Give agents a mandate. Not your wallet.
Private authorization and bounded delegation for autonomous Solana agents.
Devnet proof · How it works · Run locally · Agent skill · SOLVEIL token · @solveil_agent
Devnet · pre-audit. Solveil moves real test assets through a deployed Solana program and Arcium MPC, but it is not production custody software. Do not use production funds.
The canonical SOLVEIL project token is live on Solana Mainnet through
ClawPump → pump.fun at
6FSzTSqu...eXFTHh.
Token launch does not imply that the unaudited authorization protocol itself is
on Mainnet; the verified program and private-execution proof remain Devnet.
An autonomous agent needs enough authority to do useful work. Today, that usually means one of four bad choices:
- give the agent a hot wallet;
- publish the owner's strategy and spending limits onchain;
- trust policy checks running inside the same process as the agent; or
- require a human signature for every action and lose autonomy.
Solveil introduces a different primitive: private, bounded authority.
The owner deposits assets into a program-controlled vault, encrypts the operating limits locally, and grants an agent only the capabilities it needs. The agent can request an action, but it never receives the owner's wallet key and never sees the hidden limits. Arcium evaluates the encrypted mandate. An allowed request becomes one exact, expiring, executor-bound permit that the Solveil vault can consume once.
owner wallet
│ deposits assets + encrypts rules locally
▼
Solveil vault ── mandate ── grant ──► agent requests an exact action
▲ │
│ ▼
└──── executes once ◄── permit ◄── Arcium private allow / deny
| Property | Protocol rule |
|---|---|
| No wallet handoff | The agent receives a grant, never the owner's unrestricted signing key. |
| Private limits | Per-action and aggregate limits are encrypted before publication. |
| Exact execution | A permit commits to the executor, action, amount, destination, policy version, nonce and expiry. |
| One use | Successful execution consumes the permit; a retry cannot move funds again. |
| Bounded delegation | Every child grant must be strictly narrower than its parent. |
| Immediate invalidation | Expiry, revocation, pause and policy-version changes invalidate dependent authority. |
| Shared private budget | Mandate-wide counters stop a delegation tree from multiplying the owner's hidden budget. |
Solveil is an authorization layer, not an agent strategy and not a private DEX. It can sit behind treasury agents, trading agents, payment agents, DAOs and agent-to-agent workflows.
The strongest proof begins in the real owner interface—not in a fixture.
On 1 October 2026, a connected Phantom wallet used /app to create a new
wallet-owned vault, deposit 10 proof tokens, encrypt and publish a mandate, and
grant the registered Solveil executor bounded authority. The authenticated
agent bridge discovered that grant, requested a 0.5-token SPL transfer to the
then-current ClawPump agent wallet, waited for Arcium's private decision,
executed the exact approved transfer, and indexed the consumed receipt back
into the app.
| Evidence | Devnet account or transaction |
|---|---|
| Owner-created vault | 6a141HGH...WMwK8 |
| Encrypted mandate | Hv6uW4Jy...1yCUX |
| Bounded agent grant | ELTo5eh4...FHSV2 |
| One-use permit | DKQJWB6E...5HuMX |
| Queue private evaluation | 36b4oMnq...Gr5Ze |
| Execute exact transfer | 34yytbUR...otdHJd |
Independent reads after execution showed:
- vault balance: 9.5 tokens;
- agent-wallet balance: 0.5 token;
- grant usage: 1;
- grant spend: 500,000 base units; and
- permit state: consumed.
An immediate retry returned idempotentReplay: true and moved no additional
funds. The owner app then displayed the consumed permit and receipt.
The repeatable Devnet smoke flow also proves both execution adapters against public Arcium callbacks:
- SPL evaluation → private callback → one-use execution
- x402 evaluation → private callback → memo-bound payment
The deeper two-node localnet suite adds hidden-budget denial, mismatched-action rejection, ancestor revocation and replay rejection.
The owner connects a wallet, creates a vault and deposits an SPL asset. Solana accounts remain the source of truth for ownership; Solveil does not need a central database to decide who owns a vault.
Private values—such as the per-action ceiling, total budget and use count—are encrypted locally for Arcium. The onchain mandate stores ciphertext and public routing data, not those plaintext limits.
A grant identifies the agent executor, action family, public ceiling, expiry, remaining uses and delegation depth. The public envelope limits what may even be asked; the encrypted mandate makes the final private decision.
The agent bridge discovers only grants assigned to its registered executor. It builds an exact action and queues encrypted evaluation with an idempotency key.
Arcium MPC evaluates the request against the encrypted mandate. A denial reveals no private threshold. An approval creates a permit bound to the exact request and registered executor.
