# Supported Transactions

What the Joey browser extension will sign for a dApp, and what it always refuses.

Joey signs any transaction type it recognises, **except** the cases below. These refusals protect users from requests that would hand control of their account to someone else. They are applied:

- before the user is asked, and again at the moment of signing;
- at every level, including each inner transaction of an XLS-56 `Batch`.

The user is never asked to approve a refused request. Users can still perform these operations from Joey's own interface.

## Refused transaction types

Requests for these fail with `4100` ("transaction type not permitted").

| Type | Why |
|---|---|
| `SetRegularKey` | Grants permanent signing authority to another key |
| `SignerListSet` | Grants signing authority through multisign |
| `DelegateSet` | Grants authority through delegation |
| `AccountDelete` | Irreversible |
| `SetHook` | Installs code that runs on every future transaction |
| `EnableAmendment`, `SetFee`, `UNLModify` | Pseudo-transactions that no account signs |
| `AccountSet` with a dangerous flag | See below |

### `AccountSet` flags

Refused when **set** (`SetFlag`):

- `asfRequireAuth`
- `asfDisallowXRP`
- `asfDisableMaster`
- `asfNoFreeze`
- `asfAuthorizedNFTokenMinter`
- `asfAllowTrustLineClawback`
- `asfGlobalFreeze`
- `asfDepositAuth`

Refused when **cleared** (`ClearFlag`):

- `asfRequireAuth`
- `asfDisallowXRP`
- `asfDepositAuth`

Other flags, such as `asfDefaultRipple`, `asfRequireDest`, `asfAccountTxnID` and the `asfDisallowIncoming*` flags, are allowed.

### Future sequence numbers

A transaction that sets its own `Sequence` ahead of the account's current sequence, and has no `LastLedgerSequence` (or one too far away), is refused. Such a signature could be held and submitted much later. Add a `LastLedgerSequence`.

## Field rules

Requests that break these rules fail with `-32602` before the user is asked.

| Rule | Detail |
|---|---|
| Fee cap | `Fee` is a string of drops. With `autofill: false`, a fee above **2 XRP** (2,000,000 drops) is refused. Autofilled fees are capped at the same amount. |
| No `NetworkID` | Any `NetworkID` field is refused. Mainnet, Testnet and Devnet don't use it. |
| No X-addresses | Use a classic `r…` address and a separate `DestinationTag`. |
| Valid integers | Integer fields must be whole numbers within the field's range. |
| Known types only | `TransactionType` must be a type Joey recognises. |
| Matching account | `tx_json.Account` must be the signing account (except for `signTransactionFor`). |
| Batch rules | A `Batch` must be alone in its request and pass the checks in [Batch and bulk](/docs/browser-extension/batch-and-bulk). |

## Account types

- **Ledger hardware accounts** can sign ordinary transactions, confirmed on the device. They can't sign a `Batch`, and they [sign in](/docs/browser-extension/sign-in) with a challenge transaction.
- **Watch-only accounts** can be connected but can't sign.
