> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useotto.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Accounts & permissions

> Know where your funds are, who can sign and what an Otto permission allows.

Open [Delegation](https://useotto.xyz/app/delegate) to review or stop Otto's permission. Use your usual email address to open your Otto account; Coinbase provides the wallet and sign-in technology behind the scenes. Signing in and granting permission are separate choices, and neither moves funds.

Otto's accounts have separate balances. Connecting another wallet or opening a different dashboard does not transfer assets between them.

## Which account am I using?

| Account                                      | Used for                                                                   | Who signs                                                                                                                              |
| -------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
| **Connected wallet**                         | Stocks trades and wallet-mode swaps                                        | You review and sign in your wallet                                                                                                     |
| **Otto wallet on Base, powered by Coinbase** | [Mission Control](https://useotto.xyz/app) and supported delegated actions | Otto can execute supported actions under an active permission; an outgoing Base-USDC transfer requires your Coinbase account signature |
| **Earlier trading Safe**                     | Legacy tools and Otto-mode workflows, including funded DCA schedules       | Otto signs under that Safe's configured authority; ownership varies by account                                                         |
| **Earlier Otto Wallet funding Safe**         | The separate legacy funding account                                        | Your connected wallet owns it, but its standard owner-signed in-app withdrawal is unavailable                                          |

Fund only the address and network the action identifies. A DCA schedule starts after it is funded; its Safe balance is separate from the Coinbase account.

## Read your balances correctly

Mission Control shows available Base USDC and ETH for fees in your signed-in Otto wallet. Its holdings panel separately shows supported Base stock tokens and Morpho vault positions; vault values are not included in available USDC. Other tokens, connected wallets and legacy balances are outside that panel's coverage. An unavailable balance is not zero. Account activity is your account's record; public platform activity is not your personal transaction history.

[Stocks holdings](/using-otto-ai/stocks) describes supported assets in the connected wallet. Earlier Portfolio Co-Pilot views cover their own legacy accounts, not all of your Otto balances. Their yield suggestions are display-only.

## What a permission allows

An active permission lets Otto sign supported actions from your Otto wallet without asking for a new account signature each time. It covers **USDC swaps through LI.FI on Base** and **supported Morpho USDC vault deposits and withdrawals on Base**. It does not start an investment strategy. Yield Copilot still asks you to review the selected vault, amount, expected output and fees before confirming an action.

Vault withdrawals approve the exact supported vault's share token to LI.FI for redemption, with USDC returned to the same Otto wallet. A public MCP connection does not activate your account's permission or give another agent access to it.

### Who enforces each limit

| Limit                                              | Enforcement                                                                                                                                                        |
| -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Your chosen cap: $1–$5,000 per swap or deposit** | Otto's server records it against your permission and checks each supported USDC swap or vault deposit. It does not apply to vault withdrawals.                     |
| **Shared \$5,000 USDC limit**                      | Coinbase's engine applies the same limit across users to each permitted USDC approval or sign-only transfer. It does not enforce the lower cap you choose in Otto. |
| **Vault-share limit**                              | Coinbase's engine has a separate limit measured in shares. Otto also checks the exact supported vault, share quantity and withdrawal destination.                  |

**These are not cumulative spending budgets or maximum-loss limits.** Repeated actions can use more than your per-action cap. An approval limit also does not describe the value of a whole sequence of transactions.

If Otto cannot confirm that your chosen cap was recorded for the current permission, it refuses to use that permission. Read the status card before relying on a new or replacement permission. A permission created or changed directly through Coinbase, outside Otto's setup or command-line flow, is outside Otto's personal-cap workflow.

### Where funds can go

Coinbase's engine restricts the permitted contract calls, but it does **not** bind the output recipient of LI.FI routes. Its sign-only USDC transfer rule also has no recipient or network condition. Otto's server checks the destination of supported swaps and vault withdrawals.

For an external transfer, Otto and the browser verify the reviewed Base network, destination, exact amount, Coinbase account identity and signature before submission. These are Otto's integration checks, not guarantees made by Coinbase's engine. **A compromised Otto server could redirect funds within the engine's limits.** See [What has been audited?](/safety-and-security/security-and-audits) for the distinction between provider security material and an audit of Otto.

### Expiry, replacement and stopping

Choose a duration from **1 to 180 days**; the default is 90 days. The status card shows the exact expiry that was recorded. Granting a new permission replaces the previous one, so review its cap and expiry again before confirming.

You can stop permission before expiry. Treat it as active until revocation is confirmed. Revocation prevents future use; it does not undo a submitted transaction or cancel a signature already created. Signing out is not revocation.

## Funding and moving funds

Only fund an action that is available to your account. Copy the verified address shown in Mission Control or Delegation and send **native USDC on Base**, with **ETH on Base** for network fees. A connected-wallet balance or a card deposit into an earlier Safe does not fund this Otto wallet. Wait for the balance to be read before reviewing an action.

These are three separate actions:

1. **Stop permission** prevents future authorized use once confirmed.
2. **Redeem or sell a position** returns assets to the account holding it.
3. **Transfer assets** moves the available balance to another address.

Resolve pending or unknown activity before transferring out. See [Moving funds out](/account-and-settings/removing-funds) for the required order and recovery controls.

## If an action has no confirmed result

A timeout or missing answer does not prove that nothing happened. The transaction may have been submitted. Return to the same signed-in account and use its saved activity or transfer record to check receipts and the current status before starting another action. A transaction hash alone is not final confirmation.

If permission status cannot be read, refresh it; do not assume permission has ended. If revocation is unconfirmed, treat it as still active. For a prepared or submitted transfer, use the specific recovery action shown in [Moving funds out](/account-and-settings/removing-funds#if-signing-or-confirmation-is-interrupted), rather than creating a replacement transfer. Contact [support](/support-and-feedback/getting-help) with the public transaction hash or reference if recovery cannot resolve it.

## Earlier Safe ownership

An account named “Otto Safe” is not enough to establish ownership:

* Earlier **operator-owned trading Safes** give Otto's execution key owner authority. Your connected wallet identity does not make you an owner; exits rely on the service's withdrawal path.
* **User-owned Safes with delegated execution** can still give Otto broad authority over deposited funds. Check the installed permission, expiry and revocation controls.

Verify the exact chain, address, owners and operator authority before funding an earlier Safe. Its funding account and trading account are not interchangeable. If you cannot establish these details, contact [support](/support-and-feedback/getting-help) with the public address.

## Accounts used by other agents

MCP transaction tools return unsigned plans for your signer. Paying for an API call grants only that payment's authority; it does not grant trading access to every account.

[Hyperliquid](/acp-swarm/hyperliquid), [Prediction Markets](/acp-swarm/prediction-markets) and [Otto X](/acp-swarm/otto-x) use separate service accounts and withdrawal procedures. Check the relevant guide before funding them.
