Browser Extension

Supported Transactions

What the Joey browser extension will sign for a dApp, and what it always refuses.

Joey signs any transaction type it recognises, except the cases below. These refusals protect users from requests that would hand control of their account to someone else. They are applied:

  • before the user is asked, and again at the moment of signing;
  • at every level, including each inner transaction of an XLS-56 Batch.

The user is never asked to approve a refused request. Users can still perform these operations from Joey's own interface.

Refused transaction types

Requests for these fail with 4100 ("transaction type not permitted").

Type Why
SetRegularKey Grants permanent signing authority to another key
SignerListSet Grants signing authority through multisign
DelegateSet Grants authority through delegation
AccountDelete Irreversible
SetHook Installs code that runs on every future transaction
EnableAmendment, SetFee, UNLModify Pseudo-transactions that no account signs
AccountSet with a dangerous flag See below

AccountSet flags

Refused when set (SetFlag):

  • asfRequireAuth
  • asfDisallowXRP
  • asfDisableMaster
  • asfNoFreeze
  • asfAuthorizedNFTokenMinter
  • asfAllowTrustLineClawback
  • asfGlobalFreeze
  • asfDepositAuth

Refused when cleared (ClearFlag):

  • asfRequireAuth
  • asfDisallowXRP
  • asfDepositAuth

Other flags, such as asfDefaultRipple, asfRequireDest, asfAccountTxnID and the asfDisallowIncoming* flags, are allowed.

Future sequence numbers

A transaction that sets its own Sequence ahead of the account's current sequence, and has no LastLedgerSequence (or one too far away), is refused. Such a signature could be held and submitted much later. Add a LastLedgerSequence.

Field rules

Requests that break these rules fail with -32602 before the user is asked.

Rule Detail
Fee cap Fee is a string of drops. With autofill: false, a fee above 2 XRP (2,000,000 drops) is refused. Autofilled fees are capped at the same amount.
No NetworkID Any NetworkID field is refused. Mainnet, Testnet and Devnet don't use it.
No X-addresses Use a classic r… address and a separate DestinationTag.
Valid integers Integer fields must be whole numbers within the field's range.
Known types only TransactionType must be a type Joey recognises.
Matching account tx_json.Account must be the signing account (except for signTransactionFor).
Batch rules A Batch must be alone in its request and pass the checks in Batch and bulk.

Account types

  • Ledger hardware accounts can sign ordinary transactions, confirmed on the device. They can't sign a Batch, and they sign in with a challenge transaction.
  • Watch-only accounts can be connected but can't sign.