signer you supply, and returns a transaction that anyone may broadcast. Authority is entirely in the owner’s signature.
Two different owner paths
Do not conflate these. They are different operations with different functions and different failure modes.
An approval never fires when the account owner acts, and an account operation never grants a mandate. A mandate only ever moves value when an agent submits an action that the owner’s signed policy permits.
The five dialects
Each supported account checks a different typed-data shape for the same core digest. The SDK builds the right one from the account family the API reports, so you never assemble it yourself.
Supported accounts lists the exact implementation addresses and the GOL installation method for each. The API checks the proxy runtime or EIP-7702 delegation, the implementation, and the installed configuration at one block before every approval and action, so a family name alone is never enough. For a delegated EOA only the EOA’s key is owner authority; a validator installed on its delegate never is.
The SDK never signs an approval with
personal_sign over a raw digest. The only raw hashes it asks a wallet to sign are the EIP-7702 authorization and the Nexus 1.3.3 initialization hash of a delegated EOA’s setup, and it checks that each signature recovers to the account. Every owner approval is eth_signTypedData_v4, which shows the owner the domain, the type, and every field they are approving instead of an opaque hash.Sign an approval
The server compiles, the browser verifies, the owner signs, and anyone sends.signPreparedGasPolicy recomputes the policy bytes, the mandate and gas policy IDs, the combined digest, and the wallet payload, then compares them with the values you pass, including the relayer mode, submitter, reimbursement recipient, and any tree limits. It throws prepared_policy_mismatch: <what differed> rather than opening a wallet for something other than what you intended.
You may also verify first, show the owner a review screen, and only then sign. verifyPreparedGasPolicy does the same checks and returns nothing.
Pause, resume, and revoke a mandate
A pause, resume, or revoke is a safety action on a mandate, not a new approval. It targets the root or any child mandate of the policy’s tree and uses the same digest-and-payload verification.Revoke the gas policy
signPreparedRevocation verifies the relayed gas-policy revocation and returns the call. The same revocation is also available as a direct call the account makes itself, so the owner can always revoke without GOL.
Address or Hex when you pass it to an encoder, as above.
Revocation takes effect on-chain immediately. The next action, and any unpaid revert claim under the policy, fails. For a delegated EOA, accountExecuteCall returns the direct call itself, which the EOA sends from its own key. See integrate hosted gas for the full sequence.
What the helpers throw
These are plainError objects with a stable message, thrown before a wallet is asked to sign anything.
A throw means GOL or the SDK would not proceed. None of them means the owner’s account is unsafe, and none of them should be resolved by retrying with modified inputs.
Safe threshold signatures
packOwnerSignature deliberately does not reshape a Safe signature. Safe’s own checkSignatures enforces the threshold and accepts assembled multisignature payloads, including contract-signature offsets, so the SDK preserves the wallet’s exact bytes instead of imposing a one-owner ECDSA shape.
operation.encode.
Confirm the owner path independently
ownerSigningHash and ownerSafetySigningHash read the account’s own domain separator and validator configuration and compute the hash the account will check. They are the on-chain cross-check for a payload the SDK built.
ownerSigningHash runs the full implementation preflight first and throws if the account is not the reviewed configuration, because a new authority should not be prepared for an unrecognized account. ownerSafetySigningHash skips that check on purpose: an owner must be able to pause and revoke even after their account’s implementation changes. The difference is the whole reason a mandate can always be stopped.