Overview
This guide explains how to connect your Coinbase Prime portfolio to Coinbase Token Manager so Token Manager can:
Read balances in a designated Prime wallet
Propose transfers and payouts to approved external addresses
Respect your consensus, transfer policies, and Trusted Address Book configuration in Prime
Prerequisites
Before you begin, make sure:
You have an active Coinbase Prime account and portfolio.
The token/asset you plan to distribute via Coinbase Token Manager is supported by Coinbase Prime (see the supported assets and trading pairs list).
Your Prime account has:
Appropriate user roles and consensus policies configured (Admins / Signers).
At least one portfolio that will fund Token Manager payouts.
Set up API keys in your Coinbase Prime account
Overview
This article explains how to create and share a Coinbase Prime API key so Coinbase Token Manager can read balances and propose transfers from a designated Prime portfolio.
At a high level, you will:
(Optionally) create a dedicated portfolio for Token Manager distributions.
Capture your portfolio URL (including the portfolio ID).
Confirm security and transfer settings.
Create and activate a portfolio API key.
Share the key’s credentials with Coinbase Token Manager via a secure channel.
Optional – Create a dedicated “Token Manager Distributions” portfolio
To limit the exposure of the API key used by Coinbase Token Manager, you can ask Prime Ops to create a dedicated portfolio for Token Manager payouts.
Email primeops@coinbase.com (copy your Coinbase Token Manager onboarding contact).
Include:
Your Coinbase entity name.
A proposed portfolio name (for example, “Token Manager Distributions”).
Whether it should mirror an existing portfolio’s settings.
If not mirroring: which users should be added and the desired consensus and transfer policies.
Which admins should sign for creation/changes.
Once Prime Ops confirms that the new portfolio is created, use that portfolio for the remaining steps in this guide.
Step 1 – Capture your portfolio URL (portfolio ID)
Sign in to Coinbase Prime.
In the Portfolio view, select the asset you will use for distributions via Coinbase Token Manager.
Copy the full browser URL for that portfolio view.
Paste this URL into a secure note (for example, in 1Password or your internal secrets manager).
This URL contains the portfolio ID that Coinbase Token Manager will target.
Step 2 – Review security settings
Before creating an API key, confirm that your security posture supports Token Manager‑initiated transfers.
In Prime, go to Settings → Security → Transfers.
Review:
Maximum Transfer Amount
Make sure the limit is high enough that Token Manager payouts will not be blocked.
Trusted Address Protection
Ensure this is enabled so withdrawals can only go to addresses in your Trusted Address Book.
If you make any changes, confirm them with your YubiKey and satisfy any required consensus approvals.
These settings work together with Token Manager so that:
Large payouts are allowed only within your defined limits.
Transfers can only go to trusted addresses you have explicitly allowlisted.
Step 3 – Create a portfolio API key
In Coinbase Prime, go to Settings → APIs.
Click Create API Key.
Configure the key:
Name: for example, Token Manager Transfers.
Scope / Type: portfolio‑level key for the portfolio that will fund Token Manager payouts.
Access Type: must include at least Read and Transfer so Token Manager can:
Read balances and account information.
Propose transfer operations for payouts.
Expiration date: choose a date that fits your internal policy (you can revoke and rotate keys later).
Click Continue.
Complete any required consensus approvals and YubiKey verification.
After this step, the key will appear in your list of pending or inactive API keys until it is activated.
Step 4 – Activate the API key and record credentials
In the APIs section, locate the new key under Pending keys (or the equivalent).
Click Activate key and follow the prompts, including YubiKey verification.
Once activated, Prime will display the key’s credentials, typically including:
Access key
Service account ID
Passphrase
Signing key
Immediately copy each of these values into the same secure note where you saved the portfolio URL in Step 1.
Do not paste these credentials into plain‑text chat or unencrypted email.
These four values, together with your portfolio ID, are what Coinbase Token Manager will use to connect to your Prime portfolio.
Step 5 – Share credentials securely with Coinbase Token Manager
Verify that your secure note includes:
The Coinbase Prime portfolio URL (with portfolio ID).
The API key Access key.
The Service account ID.
The Passphrase.
The Signing key.
Contact your Coinbase Token Manager onboarding manager to confirm the appropriate recipient and method for sharing the note.
Share the secure note using an approved secure channel (for example, a one‑time, encrypted 1Password share link).
Coinbase Token Manager will then:
Store these credentials in a secure secrets manager.
Validate that the key has the correct scope and can access the designated portfolio.
Run limited test calls to confirm connectivity before live payouts are processed.
Ongoing maintenance for new stakeholders
For every new stakeholder you add in Coinbase Token Manager whose payouts will be sent from Coinbase Prime:
Ensure their wallet address is added as a Trusted Address in your Prime Address Book before sending tokens.
Keep your Maximum Transfer Amount and consensus policies aligned with your evolving payout patterns and internal controls.
This ensures all Token Manager‑initiated payouts remain compliant with your Prime security configuration.
