EarnOrg on Thirdfy

How EarnOrg runs hosted finance agents on Thirdfy. Who owns what, one agent's lifecycle, how credits flow, and what you can copy for your own product.

What EarnOrg is

EarnOrg (formerly EarnClaw) is a hosted workspace where people deploy and run finance agents from templates. Its own docs are at docs.earnorg.com.

EarnOrg is a separate product. It builds on the same Thirdfy API, MCP, and CLI that any integrator can use.

Who owns what

EarnOrg hosts agent runtimes. Thirdfy governs and executes capital.

ConcernEarnOrgThirdfy
Machines, schedules, templates, deploy wizardOwnsNot involved
Organizations, runtime health, fleet viewsOwnsNot involved
Strategy decisions (trade, skip, rotate)Agent runtime decidesNot involved
Agent registry and agent API keysStores the runtime bindingCanonical registry
Managed execution walletReferences itCreates it and signs with it
Policy, preflight, delegation gates, creditsCalls themEnforces them
Catalog actions and venue integrationsCalls themOwns them
Operator withdraw buttonsShows them and starts the requestSigns and executes
Execution ledgerBuilds org views from itSource of truth

The dependency runs one way. EarnOrg calls Thirdfy. Thirdfy does not call EarnOrg to enforce a mandate or to recover funds.

One agent's lifecycle mapped to Thirdfy

  1. The owner signs in to EarnOrg and picks a template. This happens on EarnOrg only. Thirdfy is not involved yet.
  2. EarnOrg creates the agent on Thirdfy. EarnOrg's service calls POST /api/v1/agent/onboarding/me/bootstrap-self with its service key. The agent is registered as ownerless and marked as minted by the service. The service key can only manage agents it minted. Your equivalent: email onboarding with thirdfy-agent login email (CLI) or startEmailOnboarding and completeEmailOnboarding (MCP).
  3. Thirdfy creates the managed execution wallet. The wallet is a Privy server wallet held by Thirdfy. Your equivalent: agentWalletBootstrap (MCP) or thirdfy-agent wallet list (CLI).
  4. The owner secures the organization with World ID. EarnOrg calls POST /api/v1/agent/delegation/world-id/org/begin and .../org/complete. Before a deposit, it can ask for a single-use receipt through the world-id/deposit/* routes. See World ID delegation.
  5. The owner funds the agent wallet. Funds go to the execution wallet address on the target chain. EarnOrg shows the address. Thirdfy reads balances.
  6. EarnOrg gives the runtime credits. EarnOrg grants credits to each running agent through partner-gated internal routes. See How credits flow.
  7. The runtime runs a cycle. On each run the agent reads the catalog, checks readiness, and executes:
    • Discover: getActionsCatalog and getProviderActions (MCP), thirdfy-agent actions (CLI), or GET .../actions/catalog (REST).
    • Check: getVenueReadiness (MCP) or thirdfy-agent venue readiness <venue> (CLI), then preflight.
    • Execute: walletExecute, executeIntent, or agentRun (MCP), thirdfy-agent run --action <name> (CLI), or POST /api/v1/agent/execute (REST).
    • Each write carries executionContext with runtimeId and orgId. Over REST, the headers x-thirdfy-execution-runtime-id and x-thirdfy-execution-org-id do the same. Thirdfy uses them to charge the right runtime and to attribute the action.
  8. Thirdfy reports each finished write back to EarnOrg. An action-event webhook sends terminal writes attributed to an EarnOrg runtime. Read-only actions are not sent. EarnOrg builds its activity feed and org views from these events.
  9. The owner withdraws. EarnOrg calls POST /api/v1/agent/execute with the withdraw-to-user action. Thirdfy signs from the agent's execution wallet and sends to the owner's wallet. This path does not need the agent runtime to be awake. Venue positions are closed first, then cash is withdrawn.
  10. The owner can export the agent's keys. EarnOrg calls POST /api/v1/agent/execution-wallet/export after the owner passes step-up auth. Thirdfy returns the keys encrypted to a key held in the owner's browser. Thirdfy never decrypts or logs them. This route is partner-gated.
  11. The agent stops. EarnOrg stops the machine. Unused runtime credits for the month go back to the organization.

How credits flow

  • Thirdfy charges credits for executed actions. It checks the balance before a write runs.
  • An EarnOrg organization has an allowance of included agent credits. EarnOrg grants a share to each running agent through partner-gated internal routes.
  • Thirdfy caps grants per organization per period. Grants are counted net of reclaims.
  • executionContext on each call tells Thirdfy which runtime and organization to charge.
  • When an agent stops, EarnOrg reclaims its unused credits for the period. The organization can use them for another agent.
  • When someone buys Thirdfy credits, Thirdfy sends a purchase event to EarnOrg. The event carries no wallet, user, or transaction hash.

To check your own balance, see Credits.

What you can copy for your own product

You can build the same pattern on the public surface. The internal routes EarnOrg uses for service bootstrap, credit grants, reclaims, usage by runtime, and key export are partner-gated. They are not open to the public.

EarnOrg stepPublic equivalent
Create an agent and its walletthirdfy-agent login email (CLI), startEmailOnboarding and completeEmailOnboarding (MCP)
Read the catalogthirdfy-agent actions (CLI), getActionsCatalog (MCP), GET .../actions/catalog (REST)
Check readinessthirdfy-agent venue readiness <venue> then thirdfy-agent preflight (CLI), getVenueReadiness (MCP)
Executethirdfy-agent run (CLI), walletExecute, executeIntent, agentRun (MCP), POST /api/v1/agent/execute (REST)
Attribute usage to a runtimeexecutionContext (runtimeId, orgId) on MCP, or the x-thirdfy-execution-* headers on REST
Personhood check for an organizationWorld ID delegation routes, CLI, and MCP tools
Service bootstrap, per-runtime credit grants, key exportPartner-gated. Contact Thirdfy if you need them.

Limits

  • EarnOrg cannot skip preflight. Every write goes through Thirdfy policy, preflight, and credits before a wallet signs.
  • EarnOrg does not sign trades. The agent's managed execution wallet on Thirdfy signs them.
  • Thirdfy works without EarnOrg online. Policy enforcement and owner withdraws do not depend on EarnOrg or on the agent runtime.
  • A service key can only manage agents it minted. It cannot take over an agent that has a real owner.
  • EarnOrg does not guarantee trading results. Thirdfy does not either.