Skip to content
Femtech-webPublic

About

Private authorization for autonomous Solana agents, encrypted mandates, bounded delegation, and one-use vault execution without sharing wallet keys.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

6 Commits

Folders and files

Repository files navigation

Solveil

Solveil

Give agents a mandate. Not your wallet.

Private authorization and bounded delegation for autonomous Solana agents.

Devnet proof · How it works · Run locally · Agent skill · SOLVEIL token · @solveil_agent

Devnet · pre-audit. Solveil moves real test assets through a deployed Solana program and Arcium MPC, but it is not production custody software. Do not use production funds.

The canonical SOLVEIL project token is live on Solana Mainnet through ClawPump → pump.fun at 6FSzTSqu...eXFTHh. Token launch does not imply that the unaudited authorization protocol itself is on Mainnet; the verified program and private-execution proof remain Devnet.

The problem

An autonomous agent needs enough authority to do useful work. Today, that usually means one of four bad choices:

  • give the agent a hot wallet;
  • publish the owner's strategy and spending limits onchain;
  • trust policy checks running inside the same process as the agent; or
  • require a human signature for every action and lose autonomy.

Solveil introduces a different primitive: private, bounded authority.

The owner deposits assets into a program-controlled vault, encrypts the operating limits locally, and grants an agent only the capabilities it needs. The agent can request an action, but it never receives the owner's wallet key and never sees the hidden limits. Arcium evaluates the encrypted mandate. An allowed request becomes one exact, expiring, executor-bound permit that the Solveil vault can consume once.

owner wallet
    │ deposits assets + encrypts rules locally
    ▼
Solveil vault ── mandate ── grant ──► agent requests an exact action
    ▲                                      │
    │                                      ▼
    └──── executes once ◄── permit ◄── Arcium private allow / deny

What Solveil guarantees

Property Protocol rule
No wallet handoff The agent receives a grant, never the owner's unrestricted signing key.
Private limits Per-action and aggregate limits are encrypted before publication.
Exact execution A permit commits to the executor, action, amount, destination, policy version, nonce and expiry.
One use Successful execution consumes the permit; a retry cannot move funds again.
Bounded delegation Every child grant must be strictly narrower than its parent.
Immediate invalidation Expiry, revocation, pause and policy-version changes invalidate dependent authority.
Shared private budget Mandate-wide counters stop a delegation tree from multiplying the owner's hidden budget.

Solveil is an authorization layer, not an agent strategy and not a private DEX. It can sit behind treasury agents, trading agents, payment agents, DAOs and agent-to-agent workflows.

Real Devnet proof

The strongest proof begins in the real owner interface—not in a fixture.

On 1 October 2026, a connected Phantom wallet used /app to create a new wallet-owned vault, deposit 10 proof tokens, encrypt and publish a mandate, and grant the registered Solveil executor bounded authority. The authenticated agent bridge discovered that grant, requested a 0.5-token SPL transfer to the then-current ClawPump agent wallet, waited for Arcium's private decision, executed the exact approved transfer, and indexed the consumed receipt back into the app.

Evidence Devnet account or transaction
Owner-created vault 6a141HGH...WMwK8
Encrypted mandate Hv6uW4Jy...1yCUX
Bounded agent grant ELTo5eh4...FHSV2
One-use permit DKQJWB6E...5HuMX
Queue private evaluation 36b4oMnq...Gr5Ze
Execute exact transfer 34yytbUR...otdHJd

Independent reads after execution showed:

  • vault balance: 9.5 tokens;
  • agent-wallet balance: 0.5 token;
  • grant usage: 1;
  • grant spend: 500,000 base units; and
  • permit state: consumed.

An immediate retry returned idempotentReplay: true and moved no additional funds. The owner app then displayed the consumed permit and receipt.

Additional protocol proof

The repeatable Devnet smoke flow also proves both execution adapters against public Arcium callbacks:

The deeper two-node localnet suite adds hidden-budget denial, mismatched-action rejection, ancestor revocation and replay rejection.

How it works

1. The owner creates the boundary

The owner connects a wallet, creates a vault and deposits an SPL asset. Solana accounts remain the source of truth for ownership; Solveil does not need a central database to decide who owns a vault.

2. The owner encrypts the mandate

Private values—such as the per-action ceiling, total budget and use count—are encrypted locally for Arcium. The onchain mandate stores ciphertext and public routing data, not those plaintext limits.

3. The owner grants a capability

A grant identifies the agent executor, action family, public ceiling, expiry, remaining uses and delegation depth. The public envelope limits what may even be asked; the encrypted mandate makes the final private decision.

4. The agent requests work

The agent bridge discovers only grants assigned to its registered executor. It builds an exact action and queues encrypted evaluation with an idempotency key.

