Bounded execution for agent-native DeFi

Policy capsulesfor agents thatcannot freelance.

OpenZaps turn approved DeFi workflows into sealed policy capsules. Hermes can simulate, submit, monitor, alert, and revoke, but it cannot choose arbitrary targets, recipients, assets, or calldata.

$0xZAPS liveClanker V4 · Robinhood ChainCA 0xDd90bFa4adC7F4401E611AbaC692D939F9F4CB07
ERC-20 firstEIP-712 intentsERC-1271 readyRevocable policiesPrivate orderflow
0Broad wallet approvals
4Policy templates
47 / 0Contract tests passing / failing
9 / 9Internal findings fixed
0xZAPS

$0xZAPS is live through a creator-verified Clanker V4 market on Robinhood Chain. It is the community and operator coordination token for OpenZaps; the protocol remains usable without treating the token as yield, equity, or a fee claim.

Product flow

Every useful automation starts as a reviewable policy.

The app is a production review console first: template selection, bounded policy design, simulation checks, audit history, and revoke controls before the wallet integration is allowed to touch mainnet funds.

01 / Draft

Choose a reusable policy template

Start from DCA, pool deposit, claim-and-compound, or a gated guarded-exit design. Every template has explicit production status.

Policy versioning
02 / Simulate

Review checks before signing

See slippage, spend ceilings, postconditions, submitter scope, human approval gates, and simulation diffs before any wallet prompt.

No broadcast
03 / Operate

Monitor, pause, revoke, and export

Each capsule carries audit history, dry-run receipts, local revoke controls, and JSON manifests for SDK or backend integration.

Audit trail
Authority model

Execution authority must live somewhere explicit.

OpenZaps split creation, execution, and submission authority so you can walk away without handing an agent broad approvals or custody. Pick the surface that fits the workflow.

01 / Deposit

Pre-funded immutable zap

Assets sit inside a narrow policy capsule. Hermes triggers only the frozen action graph; you keep an unconditional withdraw and revocation path.

Recurring automation
02 / Signature

EIP-712 typed intent

One-shot authority binds chain, zap, nonce, deadline, recipient, fee cap, gas, and policy hash before any relayer touches it.

Infrequent execution
03 / Wallet-native

Safe / ERC-1271 signer

Contract wallets sign the same typed policy. Hermes stays a submitter, simulator, and monitor — never an operator with discretion.

Power users
Reusable templates

Start narrow. Expand only after the controls hold.

Templates turn successful workflows into reviewable policy manifests. Some are ready for preview, some require governance review, and protective zaps stay deferred until external risk review clears.

ready preview

Recurring DCA

A user pre-commits spend, frequency, recipient, slippage, relayer fee cap, and private submission for recurring ERC-20 buys.

automation
requires review

Launch pool deposit

A bounded deposit policy for CliqueClaw or pool.fans launch pools, with a fixed recipient vault and no arbitrary calldata.

launch
requires review

Claim and compound

A repeatable fee-claim policy for audited reward sources, exact approvals, and balance-delta postconditions.

yield
deferred

Guarded exit

A protective policy for liquidity or oracle-risk exits. This is deliberately blocked in v1 until protective-zap review is complete.

protection
Security posture

Narrow policy beats universal routing.

The v1 contracts are a complete, internally-reviewed reference implementation: 47 passing tests, an adversarial multi-agent review, and 9 internal findings fixed — including a critical clone-hijack (all documented in the linked repo). Not externally audited; we say so plainly.

No arbitrary target + calldata — fixed adapters only
Exact approvals, reset to zero on every path
Authorization consumed before any external call
Measured balance-delta postconditions
Unconditional owner emergency exit
ERC-1271 contract-wallet signatures
Read the contracts + audit on GitHub ↗
Security architecture →

v1 reference contracts deployed on Base · factory 0xc7C5926C

Build the policy first. Let agents act second.

Use the console to design, simulate, save, dry-run, and revoke bounded policy capsules.

Not financial advice. 0xZAPS is a community token with no claim on revenue, yield, or assets; onchain actions are irreversible and the protocol is pre-external-audit.