The executor submits the approved action. The Solana program validates the permit again, signs only through the vault PDA, updates shared counters and marks the permit consumed.
A parent agent can issue a child grant only when it has the Redelegate right.
The child must preserve the same owner, vault, mandate and asset while reducing
rights, actions, amount, uses, expiry or remaining depth. It can never grow
beyond the parent.
| Object | Role |
|---|---|
| Owner | Holds root authority and can pause, revoke, rotate policy or withdraw. |
| Vault | Holds the asset and signs only protocol-validated execution. |
| Mandate | Stores encrypted policy material, version and shared counters. |
| Grant | Gives one registered executor a bounded public capability. |
| Permit | Commits one approved request to one executor and one expiry. |
| Executor | Signs restricted Solveil instructions through the authenticated bridge. |
| Public agent | Provides the user-facing identity and job interface; it is not the custody boundary. |
The public ClawPump agent wallet and the registered Solveil executor are intentionally separate. Replacing the public agent does not transfer root authority or invalidate the protocol deployment. Owners grant the restricted executor; the hosted agent supplies identity, conversation and tokenization.
Solveil supports four ways to use confidential policy data:
- Compute — evaluate privately and reveal no plaintext.
- Recipient sealed — re-encrypt an authorized result to one registered user or agent key.
- Execute — consume an exact, expiring, one-use permit through the vault.
- Public reveal — deliberately reveal selected policy values. This is owner-only and irreversible.
Delegation applies the same principle to agents: each specialist receives a smaller keycard, not the parent's key.
All adapters share the same private approval core.
| Adapter | What the permit binds | Status |
|---|---|---|
| SPL transfer | Mint, destination token account and exact amount | Verified on Devnet |
| x402 exact payment | Merchant ATA, amount and required invoice memo | Verified on Devnet |
| Jupiter swap | Input/output pair, exact input, minimum output, slippage, raw Router instruction and ordered account privileges | Implemented and unit-tested; Mainnet-fork validation and tiny canary still pending |
Jupiter does not exist on Solana Devnet, so Solveil does not mislabel a mocked Devnet route as live Jupiter proof.
The same restricted service is available as an authenticated HTTP bridge and an MCP server.
| Tool | Purpose |
|---|---|
solveil_list_grants |
Discover active grants assigned to the registered executor. |
solveil_request_permit |
Queue encrypted evaluation for an exact public request. |
solveil_permit_status |
Read the public permit lifecycle without exposing private limits. |
solveil_execute_permit |
Execute only the adapter call committed by an approved permit. |
solveil_delegate_grant |
Create a strictly narrower child grant. |
The reusable skills/solveil/SKILL.md teaches an
agent the safe workflow and forbids wallet-key fallbacks, policy probing and
fabricated execution claims.
ClawPump custom skills currently provide prompt instructions, not an automatic
external tool installation. The Solveil skill therefore emits a structured
SOLVEIL_HANDOFF when those tools are absent. The bridge is implemented and
Devnet-tested locally; stable HTTPS hosting and a supported hosted-agent tool
connection are still required before claiming that ClawPump chat executes the
flow by itself.
| Surface | Status |
|---|---|
| Upgradeable Solveil program | Deployed on Solana Devnet |
| Four encrypted computation definitions | Finalized on public Arcium Devnet |
| Browser vault → mandate → grant flow | Verified with a real wallet |
| Private allow and deny decisions | Verified through public Arcium callbacks |
| SPL and x402 vault execution | Verified on Devnet |
| Replay protection and exact one-use permits | Verified |
| Wallet-scoped Helius indexing | Implemented and tested |
| Authenticated agent bridge and MCP tools | Implemented and Devnet-tested locally |
| Narrower agent-to-agent delegation | Implemented and tested |
| Jupiter adapter | Implemented; fork/canary testing pending |
| Public HTTPS bridge | Not deployed |
| Native ClawPump hosted-tool connection | Not available in the current dashboard |
| SOLVEIL project token | Live on Mainnet through ClawPump |
| Mainnet Solveil deployment | Not deployed |
| Independent security audit | Not completed |
The deployment was independently read back on 1 October 2026.
