Skip to main content

Best relayers in 2026

Relayers evaluated across what the relayer is authorised to do, and whether you can keep the address, exactly-once execution and stuck-queue recovery, what a stolen API credential can do before anyone notices, and where the gas float sits and how you get it back.

#1 of 7 · published ranking
Coinbase CDP Server Wallets (API-key wallets)
81ChainChoice Score
Why it leads
Best in the pool on credential blast radius (10/10; next 9/10)
Cost
Not priced · No comparable price is published
7 compared Ranking-blind · 392 modules checked 2026-09-18Evidence read 2026-08-11Scored under methodology v2026.09.15 (2026-09-16)28 receipts quoted
7relayers · sorted by chainchoice score
ranked before any payout data is seen
#1 overallcomputed before any payout data is seenOverall
Coinbase CDP Server Wallets (API-key wallets)
A backend API that creates EOAs whose private keys are generated inside Coinbase's AWS Nitro Enclave TEE, then signs and broadcasts transactions from them on seven EVM mainnets and Solana, with import and export of the raw private key both exposed as REST endpoints.
Leads the pool on What a stolen API credential can do before anyone notices
81ChainChoice Score · first of 7
Catalog strengths
What a stolen API credential can do before anyone noticesWhat the relayer is authorised to do, and whether you can keep the addressWhere the gas float sits and how you get it back
Why it leads
  • Best in the pool on credential blast radius (10/10; next 9/10)
  • 3 points ahead of Privy server wallets: +1.4 pts credential blast radius, +1.2 pts gas float custody
  • Provider states broad availability
Evidence
4/4
criteria scored · 4 receipts quoted
Margin
+3
over Privy server wallets, ranked #02
Rank stability
Firm
#1 holds when every published criterion is moved ±1
Tradeoff
−1
What the relayer is authorised to do, and whether you can keep the address — behind this pool's best
Jurisdiction
Global
no restricted market on record
Score breakdowntick = pool best
Relayer authority and key custody9/10
Exactly once execution7/10
Credential blast radius10/10
Gas float custody8/10
Ranking-blind · a guided run tailors this to your size, custody & jurisdiction
#ProviderScoreEvidenceKey strengths
2−3
Privy server wallets
What the relayer is authorised to do, and whether you can keep the addressWhat a stolen API credential can do before anyone notices
3−3
Openfort backend wallets
Openfort backend wallets
What the relayer is authorised to do, and whether you can keep the addressWhat a stolen API credential can do before anyone notices
4−2
OpenZeppelin Relayer
OpenZeppelin Relayer
What the relayer is authorised to do, and whether you can keep the addressWhere the gas float sits and how you get it back
Same score, not joint · ordered by weighted total (45.50 against 45.40)
5=
Sequence Transactions API (Relayer)
Sequence Transactions API (Relayer)
What the relayer is authorised to do, and whether you can keep the addressWhere the gas float sits and how you get it back
6−2
Circle Gas Station
Circle Gas Station
Where the gas float sits and how you get it backExactly-once execution and stuck-queue recovery
7−12
Gelato Relay
What the relayer is authorised to do, and whether you can keep the addressWhat a stolen API credential can do before anyone notices
Ranking-blind — order computed before any payout data is joined
Below the table

How this ranking works

Everything the table draws on continues here: how firm the #1 is, the per-criterion arithmetic behind each score, who pays ChainChoice, and the full guide to choosing.

Direct answer

What is the best relayers in 2026?

Coinbase CDP Server Wallets (API-key wallets) ranks #1 overall for relayers on ChainChoice. A backend API that creates EOAs whose private keys are generated inside Coinbase's AWS Nitro Enclave TEE, then signs and broadcasts transactions from them on seven EVM mainnets and Solana, with import and export of the raw private key both exposed as REST endpoints. It holds that rank under an affiliate-blind methodology scored across 4 published, weighted criteria — the code that ranks providers physically cannot read affiliate payouts (CI-enforced), so a payout can't move a rank. The verdict re-computes on every fee change, incident, or regulatory action; full reasoning and the audit receipt are below.

