Security Model
Sweepr V2 is designed so partners do not need to manually calculate or enforce fee splits.
Partner Identity
Partner identity comes from x-api-key. Sweepr never trusts partner identity, fee share, or payout recipient from a client request body.
Partner-facing status and confirm routes are scoped to the partner that owns the API key. A partner cannot confirm or inspect another partner’s sweep by guessing a sweep id.
Fee Authorization
The backend signs a short-lived EIP-712 FeeAuthorization with a dedicated fee signer. The deployer wallet and fee signer should be operationally separate.
The SDK verifies the authorization before the user signs Permit2.
The V5 contract verifies the authorization on-chain before any split is paid.
Replay Protection
Each fee authorization has:
nonce
deadline
- EIP-712 domain with
chainId
- EIP-712 domain with
verifyingContract
The contract stores used nonces per user.
Confirmation Safety
The V2 backend does not trust a transaction hash by itself. To mark a sweep complete, Sweepr reads the transaction receipt and verifies a SweepExecutedV5 event emitted by the configured V5 contract.
The event must match the stored fee authorization:
- user
- partner id
- partner recipient
- output token
- token count
Confirm is idempotent for the same transaction hash. If a sweep is already confirmed with another hash, or already void or expired, Sweepr rejects the request.
Fee Cap
The V5 contract has a hard fee cap:
This means total Sweepr platform fee cannot exceed 5% of gross output.
Router Allowlist
V5 only calls routers that are allowlisted by the contract owner.
The backend also validates quote-provider routers against the same canonical allowlist before returning transaction calldata. If an aggregator starts returning a new router, the build fails before the user signs.
Indexer Reliability
V2 uses tx-scoped reconciliation. Sweepr only polls transaction hashes submitted through the confirm endpoint, not every block or log on the chain.
The indexer uses:
- retry backoff
- fallback RPC URLs
checkAttempts
nextCheckAt
lastError
- heartbeat state in
indexer_state
This keeps the first version operationally simple while still making pending or stuck sweeps visible.
Solana
Solana is not part of V2 trustless split. Solana remains V1/off-chain accounting until the Sweepr settlement program is implemented.
V2 also does not support cross-chain sweeps. Each V2 fee authorization is single-chain and bound to one V5 contract address.Last modified on June 28, 2026