{"_id":"@botanary/wallet","_rev":"9-bfd9aff9e67e5d699a885772cf66c7d5","name":"@botanary/wallet","dist-tags":{"alpha":"0.1.0-alpha.12","latest":"0.1.0-alpha.12","next":"0.1.0-alpha.12"},"versions":{"0.1.0-alpha.1":{"name":"@botanary/wallet","version":"0.1.0-alpha.1","license":"MIT","_id":"@botanary/wallet@0.1.0-alpha.1","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"dist":{"shasum":"f7ae7e432030bae285c2c63473dbf5d98989164c","tarball":"https://registry.npmjs.org/@botanary/wallet/-/wallet-0.1.0-alpha.1.tgz","fileCount":68,"integrity":"sha512-XjyBe6du5QmxdErjFOf8lsDokMW68NWBm3ozVxiLPEzzFuqBcWzXaUSpUmRR0XaomyZW37V1vRgCt7Vo+N0JrQ==","signatures":[{"sig":"MEYCIQDglbX51Bg6L1yo86oevgCCpwD9LfPWIv0SA2DGszSYsQIhAKZYGjptsHAAWv+YSaa/SFhljmpCarlA0ctTTwM0YVXb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":259092},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./types":{"types":"./dist/types.d.ts"}},"gitHead":"cf69c1b46ffd91a005d8fa12bac33a391a82e77f","scripts":{"test":"vitest run --maxWorkers=2 --minWorkers=1","build":"tsc","prepack":"pnpm build","typecheck":"tsc --noEmit && tsc --noEmit --strict --skipLibCheck --module NodeNext --moduleResolution NodeNext --target ES2022 test/sdk-types.ts","test:packed":"node scripts/verify-packed.mjs"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Browser-safe canonical Botanary owner transaction review","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"viem":"2.54.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"vitest":"2.1.9","esbuild":"0.25.12","typescript":"5.9.3","@types/node":"22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/wallet_0.1.0-alpha.1_1788972311223_0.6761648163844176","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-alpha.2":{"name":"@botanary/wallet","version":"0.1.0-alpha.2","license":"MIT","_id":"@botanary/wallet@0.1.0-alpha.2","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"dist":{"shasum":"6fd65c524b227f6830e9f0bf22ee91758ba1e9c9","tarball":"https://registry.npmjs.org/@botanary/wallet/-/wallet-0.1.0-alpha.2.tgz","fileCount":21,"integrity":"sha512-2jiqPqCYmqx82tXqx4oig0f0+oPrhhEnLev3UsAiXoip3yLivW7YmhNjqXvtkTHwD1sx8TDJ27lVj8WFf2BvYQ==","signatures":[{"sig":"MEQCIHzbLVR2Flotc3JOyCpNxetFJdh0rfYQugyray5m8cVcAiAqZFmo5F6qscwINaLLHxnTWnwbkBQSMY67h6HjkQEPzg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":105930},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./types":{"types":"./dist/types.d.ts"}},"gitHead":"b445ef7c1d6341069893835a12e7728c03eca8d5","scripts":{"test":"vitest run --maxWorkers=2 --minWorkers=1","build":"node ../protected-boundary/release-build.mjs wallet","prepack":"pnpm build","build:tsc":"tsc","typecheck":"tsc --noEmit && tsc --noEmit --strict --skipLibCheck --module NodeNext --moduleResolution NodeNext --target ES2022 test/sdk-types.ts","test:packed":"node scripts/verify-packed.mjs","audit:artifact":"node ../protected-boundary/audit-artifact.mjs wallet","check:inventory":"node ../protected-boundary/check-inventory.mjs wallet"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Browser-safe canonical Botanary owner transaction review","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"viem":"2.54.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","readmeFilename":"README.md","devDependencies":{"vitest":"2.1.9","esbuild":"0.25.12","typescript":"5.9.3","@types/node":"22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/wallet_0.1.0-alpha.2_1789053831258_0.9082252380939997","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-alpha.3":{"name":"@botanary/wallet","version":"0.1.0-alpha.3","license":"MIT","_id":"@botanary/wallet@0.1.0-alpha.3","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"dist":{"shasum":"3a1f4d20a680fc45bb25c19d710830ecffd75307","tarball":"https://registry.npmjs.org/@botanary/wallet/-/wallet-0.1.0-alpha.3.tgz","fileCount":23,"integrity":"sha512-vnAv2FBsfVNONgRX72F8k1sAq/Lj7Ic8pVhd/VpJb4jfqyUq7FFflrxuz1wqPGnS5R4eUglhb4HpsyW4BRj27Q==","signatures":[{"sig":"MEUCIH5PNz8Asj2F3Wa+1gP7xyPsqW2xCYlSefBMzqyMHSWaAiEA1rt2SoqLdxNf+zxcddoBhd0AxlQdHdJ/hTBFLatT1/4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIEXDXp+/UB4ur6ztfRFrFHhfvgTcqVxKECf0mb7SxiL9AiEAoTiGiiEMQZFrQAZSla4Nt4DShWviCRRwvEvu+aDmgAE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":111061},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./types":{"types":"./dist/types.d.ts"}},"gitHead":"54f5e25bdfee09050e3e25603e4982d805806d7a","scripts":{"test":"vitest