Best picks

Best relayers in 2026

This page deliberately publishes no cost ranking, and that is the first thing to know about it. Price per transaction and the markup on sponsored gas are already scored on Account Abstraction Infra, and cost per call on RPC & Node Services, so ranking them again here would print the same numbers under a different heading — and in one case contradict them. What is left is the part nobody else asks, because a relayer inverts the usual arrangement: everywhere else on this site the user signs and the vendor forwards, but a relayer holds a key and transacts as your backend, which means its address ends up holding a privileged role inside your own contracts. So start with what that address is allowed to do and whether you can keep it, because an address is wired into contracts as a role grant and a key you cannot export turns leaving into an on-chain re-permissioning exercise. Then read the retry semantics, where this pool is uniformly weak: nobody here scores above 7, because vendors publish the words "nonce management, gas estimation and resubmission" and stop short of saying whether a repriced transaction reuses its nonce. Then check what a leaked API token can actually send, and last, whether the gas you deposit can ever come back out.
Best overall
Coinbase CDP Server Wallets (API-key wallets)
A backend API that creates EOAs whose private keys are generated inside Coinbase's AWS Nitro Enclave TEE, then signs and broadcasts transactions from them on seven EVM mainnets and Solana, with import and export of the raw private key both exposed as REST endpoints.
Data checked Aug 2026
A backend API that creates EOAs whose private keys are generated inside Coinbase's AWS Nitro Enclave TEE, then signs and broadcasts transactions from them on seven EVM mainnets and Solana, with import and export of the raw private key both exposed as REST endpoints. Strongest on what a stolen api credential can do before anyone notices (10/10): Raised from 9: the draft's central deduction was a false absence. Read off the create-policy OpenAPI schema (fetched 2026-08-11), `SendEvmTransactionCriteria` — the criteria set for the relayer endpoint itself — accepts five criteria, all enforced server-side: EvmAddressCriterion (destination allowlist/denylist… Weakest on exactly-once execution and stuck-queue recovery (7/10): Raised from 6 on adversarial re-read: the draft asserted CDP publishes no at-most-once semantics, and that is wrong. docs.cdp.coinbase.com/webhooks/wallets (fetched 2026-08-11) publishes a replacement lifecycle: `wallet.transaction.replaced` — "Transaction replaced an existing pending transaction"… Published price: "CDP non-custodial wallets use a pay-as-you-go model with no contracts or minimum commitments." / "Wallet usage is billed in `wallet operations`.
Best for: What a stolen API credential can do before anyone notices — 10/10
Why this score4 published criteria · leads 2 of 4
Published criterionWtScore, and the best hereGap/10Pts
What the relayer is authorised to do, and whether you can keep the address7.7−199.2
Exactly-once execution and stuck-queue recovery6.2·75.8
What a stolen API credential can do before anyone notices5.3·107.0
Where the gas float sits and how you get it back4.8−185.1
Σ methodology points27.2/32

Each bar is the score on that criterion’s own 0–10 scale, never rescaled to the pool. The dark line is the best any product here reached on that axis. Wt is the most the criterion can add to the 86-point weighted total. Pts is weight × score × 32; the sum is the methodology score, and each weighted point behind the leader costs 2.6 on the displayed score. how these are weighted

