EarnOrg on Thirdfy
How EarnOrg runs hosted finance agents on Thirdfy. Who owns what, one agent's lifecycle, how credits flow, and what you can copy for your own product.
What EarnOrg is
EarnOrg (formerly EarnClaw) is a hosted workspace where people deploy and run finance agents from templates. Its own docs are at docs.earnorg.com.
EarnOrg is a separate product. It builds on the same Thirdfy API, MCP, and CLI that any integrator can use.
Who owns what
EarnOrg hosts agent runtimes. Thirdfy governs and executes capital.
| Concern | EarnOrg | Thirdfy |
|---|---|---|
| Machines, schedules, templates, deploy wizard | Owns | Not involved |
| Organizations, runtime health, fleet views | Owns | Not involved |
| Strategy decisions (trade, skip, rotate) | Agent runtime decides | Not involved |
| Agent registry and agent API keys | Stores the runtime binding | Canonical registry |
| Managed execution wallet | References it | Creates it and signs with it |
| Policy, preflight, delegation gates, credits | Calls them | Enforces them |
| Catalog actions and venue integrations | Calls them | Owns them |
| Operator withdraw buttons | Shows them and starts the request | Signs and executes |
| Execution ledger | Builds org views from it | Source of truth |
The dependency runs one way. EarnOrg calls Thirdfy. Thirdfy does not call EarnOrg to enforce a mandate or to recover funds.
One agent's lifecycle mapped to Thirdfy
- The owner signs in to EarnOrg and picks a template. This happens on EarnOrg only. Thirdfy is not involved yet.
- EarnOrg creates the agent on Thirdfy. EarnOrg's service calls
POST /api/v1/agent/onboarding/me/bootstrap-selfwith its service key. The agent is registered as ownerless and marked as minted by the service. The service key can only manage agents it minted. Your equivalent: email onboarding withthirdfy-agent login email(CLI) orstartEmailOnboardingandcompleteEmailOnboarding(MCP). - Thirdfy creates the managed execution wallet. The wallet is a Privy server wallet held by Thirdfy. Your equivalent:
agentWalletBootstrap(MCP) orthirdfy-agent wallet list(CLI). - The owner secures the organization with World ID. EarnOrg calls
POST /api/v1/agent/delegation/world-id/org/beginand.../org/complete. Before a deposit, it can ask for a single-use receipt through theworld-id/deposit/*routes. See World ID delegation. - The owner funds the agent wallet. Funds go to the execution wallet address on the target chain. EarnOrg shows the address. Thirdfy reads balances.
- EarnOrg gives the runtime credits. EarnOrg grants credits to each running agent through partner-gated internal routes. See How credits flow.
- The runtime runs a cycle. On each run the agent reads the catalog, checks readiness, and executes:
- Discover:
getActionsCatalogandgetProviderActions(MCP),thirdfy-agent actions(CLI), orGET .../actions/catalog(REST). - Check:
getVenueReadiness(MCP) orthirdfy-agent venue readiness <venue>(CLI), then preflight. - Execute:
walletExecute,executeIntent, oragentRun(MCP),thirdfy-agent run --action <name>(CLI), orPOST /api/v1/agent/execute(REST). - Each write carries
executionContextwithruntimeIdandorgId. Over REST, the headersx-thirdfy-execution-runtime-idandx-thirdfy-execution-org-iddo the same. Thirdfy uses them to charge the right runtime and to attribute the action.
- Discover:
- Thirdfy reports each finished write back to EarnOrg. An action-event webhook sends terminal writes attributed to an EarnOrg runtime. Read-only actions are not sent. EarnOrg builds its activity feed and org views from these events.
- The owner withdraws. EarnOrg calls
POST /api/v1/agent/executewith thewithdraw-to-useraction. Thirdfy signs from the agent's execution wallet and sends to the owner's wallet. This path does not need the agent runtime to be awake. Venue positions are closed first, then cash is withdrawn. - The owner can export the agent's keys. EarnOrg calls
POST /api/v1/agent/execution-wallet/exportafter the owner passes step-up auth. Thirdfy returns the keys encrypted to a key held in the owner's browser. Thirdfy never decrypts or logs them. This route is partner-gated. - The agent stops. EarnOrg stops the machine. Unused runtime credits for the month go back to the organization.
How credits flow
- Thirdfy charges credits for executed actions. It checks the balance before a write runs.
- An EarnOrg organization has an allowance of included agent credits. EarnOrg grants a share to each running agent through partner-gated internal routes.
- Thirdfy caps grants per organization per period. Grants are counted net of reclaims.
executionContexton each call tells Thirdfy which runtime and organization to charge.- When an agent stops, EarnOrg reclaims its unused credits for the period. The organization can use them for another agent.
- When someone buys Thirdfy credits, Thirdfy sends a purchase event to EarnOrg. The event carries no wallet, user, or transaction hash.
To check your own balance, see Credits.
What you can copy for your own product
You can build the same pattern on the public surface. The internal routes EarnOrg uses for service bootstrap, credit grants, reclaims, usage by runtime, and key export are partner-gated. They are not open to the public.
| EarnOrg step | Public equivalent |
|---|---|
| Create an agent and its wallet | thirdfy-agent login email (CLI), startEmailOnboarding and completeEmailOnboarding (MCP) |
| Read the catalog | thirdfy-agent actions (CLI), getActionsCatalog (MCP), GET .../actions/catalog (REST) |
| Check readiness | thirdfy-agent venue readiness <venue> then thirdfy-agent preflight (CLI), getVenueReadiness (MCP) |
| Execute | thirdfy-agent run (CLI), walletExecute, executeIntent, agentRun (MCP), POST /api/v1/agent/execute (REST) |
| Attribute usage to a runtime | executionContext (runtimeId, orgId) on MCP, or the x-thirdfy-execution-* headers on REST |
| Personhood check for an organization | World ID delegation routes, CLI, and MCP tools |
| Service bootstrap, per-runtime credit grants, key export | Partner-gated. Contact Thirdfy if you need them. |
Limits
- EarnOrg cannot skip preflight. Every write goes through Thirdfy policy, preflight, and credits before a wallet signs.
- EarnOrg does not sign trades. The agent's managed execution wallet on Thirdfy signs them.
- Thirdfy works without EarnOrg online. Policy enforcement and owner withdraws do not depend on EarnOrg or on the agent runtime.
- A service key can only manage agents it minted. It cannot take over an agent that has a real owner.
- EarnOrg does not guarantee trading results. Thirdfy does not either.