| Component | Devnet address |
|---|---|
| Solveil program | 99Ds3myo...NbJyum |
| Arcium MXE | 5r4az19J...4jh5N |
| Registered executor | 4DC2y9P4...xCoJp |
| SOLVEIL token | 6FSzTSqu...eXFTHh |
evaluate_policy |
ARP599YfNrqsK8cqmGzLsqYjf5vRTwbATVbSNnqCLrEs |
disclose_policy |
CUoeJ7V8SSxsQ7qS5rRgord97pLS1uxXrtUdG4P9tWUZ |
private_summary |
Fsb8BGGXojHzRFKUbGiYh2UgTx3cTFnj5RGxSXSGSxSV |
reveal_policy |
DsRmWjBHPV4KswNxJ21kHbGxTeK8Ta9xD9WWPW92fuVL |
apps/web/ landing page, owner workspace and compact docs
encrypted-ixs/ Arcis encrypted policy instructions
packages/protocol/ deterministic rights, grants, policy and permit model
packages/sdk/ encryption, disclosure and PDA helpers
packages/mcp/ MCP server and authenticated execution bridge
programs/solveil/ Anchor vault, callbacks, delegation and execution
scripts/ deployment, registration and Devnet proof scripts
skills/solveil/ reusable agent instructions and tool reference
tests/ Solana + Arcium end-to-end test
- Node.js 20+
- pnpm 10+
- Solana CLI 3.1.10
- Anchor CLI 1.0.2
- Rust 1.89.0
- Docker Desktop for the full Arcium localnet suite
pnpm install
pnpm check
pnpm test
pnpm buildThe current suite contains 47 passing tests across the protocol, SDK, MCP bridge and web application.
Start the web app:
pnpm dev/— product story and protocol proof/app— wallet-owned vault, mandate, grant and receipt workspace/docs— compact owner and agent integration guide
Copy the example and keep every secret server-side:
cp .env.example .env
chmod 600 .envUse a dedicated Devnet keypair and a reliable Devnet RPC. The browser receives
only public program and identity values; Helius, Jupiter, bridge and executor
secrets must never use a VITE_ prefix.
SOLANA_RPC_URL=https://devnet.helius-rpc.com/?api-key=<HELIUS_API_KEY>
ANCHOR_PROVIDER_URL=https://devnet.helius-rpc.com/?api-key=<HELIUS_API_KEY>
HELIUS_RPC_URL=https://devnet.helius-rpc.com/?api-key=<HELIUS_API_KEY>
ANCHOR_WALLET=/absolute/path/to/target/devnet-deployer.json
SOLVEIL_PROGRAM_ID=99Ds3myogFWUbQXqec1T3EbhhFpqqB6huiUW8sNbJyumCreate free API keys through the Helius dashboard and Jupiter developer portal. Jupiter is used server-side and is not required for the verified Devnet SPL/x402 proof.
pnpm bridgeThe bridge exposes:
GET /healthzGET /v1/capabilities- authenticated
GET /v1/grants POST /v1/permit-requestsGET /v1/permits/{permit}POST /v1/permits/{permit}/executionsPOST /v1/delegationsGET /openapi.json
Configure SOLVEIL_EXECUTOR_PUBLIC_KEY, a long random
SOLVEIL_BRIDGE_API_KEY, and exactly one executor-secret source. Local
development may use the ignored SOLVEIL_EXECUTOR_KEYPAIR_PATH. Production
must inject the base64-encoded 64-byte secret as
SOLVEIL_EXECUTOR_SECRET_KEY through the host's secret manager; production
rejects keypair-file loading.
Compile the Solana program and encrypted instructions:
pnpm build:programRun the two-node Solana + Arcium localnet suite:
solana-keygen new --outfile target/test-wallet.json --no-bip39-passphrase
pnpm test:programInitialize or resume the four Devnet computation definitions, then run the repeatable public-Devnet proof:
pnpm deploy:devnet:circuits
pnpm test:devnet:smoke
pnpm test:devnet:bridgeThe deployment helper skips finalized definitions, verifies pending circuit bytes before upload, throttles writes and retries transient blockhash failures.
Solveil protects mandate values and recipient-sealed results. It does not claim to hide all Solana metadata or downstream protocol effects. Public execution still reveals whatever the selected adapter and destination protocol publish onchain.
Allow/deny outcomes can leak information when an attacker is allowed to probe a policy repeatedly. Narrow grants, rate limits, short expiries and the rule to stop after denial are part of the security model.
Before Mainnet custody, Solveil still needs:
- an independent Solana/Anchor and cryptographic-integration review;
- production monitoring and a tested incident runbook;
- multisig-controlled upgrade and recovery authorities;
- Mainnet Arcium configuration and cost verification; and
- adversarial Jupiter fork tests followed by a deliberately tiny canary.
- Solana and Anchor for vault enforcement
- Arcium for encrypted MPC evaluation and recipient re-encryption
- Helius for reliable RPC and wallet-scoped account indexing
- Jupiter for composable swap instructions
- x402 exact SVM for outcome-verifiable agent payments
- Model Context Protocol for reusable agent tooling
- ClawPump for the public agent identity and token launch surface
MIT. See LICENSE.