Skip to content

Onboard a trading wallet

Onboarding creates a narrowly scoped one-click trading identity without changing the user's main wallet.

Wallet model

The main wallet remains the AccountCore owner or administrator. It signs permission for a separate trading EOA. The trading EOA can be created by an embedded-wallet or passkey provider, but it must be able to sign secp256k1 EIP-712 data and an EIP-7702 authorization.

Grant only the TRADE permission (1) unless the product has a separate, reviewed reason to grant more. The trading EOA does not need ADMIN or withdrawal permission to place orders.

Values to read before signing

Value Source
account AccountCore account address owned or administered by the main wallet.
accountId AccountCore ID for that account; used by later wallet intents.
Account authorization nonce AccountCore.accountSignerAuthorizationNonces(account).
EIP-7702 nonce Current transaction count of the secondary trading EOA.
chainId Live network chain ID. Testnet currently uses 10143.
delegate Deployed KuruTradingWallet implementation from the deployment configuration.
deadline Near-future Unix timestamp for the AccountCore signature.
expiry Unix timestamp for the trading permission, or 0 for no expiry. Prefer a bounded session expiry.

The AccountCore authorization nonce and EIP-7702 authority nonce are different values. Do not reuse one as the other.

Signature 1: main wallet grants TRADE

The main wallet, or another live AccountCore administrator, signs this EIP-712 message:

Domain
  name: KuruAccountCore
  version: 1
  chainId: <live chain ID>
  verifyingContract: <AccountCore proxy>

Primary type
  AuthorizeAccountSigner(
    address account,
    address authorizer,
    address signer,
    uint32 permissions,
    uint64 expiry,
    uint256 nonce,
    uint256 deadline
  )

Set:

  • account to the AccountCore account;
  • authorizer to the main wallet or current account administrator;
  • signer to the secondary trading EOA;
  • permissions to 1 for TRADE;
  • nonce to the current AccountCore authorization nonce; and
  • deadline and optional expiry to your session policy.

Signature 2: trading EOA delegates itself

The secondary EOA signs the EIP-7702 authorization digest:

keccak256(0x05 || rlp([chainId, delegate, nonce]))

The recovered signer must be the secondary EOA. The delegate must be the configured KuruTradingWallet implementation and nonce must be the secondary EOA's current transaction count.

Represent the resulting tuple as:

{
  "authority": "0x1111111111111111111111111111111111111111",
  "chainId": "10143",
  "delegate": "0x4444444444444444444444444444444444444444",
  "nonce": "7",
  "yParity": "0",
  "r": "0x0000000000000000000000000000000000000000000000000000000000000001",
  "s": "0x0000000000000000000000000000000000000000000000000000000000000002"
}

The values above illustrate encoding only and are not valid signatures.

account_core.authorize_account_signer_by_sig

This method grants the secondary EOA AccountCore permissions using the authorizer's signature. Attach authorization7702 when the same transaction should also delegate the secondary EOA to KuruTradingWallet.

Request

{
  "requestId": "018f5ef2-88a1-7b41-a826-4b679010f87f",
  "method": "account_core.authorize_account_signer_by_sig",
  "wallet": "0x1111111111111111111111111111111111111111",
  "payload": {
    "account": "0x3333333333333333333333333333333333333333",
    "authorizer": "0x3333333333333333333333333333333333333333",
    "signer": "0x1111111111111111111111111111111111111111",
    "permissions": "1",
    "expiry": "1722592000",
    "nonce": "0",
    "deadline": "1720000030",
    "signature": "0x..."
  },
  "authorization7702": {
    "authority": "0x1111111111111111111111111111111111111111",
    "chainId": "10143",
    "delegate": "0x4444444444444444444444444444444444444444",
    "nonce": "7",
    "yParity": "0",
    "r": "0x...32 bytes...",
    "s": "0x...32 bytes..."
  }
}

The request wallet, AccountCore signer, and EIP-7702 authority must all be the same secondary EOA. The JWT must also be bound to that address.

The relay broadcasts one type-0x04 transaction. EIP-7702 installs the trading-wallet delegation before AccountCore processes the signed permission.

Confirm onboarding

After BROADCAST:

  1. Wait for the receipt and require status = 1.
  2. Read the secondary EOA's code at the receipt block and verify the exact delegation indicator for the configured KuruTradingWallet implementation.
  3. Verify AccountSignerAuthorized identifies the expected account/trading EOA and grants TRADE with the intended expiry.
  4. Read the new AccountCore authorization nonce. Use that new value as authNonce in subsequent wallet intents.

These checks are separate. EIP-7702 delegation can remain installed even if the AccountCore call reverts.

Already-delegated wallets

If the secondary EOA is already delegated to the correct implementation, omit authorization7702 or set it to null. Submit only the AccountCore authorization method.

Revocation and rotation

To end a session, revoke the secondary EOA in AccountCore using the main wallet or an administrator. This increments the account authorization epoch and invalidates previously signed wallet intents that contain the old authNonce.

For rotation:

  1. create a new secondary EOA;
  2. onboard and verify it;
  3. switch new order signing to it; and
  4. revoke the old EOA.

The public relay API does not currently expose AccountCore revocation or EIP-7702 delegation clearing.