Allowlist stakeholder wallet addresses in Coinbase Prime as Trusted Addresses
Overview
To pay out tokens from Coinbase Prime via Coinbase Token Manager, each stakeholder’s wallet address must be added as a Trusted Address in your Prime Address Book. This article explains:
How to add a wallet address as a Trusted Address in Prime
How to confirm, from within Coinbase Token Manager, whether a stakeholder’s address is trusted
Add a stakeholder wallet as a Trusted Address in Coinbase Prime
Follow these steps in Coinbase Prime before attempting payouts from Coinbase Token Manager:
Sign in to your Coinbase Prime account.
On the left side of the page, click Settings.
Click Address Book.
Click Add Trusted Address.
Select the asset that matches the token you are distributing via Coinbase Token Manager.
Enter a clear trusted address name (for example, the stakeholder’s name and purpose).
Paste the trusted address (the stakeholder’s wallet address).
Review the details and click Confirm New Trusted Address.
Complete any required YubiKey and consensus approvals.
Once approvals are complete, the wallet is allowlisted as a Trusted Address and can receive withdrawals from your Prime portfolio, including payouts initiated via Coinbase Token Manager.
Repeat these steps for each stakeholder wallet that should receive tokens from Prime.
Confirm Trusted Addresses from Coinbase Token Manager
You can verify whether a stakeholder’s wallet has been allowlisted as a Trusted Address directly from Coinbase Token Manager.
Sign in to Coinbase Token Manager.
Navigate to the Stakeholders page.
Locate the stakeholder you want to check.
Look at the Trusted Destinations column for that stakeholder.
Interpretation:
If the value is Trusted, the stakeholder’s wallet address is allowlisted as a Trusted Address in your Coinbase Prime Address Book.
If the value is Not trusted, the address is not present in your Prime Address Book and must be added using the steps in the previous section.
Any updates you make to your Coinbase Prime Address Book (adding or removing trusted addresses) will be reflected automatically in Coinbase Token Manager once Prime syncs those changes.
Pay out tokens using a Coinbase Prime account
Overview
This article explains how to pay out tokens to stakeholders from Coinbase Prime using Coinbase Token Manager once your Prime integration is configured.
You will:
Confirm approvers, balances, and Trusted Addresses in Coinbase Prime.
Submit payout batches from Coinbase Token Manager.
Approve those payouts in your Prime Pending activity queue, including guidance for batches larger than 100 payouts.
Coinbase Prime enforces withdrawal minimums and fees that vary by asset. Be sure your test and production payouts meet Prime’s minimum withdrawal amounts for the asset you are using.
Prerequisites
Before paying out tokens from Coinbase Prime through Coinbase Token Manager, ensure:
Your Coinbase Prime integration and API key are already set up and active.
The relevant stakeholder wallet addresses are added as Trusted Addresses in your Prime Address Book and are showing as Trusted in Coinbase Token Manager’s Stakeholders view.
Your Prime Maximum Transfer Amount and Trusted Address Protection settings are configured to allow the payouts you intend to send.
You have sufficient token balance in the relevant Prime trading wallet to cover all payouts in the batch.
You have the required approvers available to approve withdrawals in Prime (per your consensus policy).
Step 1 – Confirm approvers and balances in Coinbase Prime
In your Coinbase Prime account:
Make sure there are enough admins/signers online to satisfy your consensus rules for transfers.
Check that your trading balance for the payout asset is large enough to cover all payouts (including any minimums and fees that may apply for that asset).
Verify that the Maximum Transfer Amount and other transfer policies will not block the total size of your batch.
If these conditions are not met, correct them before initiating payouts from Coinbase Token Manager.
Step 2 – Confirm stakeholder addresses are Trusted
Because Prime uses Trusted Addresses to control where funds can be sent:
In Coinbase Prime, confirm that each stakeholder wallet address is present and approved in your Address Book as a Trusted Address.
In Coinbase Token Manager, open the Stakeholders page and check the Trusted Destinations column:
Trusted means the address is allowlisted in Prime.
Not trusted means the address is not in your Prime Address Book and will be excluded from payouts until it is added.
If any stakeholders are Not trusted, add those addresses to your Prime Address Book and complete approvals before proceeding. Any addresses that are not Trusted in Prime will be excluded from the payout batch in Coinbase Token Manager and surfaced in warning banners on the Payouts page.
Step 3 – Submit payouts from Coinbase Token Manager
Sign in to Coinbase Token Manager and go to your Payouts (or equivalent) page.
Review the list of vested and unlocked payout rows for your stakeholders.
Select the payouts you want to send from Coinbase Prime.
Choose Pay via custody (or the specific Prime option, depending on your configuration).
Confirm the payout details and submit the batch.
Coinbase Token Manager will:
Build a set of payout instructions for each stakeholder with a Trusted Address.
Exclude any stakeholders whose addresses are not Trusted in Prime.
Send the payout instructions to your Coinbase Prime portfolio via your API integration.
Step 4 – Approve payouts in Coinbase Prime Pending activity
After you submit payouts from Token Manager:
Sign in to Coinbase Prime.