run --maxWorkers=2 --minWorkers=1","build":"node ../protected-boundary/release-build.mjs wallet","prepack":"pnpm build","build:tsc":"tsc","typecheck":"tsc --noEmit && tsc --noEmit --strict --skipLibCheck --module NodeNext --moduleResolution NodeNext --target ES2022 test/sdk-types.ts","test:packed":"node scripts/verify-packed.mjs","audit:artifact":"node ../protected-boundary/audit-artifact.mjs wallet","check:inventory":"node ../protected-boundary/check-inventory.mjs wallet"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"deprecated":"Superseded: registry artifact did not match the audited pnpm package metadata. Use 0.1.0-alpha.4.","_npmVersion":"11.7.0","description":"Browser-safe canonical Botanary owner transaction review","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"viem":"2.54.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","readmeFilename":"README.md","devDependencies":{"vitest":"2.1.9","esbuild":"0.25.12","typescript":"5.9.3","@types/node":"22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/wallet_0.1.0-alpha.3_1789119375336_0.07663832257553582","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-alpha.4":{"name":"@botanary/wallet","version":"0.1.0-alpha.4","license":"MIT","_id":"@botanary/wallet@0.1.0-alpha.4","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"dist":{"shasum":"f4a8e26ef07a873c039ec1c27d1b5082f0e8b403","tarball":"https://registry.npmjs.org/@botanary/wallet/-/wallet-0.1.0-alpha.4.tgz","fileCount":23,"integrity":"sha512-x7bKNVzTMjeDU8w7azx3C7uFOY5YBZe619PUhei/a02oBokJePPtqthFfouCgMrsVr/ZrDN9+bbUUQL2Anyc0w==","signatures":[{"sig":"MEUCICNgj1vzGlvj46Yi55fxZlrEHGD/+bxugRUDe72mryyWAiEA9kBDZcCKHPbpjMhBqC9zFeJIkOsRzMaFkmSnFUL48t0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCj2dZlEnuJiZLj43PdYRKh4s7KinEMNTMXGB6cAtDDxAIhALE5L3Sy2qiewigiK2eyYh/t2EhnI/ik0FbmQtjbyyHR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":110996},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./types":{"types":"./dist/types.d.ts"}},"scripts":{"test":"vitest run --maxWorkers=2 --minWorkers=1","build":"node ../protected-boundary/release-build.mjs wallet","build:tsc":"tsc","typecheck":"tsc --noEmit && tsc --noEmit --strict --skipLibCheck --module NodeNext --moduleResolution NodeNext --target ES2022 test/sdk-types.ts","test:packed":"node scripts/verify-packed.mjs","audit:artifact":"node ../protected-boundary/audit-artifact.mjs wallet","check:inventory":"node ../protected-boundary/check-inventory.mjs wallet"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"deprecated":"Use @botanary/wallet@0.1.0-alpha.5 for the Base Sepolia review policy factory.","description":"Browser-safe canonical Botanary owner transaction review","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"viem":"2.54.