5. Arcium returns a decision

Arcium MPC evaluates the request against the encrypted mandate. A denial reveals no private threshold. An approval creates a permit bound to the exact request and registered executor.

6. The vault executes once

The executor submits the approved action. The Solana program validates the permit again, signs only through the vault PDA, updates shared counters and marks the permit consumed.

7. Agents may delegate less authority

A parent agent can issue a child grant only when it has the Redelegate right. The child must preserve the same owner, vault, mandate and asset while reducing rights, actions, amount, uses, expiry or remaining depth. It can never grow beyond the parent.

Authority model

Object Role
Owner Holds root authority and can pause, revoke, rotate policy or withdraw.
Vault Holds the asset and signs only protocol-validated execution.
Mandate Stores encrypted policy material, version and shared counters.
Grant Gives one registered executor a bounded public capability.
Permit Commits one approved request to one executor and one expiry.
Executor Signs restricted Solveil instructions through the authenticated bridge.
Public agent Provides the user-facing identity and job interface; it is not the custody boundary.

The public ClawPump agent wallet and the registered Solveil executor are intentionally separate. Replacing the public agent does not transfer root authority or invalidate the protocol deployment. Owners grant the restricted executor; the hosted agent supplies identity, conversation and tokenization.

Access and delegation modes

Solveil supports four ways to use confidential policy data:

  1. Compute — evaluate privately and reveal no plaintext.
  2. Recipient sealed — re-encrypt an authorized result to one registered user or agent key.
  3. Execute — consume an exact, expiring, one-use permit through the vault.
  4. Public reveal — deliberately reveal selected policy values. This is owner-only and irreversible.

Delegation applies the same principle to agents: each specialist receives a smaller keycard, not the parent's key.

Execution adapters

All adapters share the same private approval core.

Adapter What the permit binds Status
SPL transfer Mint, destination token account and exact amount Verified on Devnet
x402 exact payment Merchant ATA, amount and required invoice memo Verified on Devnet
Jupiter swap Input/output pair, exact input, minimum output, slippage, raw Router instruction and ordered account privileges Implemented and unit-tested; Mainnet-fork validation and tiny canary still pending

Jupiter does not exist on Solana Devnet, so Solveil does not mislabel a mocked Devnet route as live Jupiter proof.

Agent integration

The same restricted service is available as an authenticated HTTP bridge and an MCP server.

Tool Purpose
solveil_list_grants Discover active grants assigned to the registered executor.
solveil_request_permit Queue encrypted evaluation for an exact public request.
solveil_permit_status Read the public permit lifecycle without exposing private limits.
solveil_execute_permit Execute only the adapter call committed by an approved permit.
solveil_delegate_grant Create a strictly narrower child grant.

The reusable skills/solveil/SKILL.md teaches an agent the safe workflow and forbids wallet-key fallbacks, policy probing and fabricated execution claims.

ClawPump custom skills currently provide prompt instructions, not an automatic external tool installation. The Solveil skill therefore emits a structured SOLVEIL_HANDOFF when those tools are absent. The bridge is implemented and Devnet-tested locally; stable HTTPS hosting and a supported hosted-agent tool connection are still required before claiming that ClawPump chat executes the flow by itself.

What is real today

Surface Status
Upgradeable Solveil program Deployed on Solana Devnet
Four encrypted computation definitions Finalized on public Arcium Devnet
Browser vault → mandate → grant flow Verified with a real wallet
Private allow and deny decisions Verified through public Arcium callbacks
SPL and x402 vault execution Verified on Devnet
Replay protection and exact one-use permits Verified
Wallet-scoped Helius indexing Implemented and tested
Authenticated agent bridge and MCP tools Implemented and Devnet-tested locally
Narrower agent-to-agent delegation Implemented and tested
Jupiter adapter Implemented; fork/canary testing pending
Public HTTPS bridge Not deployed
Native ClawPump hosted-tool connection Not available in the current dashboard
SOLVEIL project token Live on Mainnet through ClawPump
Mainnet Solveil deployment Not deployed
Independent security audit Not completed

Deployed addresses

The deployment was independently read back on 1 October 2026.

Component Devnet address
Solveil program 99Ds3myo...NbJyum
Arcium MXE 5r4az19J...4jh5N
Registered executor 4DC2y9P4...xCoJp
SOLVEIL token 6FSzTSqu...eXFTHh
evaluate_policy ARP599YfNrqsK8cqmGzLsqYjf5vRTwbATVbSNnqCLrEs
disclose_policy CUoeJ7V8SSxsQ7qS5rRgord97pLS1uxXrtUdG4P9tWUZ
private_summary Fsb8BGGXojHzRFKUbGiYh2UgTx3cTFnj5RGxSXSGSxSV
reveal_policy DsRmWjBHPV4KswNxJ21kHbGxTeK8Ta9xD9WWPW92fuVL