Navigate to your Pending activity (or equivalent queue) for the relevant portfolio.
Wait for the payouts submitted from Token Manager to appear as pending transfer requests.
Once they are visible, approve them in batches, following Prime’s UI and your operational preferences.
Recommended batching pattern
Select up to 20 payouts at a time for approval.
Approve the selected transfers and complete any YubiKey and consensus requirements.
Repeat for the next group of pending payouts until the entire batch is approved.
This approach helps ensure smooth approvals and reduces the chance of timeouts or UI limitations during large payout runs.
Handling more than 100 payouts
Coinbase Prime displays up to 100 pending transactions in the Pending activity view at once. If your batch from Coinbase Token Manager contains more than 100 payouts:
Approve the first 100 payouts in Prime (for example, in batches of 20).
Wait for those 100 payouts to process on‑chain. This typically takes several minutes.
After they complete, return to the Pending activity queue. The remaining payouts from Coinbase Token Manager should now appear.
Approve the remaining payouts in batches (again, up to 20 at a time is recommended) until no pending items remain.
If you do not see additional payouts after the first 100 have processed, refresh the page and confirm there are no warnings in Coinbase Token Manager about excluded addresses or insufficient balances.
FAQ
How will Coinbase Prime payouts appear in my Coinbase Token Manager transactions page?
Each payout that is successfully processed by Coinbase Prime will appear as a separate transaction in your Coinbase Token Manager activity or transactions view. When available, Coinbase Prime provides a transaction hash for each transfer, which Token Manager uses to link each payout to its on‑chain transaction.
Complete a test transaction using a Coinbase Prime account
Overview
Before running your first live payouts from Coinbase Prime via Coinbase Token Manager, we strongly recommend completing a small, end‑to‑end test transaction. This confirms that:
Your Coinbase Prime integration and API key are configured correctly
Trusted Addresses are set up and recognized
Payouts submitted from Token Manager are appearing and settling correctly in Prime
This guide walks through the recommended test flow.
Step 1 – Add a test address as a Trusted Address in Coinbase Prime
First, choose the wallet address you will use to receive the test payout (for example, an internal test wallet controlled by your team).
In Coinbase Prime:
Sign in to your Prime account.
Go to Settings → Address Book.
Click Add Trusted Address.
Select the asset you plan to test (the same asset you will distribute via Coinbase Token Manager).
Enter a clear name for the test address (for example, “Test Transaction – Internal Wallet”).
Paste the wallet address you will use for the test.
Review and confirm the new Trusted Address.
Complete any YubiKey and consensus approvals required.
Once approved, this wallet is now a Trusted Address and can receive test payouts from your Prime portfolio.
Step 2 – Create and publish a test token grant in Coinbase Token Manager
Next, create a simple one‑time test grant for the Trusted Address you just added.
In Coinbase Token Manager:
Navigate to your Stakeholders page and ensure the test wallet is associated with a stakeholder profile (or create a new stakeholder tied to that wallet).
Create a new token grant for this stakeholder with the following recommended settings:
Token quantity: choose a small amount that is above the Coinbase Prime minimum withdrawal amount for that asset and comfortable for testing.
Vesting schedule type: Custom.
Number of vest events: 1.
Percentage: 100% (all tokens vest in a single event).
Save the grant as a draft.
(Optional) Add a tag or label such as “Test Transaction” for clarity.
Publish the grant so that the vested amount becomes available for payout once the vesting date is reached.
This creates a single, fully vested event that you can use to test the Prime payout flow end to end.
Step 3 – Run the payout via Coinbase Prime
Once the test grant is vested and unlocked:
In Coinbase Token Manager, go to your Payouts (or equivalent) page.
Locate the payout row for the test grant you just created.
Select the payout and choose Pay via custody using your Coinbase Prime account.
Confirm the payout details and submit.
Then, in Coinbase Prime:
Go to your Pending activity (or transfers) queue for the relevant portfolio.
Wait for the test payout submitted from Token Manager to appear as a pending transaction.
Approve the payout following your normal process, including:
Applying any required consensus approvals
Confirming with your YubiKey
After approval and on‑chain processing, the test amount should arrive in the Trusted Address wallet you configured in Step 1.
Step 4 – Confirm receipt and mark the wallet as verified
To close the loop:
Confirm directly with the owner of the test wallet (or check internally if it is an internal wallet) that the test amount was received in the expected address.
Once confirmed, go back to Coinbase Token Manager and, if your process calls for it, mark the stakeholder’s wallet as verified to indicate that:
The address is correct, and
Funds can be successfully sent from Coinbase Prime to that wallet.
This gives you added confidence before running production‑scale payouts.
If you need immediate assistance, please contact our support team directly at:
tm-support@coinbase.com
References to third-party services are provided solely for your convenience and do not constitute an endorsement, approval, or recommendation by Coinbase. Coinbase does not control and is not responsible for any third-party services, websites, or content.
If you don't see what you're looking for in our support documentation, you can request a resource to be made by our support team using this form.