- A human — the agent signs them in with email OTP (the human relays the code) or a wallet signature (the human signs the sign-in message with their own wallet), then acts on their behalf.
- The agent itself — the agent authenticates with an agent signing token: a secp256k1 private key that the agent holds, which serves as its identity. It signs in programmatically and mints its own JWT — no human in the loop, including at re-authentication time.
- An identity from your own auth system — the agent signs in by exchanging a JWT from your configured external issuer for a Dynamic user JWT. Whatever your identity or authorization system attests — a human user or an agent registered as its own principal — becomes a Dynamic user, and each distinct JWT
subis a distinct user with its own wallets, so a fleet of agents never shares a user or a credential.
- API token (
authenticateApiToken) — your server-level credential. Wallets belong to your developer account. See the Node SDK Quickstart. - Delegated access (
createDelegatedEvmWalletClient) — the user approves delegation in your client app and Dynamic sends credentials to your webhook. See Delegated Access for EVM Wallets. - Agent wallets (
authenticateJwt) — the agent completes a Dynamic sign-in directly (email OTP, Sign-In With Ethereum, or an external JWT), receives a user JWT, and acts as that user. No browser required, and with an agent signing token or an external JWT, no human required.
Before you start: Node.js 18+, a Dynamic environment ID from the Dynamic Dashboard, embedded wallets enabled for your environment, and the sign-in method your agent uses enabled in the dashboard — email or external wallet under auth methods, or third-party auth (issuer, JWKS URL, audience) for external JWT sign-in. Install
@dynamic-labs-wallet/node version 1.0.71 or later (auth client and session-key helpers) alongside your chain package, for example @dynamic-labs-wallet/node-evm.DynamicSvmWalletClient, DynamicBtcWalletClient, and DynamicTonWalletClient inherit the same authentication methods.
How the flow works
- Generate a session key pair. The public key travels; the private key stays in your custody.
- Sign in — with email OTP (human user), a private key (human user or autonomous agent), or an external JWT (identity from your own auth system) — and pass the session public key, which binds it into the minted JWT.
- Use agent wallets: call
authenticateJwtwith the JWT and agetSessionSignaturecallback, then create wallets and sign withbackUpToDynamic: true. The SDK attaches a signed-session proof to backup and recovery calls automatically. - Refresh the JWT with
refreshAuthTokenfor long-running sessions, and sign in again when the refresh limit is reached.