Skip to main content
venue: starknet. There are no aliases.

What to send

The calls the account will execute in one multicall, as {calls: [{contractAddress, entrypoint, calldata}]}. Over HTTP a bare array of calls also works; over MCP, action must be an object, so use {calls: [...]}. calldata is an array of felt strings. It is detected without venue when every item has a hex contractAddress and a string entrypoint. actionType is the entrypoints joined with +, for example approve+swap.

How calls are decoded

The known tokens are the mainnet contracts of STRK, ETH, USDC, USDC.e and USDT: For a batch, the family is the riskiest call’s: unknown if any call is unknown, otherwise permission if any call grants authority, otherwise transfer.

STRK20 private operations

Calls to the STRK20 privacy pool (mainnet 0x040337b1af3c663e86e333bab5a4b28da8d4652a15a69beee2b677776ffe812a, Sepolia 0x0254a6b2997ef52e9f830ce1f543f6b29768295e8d17e2267d672c552cfe0d91) carry a zero-knowledge proof, so tokens and amounts cannot be read from the calldata.
  • apply_actions, compile_actions and execute_writes are value-moving pool calls. The payload may carry a strk20 object that declares what the call does: {action: "shield" | "unshield" | "private-transfer" | "private-swap", token, amount, toToken, minReceived, recipient, venue}. With it, the call is classified transfer and summarized from the declaration, which the judge is told is the client’s claim and not checked against the proof. Without it, the call is classified unknown.
  • grant_role, revoke_role, set_open_note_screening_policy, set_auditor_public_key and set_screener_public_key are pool administration, classified permission and flagged as never part of a user’s transfer. Any other pool entrypoint is unknown.
  • Calls to the anonymizer contracts (AVNU PrivacySwapHelper, the Ekubo swap anonymizer, the Endur deposit anonymizer and the Privacy Bridge in both directions) are classified transfer. For swaps, a note says the trade size is visible on chain: a private swap unlinks the wallet from the trade but does not hide the amount.
  • A declared shield also notes that a third-party screener signs deposits and can refuse one.
Escrow proposals (escrow_execute and POST /api/v1/wallets/{id}/propose) pass only the calls, with no strk20 declaration, so pool calls made from an escrow wallet are classified unknown. See Starknet for escrow wallets and private balances.

No live lookup

The adapter reads only the calldata. Escrow proposals on Starknet are also simulated with starknet_simulateTransactions, which supplies balance changes and events.

Example

The classifier’s summary is Transfer 10 STRK to 0x0123…cdef, with actionType: "transfer" in the transfer family.

From an MCP client

Instruct the agent to call verify_intent before executing any Starknet calls, with your rules as intent, { "calls": [...] } as action and venue: "starknet", and to act only on ALLOW.