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"2.1.9","esbuild":"0.25.12","typescript":"5.9.3","@types/node":"22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/wallet_0.1.0-alpha.4_1789119592294_0.4573387459378049","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-alpha.5":{"name":"@botanary/wallet","version":"0.1.0-alpha.5","license":"MIT","_id":"@botanary/wallet@0.1.0-alpha.5","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"dist":{"shasum":"e1cad9ff9ede26626863c20b98543d91f50e5d65","tarball":"https://registry.npmjs.org/@botanary/wallet/-/wallet-0.1.0-alpha.5.tgz","fileCount":24,"integrity":"sha512-CEoAqiTG1iVndQU19NG7naTRxYSEN+vC6twqHkeWmqo1Kq3PwYPjR3AKpi27PawL8MpBeIl34DFUqOreH+40gQ==","signatures":[{"sig":"MEUCIHasUIkpDIasEZOq06EmxiYm6AEd/Y6ZYEShXMrpc4+nAiEAtlk15SGsj95ImFOZ6KI4jKY1C3lKYjbJKF/bf7Za088=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDiEWCz2ejAP6NZm7Php6UYJl8Asqp7VmbOkFEf7eRrewIgQymAC0c9Ksqak9YYbpnuwobDWi6FCMov3tAziRU7L64=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113018},"type":"module","_from":"file:/tmp/mandate-sdk-release/botanary-wallet-0.1.0-alpha.5.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./types":{"types":"./dist/types.d.ts"}},"scripts":{"test":"vitest run --maxWorkers=2 --minWorkers=1","build":"node ../protected-boundary/release-build.mjs wallet","build:tsc":"tsc","typecheck":"tsc --noEmit && tsc --noEmit --strict --skipLibCheck --module NodeNext --moduleResolution NodeNext --target ES2022 test/sdk-types.ts","test:packed":"node scripts/verify-packed.mjs","audit:artifact":"node ../protected-boundary/audit-artifact.mjs wallet","check:inventory":"node ../protected-boundary/check-inventory.mjs wallet"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_resolved":"/tmp/mandate-sdk-release/botanary-wallet-0.1.0-alpha.5.tgz","_integrity":"sha512-CEoAqiTG1iVndQU19NG7naTRxYSEN+vC6twqHkeWmqo1Kq3PwYPjR3AKpi27PawL8MpBeIl34DFUqOreH+40gQ==","_npmVersion":"11.7.0","description":"Browser-safe canonical Botanary owner transaction review","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"viem":"2.54.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vitest":"2.1.9","esbuild":"0.25.12","typescript":"5.9.3","@types/node":"22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/wallet_0.1.0-alpha.5_1789120612427_0.7938957102730964","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-alpha.11":{"name":"@botanary/wallet","version":"0.1.0-alpha.11","license":"MIT","_id":"@botanary/wallet@0.1.0-alpha.11","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"dist":{"shasum":"486a9bcdb5c4c4e9f34057796fb71fc801e3aa89","tarball":"https://registry.npmjs.org/@botanary/wallet/-/wallet-0.1.0-alpha.11.tgz","fileCount":24,"integrity":"sha512-+VfHbCMZy9Kzubjaz/yR11y+duZqkNaftBiyG3CKPCmOTJ4iQuppYIaD9LffdJheaILsiEtj5zlhQnQ2VP7J6w==","signatures":[{"sig":"MEUCIQDPzK5KCLaBG7KPJfN49SryxI+YSXlfm1CiTu04vvmeggIgHHy9+Y3k8hUsMcSCNMi4yq8eVEV5heIgx4Xe8kdylH4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIBtdXGN3PbQmCsIL0NhQBQzokHhzX5NbDjJjAp5eFbJBAiBa3IPLLPBXbB9qse4C23054qzaXHbNgpIQa4MeH/uzGw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":113253},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./types":{"types":"./dist/types.d.ts"}},"gitHead":"d78b50e1221c59dc106cd5e26db5fd2b3eb2aff1","scripts":{"test":"vitest run --maxWorkers=2 --minWorkers=1","build":"node ../protected-boundary/release-build.mjs wallet","prepack":"pnpm build","build:tsc":"tsc","typecheck":"tsc --noEmit && tsc --noEmit --strict --skipLibCheck --module NodeNext --moduleResolution NodeNext --target ES2022 test/sdk-types.ts","test:packed":"node scripts/verify-packed.mjs","audit:artifact":"node ../protected-boundary/audit-artifact.mjs wallet","check:inventory":"node ../protected-boundary/check-inventory.mjs wallet"},"_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.7.0","description":"Browser-safe canonical Botanary owner transaction review","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"viem":"2.54.