an XRP account it can spend from but can never drain — an allowlist and a cap it cannot exceed, even prompt-injected or hijacked. The wallet the coming agent economy needs, on the ledger the assets already live on.

DAO-controlled XRP

A DAO on Flare votes; native XRP moves on XRPL. No wrapped asset, no bridge, no custodian — the treasury stays real XRP, and a contract decides what it can pay.

Why it stays this cheap to extend

The enclave is a keyring: it signs whatever payment a wallet’s rule authorizes, and nothing else. So a new product isn’t a new TEE workload — it’s one Solidity contract a wallet can point at. The hard part (a key that can only ever obey a contract, on a chain with no contracts) is already built and running.

1

The account is fixed

One key per wallet, born in the enclave, bound to Flare’s TEE. It never leaves and never changes.

2

The rules are open

Anyone can write a rule module. It governs only its own wallet, so a bad rule is self-harm — never someone else’s funds.

3

Composition is the moat

Conditions come from Flare — FTSO, FDC — and settle as native XRP on XRPL. Nobody else can do that without moving the asset off its ledger.

Stated plainly: the three above are roadmap, not shipped. What is shipped — the account, the keyring, the rule engine, a real payment that refused to be redirected — is live on Coston2 and checkable above.

An XRP account that can’t be drained.

The rules aren’t for you. They’re for whoever gets in.