venue: starknet. There are no aliases.
What to send
The calls the account will execute in one multicall, as{calls: [{contractAddress, entrypoint, calldata}]}. Over HTTP a bare array of calls also works; over MCP, action must be an object, so use {calls: [...]}. calldata is an array of felt strings. It is detected without venue when every item has a hex contractAddress and a string entrypoint.
actionType is the entrypoints joined with +, for example approve+swap.
How calls are decoded
The known tokens are the mainnet contracts of STRK, ETH, USDC, USDC.e and USDT:
For a batch, the family is the riskiest call’s:
unknown if any call is unknown, otherwise permission if any call grants authority, otherwise transfer.
STRK20 private operations
Calls to the STRK20 privacy pool (mainnet0x040337b1af3c663e86e333bab5a4b28da8d4652a15a69beee2b677776ffe812a, Sepolia 0x0254a6b2997ef52e9f830ce1f543f6b29768295e8d17e2267d672c552cfe0d91) carry a zero-knowledge proof, so tokens and amounts cannot be read from the calldata.
apply_actions,compile_actionsandexecute_writesare value-moving pool calls. The payload may carry astrk20object that declares what the call does:{action: "shield" | "unshield" | "private-transfer" | "private-swap", token, amount, toToken, minReceived, recipient, venue}. With it, the call is classifiedtransferand summarized from the declaration, which the judge is told is the client’s claim and not checked against the proof. Without it, the call is classifiedunknown.grant_role,revoke_role,set_open_note_screening_policy,set_auditor_public_keyandset_screener_public_keyare pool administration, classifiedpermissionand flagged as never part of a user’s transfer. Any other pool entrypoint isunknown.- Calls to the anonymizer contracts (AVNU PrivacySwapHelper, the Ekubo swap anonymizer, the Endur deposit anonymizer and the Privacy Bridge in both directions) are classified
transfer. For swaps, a note says the trade size is visible on chain: a private swap unlinks the wallet from the trade but does not hide the amount. - A declared shield also notes that a third-party screener signs deposits and can refuse one.
escrow_execute and POST /api/v1/wallets/{id}/propose) pass only the calls, with no strk20 declaration, so pool calls made from an escrow wallet are classified unknown. See Starknet for escrow wallets and private balances.
No live lookup
The adapter reads only the calldata. Escrow proposals on Starknet are also simulated withstarknet_simulateTransactions, which supplies balance changes and events.
Example
Transfer 10 STRK to 0x0123…cdef, with actionType: "transfer" in the transfer family.
From an MCP client
Instruct the agent to callverify_intent before executing any Starknet calls, with your rules as intent, { "calls": [...] } as action and venue: "starknet", and to act only on ALLOW.