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"vitest":"2.1.9","esbuild":"0.25.12","typescript":"5.9.3","@types/node":"22.19.15"},"_npmOperationalInternal":{"tmp":"tmp/wallet_0.1.0-alpha.11_1789496879526_0.5103085730606349","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-alpha.12":{"_id":"@botanary/wallet@0.1.0-alpha.12","dist":{"shasum":"e4dffb0b043f3223c1a0eafcb99ff4adc977c6b1","tarball":"https://registry.npmjs.org/@botanary/wallet/-/wallet-0.1.0-alpha.12.tgz","fileCount":24,"integrity":"sha512-7BOXO8+sfOrFg64XvjyYujuGnnDzY0mlnCcCACdAweYw+zpDOqka0YB9zl9M4oawC3rIVDA11Gj1ijR8hH7niw==","signatures":[{"sig":"MEQCIFJbvCIVe60jbPw7KironWujUbx1lbY22jp14wMtHYV0AiBIWRsozaiOjN565jzAgJXAtyX210zAJhLaM7apMmvoEg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCDZJasV+H9EwYEczkVzAxqfBMmwzP3YVS5naq1hPFGJAIgEjgSiM8JL71l8a0fIRkLejmxWU4/MTTMbu0Xegyw9PI="}],"unpackedSize":113253},"name":"@botanary/wallet","type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./types":{"types":"./dist/types.d.ts"}},"gitHead":"e1ecb674321b12494a7def8eb37d28aea29ad2fd","license":"MIT","scripts":{"test":"vitest run --maxWorkers=2 --minWorkers=1","build":"node ../protected-boundary/release-build.mjs wallet","prepack":"pnpm build","build:tsc":"tsc","typecheck":"tsc --noEmit && tsc --noEmit --strict --skipLibCheck --module NodeNext --moduleResolution NodeNext --target ES2022 test/sdk-types.ts","test:packed":"node scripts/verify-packed.mjs","audit:artifact":"node ../protected-boundary/audit-artifact.mjs wallet","check:inventory":"node ../protected-boundary/check-inventory.mjs wallet"},"version":"0.1.0-alpha.12","_npmUser":{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"},"_npmVersion":"11.17.0","description":"Browser-safe canonical Botanary owner transaction review","directories":{},"maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"sideEffects":false,"_nodeVersion":"25.3.0","dependencies":{"viem":"2.54.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.5.1","devDependencies":{"vitest":"2.1.9","esbuild":"0.25.12","typescript":"5.9.3","@types/node":"22.19.15"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wallet_0.1.0-alpha.12_1789559924014_0.3784391094209587"}}},"time":{"created":"2026-09-09T16:45:10.968Z","modified":"2026-09-16T11:58:44.392Z","0.1.0-alpha.1":"2026-09-09T16:45:11.356Z","0.1.0-alpha.2":"2026-09-10T15:23:51.381Z","0.1.0-alpha.3":"2026-09-11T09:36:15.420Z","0.1.0-alpha.4":"2026-09-11T09:39:52.387Z","0.1.0-alpha.5":"2026-09-11T09:56:52.507Z","0.1.0-alpha.11":"2026-09-15T18:27:59.621Z","0.1.0-alpha.12":"2026-09-16T11:58:44.102Z"},"license":"MIT","description":"Browser-safe canonical Botanary owner transaction review","maintainers":[{"name":"andersonweb3dev","email":"andersonweb3dev@gmail.com"}],"readme":"# @botanary/wallet\n\nVersion 0.1.0-alpha.12. Browser-safe canonical owner transaction review and per-instance signing for Botanary. MIT alpha, ESM, viem `2.54.6`. Inject the owner signer, current authenticated context and transport. No global account, provider, authentication store or backend key is used.\n\n```ts\nimport { reviewOwnerOperation } from '@botanary/wallet';\nimport type { OwnerOperationBinding, OwnerReviewPolicy } from '@botanary/wallet';\n\nconst binding: OwnerOperationBinding = {\n  accountId: selectedAccount.id,\n  accountAddress: selectedAccount.address,\n  ownerAddress: selectedOwner.address,\n  chainId: 84532,\n  intent: approvedIntent,\n  expiresAt: approvedOperation.expiresAt,\n  operationId: approvedOperation.id,\n};\nconst policy: OwnerReviewPolicy = {\n  chainId: 84532,\n  entryPoint: '0x0000000071727De22E5E9d8BAf0edAc6f37da032',\n  rootValidator: checkedAccountRoot,\n  rootScheme: 'kernel-v3.3-single-owner',\n  gas: { method: 'native' },\n  maxGasCostRaw: '1000000000000000',\n};\nconst review = reviewOwnerOperation(unknownBuild, binding, policy);\n// Render every call, deployment, fee authorization and issue.\n// Only a signable review may enter an independently fenced signing lifecycle.\n```\n\nFor Base Sepolia authority operations, use the reviewed policy shipped with the exact package version:\n\n```ts\nimport { baseSepoliaOwnerReviewPolicy } from '@botanary/wallet';\n\nconst policy = baseSepoliaOwnerReviewPolicy({\n  gas: { method: 'native' },\n  maxGasCostRaw: '1000000000000000',\n});\n```\n\nThe factory pins only public deployment identities. The caller still selects and bounds the gas path.