Wallets
A Starknet escrow wallet is a Ready v0.5.0 account contract on Starknet mainnet. Its address is known at creation, before the contract exists on chain, so you can fund it right away.- Fees are paid in STRK. Keep STRK in the wallet in addition to what it will spend.
escrow_executewithstarknetCallsruns the calls as one multicall through the account’s__execute__. It succeeds or fails as a whole.escrow_transfersupportsSTRK,ETH,USDCandUSDT. For other tokens, propose the token’stransfercall withescrow_execute.- Swaps, x402 payments and dashboard withdrawals are not available on Starknet.
- Explorer links for escrow transactions point to voyager.online.
Private balances
STRK20 is Starknet’s privacy pool. A supported token can have a shielded balance in the pool beside its ordinary public balance. The wallet page in the dashboard shows a Private section for Starknet wallets: the shielded balance, found by scanning the pool with the wallet’s viewing key.- A private balance is hidden from people watching the chain. It is not hidden from Chance, which derives the viewing key to scan it, and the pool shares it with an auditor for legal requests.
- The viewing key reads every amount and counterparty the wallet has ever had in the pool. The pool records it once and it cannot be rotated. It cannot spend funds.
strk20_viewing_key_signaturereturns the wallet’s signature over a fixed derivation message built from a constant domain string and the wallet’s address. A client folds that signature into the viewing key. No caller-supplied bytes are signed.
Private actions over MCP
A private action is proved first, then submitted. All STRK20 tools are free and, exceptstrk20_relay_status, need the wallet scope.
1
Check the relay
strk20_relay_status reports whether the relay key is configured, whether the relay service is reachable, and whether the key is accepted for private actions. Skip this if you will submit through escrow_execute.2
Get the relay fee
To relay, call
strk20_pool_fee (optional feeToken, default STRK). It returns a withdraw action that pays the relayer from the private balance. Add it to your actions before proving. A proof commits to its actions, so a fee cannot be added afterwards.3
Serialize the actions
Build the arguments of the pool’s
compile_actions(user_addr, user_private_key, client_actions) as felts. The first felt must be the wallet’s own address. The second is the wallet’s viewing key, so Chance sees it when it signs.4
Sign and prove
strk20_sign_proof_invocation takes wallet and compileActionsCalldata. It builds the invocation against the pinned pool address, signs it with the wallet’s key, sends it to the proving service, and returns the calldata it signed, the signature and the proof (proof.proof and proof.proof_facts). It never signs a hash supplied by the caller. It signs with Chance’s authorization on the wallet, so it works on autonomous wallets only. The proof expires about five minutes after it is produced.5
Submit
Use one of the two paths below before the proof expires.
The proof is not stored with a proposal. Through
escrow_execute, a private action completes only when it executes immediately: an autonomous wallet, an ALLOW and a clean simulation. A held proposal cannot be completed from its approval link; propose again with a fresh proof.
