AgentVault contract reference
Roles
- Owner — the wallet that created the vault (
AgentVaultFactory.createVault's caller). Full control, never capped:ownerExecute,withdraw,withdrawToken,withdrawNFT,setAgent,setCaps,pause/unpause,revoke. - Agent — a key set by the owner. May only call
execute(target, value, data), and only within the allowlist and caps below.
execute(address target, uint256 value, bytes data)
Agent-only, reverts while paused. Checks, in order:
- Target allowlist: the Hartii
TokenFactory, a token's own registered bonding curve (verified live againstTokenFactory.curveOf), the HartiiSwap router,WQUAI, and the Gallery NFT factory. - Per-selector rules —
approveis only allowed against a token this vault can actually trade (WQUAI, a Hartii launch token registered inTokenFactory, or a HartiiSwap LP pair), must carryvalue == 0, and its spender must be either the router or that token's own registered curve;transfer/transferFromare always forbidden; router calls must payaddress(this)(the vault); a router swap call (swapExactETHForTokens,swapExactTokensForETH,swapExactTokensForTokens) additionally has itspathchecked: 2–3 hops only, and every consecutive hop must have a real registered HartiiSwap pair (samefactory.getPair(...)lookup the approvable-token check uses) — anything longer or routed through a non-existent pair reverts before the router is even called;TokenFactory.launch, curvebuy/sell/withdrawCreatorFees,WQUAI.deposit/withdraw, anddeployCollectionare allowed; anything else revertsselector. - Caps —
value(native QUAI sent) must be ≤maxPerTx, and the sum over the last 24 hourly buckets must be ≤maxPerDay.
Emits AgentAction(address indexed target, bytes4 indexed selector, uint256 value).
Owner functions
| Function | Effect |
|---|---|
setAgent(address) | Replace the agent key. |
setCaps(uint256 maxPerTx, uint256 maxPerDay) | maxPerTx must be ≤ maxPerDay; both must be > 0 while an agent is set. |
pause() / unpause() | Agent calls revert while paused. |
revoke() | Clears the agent and pauses in one call. |
withdraw(address to, uint256 amount) | QUAI. |
withdrawToken(address token, address to, uint256 amount) | Any ERC-20. |
withdrawNFT(address collection, address to, uint256 id) | Any ERC-721. |
ownerExecute(address target, uint256 value, bytes data) | Unrestricted — the owner's own escape hatch. |
Revert reasons
not agent, paused, target, selector, recipient, spender, value, per-tx cap,
daily cap, transfer forbidden, caps, not owner, initialized, reentrant, path (a
router swap's path was not 2–3 hops), hop (a router swap path had a hop with no real HartiiSwap
pair).
AgentVaultFactory
function createVault(address agent, uint256 maxPerTx, uint256 maxPerDay) external payable returns (address vault);
function vaultsOf(address owner) external view returns (address[] memory);
event VaultCreated(address indexed vault, address indexed owner, address indexed agent);The target allowlist (TokenFactory, HartiiSwap router, WQUAI, the Gallery NFT factory) is fixed
in the factory's constructor at deploy time and is the same for every vault it creates.