\n\nThe example names application-owned values explicitly. Supply policy from trusted integrating-application configuration and an owner-approved expectation, never by copying unchecked assertions from the same build. Optional setup policy names the ordered SmartSession, MandateExecutor and GrantExecutor installations and their hooks. A setup prefix can be omitted, but when present it must match the entire configured list and a recognized new-account deployment. Executor setup is available only on Base Sepolia.\n\n`reviewOwnerOperation(build, binding, policy, { now? })` copies and freezes inputs and results. The optional clock is Unix milliseconds. Invalid untrusted build data returns structured issues and `signable: false`. Invalid expected binding throws `WalletError` as a caller configuration error. Unsupported inner calls retain target, value, full calldata and hash; unsupported outer execution retains the full UserOp calldata. Partially recognized deployment retains raw factory and initialization bytes. Never render absent metadata as zero or as a fabricated asset name.\n\nSupported financial chains are Base `8453` and Base Sepolia `84532`, using EntryPoint v0.7 and Kernel v3.3 single-owner policy. Exact Kernel default single and batch CALL modes, with at most one owner wrapper, are supported. Delegatecall, try modes, extra wrappers and noncanonical/trailing ABI bytes refuse signing. Current factory paths must initialize exactly the selected sole owner at threshold one, without a root hook or extra initConfig. Review does not prove a counterfactual address from CREATE2, current deployed root state, or wallet signer capability; the integrating runtime must establish account identity and current signer state.\n\nSend review permits one exact native or ERC20 transfer after independently approved gas/setup calls. Swap review permits one configured router call with exact input approval, optional zero reset and optional zero cleanup. All approval calls are visible as persistent allowance changes; calldata alone never proves the consumed allowance or settlement.\n\nUSDC policy binds the token, paymaster, token domain, Kernel version, root envelope, maximum base-unit permit amount and explicit maximum permit deadline. Review displays nonce and deadline and re-derives the full EIP-2612 and Kernel wrapped digest. The independent permit is not transaction-scoped. The signing runtime requires explicit raw-digest capability, attaches the permit, recomputes the completed UserOp hash and only then EIP-191 signs the operation. USDT policy supplies the exact ordered allowance amounts, including any zero reset; informational `usdtApproval` is ignored. The actual paymaster and all its bytes remain in the validated UserOp.\n\nLI.FI V3 recognizes all three single and three multiple native/ERC20 entrypoint signatures from the public [GenericSwapFacetV3 interface](https://github.com/lifinance/contracts/blob/main/src/Facets/GenericSwapFacetV3.sol) and [SwapData tuple](https://github.com/lifinance/contracts/blob/main/src/Libraries/LibSwap.sol), inspected 2026-09-08. The supported subset is ordered linear routes, one authorized deposit, consistent first/last assets, no cycles or split input deposits, and an encoded positive output minimum. Nested target, spender, assets, amount, deposit flag and full bytes/hash remain visible. No router address, including a local fixture, is trusted by default. A custom pure verifier must return the same immutable financial facts; its implementation is application-owned trusted code.