Skip to main content
An owner approves a mandate in their own wallet. GOL never receives, stores, or transmits the owner’s key, and the SDK has no function that accepts one: every owner helper takes a signer you supply, and returns a transaction that anyone may broadcast. Authority is entirely in the owner’s signature.

Two different owner paths

Do not conflate these. They are different operations with different functions and different failure modes. An approval never fires when the account owner acts, and an account operation never grants a mandate. A mandate only ever moves value when an agent submits an action that the owner’s signed policy permits.

The five dialects

Each supported account checks a different typed-data shape for the same core digest. The SDK builds the right one from the account family the API reports, so you never assemble it yourself. Supported accounts lists the exact implementation addresses and the GOL installation method for each. The API checks the proxy runtime or EIP-7702 delegation, the implementation, and the installed configuration at one block before every approval and action, so a family name alone is never enough. For a delegated EOA only the EOA’s key is owner authority; a validator installed on its delegate never is.
The SDK never signs an approval with personal_sign over a raw digest. The only raw hashes it asks a wallet to sign are the EIP-7702 authorization and the Nexus 1.3.3 initialization hash of a delegated EOA’s setup, and it checks that each signature recovers to the account. Every owner approval is eth_signTypedData_v4, which shows the owner the domain, the type, and every field they are approving instead of an opaque hash.

Sign an approval

The server compiles, the browser verifies, the owner signs, and anyone sends.
The third argument is what makes this safe. signPreparedGasPolicy recomputes the policy bytes, the mandate and gas policy IDs, the combined digest, and the wallet payload, then compares them with the values you pass, including the relayer mode, submitter, reimbursement recipient, and any tree limits. It throws prepared_policy_mismatch: <what differed> rather than opening a wallet for something other than what you intended. You may also verify first, show the owner a review screen, and only then sign. verifyPreparedGasPolicy does the same checks and returns nothing.

Pause, resume, and revoke a mandate

A pause, resume, or revoke is a safety action on a mandate, not a new approval. It targets the root or any child mandate of the policy’s tree and uses the same digest-and-payload verification.
A paused policy refuses new submissions before they are signed or sent, so no value moves. An action already accepted and waiting to be send is held while paused, proceeds if the owner resumes before its quote expires, and closes with no owner liability at quote expiry. The policy identity, caps, and expiry never change across a pause or resume.

Revoke the gas policy

signPreparedRevocation verifies the relayed gas-policy revocation and returns the call. The same revocation is also available as a direct call the account makes itself, so the owner can always revoke without GOL.
Response types are generated from the OpenAPI contract, where every field is a JSON string. Narrow an address or a hash to viem’s Address or Hex when you pass it to an encoder, as above. Revocation takes effect on-chain immediately. The next action, and any unpaid revert claim under the policy, fails. For a delegated EOA, accountExecuteCall returns the direct call itself, which the EOA sends from its own key. See integrate hosted gas for the full sequence.

What the helpers throw

These are plain Error objects with a stable message, thrown before a wallet is asked to sign anything. A throw means GOL or the SDK would not proceed. None of them means the owner’s account is unsafe, and none of them should be resolved by retrying with modified inputs.

Safe threshold signatures

packOwnerSignature deliberately does not reshape a Safe signature. Safe’s own checkSignatures enforces the threshold and accepts assembled multisignature payloads, including contract-signature offsets, so the SDK preserves the wallet’s exact bytes instead of imposing a one-owner ECDSA shape.
For a one-owner Safe, the wallet’s own signature passes through unchanged. For a multi-owner Safe, collect the threshold of signatures through your own coordination and pass the assembled payload to operation.encode.

Confirm the owner path independently

ownerSigningHash and ownerSafetySigningHash read the account’s own domain separator and validator configuration and compute the hash the account will check. They are the on-chain cross-check for a payload the SDK built.
ownerSigningHash runs the full implementation preflight first and throws if the account is not the reviewed configuration, because a new authority should not be prepared for an unrecognized account. ownerSafetySigningHash skips that check on purpose: an owner must be able to pause and revoke even after their account’s implementation changes. The difference is the whole reason a mandate can always be stopped.