Agent approvals and wallet permissions on Hyperliquid

Public wallet research needs only an address. Copy-account setup can require separate ownership, agent and builder-fee approvals. In WalletFollow’s approved connection flow, the wallet signs sign-in ownership proof, approval of the engine-reported agent and approval of the pinned builder fee, with a maximum of 0.05%.

Understand which permission is being requested

A sign-in message proves control of an address for an application session. It is different from authorizing an agent to act at the venue. Builder-fee approval establishes a permitted fee for a specified builder address; it is not itself an order. Read the domain, account, agent address and fee details presented in the wallet before confirming.

A public profile, educational article or AI report should not require any of these signatures. If you only intend to research a wallet, do not treat a trading approval as a necessary reading step.

The engine and the platform have different roles

The registered copy engine generates and holds its agent keys and performs permitted execution. WalletFollow’s platform servers do not hold your wallet private key or agent private key and do not sign venue orders. The browser’s supported approval flow submits the permitted approval actions directly to Hyperliquid.

This separation does not remove trading risk. An authorized execution agent still has meaningful authority, so verify that it is the agent assigned to your account by the registered engine rather than an address copied from an unofficial message.

Keep key types separate

A Data API key permits access to WalletFollow’s metered read-only data service. A Hyperliquid agent wallet is a venue signing identity. The two are not substitutes. An AI assistant researching public data should receive only the intended data-access capability through a secure integration, not a wallet seed phrase or trading agent key.

To query a Hyperliquid account’s public information, use the actual main or subaccount address. The agent address can yield an empty account view because its role is to sign for another account.

Review revocation and current status

Know where to inspect and revoke venue approvals. Revoking authority can prevent future permitted actions, but it does not automatically close existing positions. Review open exposure and the subscription’s effective state as separate tasks. Never sign a transfer, withdrawal or invoice-payment action merely because it appears in a WalletFollow-branded research workflow.

  • Check the sign-in domain and message.
  • Check the exact engine-reported agent.
  • Check the pinned builder and fee ceiling.
  • Keep seed phrases and private keys out of the platform.

Sources and further reading