\n\nA swap policy supplies an independently approved estimate and minimum. Review binds the encoded minimum to that policy, the build quote and the intent's slippage floor. If the first quote arrives only in the unsigned build, the application must establish the owner's quote expectation before preparing a signable review. ABI validation does not prove quote authenticity, deployed diamond facets, router bytecode integrity, delivery, or testnet router availability. Durable receipts establish settlement. No on-chain authority is promised for Base mainnet.\n\nLimits: 128 KiB per byte field, bounded total snapshot size and depth, 64 Kernel calls, 16 route steps and 16 initialization owners. All financial amounts use integer base units without floating-point conversion. `computeUserOpHash` and `deriveGasPermitDigest` remain pure helpers for explicit positive EVM chain IDs; computing a hash never grants chain capability.\n\nDevelopment from this repository:\n\n```sh\npnpm install --frozen-lockfile\npnpm typecheck\npnpm exec vitest run test/review.spec.ts test/client.spec.ts --maxWorkers=2 --minWorkers=1\npnpm build\npnpm test:packed\n```\n\nThe compact harness consumes actual backend Kernel byte producers. Typecheck checks bidirectional structural compatibility against the sibling SDK's public wire schema. These repository checks need the backend and SDK source; the packed runtime and external consumer need neither. Packed verification installs the tarball into a clean temporary Node 22 project, checks external TypeScript exports, executes a Node ESM review and bundles/runs the browser target in an isolated JavaScript context without Node globals. It does not claim an actual wallet, browser brand, chain execution or settlement. Artifacts and SHA-256 are printed for review. React and first-party integration are separate tasks.\n\n\n## Per-instance signing and recovery\n\n```ts\nimport { createWallet, createEip1193OwnerSigner, createOperationStorage, WalletSubmissionError } from '@botanary/wallet';\n\nconst signer = createEip1193OwnerSigner({ provider, address: selectedOwner.address, chainId: 84532,\n  sessionId: providerSessionRevision });\nconst wallet = createWallet({\n  binding: { customerId, sessionId, accountId, accountAddress, ownerAddress, chainId: 84532 },\n  currentContext: () => readCurrentHostContext(),\n  signer,\n  policy: approvedPolicy,\n  transport: authenticatedTransport,\n  storage: createOperationStorage(localStorage, 'my-app-wallet'),\n});\nconst action = wallet.prepare(unsignedBuild, { ...approvedBinding, operationId, attemptId });\n// Present action.review before the owner explicitly requests submission.\ntry {\n  const result = await action.submit({ signal: abortController.signal });\n  showDurableStatus(result.status);\n} catch (error) {\n  if (error instanceof WalletSubmissionError) rememberHandle(error.handle);\n}\n// A later explicit lookup, including after a page reload:\nconst result = await wallet.recover(operationId, attemptId);\n// Dispose provider listeners when the signer is replaced.\nsigner.dispose();\n```\n\nApplication values in this example are integration inputs, not package globals. `currentContext` is required and synchronous: return the live customer, host session, account ID/address, owner and chain, or null. Use public opaque identifiers, never bearer tokens. Rotate the host `sessionId` on logout/login or account-context replacement, including a switch away and back. A recovery handle belongs to that exact context; applications that replace their session identity must explicitly restore an authorized matching context for lookup or perform their own authenticated durable-status lookup. No handle grants authentication.\n\n`prepare` synchronously snapshots the build, expected binding and application policy. Each returned action exposes its immutable canonical review, `state`, `handle`, one-shot `submit`, local `cancel`, and status-only `reconcile`. The wallet also claims each operation/attempt pair once per instance. An existing saved handle refuses signing after reload. A fresh build or gas fallback is an explicit new owner review; the package never rebuilds, switches chains, retries relay or silently changes fees.