Why it ranks first
Why Coinbase CDP Server Wallets (API-key wallets) leads this category right now
A backend API that creates EOAs whose private keys are generated inside Coinbase's AWS Nitro Enclave TEE, then signs and broadcasts transactions from them on seven EVM mainnets and Solana, with import and export of the raw private key both exposed as REST endpoints. Strongest on what a stolen api credential can do before anyone notices (10/10): Raised from 9: the draft's central deduction was a false absence. Read off the create-policy OpenAPI schema (fetched 2026-08-11), `SendEvmTransactionCriteria` — the criteria set for the relayer endpoint itself — accepts five criteria, all enforced server-side: EvmAddressCriterion (destination allowlist/denylist… Weakest on exactly-once execution and stuck-queue recovery (7/10): Raised from 6 on adversarial re-read: the draft asserted CDP publishes no at-most-once semantics, and that is wrong. docs.cdp.coinbase.com/webhooks/wallets (fetched 2026-08-11) publishes a replacement lifecycle: `wallet.transaction.replaced` — "Transaction replaced an existing pending transaction"… Published price: "CDP non-custodial wallets use a pay-as-you-go model with no contracts or minimum commitments." / "Wallet usage is billed in `wallet operations`.
Best for
What a stolen API credential can do before anyone notices — 10/10
Main tradeoff
CDP does publish replacement semantics — a replaced original "will never land onchain" and fires a `failed` event — but it never uses the word nonce, and there is no cancel or nonce-reset endpoint anywhere in the v2 API. After 30 seconds it hands your backend the stuck transaction's gas parameters and expects you to build the replacement yourself. The X-Idempotency-Key that would protect you cannot be reused: the API "Returns an error if the same key is used with different request parameters", so a higher-gas payload needs a NEW key — and if you then omit the optional nonce field, "the API will assign a nonce to the transaction based on the current state of the account." A fresh nonce makes it a second transaction, not a replacement, and both can land. Pin the nonce yourself or the same intent can be mined twice.
Verify before signup
"CDP non-custodial wallets use a pay-as-you-go model with no contracts or minimum commitments." / "Wallet usage is billed in `wallet operations`. A wallet operation is consumed by write actions such as wallet creation, message signing, transaction signing, transaction broadcasting, and policy evaluation." / "Read operations are not billed." / table rows: "Send a transaction (sign + broadcast) | 2" and "Policy evaluation (API key auth workflows) | 1" / "Each wallet operation costs **\$0.005**." / "The first **5,000 wallet operations per month** are free." / "Usage is billed at the beginning of each calendar month for the previous month." (docs.cdp.coinbase.com/wallets/pricing, re-fetched as raw markdown and confirmed character-exact 2026-08-11). Recorded for the record only — this page publishes NO cost ranking for relayers, because per-transaction price is already scored on account_abstraction_infra (publishedUnitPrice, 30%) and cost-per-call on rpc_nodes (35%). No criterion below touches this figure. Note the unit is a "wallet operation", not a transaction: a send costs 2, and 3 if an API-key policy is evaluated. Separately, the gas itself is NOT priced here — on the EOA path it is paid from the buyer's own account balance, so no markup or premium is published for it at all.
Recommendation summary
What should decide this category
Does the vendor's address become msg.sender inside your contracts, or does it only fund a call your end user signed?
Can you keep the address — import a key, export the one they generated, or point the service at a signer you control?
If a repriced transaction is resubmitted, does it reuse the original nonce, so the intent executes at most once?
What can a stolen API token send before anyone notices — and can that same token delete the limits meant to bound it?
Quick picks
Strong options in this category
Start with the lead choice first, then use the shortlist only if you still need a challenger or stronger fit for a specific setup.
Best overall
Coinbase CDP Server Wallets (API-key wallets)
A backend API that creates EOAs whose private keys are generated inside Coinbase's AWS Nitro Enclave TEE, then signs and broadcasts transactions from them on seven EVM mainnets and Solana, with import and export of the raw private key both exposed as REST endpoints.
