# Tozzecard > Your stocks, managed by an agent. Your spending, from a card you own. Built on BNB Chain. - [Introduction](https://docs.tozzecard.xyz/index.md): Your stocks, managed by an agent. Your spending, from a card you own. - [How it works](https://docs.tozzecard.xyz/overview/how-it-works.md): Two wallets, one agent, and only official contracts. - [Supported](https://docs.tozzecard.xyz/overview/supported.md): Network, tokens, stocks, devices. - [Fees and limits](https://docs.tozzecard.xyz/overview/fees-and-limits.md): What a payment, a refill and a swap cost, and the limits that apply. - [Create your card](https://docs.tozzecard.xyz/guides/create-card.md): One Face ID prompt. No seed phrase, no wallet to install. - [Activate your card](https://docs.tozzecard.xyz/guides/activate-card.md): An ID photo and a selfie. About a minute. - [Top up](https://docs.tozzecard.xyz/guides/top-up.md): Send USD1 on BNB Chain to your card address. - [Pay](https://docs.tozzecard.xyz/guides/pay.md): Face ID, USD1, and no gas. - [Set your strategy](https://docs.tozzecard.xyz/guides/strategy.md): Connect the agent, lock it to your card, and pick your split. - [Use another device](https://docs.tozzecard.xyz/guides/other-devices.md): Open the same card on your iPhone, iPad, Mac or Android phone. - [Status](https://docs.tozzecard.xyz/overview/status.md): What is live today, and what is not yet. - [FAQ](https://docs.tozzecard.xyz/overview/faq.md): Short answers to common questions. - [The card](https://docs.tozzecard.xyz/learn/card.md): A wallet made from your passkey. Nothing is stored. - [Agent wallet](https://docs.tozzecard.xyz/learn/agent-wallet.md): Your own Binance Agentic Wallet, and the address book that guards it. - [How refills work](https://docs.tozzecard.xyz/learn/refill.md): Forecast what you'll spend, and sell before the market closes. - [Weekend prices](https://docs.tozzecard.xyz/learn/weekend-prices.md): Why selling a tokenized stock on a Saturday can cost you. - [Rebalance](https://docs.tozzecard.xyz/learn/rebalance.md): Keeping your stocks at the split you chose. - [Decisions](https://docs.tozzecard.xyz/learn/decisions.md): Every choice the agent makes, with its reason. - [Trust model](https://docs.tozzecard.xyz/learn/trust-model.md): What you trust, who you trust, and what limits it. - [Risks](https://docs.tozzecard.xyz/learn/risks.md): What can go wrong, plainly. - [Architecture](https://docs.tozzecard.xyz/developers/architecture.md): The repository, the services, and how a refill moves through them. - [Run locally](https://docs.tozzecard.xyz/developers/run-locally.md): The app, the API and the docs on your machine. - [Authentication](https://docs.tozzecard.xyz/developers/authentication.md): Sign in with the card key itself: no passwords, no custody. - [Payments](https://docs.tozzecard.xyz/developers/payments.md): B402 (x402 v2) with an EIP-3009 authorization signed by the card. - [Agent API](https://docs.tozzecard.xyz/developers/agent-api.md): Read the agent's wallet, decisions and session, and ask what it would do. - [Deploy](https://docs.tozzecard.xyz/developers/deploy.md): Where each part runs, and how to run the API yourself. - [Liveness and last market poll](https://docs.tozzecard.xyz/api-reference/system/liveness-and-last-market-poll.md) - [One-time message for the card key to sign (valid 5 min)](https://docs.tozzecard.xyz/api-reference/card/one-time-message-for-the-card-key-to-sign-valid-5-min.md) - [Signed message → bearer token](https://docs.tozzecard.xyz/api-reference/card/signed-message-→-bearer-token.md) - [End the session](https://docs.tozzecard.xyz/api-reference/card/end-the-session.md) - [Identity check state, card face (null until approved), balance, agent link](https://docs.tozzecard.xyz/api-reference/card/identity-check-state-card-face-null-until-approved-balance-agent-link.md) - [Start the identity check: a Didit session → { url } to