\n\n`WalletTransport<Status>` has `relay({handle, userOp, userOpHash})` and `lookup(handle)`. Both return `{handle, status}`. The application adapter must map the durable API result to the original operation ID, attempt ID, original hash, completed hash and context; the package checks that returned envelope before exposing status. Do not fabricate a matching envelope around an unchecked response. Authentication and durable status interpretation belong to that adapter. A submitted acknowledgement does not establish settlement.\n\nBefore relay, the package saves only `{version, binding, operationId, attemptId, originalHash, userOpHash}`. `OperationStorage` can be backed by IndexedDB or another durable application store; `createOperationStorage` adapts an explicitly supplied Web Storage object and refuses conflicting overwrites. Storage failure blocks relay. Without injected storage, the frozen handle is retained only in the action/error and the application must preserve it for reload recovery. Stored handles never contain signatures, signed UserOps, callback functions or credentials. Separate browser tabs need application coordination and server idempotency for the same logical operation; local storage is not a distributed submission lock.\n\nEvery signer/storage/transport boundary checks the host context, with provider checks and expiry/cancellation fences throughout submission. Cancellation before relay stops subsequent work and cannot close an already displayed provider prompt. An already signed independent USDC permit cannot be revoked by cancelling this local action. Once relay starts, cancellation returns false. Any error after that point, including a lost response, changed identity or mismatched acknowledgement, becomes `WalletSubmissionError` with the original handle and `state: 'uncertain'`. Only explicit read-only lookup follows. Recovery needs the authenticated host context but does not require a connected signer or an unexpired review.\n\n## Owner signer protocols\n\n`createEip1193OwnerSigner` accepts an explicit provider implementing `request`, `on` and `removeListener`. It requires a caller-supplied provider session revision, reads `eth_accounts` and `eth_chainId` before and after prompts, sends `personal_sign` with `[digest32, ownerAddress]`, normalizes 65-byte signature recovery parity, and verifies the recovered EIP-191 signer. Account, chain, and disconnect events permanently invalidate that adapter instance. The [EIP-1193 request, events and errors](https://eips.ethereum.org/EIPS/eip-1193) were inspected on 2026-09-08. The adapter does not request permissions, switch chains, use `eth_sign`, extract keys, or advertise raw signing. Missing raw capability produces `raw_digest_unsupported` before any prompt; explicitly choose native or an available USDT method and approve a new build.\n\n`createViemOwnerSigner` supports a caller-owned viem account. It calls `account.signMessage({ message: { raw: digest32 } })`, which signs the 32 message bytes with the EIP-191 prefix. It does not accept private-key material. The caller provides a live identity callback and rotates `sessionId` whenever its account session is restored. Raw digest support is absent unless the caller separately supplies a documented `signRawDigest` callback.\n\n`createPrivyOwnerSigner` is the named Privy embedded-wallet adapter. Pass the selected Privy `ConnectedWallet`, reviewed `userId`, wallet ID, address, chain, session revision, and a callback that reads those current facts. The asynchronous factory gets the wallet's documented EIP-1193 provider and uses `personal_sign`; it accepts no Privy app secret or private key. It refuses a non-Privy wallet, logout, user replacement, wallet replacement, address or chain change, restored provider session, and disconnected provider. Dispose it on logout or wallet replacement. The adapter is supported by protocol conformance tests. Calling the complete Privy and Base Sepolia journey verified remains pending until the live acceptance report exists.