Get in touch
Transaction control

Know what you sign.

An application asks for permission to spend your tokens. Your wallet shows you one button. We read what is really being requested, and rewrite it to fit what you were doing.

01 · Intent

What were you doing?

The action you started, before anyone asked you to approve anything.

ConcludesSwap 100 USDC with app.example.xyz
02 · Inspect

What is it asking for?

The raw call decoded into the authority it creates. Not the label on the button, the object underneath it.

Concludesapprove(spender, 2^256−1) · ERC-20 · no expiry field
03 · Decide

Far wider than needed.

You are spending a hundred. The request reaches your whole balance and every deposit you make after it, permanently.

ConcludesOver-requested. The action needs 100. The request reaches the entire balance and every future deposit.
04 · Fix

So we rewrite it.

The smallest permission that still completes what you wanted, with an expiry attached where none existed.

Concludesapprove(spender, 100 USDC) · expires in 30 minutes
05 · Authorize

Your wallet. Never ours.

We hand over an unsigned payload and stop. Accept the correction, keep the original, or walk away.

ConcludesUnsigned payload handed to your wallet. You sign, or you refuse.
06 · Verify

Confirm what landed.

Read the chain back. The stated intent and the resulting onchain state have to agree, or it is not done.

Concludesallowance = 100 USDC · matches intent
07 · Monitor

It stays visible.

Standing authority stays visible for as long as it exists, and takes one action to revoke.

Concludes1 open permission · expires in 28 minutes
Design partners

Build it with us.

If your users are granting standing authority and you would rather they understood it, we want to build the first integration with you.

Leslie Khumalo · EngineeringBlagoja Mojsoski · Product and quality
app.example.xyz

Allow access to USDC?

This site is requesting permission to spend your tokens. Approve
One button. That is all you get.