Altana sessions

Each of our four reference agents holds its own self-custodial Altana wallet. A session key on that wallet is scoped to a short allowlist of calls, a daily spend cap and an expiry, so the agent can act on chain without holding the keys to everything. The scope lives on the wallet, so a stranger can read it. Everything below the planned scope is read live from BSC testnet, contract by contract, not from a config file. Where a value is not on chain yet it says unknown, never a zero.

All four sessions are registered on chain

Each of the four agents holds a Keystore session registered on chain, on BSC testnet (chain 97). Every status below is read live from chain, not from a config file: getKeys returns each keyId, isValidKey reads true, and each account's allowlist and daily cap are the calls and the USDT limit you can read with free eth_calls. The wallet addresses and both key identifiers are real, derived from keys we hold. tools/altana-grant.ts is the command that landed them; mainnet (chain 56) is the same one command and is never run automatically. Where any value is not on chain it says unknown, never a zero. The method is in the repository at docs/16-ALTANA.md.

The four wallet addresses

One wallet per agent, never one shared. Include these in the submission. Same address on chain 56 and chain 97.

Venus Health Factor Watchoperated by us

Health factor shelf, reserved id 900000001, not a registry id

live on chain

The wallet and its keys

Account keyHash0xcea9d48fd3bb80d63dd5981d3e1f64c1e7e125ed82873ee1396c5ea96fd96ee9
Session EOA0x80e8c686A4D1F7D8c007049a05CD1c1817BDeEFf

The Keystore takes the keyId, which is keccak256 of the session public key. The account takes the keyHash, a different value for the same key. Both are shown so the derivation reconciles.

Read live from BSC testnet, 1s ago

Registered in Keystoreyes
isValidKeytrue, live
Expiry2026-10-01T00:00:00Z
Allowlist on chain4 entries
Spend cap on chain100000000000000000000 @ token 0x55d39832…

Planned scope, written to chain at grant

Approve USDT to the Aave V3 pool, then only add collateral or repay debt, at most 100 USDT a day. The tightest of the four scopes: it can defend a position and nothing else.

Calls this session may make
  • approve(address,uint256)on 0x55d398326f99059fF775485246999027B3197955
  • supply(address,uint256,address,uint16)on 0x6807dc923806fE8Fd134338EABCA509979a7e0cB
  • repay(address,uint256,uint256,address)on 0x6807dc923806fE8Fd134338EABCA509979a7e0cB
Daily spend cap
  • 100 USDT per day, token 0x55d398326f99059fF775485246999027B3197955
Reads the chain, then revokes if the session is live. It says so when there is nothing to revoke yet, which is the case until the grant lands.

BSC Yield Routeroperated by us

Yield shelf, reserved id 900000002, not a registry id

live on chain

The wallet and its keys

Account keyHash0x84bc4a0eb60b8c8af94250c68da8fc38ee2e9df512e4e611e349773e43542252
Session EOA0xfa49C0198Fad2a95982E10a1D85a874E001Abb6E

The Keystore takes the keyId, which is keccak256 of the session public key. The account takes the keyHash, a different value for the same key. Both are shown so the derivation reconciles.

Read live from BSC testnet, 1s ago

Registered in Keystoreyes
isValidKeytrue, live
Expiry2026-10-01T00:00:00Z
Allowlist on chain4 entries
Spend cap on chain50000000000000000000 @ token 0x55d39832…

Planned scope, written to chain at grant

Approve USDT to the Aave V3 pool, supply and withdraw, at most 50 USDT a day. It cannot borrow and cannot touch any other contract.

Calls this session may make
  • approve(address,uint256)on 0x55d398326f99059fF775485246999027B3197955
  • supply(address,uint256,address,uint16)on 0x6807dc923806fE8Fd134338EABCA509979a7e0cB
  • withdraw(address,uint256,address)on 0x6807dc923806fE8Fd134338EABCA509979a7e0cB
Daily spend cap
  • 50 USDT per day, token 0x55d398326f99059fF775485246999027B3197955
Reads the chain, then revokes if the session is live. It says so when there is nothing to revoke yet, which is the case until the grant lands.

PancakeSwap LP Range Checkoperated by us

Rebalancing shelf, reserved id 900000003, not a registry id

live on chain

The wallet and its keys

Account keyHash0x0eb5f35a85ac53096e7b71e0b4e7ba377e86c51faa5d031ec47e3509a68a7f88
Session EOA0x70202BB511B45E3f1c311C632D4D36a963b0860e

The Keystore takes the keyId, which is keccak256 of the session public key. The account takes the keyHash, a different value for the same key. Both are shown so the derivation reconciles.

Read live from BSC testnet, 1s ago

Registered in Keystoreyes
isValidKeytrue, live
Expiry2026-10-01T00:00:00Z
Allowlist on chain3 entries
Spend cap on chain50000000000000000000 @ token 0x55d39832…

Planned scope, written to chain at grant

Approve USDT to the PancakeSwap V2 router and swap through it, at most 50 USDT a day. No other target, no plain transfer, no approval to anyone else.

Calls this session may make
  • approve(address,uint256)on 0x55d398326f99059fF775485246999027B3197955
  • swapExactTokensForTokens(uint256,uint256,address[],address,uint256)on 0x10ED43C718714eb63d5aA57B78B54704E256024E
Daily spend cap
  • 50 USDT per day, token 0x55d398326f99059fF775485246999027B3197955
Reads the chain, then revokes if the session is live. It says so when there is nothing to revoke yet, which is the case until the grant lands.

Grid Ladder Planneroperated by us

Grid trading shelf, reserved id 900000004, not a registry id

live on chain

The wallet and its keys

Account keyHash0x492515a2585263d0a1012b696c2d861b9783f97186bc73ef465e486f4a43dbdd
Session EOA0x8820778673b8df125f14b00B1AbC17d415a9B3a7

The Keystore takes the keyId, which is keccak256 of the session public key. The account takes the keyHash, a different value for the same key. Both are shown so the derivation reconciles.

Read live from BSC testnet, 1s ago

Registered in Keystoreyes
isValidKeytrue, live
Expiry2026-10-01T00:00:00Z
Allowlist on chain3 entries
Spend cap on chain50000000000000000000 @ token 0x55d39832…

Planned scope, written to chain at grant

Approve USDT to the PancakeSwap V2 router and swap through it, at most 50 USDT a day. No other target, no plain transfer, no approval to anyone else.

Calls this session may make
  • approve(address,uint256)on 0x55d398326f99059fF775485246999027B3197955
  • swapExactTokensForTokens(uint256,uint256,address[],address,uint256)on 0x10ED43C718714eb63d5aA57B78B54704E256024E
Daily spend cap
  • 50 USDT per day, token 0x55d398326f99059fF775485246999027B3197955
Reads the chain, then revokes if the session is live. It says so when there is nothing to revoke yet, which is the case until the grant lands.

Verify it without us

Every value above is a free call anyone can repeat. The Keystore on chain 97 is 0x6b8361C29d05D498b1a12B54A37310f94171E94A. Read getKeys(wallet), isValidKey(wallet, keyId) and getExpiry(wallet, keyId) on it. Read canExecutePackedInfos(keyHash) plus spendInfos(keyHash) on the wallet once it is delegated. The Altana explorer at https://testnet.altana.network shows the same, as an indexed view rather than the authority.