A backend API that creates EOAs whose private keys are generated inside Coinbase's AWS Nitro Enclave TEE, then signs and broadcasts transactions from them on seven EVM mainnets and Solana, with import and export of the raw private key both exposed as REST endpoints. Strongest on what a stolen api credential can do before anyone notices (10/10): Raised from 9: the draft's central deduction was a false absence. Read off the create-policy OpenAPI schema (fetched 2026-08-11), `SendEvmTransactionCriteria` — the criteria set for the relayer endpoint itself — accepts five criteria, all enforced server-side: EvmAddressCriterion (destination allowlist/denylist… Weakest on exactly-once execution and stuck-queue recovery (7/10): Raised from 6 on adversarial re-read: the draft asserted CDP publishes no at-most-once semantics, and that is wrong. docs.cdp.coinbase.com/webhooks/wallets (fetched 2026-08-11) publishes a replacement lifecycle: `wallet.transaction.replaced` — "Transaction replaced an existing pending transaction"… Published price: "CDP non-custodial wallets use a pay-as-you-go model with no contracts or minimum commitments." / "Wallet usage is billed in `wallet operations`.
Best for: What a stolen API credential can do before anyone notices — 10/10
What the relayer is authorised to do, and whether you can keep the address · 32%
9/10
Exactly-once execution and stuck-queue recovery · 26%
7/10
What a stolen API credential can do before anyone notices · 22%
10/10
Where the gas float sits and how you get it back · 20%
8/10
Quick pick
Privy server wallets
A REST/SDK service that generates or imports secp256k1 and Ed25519 keys into a TEE, holds them under an app-held P-256 authorization key (optionally an m-of-n key quorum), and signs and broadcasts transactions from those addresses on request from the buyer's backend — with gas paid by default from the wallet's own native balance, or optionally sponsored from a prepaid app-level gas-credits balance, or collected on-chain from the wallet's stablecoin balance by an ERC-20 paymaster in 'User pays' mode.
A REST/SDK service that generates or imports secp256k1 and Ed25519 keys into a TEE, holds them under an app-held P-256 authorization key (optionally an m-of-n key quorum), and signs and broadcasts transactions from those addresses on request from the buyer's backend — with gas paid by default from the wallet's own native balance, or optionally sponsored from a prepaid app-level gas-credits balance, or collected on-chain from the wallet's stablecoin balance by an ERC-20 paymaster in 'User pays' mode. Strongest on what the relayer is authorised to do, and whether you can keep the address (9/10): Principal architecture, re-confirmed 2026-08-11. I tried hard to falsify the asserted absence and could not: 'erc2771', 'erc-2771' and 'forwarder' appear nowhere in Privy's docs index (llms.txt), llms-full.txt, any page I pulled, or the 128-path OpenAPI spec at https://api.privy.io/v1/openapi.json — the only ERC-2771… Weakest on where the gas float sits and how you get it back (7/10): THREE float models, not the two the draft scored — and the missed one is the strongest. (a) UNSPONSORED, the default: no vendor-held balance at all; the float is native token at the server wallet's own address, and the buyer's exit is unilateral via POST /v1/wallets/{wallet_id}/rpc or POST… Published price: NOT USED IN ANY SCORE ON THIS PAGE (cost is scored on account_abstraction_infra and rpc_nodes). Recorded only because the schema requires it.
Best for: What the relayer is authorised to do, and whether you can keep the address — 9/10
What the relayer is authorised to do, and whether you can keep the address · 32%
9/10
Exactly-once execution and stuck-queue recovery · 26%
7/10
What a stolen API credential can do before anyone notices · 22%
9/10
Where the gas float sits and how you get it back · 20%
7/10
Quick pick
Openfort backend wallets
Openfort backend wallets
A custodial server-side signer: Openfort generates and holds an EVM or Solana private key inside a GCP Confidential Space TEE, exposes sign/import/export over a REST API gated by a fail-closed rule-based policy engine, and can also submit transactions for that wallet via EIP-7702 delegation with gas optionally sponsored from a prepaid project credit balance.
