Repository navigation
Headless identity: restore, profile, custody changes, create, storage, transfer - #5
Merged
Merged
Conversation
…ab or with the operator key - Browser wallet sessions pass the prepared gas and fees to the page, as one-shot requests already did. - The Vault deploy, deposit, unwrap, and withdraw runners and the operator sync take an optional wallet session, so a command can run every prompt in one tab. - Restore and refetch take an optional signer: a wallet session, or the operator key, which decrypts locally through the snapshot's slot. Without a known requester, restore asks whichever wallet connects for its own slot. - Revoke the Vault's operator approvals before withdrawing on the switch to Simple; some Vault builds keep them across a withdraw. - Shared helpers for the headless commands: one lazy wallet tab, operator key and storage checks, network registries, and saving a completed identity. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
- restore <token-id> | <name>: rebuild an agent on this machine; restore --owner <address|name> lists what a wallet holds; restore with an identity pulls the newest onchain snapshot into the vault. - Previews until --yes: agent, snapshot, who decrypts it, and warnings for local changes, a pending publish, or switching agents. - The browser wallet signs in one tab, or --operator decrypts with the operator key and opens nothing. Config is saved only after the files land. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
- profile shows the public name, description, image, and agent card; --name, --description, and --image <path|url|none> change them and publish in one save, previewing until --yes. - Validates the name and image before anything is pinned, and sends nothing when nothing changes. - The owner wallet signs in one tab; --operator signs with the operator key when advanced custody with a linked ENS name allows it, and otherwise refuses with what is missing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
- custody --advanced deploys a Vault (or reuses one), deposits the token, and saves; --simple revokes the Vault's operator approvals, withdraws, and saves; --add-operator, --remove-operator, and --activate-operator manage operators. - Each change is planned from chain state, previews until --yes, and runs every wallet prompt in one tab. A run that stops part way says what landed and resumes when run again. - --add-operator --operator lets the injected operator key sign its own restore-access proof, so authorizing it needs only the owner's approval. - Move the operator proof out of the manager screen into a shared helper the screen now uses, and label the wallet page's custody-switch steps as they run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
- create --name <text> --network mainnet|base mints a new agent with its first encrypted snapshot, previewing until --yes; --description, --import (fold this machine's notes into MEMORY.md), and --replace (when an agent already exists; its vault stays on disk). - --advanced continues into deploy, deposit, and the custody save in the same browser tab; if the mint lands but custody does not, it says so and points at custody --advanced. - The mint runner takes an optional wallet session; the manager is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
- storage shows where snapshots are pinned and whether a credential is set; --set reads a Pinata JWT from stdin only, checks it with Pinata, and saves it; --forget removes it after a preview. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
- transfer <address|name> prepares the agent for a new owner: both wallets sign in one browser tab and the owner publishes the re-encrypted snapshot, previewing until --yes. - Refuses the owner itself and a token still in a Vault, and ends by naming the step ethagent never takes: sending the token from your wallet. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
- README: common tasks, command rows, and a Setting up and moving an agent section covering previews, the one wallet tab, resuming, restoring and approving with the operator key, revoking on the switch to Simple, transfers, and storage. Quick start mentions create. - --help lists the new commands; agent guidance says previews and read-only forms are the agent's to run, --yes is the user's, and restore --operator --yes may run when the user asks. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
Resolve src/identity/manager/custody/helpers.ts: keep master's removal of buildSeedConfigFromStep and keep localOperatorAddresses, which the custody changes use. Restore envelopeChallengeFor in localKeyDecrypt.ts, removed on master as unreferenced and now used by restore previews. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every action in the interactive manager now has a headless command. An agent can be restored, edited, re-custodied, created and handed over without a TTY.
Each command follows the same conventions as
custodyandens:--yes.{"schema":1}JSON envelope and the existing exit codes.The commands reuse the manager's existing runners, so the headless and interactive paths share their logic. One commit per step:
ens.restorerestore <token-id>|<name>rebuilds an agent on this machine.restore --owner <address>lists the agents a wallet holds.restorewith no target pulls the newest onchain snapshot into the vault.--operatordecrypts with the operator key and opens no browser. The vault is checkpointed first, and config is saved only after the files land.profile--image noneremoves it) in one save.--operatorworks in Advanced custody with a linked ENS name; otherwise it says what is missing.custody --advanceddeploys or reuses a Vault, deposits the token and saves.custody --simplerevokes the Vault's operators, withdraws the token and saves.--add-operator,--remove-operatorand--activate-operatormanage operators.--add-operator --operatorhas the injected key sign its own proof.create--advancedcontinues into the Vault in the same tab,--importfolds in notes from local tools, and--replaceis required when an agent already exists.storage--setreads a Pinata JWT from stdin only;--forgetremoves it after a preview.transfer <address|name>createin the quick start.--helplists the new commands.--yesis the user's, andrestore --operator --yesmay run when the user asks.Testing
npm run typecheckis clean.npm testpasses all 763 tests in a clean CI-like environment.restoreCommand, including an end-to-end decrypt with a local key against a real envelope that writes the vault;profileCommand;custodyWrite, covering step order, the single wallet tab, resuming, partial cancellation, revoking, and the operator-key proof;setupCommands(create, storage, transfer);Live checks after merge (non-destructive first)
keychain exec ethagent -- ethagent restore 45744 --network base --operator(preview), then with--yesinto a temporaryHOME.ethagent profileand aprofile --name <text>preview.ethagent custody --add-operator --operatorpreview, thencustody --simplepreview, to check the revoke step lists the current operators.🤖 Generated with Claude Code
https://claude.ai/code/session_01HG2miyE22qTuug1Quxj7iw
Generated by Claude Code