Spending rules · EIP-7702 · Robinhood Chain

Give your agent a wallet.
Keep the leash.

Leash is a contract your wallet delegates to. You say who your AI agent may pay, how much and until when. The chain refuses everything else.

The leash

What you gave the agent. Change a rule and the counters start over, like on the chain.

day 0, 00:00
The policy, in words

Or send the dog on an errand.

Drag the dog to a shop, or pick an errand. The call, the verdict and the reason show up here.
This session

    The rulebook, knotted on the leash

    Seven rules. That is all the leash is made of.

    How it is wired

    Your wallet, with a rulebook bolted on.

    EIP-7702 lets an ordinary wallet run a contract's code for as long as its owner wants. Leash is that code. You keep your key and your address. The agent gets its own key and its own gas, and can only act through the rules.

    1

    Delegate

    One transaction of type 4 points your address at the Leash contract. Your address now holds this marker as code:

    0xef0100...

    Undo it any time by delegating somewhere else, or to nothing.

    2

    Set a policy

    You call your own address once, with the agent, the limits and the call list. In the same transaction as step 1 if you like. This is the real calldata of the policy on the left:

    ...
    3

    The agent works

    The agent signs transactions with its own key and sends batches to your address. Each call is checked against the policy first, then made as you. One refusal cancels the whole batch.

    // agent -> your address
    execute([ { target, value, data }, ... ])
    Why you can believe the screen above

    The page and the chain give the same answer.

    36tests that pass, on a real EVM, with a real EIP-7702 transaction
    580random batches where contract and rules engine never disagreed, on the error and on the call
    6live checks where Robinhood Chain itself runs the contract and agrees
    0admin keys, upgrade rights or fees in the contract

    Status: written, compiled and tested. Not audited, not deployed. Its address is fixed by the compiled code (CREATE2, salt 0): -. The button in the session above asks the real chain to run your session against this code, with nothing sent.

    Straight talk

    What it guarantees, and what it does not.

    The leash holds

    • An agent can only call what the policy lists, send only what the limits allow, and pay only who you named.
    • An agent can never make the account call itself: the admin functions stay yours.
    • A refused call cancels the whole batch. Nothing half-happens.
    • Pause, revoke and expiry stop the agent at once. Replacing a policy restarts its counters.
    • No owner but you, no upgrade, no fee.

    What it cannot do

    • Approvals you gave before Leash are outside the policy. If a router already holds an unlimited approval and the agent may call it, the agent can pull through it. Revoke old approvals first.
    • Limits are ceilings, not judgement. An agent can still spend its whole allowance on things you listed.
    • Periods are fixed windows: a burst at the end of one and the start of the next can reach twice the cap.
    • Not audited and not deployed. Nothing here holds funds today.
    FAQ

    The honest answers.

    Is the page above real?

    Yes. The errands go through the same rules engine the contract's tests are checked against, and the button runs your whole session on Robinhood Chain itself with a code override, so the contract that is not yet deployed runs on the real chain's state. No funds exist and nothing is sent.

    Do I lose control of my wallet?

    No. Your key still works as before and can do anything. Leash only gives the agent a narrow door. You can pause it, revoke it or undelegate in one transaction.

    What stops the agent from editing its own rules?

    Only a call from your account to itself can change the policy, and the agent cannot make that call: the contract refuses any call from the agent to your own address. A contract the agent is allowed to call cannot do it either, because it would be the caller, not your account.

    Is it live?

    No. The contract is written, compiled and tested, not audited and not deployed. The read-only checks against Robinhood Chain confirm there is no code at its future address yet.

    Do I need $LEASH?

    No. The contract has no token and no fee. See the token page.

    A dog on a long red leash, with gold coins marking the limits along it

    A long leash is still a leash.

    Build a policy in the studio, run it on the real chain, and take the calldata with you. Nothing to install, no wallet to connect.

    $LEASHCommunity coin: address to be announced. It will be posted here and on the project's X first. Token page.