A custodial server-side signer: Openfort generates and holds an EVM or Solana private key inside a GCP Confidential Space TEE, exposes sign/import/export over a REST API gated by a fail-closed rule-based policy engine, and can also submit transactions for that wallet via EIP-7702 delegation with gas optionally sponsored from a prepaid project credit balance. Strongest on what the relayer is authorised to do, and whether you can keep the address (9/10): PRINCIPAL architecture, no payer-only path. Re-verified 2026-08-11. https://www.openfort.io/docs/products/server: "Backend wallets are developer-controlled, custodial wallets that live in your server environment." (character-exact). The wallet is an EOA, so its address is msg.sender in the buyer's contracts. I… Weakest on exactly-once execution and stuck-queue recovery (5/10): CORRECTED UPWARD. The prior draft's central absence claim — that Openfort only signs and never submits — is false. https://www.openfort.io/docs/api-reference/transaction-intents (re-fetched 2026-08-11) documents POST /v1/transaction_intents whose account field reads verbatim: "ID of the Account this TransactionIntent… Published price: NOT SCORED ON THIS PAGE — per-operation price belongs to account_abstraction_infra publishedUnitPrice and the paymaster surcharge to sponsoredGasMarkup; neither figure is used in any criterion above.
Best for: What the relayer is authorised to do, and whether you can keep the address — 9/10
What the relayer is authorised to do, and whether you can keep the address · 32%
9/10
Exactly-once execution and stuck-queue recovery · 26%
5/10
What a stolen API credential can do before anyone notices · 22%
9/10
Where the gas float sits and how you get it back · 20%
7/10
Quick pick
OpenZeppelin Relayer
OpenZeppelin Relayer
An AGPL-licensed Rust service a backend team runs itself to submit transactions from its own EOA on EVM, Solana and Stellar networks, where the signing key stays in the buyer's own keystore file, HashiCorp Vault, AWS KMS, Google Cloud KMS, Turnkey or Coinbase CDP account rather than in a vendor's vault.
An AGPL-licensed Rust service a backend team runs itself to submit transactions from its own EOA on EVM, Solana and Stellar networks, where the signing key stays in the buyer's own keystore file, HashiCorp Vault, AWS KMS, Google Cloud KMS, Turnkey or Coinbase CDP account rather than in a vendor's vault. Strongest on what the relayer is authorised to do, and whether you can keep the address (10/10): PRINCIPAL on EVM, payer-only on Stellar, and the key is importable. EvmTransactionRequest (OpenAPI 3.1.0, info.version "1.5.0", re-fetched 2026-08-11) requires only ["value"], with properties data, gas_limit, gas_price, max_fee_per_gas, max_priority_fee_per_gas, speed, to, valid_until, value — no end-user signature… Weakest on what a stolen api credential can do before anyone notices (3/10): SCORE LOWERED: the published limits are revocable by the credential they are supposed to limit. RelayerEvmPolicy (additionalProperties: false, re-verified 2026-08-11) has exactly seven fields — eip1559_pricing, gas_limit_estimation, gas_price_cap, include_revert_data, min_balance, private_transactions… Published price: No price of any kind is published for OpenZeppelin Relayer. https://www.openzeppelin.com/pricing returns HTTP 404 (re-checked 2026-08-11).
Best for: What the relayer is authorised to do, and whether you can keep the address — 10/10
What the relayer is authorised to do, and whether you can keep the address · 32%
10/10
Exactly-once execution and stuck-queue recovery · 26%
6/10
What a stolen API credential can do before anyone notices · 22%
3/10
Where the gas float sits and how you get it back · 20%
9/10
Frequently asked
Questions people ask before choosing relayers
What can a stolen API credential actually send?
On OpenZeppelin Relayer the credential that sends your transactions can also delete the limits that bound it. RelayerEvmPolicy carries exactly seven fields and, because additionalProperties is false, the absences are provable: no per-transaction value cap, no function-selector restriction, no daily or monthly ceiling. Only two fields bound a stolen token at all — whitelist_receivers and gas_price_cap — and PATCH /api/v1/relayers/{relayer_id} accepts the policy object, so the same unscoped bearer token can rewrite both, repoint custom_rpc_urls, execute plugins and call POST /sign. It is an operator-error guard, not a security boundary.
If the relayer retries, can the same transaction execute twice?
Not one relayer in this pool can tell you whether a retry charges your user twice. Every provider scored here lands between 4 and 7 out of 10 on exactly-once execution, and the reason is uniform: they publish the words "nonce management, gas estimation and resubmission" and stop. Across all 38 live Gelato relay and Gas Tank pages the strings retry, resubmit, reprice, idempotent, at-most-once, duplicate, cancel, stuck and escalate occur ZERO times, and the two knobs its older docs advertised now survive only on pages Gelato itself files under "Legacy Documentation". Coinbase does state that a replaced transaction "will never land onchain" — and never once uses the word nonce.
