The four limits
maxPerTxUsd
Compared with the simulation’s total priced outflow. Token approvals are not counted as outflow. If any outflow has no USD price, the proposal is blocked, because the cap cannot be checked.dailyCapUsd
Checked when a proposal is claimed for execution, in the same database transaction as the claim. The total counts:- proposals executed in the last 24 hours,
- proposals currently executing,
- x402 payments that failed in the last 24 hours, because a signed authorization may still have been settled,
- the proposal being claimed.
tokenAllowlist
Entries are contract addresses. A symbol is accepted only when it is in Chance’s verified token list for the wallet’s chain, and it resolves to that token’s one address. Any other symbol permits nothing. Chance never matches a token by the symbol the contract reports about itself. The list applies to tokens leaving the wallet and to token approvals. Native value (ETH on Base and Ethereum, SOL on Solana) has no contract address and is not covered: restrict it withrecipientAllowlist or the mandate. On Starknet, STRK and ETH are token contracts and are covered.
Verified tokens by chain:
The MCP tool
list_swap_tokens returns the Base and Ethereum rows.
recipientAllowlist
Every outflow and every approval in the simulation must go to a listed address. For an approval, the spender is checked. If the simulation cannot show where a movement goes, the proposal is blocked. Hex addresses are compared without case, and Starknet addresses with their zero padding normalized. Solana addresses are compared exactly, because base58 is case-sensitive.When effects cannot be measured
Some proposals have no measured effects: the simulation failed to run, or the chain reports no balance changes. For these:
A proposal with measured effects but no asset movements executes automatically only on a wallet with no limits. On a wallet with any limit it waits for the owner.
Solana simulations report success or failure but no balance changes. On a Solana wallet with any limit, a raw transaction proposed with
escrow_execute is blocked. Named SOL and USDC transfers are measured from the request itself, so limits apply to them normally, and they always wait for the owner.Where each limit is enforced
Chance enforces every limit, before the judge and again at execution. On some Base wallets the signing provider also enforcesmaxPerTxUsd and recipientAllowlist on its own, so those two hold even if Chance’s own checks were bypassed.
list_escrow_wallets reports this per wallet in rules.enforcement: signer means the signing provider refuses a violating transaction itself, and chance means Chance’s checks enforce it.
Changing limits
Over MCP
update_escrow_wallet takes the wallet and any of name, mandate and limits. It is free.
limitsreplaces the whole set. A limit you leave out is removed.- A change that loosens the rules (a mandate rewrite, a raised or removed cap, a new token or recipient, or a removed allowlist) is applied, and the reply says it loosened the rules. It is not refused.
- On some wallets the signing provider’s policy can be changed only from the owner’s dashboard session. The tool then returns an error, and the owner changes the limits in the dashboard.
In the dashboard
Open the wallet at harness.chance.cc/escrow and edit its rules. The rules editor offers templates that fill in a mandate and limits. A template fills the form; nothing is saved until you click Save rules.
Limits do not apply to the owner’s own withdrawals from the dashboard. See Escrow wallets.
