Reads an authorization payload before a key touches it, and reports how that payload stands against a signing policy you declare. Three declared modes. In typed_data the input is the EIP-712 object your wallet would receive from eth_signTypedData_v4. In eip7702_tuple it is a delegation tuple of chain id, delegate address and nonce. In raw_hash it is a bare 32-byte hash about to be signed blind, which raises BLIND_SIGNATURE and stops, because nothing about what is being authorized can be read from it. Classification is string equality of the computed EIP-712 encodeType against canonical type strings, so a struct carrying a known name with a different member list comes back as LOOKALIKE_TYPE and an unknown struct comes back as UNRECOGNIZED instead of a guess. Every check returns FLAGGED, CLEAR or NOT_EVALUATED with the field path, the observed value and the policy value. There are no numeric defaults on this page: every threshold, allowlist, counterparty set and clock reading is yours, and a check whose input you did not declare reports NOT_EVALUATED and is listed separately. This tool performs no chain read, recovers no signer, computes no digest, and never submits anything.
CONFORMS result covers only the checks it could evaluate, so read not_evaluated alongside it. Every chain fact here stays a caller assertion: on-chain nonce state, current allowances and whether an address holds code are inputs you declare, signer recovery and digest recomputation belong to the sibling nodes named under handoffs, agent-counterparty credential scope belongs to art-565, and this node ships compute_proof_ready: deferred as the proof-status note below records.compute_proof_ready: deferred. Standards-implementing nodes here land without a receipt, pass a line-by-line reconciliation against the pinned primary text, and are proved after that. The result above is a deterministic recompute of the published kernel, pinned to it by the kernel-digest stamp in this page's head, with a property-test floor over its branches.Observation table recorded 2026-09-28 from the research record in this node's build spec (section 7.4). The cells below were not primary-retrieved in this build row, so treat each as a dated observation and confirm against the vendor's current documentation before you rely on it. A wider platform and protocol comparison lives in tools/644.
| Policy field here | Turnkey | Privy | Coinbase CDP |
|---|---|---|---|
| allowed_primary_types | eth.eip_712.primary_type (2026-09-28) | none recorded (2026-09-28) | none recorded (2026-09-28) |
| allowed_verifying_contracts | eth.eip_712.message[...] with any() and all() (2026-09-28) | field_source ethereum_typed_data_domain (2026-09-28) | evmTypedDataVerifyingContract (2026-09-28) |
| allowed_chain_ids and active_chain_id | eth.eip_712.message[...] with any() and all() (2026-09-28) | field_source ethereum_typed_data_domain (2026-09-28) | evmNetwork (2026-09-28) |
| spender_allowlist and payee_allowlist | eth.eip_712.message[...] with any() and all() (2026-09-28) | field_source ethereum_typed_data_message (2026-09-28) | none recorded for a typed-data counterparty field (2026-09-28) |
| max_amount_by_token | eth.eip_712.message[...] with any() and all() (2026-09-28) | field_source ethereum_typed_data_message (2026-09-28) | netUSDChange, which needs a price oracle and has no offline equivalent (2026-09-28) |
| delegate_allowlist for an EIP-7702 tuple | none: a delegation tuple is not EIP-712 (2026-09-28) | none: a delegation tuple is not EIP-712 (2026-09-28) | none: a delegation tuple is not EIP-712 (2026-09-28) |