Can I get the gas I deposit back out?
Ask before you fund, because one provider's answer is no and it is not written where you would look. Money goes into Gelato's Gas Tank and the only statement in the whole of its documentation about getting it out is "It's important to remember that the current Gas Tank system does not support withdrawals after depositing funds." — published on a VRF integration guide, not on any relay page, and not on the Gas Tank page that the relay setup guide itself links to, which walks through depositing in five numbered steps and never mentions withdrawal. The float is also single-chain and single-token: "Since Gas Tank is deployed on Polygon, you can deposit USDC in one step", funding all 42 mainnets from one bridged balance. Elsewhere the mechanics differ enough to matter — a prefunded balance in a vendor-controlled address, a deposit contract you can withdraw from, a fee taken on-chain out of the transaction itself, or a postpaid invoice — and where a vendor is silent about what happens to a residual balance on shutdown, that silence is recorded here as the finding rather than smoothed over.
Why is there no price ranking on this page?
Because it is already published twice, and printing it a third time would make this site contradict itself. Price per user operation and the markup a vendor adds to the gas it fronts are scored on Account Abstraction Infra; cost per call is scored on RPC & Node Services. Several vendors here sell across those pages on one meter — one bills relay, bundling and node access from a single compute-unit balance whose plan table is already quoted verbatim on the rollup-as-a-service page, and another is already ranked as having the lowest published gas surcharge in its pool, on a different product line from the one ranked here. Publishing a second number for the same company under a new heading would be a contradiction a reader would find before we did. So this page ranks trust and correctness instead: authority over the address, retry semantics, credential blast radius, and float custody. Every provider's published pricing is still recorded verbatim in its entry — it is simply not permitted to move the ranking.
Does the advertised chain list mean the relayer actually works there?
Not reliably. Seven mainnet chains one provider advertises do not resolve at all: Sequence's own OpenAPI servers block publishes relayer hosts for polygon-zkevm, blast, sei, xai, incentiv, laos and rootnet that return NXDOMAIN, and 18 of the 57 published hosts overall have no DNS record (checked 2026-08-11). Nothing on any Sequence page says whether those are deprecated, pre-announced or an oversight, so the published grid cannot be read as a capability list — verify your chain answers before you build on it. A related trap runs the other way: enabling gas sponsorship on Circle requires an ERC-4337 smart contract account, and Circle's own queue table gives that wallet a limit of 1 transaction on Ethereum, Polygon and Avalanche against 32, 16 and 32 for a plain EOA, so the buyer who turns sponsorship on to improve the experience drops to one in-flight transaction at a time on three of the largest chains.
Free advisorNo signup needed

Still unsure? Get your best relayers pick

Answer a few quick questions and get one clear recommendation based on how you actually plan to use crypto — then review the evidence before deciding.

No signupFree first pass · PrivateNo spam · No account

Not financial advice · Independent · Always do your own research

Browse this network
How this ranking is built
Reviewed on what the relayer is authorised to do, and whether you can keep the address, exactly-once execution and stuck-queue recovery, what a stolen API credential can do before anyone notices, and where the gas float sits and how you get it back.
Data checked Aug 2026 · Independent rankings · We show our work
Not financial advice · For informational purposes only · Always do your own research
ChainChoice
Compare onchain. A brighter future.
© 2026 ChainChoice. All rights reserved.
System statusFeeds last refreshed 9 days ago
Built from commit ba0993b · rankings.json sha256 e1eb24980abb
ChainChoice · The decision layer for crypto · Not financial adviceEducational analysis, not investment advice. Affiliate links may contribute to operations but never alter rankings.

ChainChoice provides informational content only. Nothing on this site constitutes financial, investment, legal, or tax advice. Always do your own research and consult a qualified professional before making financial decisions.