Permissions and Approvals
The policy layer defines what may happen without a new explicit authorization. It is evaluated before any wallet request is created.
Policy dimensions
- Allowed networks
- Allowed assets and contracts
- Maximum amount per action
- Maximum cumulative spending
- Maximum slippage
- Time windows
- Approved action types
- Required human confirmation
- x402 payment limits
- Session duration
Design rules
- Permissions are narrowly scoped, visible, revocable, and recorded.
- High-risk or irreversible actions require stronger confirmation.
- A failure to validate policy stops execution.
Security
Wallet connection is never treated as blanket approval. Users can inspect and revoke active permissions at any time.