Repository map

apps/web/            landing page, owner workspace and compact docs
encrypted-ixs/       Arcis encrypted policy instructions
packages/protocol/   deterministic rights, grants, policy and permit model
packages/sdk/        encryption, disclosure and PDA helpers
packages/mcp/        MCP server and authenticated execution bridge
programs/solveil/    Anchor vault, callbacks, delegation and execution
scripts/             deployment, registration and Devnet proof scripts
skills/solveil/      reusable agent instructions and tool reference
tests/               Solana + Arcium end-to-end test

Run it locally

Prerequisites

  • Node.js 20+
  • pnpm 10+
  • Solana CLI 3.1.10
  • Anchor CLI 1.0.2
  • Rust 1.89.0
  • Docker Desktop for the full Arcium localnet suite

Install and verify

pnpm install
pnpm check
pnpm test
pnpm build

The current suite contains 47 passing tests across the protocol, SDK, MCP bridge and web application.

Start the web app:

pnpm dev
  • / — product story and protocol proof
  • /app — wallet-owned vault, mandate, grant and receipt workspace
  • /docs — compact owner and agent integration guide

Configure Devnet

Copy the example and keep every secret server-side:

cp .env.example .env
chmod 600 .env

Use a dedicated Devnet keypair and a reliable Devnet RPC. The browser receives only public program and identity values; Helius, Jupiter, bridge and executor secrets must never use a VITE_ prefix.

SOLANA_RPC_URL=https://devnet.helius-rpc.com/?api-key=<HELIUS_API_KEY>
ANCHOR_PROVIDER_URL=https://devnet.helius-rpc.com/?api-key=<HELIUS_API_KEY>
HELIUS_RPC_URL=https://devnet.helius-rpc.com/?api-key=<HELIUS_API_KEY>
ANCHOR_WALLET=/absolute/path/to/target/devnet-deployer.json
SOLVEIL_PROGRAM_ID=99Ds3myogFWUbQXqec1T3EbhhFpqqB6huiUW8sNbJyum

Create free API keys through the Helius dashboard and Jupiter developer portal. Jupiter is used server-side and is not required for the verified Devnet SPL/x402 proof.

Run the agent bridge

pnpm bridge

The bridge exposes:

  • GET /healthz
  • GET /v1/capabilities
  • authenticated GET /v1/grants
  • POST /v1/permit-requests
  • GET /v1/permits/{permit}
  • POST /v1/permits/{permit}/executions
  • POST /v1/delegations
  • GET /openapi.json

Configure SOLVEIL_EXECUTOR_PUBLIC_KEY, a long random SOLVEIL_BRIDGE_API_KEY, and exactly one executor-secret source. Local development may use the ignored SOLVEIL_EXECUTOR_KEYPAIR_PATH. Production must inject the base64-encoded 64-byte secret as SOLVEIL_EXECUTOR_SECRET_KEY through the host's secret manager; production rejects keypair-file loading.

Run protocol proofs

Compile the Solana program and encrypted instructions:

pnpm build:program

Run the two-node Solana + Arcium localnet suite:

solana-keygen new --outfile target/test-wallet.json --no-bip39-passphrase
pnpm test:program

Initialize or resume the four Devnet computation definitions, then run the repeatable public-Devnet proof:

pnpm deploy:devnet:circuits
pnpm test:devnet:smoke
pnpm test:devnet:bridge

The deployment helper skips finalized definitions, verifies pending circuit bytes before upload, throttles writes and retries transient blockhash failures.

Security and privacy boundary

Solveil protects mandate values and recipient-sealed results. It does not claim to hide all Solana metadata or downstream protocol effects. Public execution still reveals whatever the selected adapter and destination protocol publish onchain.

Allow/deny outcomes can leak information when an attacker is allowed to probe a policy repeatedly. Narrow grants, rate limits, short expiries and the rule to stop after denial are part of the security model.

Before Mainnet custody, Solveil still needs:

  • an independent Solana/Anchor and cryptographic-integration review;
  • production monitoring and a tested incident runbook;
  • multisig-controlled upgrade and recovery authorities;
  • Mainnet Arcium configuration and cost verification; and
  • adversarial Jupiter fork tests followed by a deliberately tiny canary.

Built with

  • Solana and Anchor for vault enforcement
  • Arcium for encrypted MPC evaluation and recipient re-encryption
  • Helius for reliable RPC and wallet-scoped account indexing
  • Jupiter for composable swap instructions
  • x402 exact SVM for outcome-verifiable agent payments
  • Model Context Protocol for reusable agent tooling
  • ClawPump for the public agent identity and token launch surface

License

MIT. See LICENSE.

About

Private authorization for autonomous Solana agents, encrypted mandates, bounded delegation, and one-use vault execution without sharing wallet keys.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages