Resources
How it works
Every execution intent maps to one blockchain address.
An intent
An intent is seven values, and every one of them is part of its address:
| Field | What it fixes |
|---|---|
token | The ERC-20 the address accepts. |
amount | Exactly how much of it the calls spend. |
calls | The contracts it calls, the functions and the arguments, in order. |
expirationTimestamp | When it stops waiting, and returns what it holds. |
recovery | Where anything that can’t be spent goes. |
salt | What makes it unique among identical intents. |
chainId | The one chain it executes on. |
The address is the counterfactual address of a smart contract that isn’t deployed yet, and that’s hardcoded to route your funds and make its calls exactly as you, or an app, intend. That contract is Payment.
- token
- USDC
- amount
- 100 USDC
- calls
- 1. approve(vault, 100 USDC)2. deposit(100 USDC, your wallet)
- recovery
- your wallet
- chainId
- 8453 (Base)
From payment to execution
You send exactly 100 USDC to the address. Execute detects it, and deploys the Payment contract, which executes your actions. The deployment is a call to PaymentFactory: permissionless, non-upgradeable and non-custodial, and deployed at the same address on every chain.
- 01PayYou send exactly 100 USDC to the address, with an ordinary transfer from any wallet or exchange.
- 02DetectExecute sees the transfer land and waits for it to confirm.
- 03ExecuteExecute calls
PaymentFactory., which deploysexecute Paymentat the address. Its constructor makes the calls. - 04SettleThe transaction confirms. The vault’s shares are in your wallet, and the address is spent.
Execute holds no funds and no keys to the address: nobody does. It only sends the transaction the terms already decide, and anyone could send it instead.
Recovery
Payment also handles funds that arrive when the intent can’t run as written: the wrong token, part of the amount, after expiry, more than the amount, or a call that fails.
- Too much
- Everything above the amount goes to recovery, and the calls run with exactly the amount.
- Too little
- The address waits for the rest. If it’s still short at expiry, everything goes to recovery.
- Too late
- After expiry, no call runs: the whole balance goes to recovery.
- A call fails
- Nothing happens: the calls run together or not at all. Execute retries until expiry, then refunds.
- Another chain
- Executed on a chain the intent doesn’t name, the address sends its whole balance to recovery.
- Another token
- Once the address is deployed, anyone can call
recover(token), which sends that token to recovery.
Verification
Every executable address can be checked before a single token is sent to it. The address is computed from its terms: the token, the exact amount and every call it will make. Anyone can recompute it before sending, and change one byte and it’s a different address.
Any address can be checked at execute.cash/address/<address>. This is that page’s check, on the vault deposit above: it reads each field from the terms, hashes them in your browser, and compares the result with the address. Change a byte to see the address move.
- Expires
- —
- Refunds to
- —
- Salt
- 0x0000…0000
- Chain
- —
0x092dae7201Cc39437042194D671dDae2628dF8600x0000000000000000000000000000000000000000