When you add a recipient you can create a USDC wallet on the spot instead of pasting one in. The wallet is created by Coinbase, secured by Coinbase, and controlled by your workspace. Fiatswaps cannot move the money in it.
1. Who creates the wallet
Coinbase does, through its Developer Platform embedded wallets. Fiatswaps asks Coinbase for a new address and records which recipient it belongs to. The private key is generated and held inside Coinbase's infrastructure — it is never sent to Fiatswaps, and no one here ever sees it.
The address works like any other Base address. It starts with 0x, it receives
USDC on Base, and it can be used in any wallet app once you export it.
2. Who can move the money
Only someone who can read the email address the wallet was created under — the workspace owner's email.
Moving funds out of the wallet needs a signature, and Coinbase only produces one for someone who has proved they control that inbox. That is why exporting asks for a code by email even though you are already signed in to Fiatswaps — the two logins are unrelated, and only the Coinbase one can release a key.
Two things follow from this:
- Fiatswaps cannot spend from the wallet. Our credentials can create a wallet and read its address. They cannot authorise a single transaction.
- Nor can the recipient. The wallet belongs to your workspace, not to them. They do not receive a login, and they are not emailed about it.
The Coinbase code, and how often you will see it
The first time you download a key in a given browser, Coinbase emails you a code. This is a separate login from your Fiatswaps one, and it is the whole reason we can say we do not hold your keys: Coinbase releases a key only to someone who has just proved they can open that inbox, and we cannot do that.
Once you have entered it, the browser stays signed in and later downloads are a single click. You will be asked again on:
- a different browser, or a different computer or phone
- a private or incognito window
- the same browser after you clear its site data
Coinbase does not publish how long a session lasts, so we will not promise it never expires. In normal use you should expect to enter a code once per browser, not once per wallet.
3. What Fiatswaps can and cannot do
| Fiatswaps can | Fiatswaps cannot |
|---|---|
| Create a wallet for a recipient | See the private key |
| Show you the address | Sign a transaction |
| Show it to you again later | Move, hold or freeze the funds |
| Send USDC payouts to the address | Recover the wallet if you lose the key and your email |
4. Take the wallet with you at any time
Open the recipient, go to the Wallet tab, and choose Download the key. Your browser saves a small text file containing the key.
You can also download it straight from the confirmation shown when the wallet is created — it is the same button and the same file.
If this browser has never signed in to Coinbase, it asks for a code first, once. See the section above for when that happens. After that, downloading is a single click, on any recipient.
The key never touches a Fiatswaps server. Coinbase releases it to your browser and your browser writes the file — which is why we can say we do not see it.
Open the file and paste the key into MetaMask, Rabby, or any other wallet that supports Base, using Import account → Private key. It is a private key, not a twelve-word phrase, and there is no way to convert one into the other.
You can download it as often as you like. The key never changes, so there is nothing to write down the first time.
Then move the file somewhere private. A password manager is a good home for it; a downloads folder is not.
Anyone holding that key can spend the funds. Treat it like the money itself: do not email it, paste it into a chat, or keep it in a shared document.
5. If you stop using Fiatswaps
The wallet is not tied to your account here. Export the key before you leave and the wallet keeps working exactly as it did — same address, same funds, now in whatever app you imported it into. Nothing needs to be moved.