\n\nSignature inputs are exact. Proof signatures and owner UserOp signatures are EIP-191 signatures over the 32 digest bytes, not the UTF-8 characters of their hexadecimal spelling. A reviewed USDC permit uses an optional raw secp256k1 signature over the 32-byte Kernel-wrapped permit digest. The resulting signature is a recoverable 65-byte `r || s || v` value; parity `0` or `1` is normalized to `27` or `28`, and recovery must equal the reviewed owner. Generic `eth_sign` is never treated as a raw-digest capability.\n\n`createCallbackOwnerSigner` requires `identity`, a live `currentIdentity` callback, and `signPersonalMessage(digest32)` implementing EIP-191 over the digest bytes. Its identity includes address, chain and a non-secret provider-session revision; change that revision when the provider session changes. Supply `signRawDigest(digest32)` only for an explicit documented secp256k1 raw-digest callback. Both modes verify recovery against the exact requested digest. For USDC the sequence is raw wrapped permit signature, exact packed paymaster data `(uint8(0), token, uint256 amount, root-prefix + signature)`, completed UserOp hash, then EIP-191 owner signature. No provider-specific SDK is imported.\n\nLocal evidence uses deterministic fixture keys through callback, viem, Privy-shaped, and EIP-1193 protocol doubles, plus the clean packed Node and browser-target lifecycle. It does not certify an actual Privy browser session, hardware wallet, browser extension, current Kernel deployment, public testnet execution, or settlement. Provider rejection, unauthorized or locked state, disconnect, unsupported method, changed identity, and invalid signature are mapped to safe structured codes without forwarding provider messages or payloads.\n\nPublic authority intents add an immutable `authority` expectation and a caller-owned trusted module policy. The reviewer derives the permanent permission ID from the validator, initialization and salt, requires one registered agent owner, refuses ERC-7739 message permissions, decodes all known session and action policies, and compares every executor and account-global configuration call with the durable compiled snapshot. Unknown policy, selector, module or configuration bytes remain visible and make the review nonsignable. Permanent revocation requires the exact GrantExecutor revoke plus Smart Session removal pair under the explicit sponsored-revocation gas policy. The common one-shot signer and recovery lifecycle is unchanged.\n\n## What ships in the npm tarball\n\nAllowlisted declarations (no declaration maps), one bundled and minified `dist/index.js` (no source\nmaps, no comments; `viem` external), this README, the changelog, and `LICENSE`.\n`pnpm run audit:artifact` verifies the exact tarball.\n\nThis is an **advanced transparent security package, not a concealed implementation.** Fifteen of its\nsixteen runtime exports are `signer-defense` - exact calldata decoding, canonical-encoding\nenforcement, EntryPoint v0.7 hash and EIP-2612/Kernel permit-digest re-derivation, intent\ncomparison, signer identity fencing, one-shot relay and opaque recovery handles - each with a\nwritten threat argument in\n[`docs/specs/2026-09-10-protected-sdk-integration-boundary.inventory.md`](../../docs/specs/2026-09-10-protected-sdk-integration-boundary.inventory.md).\nIt contains no private route construction, no provider assumptions and no duplicated backend\ndecision. The implementation of any downloaded browser artifact is inspectable; this package does\nnot claim otherwise.\n","readmeFilename":"README.md"}