If software is going to spend your money, two questions have to be answerable before it does: which software is this, and what is it allowed to spend? Those are different questions and they need different answers.
An API key says a request is authorised. It does not say who the agent is to the merchant on the other side, and it carries no limit of its own.
Cloudflare describes Account Wallets as designed for humans who are owners and users of Cloudflare accounts. Virtual Wallets are designed for agents, operate via API keys, and are capped by the Account Wallet owner.
An allowance, an allow list and a maximum transaction size. All three are set by the human who owns the account, which is what makes delegating spend to software survivable.
The address a merchant sees needs to mean something to a person reading a statement later. That is the job a name does, and it is the reason a payment namespace opened for agents at all.
The way a merchant, a protocol or an auditor can tell which piece of software is making a payment, who owns it, and what it has been permitted to spend. It is a separate problem from authentication — a key proves a request is allowed, not who is behind it.
Cloudflare’s Virtual Wallets are capped by the Account Wallet owner with three controls: an allowance, an allow list of approved destinations, and a maximum transaction size. All three are set by the human who owns the account.
Cloudflare describes Account Wallets as designed for humans who are owners and users of Cloudflare accounts — they add funds, delegate spend to virtual wallets managed by agents, and remove funds. Virtual Wallets are designed for agents and operate via API keys.
Because somebody eventually reads the statement. An address is unusable by a person — a Solana address is forty-four case-sensitive characters — and an agent’s spending is exactly the kind of thing a human has to be able to review.