Contracts — Architecture
🏛️ Custom Account Abstraction Topology
Host Invocation (e.g. transfer call)
│
▼
Soroban Host Auth Interception
│
▼
┌────────────────────────────────────────────────────────┐
│ __check_auth() │
│ 1. Verify Agent Ed25519 Signature │
│ 2. Evaluate Account State (Admin Frozen / Dead-Man) │
│ 3. Evaluate Policy Decision Matrix over Context │
└───────────────────────────┬────────────────────────────┘
│
┌─────────────┴─────────────┐
▼ ▼
Policy Pass Policy Refused
(Transaction Runs) (Err #code, Rollback)
Zero network fee spent🔒 Policy Engine Evaluation Order
__check_auth evaluates checks in strict priority order:
- Host Crypto: Verifies the agent's Ed25519 signature against
signature_payload. - Account State:
admin_frozen == true──► Blocks withAdminFrozen.dead_man_switchexpired (now - last_heartbeat > grace_secs) ──► Blocks withHeartbeatExpired.paused == true──► Blocks withPaused.- Active window inactive (
now < startornow > end) ──► Blocks withOutsideActiveWindow.
- Context Classification:
AssetTransfer(transfer/transfer_fromon SAC tokens): Enforcesper_tx_cap,recipient_allowlist, andwindow_cap.Protocol(Calls to non-token contracts): Enforcesprotocol_allowlistandfunction_allowlist.Unknown: Default-deny refusal withUnknownContract.
⏳ Rolling Window Algorithm
The rolling window spend cap uses a bounded circular log in contract storage:
- Stores
(timestamp, amount)entries within the duration window (e.g. 60s). - Prunes expired entries dynamically during pre-flight checks.
- Guarantees exact rolling volume accumulation across transactions without storage underflow or un-pruned state explosion.
