Skip to content

Relay trust boundaries

The controlled deployment assumes relay API and signer workloads are trusted and protected from compromise. The split architecture still minimizes exposed authority and fails closed at every boundary.

Public client boundary

  • Every request requires a wallet-bound bearer JWT and a successful wallet-admission decision. Static deployments require a real allowlist record; an explicitly configured allow-all testnet deployment admits every valid nonzero wallet.
  • Testnet JWT issuance requires a server-generated one-time challenge, a canonical low-s EOA personal_sign signature, and a fresh admission check. Initial issuance does not accept ERC-1271 signatures.
  • Challenge messages bind the domain, token URI, chain, wallet, nonce, issue time, expiry, and request ID; a successfully exchanged challenge is consumed atomically.
  • JSON decoding is strict and bounded; unknown and duplicate fields are rejected.
  • Only configured typed methods and verified markets are accepted.
  • User-controlled identifiers, payloads, signatures, raw errors, and RPC URLs are excluded from metric labels.
  • Authentication logs and telemetry exclude wallet addresses, challenge text, signatures, and JWTs.
  • Rate, concurrency, frame, body, queue, and owned-byte limits are enforced before expensive work where possible.

API-to-signer boundary

  • The signer is reachable only through the private authenticated transport.
  • The API sends an immutable typed plan, never an arbitrary transaction or signing digest.
  • The signer independently validates method, target, selector, value, calldata, deadline, chain, contract identity, plan digest, and optional authorization.
  • WebSocket affinity can select only a configured sponsor lane; it cannot select a key reference or nonce.
  • Key material is supplied through deployment secrets and never enters configuration files, logs, traces, metrics, API responses, or documentation.
  • The key provider accepts only an opaque key reference and the frozen typed-transaction signing hash.
  • Signed bytes are decoded and compared with every frozen field before broadcast.
  • RPC errors are mapped into bounded accepted, rejected, or unknown classes; raw provider text is not returned to clients.

Chain and dependency authority

Preflight checks reduce avoidable failures but do not replace contract authority at inclusion. Contract state can change after a pinned read. The client must reconcile canonical receipts and expected events/state. Wallet admission, JWT keys, proposed heads, contract identity, key providers, and RPC connectivity are readiness dependencies and fail closed after their documented freshness or timeout bounds.

Explicit non-goals

The public relay does not expose generic calls, arbitrary calldata, payable calls, receipt storage, durable idempotency, client-selected gas/fees, sponsor nonce control, private trigger execution, administrative probes, metrics, or key-management operations.