open](https://docs.tozzecard.xyz/api-reference/card/start-the-identity-check:-a-didit-session-→--to-open.md) - [Didit webhook (server to server, not for the app)](https://docs.tozzecard.xyz/api-reference/card/didit-webhook-server-to-server-not-for-the-app.md): Checks X-Signature (HMAC-SHA256 of the raw body with the webhook secret) and X-Timestamp (±5 min). On Approved, reads the document from Didit's decision endpoint and issues the card. - [Card statement: B402 payments and agent refills, newest first](https://docs.tozzecard.xyz/api-reference/card/card-statement:-b402-payments-and-agent-refills-newest-first.md) - [The agent's target weights and weekly spend estimate](https://docs.tozzecard.xyz/api-reference/agent/the-agents-target-weights-and-weekly-spend-estimate.md) - [Set the strategy (onboarding step 4). Only the agent's card](https://docs.tozzecard.xyz/api-reference/agent/set-the-strategy-onboarding-step-4-only-the-agents-card.md): Tokens by symbol (from /market) or address. Weights in (0, 1], summing to 1, max 10 tokens. The scheduler uses it from its next tick; in live mode a drift over 5% rebalances on the next market day. - [Agent wallet holdings vs targets, with market data, plus the card's USD1](https://docs.tozzecard.xyz/api-reference/agent/agent-wallet-holdings-vs-targets-with-market-data-plus-the-cards-usd1.md): Exists only when the server runs with AGENT_MODE=dry|live (404 otherwise). 502 with code SESSION_EXPIRED / NOT_LOGGED_IN means the Agentic Wallet needs a sign-in in the Binance App. Runs baw: a few seconds per call. - [Agent feed (decision log), newest first](https://docs.tozzecard.xyz/api-reference/agent/agent-feed-decision-log-newest-first.md): Exists only when the server runs with AGENT_MODE=dry|live (404 otherwise). 502 with code SESSION_EXPIRED / NOT_LOGGED_IN means the Agentic Wallet needs a sign-in in the Binance App. - [Agentic Wallet session: connected, Developer Mode, expiry, daily quota](https://docs.tozzecard.xyz/api-reference/agent/agentic-wallet-session:-connected-developer-mode-expiry-daily-quota.md): Exists only when the server runs with AGENT_MODE=dry|live (404 otherwise). 502 with code SESSION_EXPIRED / NOT_LOGGED_IN means the Agentic Wallet needs a sign-in in the Binance App. - [What the agent would decide at a given time (demo time travel, never trades)](https://docs.tozzecard.xyz/api-reference/agent/what-the-agent-would-decide-at-a-given-time-demo-time-travel-never-trades.md): Exists only when the server runs with AGENT_MODE=dry|live (404 otherwise). 502 with code SESSION_EXPIRED / NOT_LOGGED_IN means the Agentic Wallet needs a sign-in in the Binance App. - [Every tokenized stock: status, on-chain price, close reference, spread](https://docs.tozzecard.xyz/api-reference/market/every-tokenized-stock:-status-on-chain-price-close-reference-spread.md) - [One token (SPYon is the market clock)](https://docs.tozzecard.xyz/api-reference/market/one-token-spyon-is-the-market-clock.md) - [Create an order (demo merchant)](https://docs.tozzecard.xyz/api-reference/merchant/create-an-order-demo-merchant.md): Exists only when MERCHANT_PAY_TO is set (B402 approved). - [Order status](https://docs.tozzecard.xyz/api-reference/merchant/order-status.md) - [Payment requirements (402) for an open order](https://docs.tozzecard.xyz/api-reference/merchant/payment-requirements-402-for-an-open-order.md) - [Pay with a signed EIP-3009 authorization](https://docs.tozzecard.xyz/api-reference/merchant/pay-with-a-signed-eip-3009-authorization.md) - [Contracts and tokens](https://docs.tozzecard.xyz/resources/contracts.md): Every on-chain address Tozzecard touches. None of them is ours. - [Parameters](https://docs.tozzecard.xyz/resources/parameters.md): Every number the agent uses, and where it lives in the code. - [Glossary](https://docs.tozzecard.xyz/resources/glossary.md): The words these docs use. ## OpenAPI Specs - [openapi](https://api.tozzecard.xyz/openapi.json) This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.