Skip to main content
Limits are the arithmetic half of an escrow wallet’s rules. Chance checks them in code against the simulated effects of a proposal, before the judge runs and again at execution. A proposal that fails a limit before the judge runs is blocked and charged nothing. The judge also sees the limits, marked as set by the owner. Every limit is optional. A limit that is not set does not restrict anything.

The four limits

maxPerTxUsd

Compared with the simulation’s total priced outflow. Token approvals are not counted as outflow. If any outflow has no USD price, the proposal is blocked, because the cap cannot be checked.

dailyCapUsd

Checked when a proposal is claimed for execution, in the same database transaction as the claim. The total counts:
  • proposals executed in the last 24 hours,
  • proposals currently executing,
  • x402 payments that failed in the last 24 hours, because a signed authorization may still have been settled,
  • the proposal being claimed.
Proposals waiting for approval reserve nothing. If the proposal’s outflow cannot be priced, it is refused. Before the judge, the cap only blocks proposals whose outflow cannot be measured or priced; the running total is checked at execution. So on an autonomous wallet a proposal that would exceed the cap is judged and charged, then fails at execution. A held proposal that would exceed it cannot be confirmed.

tokenAllowlist

Entries are contract addresses. A symbol is accepted only when it is in Chance’s verified token list for the wallet’s chain, and it resolves to that token’s one address. Any other symbol permits nothing. Chance never matches a token by the symbol the contract reports about itself. The list applies to tokens leaving the wallet and to token approvals. Native value (ETH on Base and Ethereum, SOL on Solana) has no contract address and is not covered: restrict it with recipientAllowlist or the mandate. On Starknet, STRK and ETH are token contracts and are covered. Verified tokens by chain: The MCP tool list_swap_tokens returns the Base and Ethereum rows.

recipientAllowlist

Every outflow and every approval in the simulation must go to a listed address. For an approval, the spender is checked. If the simulation cannot show where a movement goes, the proposal is blocked. Hex addresses are compared without case, and Starknet addresses with their zero padding normalized. Solana addresses are compared exactly, because base58 is case-sensitive.

When effects cannot be measured

Some proposals have no measured effects: the simulation failed to run, or the chain reports no balance changes. For these: A proposal with measured effects but no asset movements executes automatically only on a wallet with no limits. On a wallet with any limit it waits for the owner.
Solana simulations report success or failure but no balance changes. On a Solana wallet with any limit, a raw transaction proposed with escrow_execute is blocked. Named SOL and USDC transfers are measured from the request itself, so limits apply to them normally, and they always wait for the owner.

Where each limit is enforced

Chance enforces every limit, before the judge and again at execution. On some Base wallets the signing provider also enforces maxPerTxUsd and recipientAllowlist on its own, so those two hold even if Chance’s own checks were bypassed. list_escrow_wallets reports this per wallet in rules.enforcement: signer means the signing provider refuses a violating transaction itself, and chance means Chance’s checks enforce it.

Changing limits

Over MCP

update_escrow_wallet takes the wallet and any of name, mandate and limits. It is free.
  • limits replaces the whole set. A limit you leave out is removed.
  • A change that loosens the rules (a mandate rewrite, a raised or removed cap, a new token or recipient, or a removed allowlist) is applied, and the reply says it loosened the rules. It is not refused.
  • On some wallets the signing provider’s policy can be changed only from the owner’s dashboard session. The tool then returns an error, and the owner changes the limits in the dashboard.

In the dashboard

Open the wallet at harness.chance.cc/escrow and edit its rules. The rules editor offers templates that fill in a mandate and limits. A template fills the form; nothing is saved until you click Save rules. Limits do not apply to the owner’s own withdrawals from the dashboard. See Escrow wallets.