Pyre Scope mark Pyre Scope PS-1 read at block {{ liveBlock }} Open Kiosk
Copper key plate etched with receiver_id perp.near, method tabs and an allowance gauge, one refused withdraw call scorched red at its edge
receiver_id · perp.near
withdraw · refused at the edge
ledger · one row per DeleteKey
U1 · ScopeR12 · C4

A key that only opens perp.near

One function-call access key, limited to named perp methods and a fixed allowance. You delete it on-chain when the session ends.

J1 · receiver_id3 methodsallowance gauge1 refusal edge
U7 · Probe bench {{ heroStatus }}
{{ heroPk }}perp.near
Allowance left{{ heroAllowLeft }} NEAR
{{ l.time }} {{ l.text }}{{ l.res }}
Simulated calls. No wallet is connected.
DENIED {{ heroDeniedMsg }}
U2 · Sequence

The Rotation Ceremony

Choose the receiver, the methods and the allowance. Sign AddKey and trade inside those limits. When you close the session, sign DeleteKey. Each burned key leaves one row in the ledger: public key, scope, and the hash of its deletion.

{{ s.ref }}
{{ s.n }}
{{ s.title }}
{{ s.action }}

{{ s.body }}

U3 · Scope map

What the key can touch

place_order, cancel_order and close_position on perp.near, plus a gas allowance you set. A withdraw or a call to any other contract is rejected, and the kiosk shows the rejection instead of hiding it.

SCH-2 · FunctionCall permissionR4 · R5 · R6 · Q1 · Q2
{{ t.m }}
✕
{{ t.r }} {{ t.res }}
allowance gas fees only, set by you deposit refused with any function-call key refusals rejected before inclusion, no gas spent
Ledger of burned key plates stacked in rows, each stamped with a DeleteKey hash, one live plate at the top
L1 · BURNED PLATES
U4 · Ledger

Every burn leaves a row

{{ ledgerCount }} keys burned · simulated, kept in this browser
StampPublic key · scopeCalls
{{ r.stamp }} {{ r.pkShort }} · {{ r.scope }} {{ r.calls }}
Burn one yourself
U5 · Chain readout

NEAR Protocol logo {{ chainLogoLetter }} {{ chainName }}

snapshot block {{ snapBlock }} {{ snapAt }} read at block {{ liveBlock }} · https://free.rpc.fastnear.com block
R21 · Top {{ topCount }} pools · 24h volume
{{ volTotal }}
{{ srcPools }}
R22 · New pools listed
{{ newCount }}
{{ srcNew }}
R23 · Snapshot block
{{ snapBlockRoll }}
https://free.rpc.fastnear.com block · {{ snapAt }}
T1 · Top pools by 24h volumeread {{ snapAt }} · block {{ snapBlock }}
Pool DEX Price 24h vol Reserve Buys / sells 24h
{{ p.bAlt }} {{ p.bLetter }} {{ p.qAlt }} {{ p.qLetter }} {{ p.name }} {{ p.baseAddr }}{{ p.quoteAddr }}
{{ p.dAlt }} {{ p.dLetter }} {{ p.dex }} {{ p.price }} {{ p.vol }} {{ p.res }} {{ p.buys }} / {{ p.sells }}
Source: {{ srcPools }} · {{ srcLogos }}
T2 · Newest poolsread {{ snapAt }}
{{ p.bAlt }} {{ p.bLetter }} {{ p.qAlt }} {{ p.qLetter }} {{ p.name }}
{{ p.dAlt }} {{ p.dLetter }} {{ p.dex }} · created {{ p.created }}
reserve {{ p.res }}24h vol {{ p.vol }}
Source: {{ srcNew }} · {{ srcLogos }} · {{ chainSrcNote }}
U6 · Kiosk PS-1
Scope it. Manifest it. Burn it.
Open Kiosk
Keyhole eyelet mark
Key kiosk PS-1
Simulated · no wallet connected
{{ st.n }} {{ st.label }}
J1 · receiver_idR12
J2 · method_namesC4
J3 · allowanceR7
{{ kAllow }} NEAR
0.01gas only1.00
Manifest preview · FunctionCall
{{ kPreview }}
Scope locked
while a key is live
D1 · Displaycalls {{ kCalls }} · refused {{ kRefused }}
{{ l.t }}
{{ kHint }}
DENIED {{ kFlashMsg }}
ACCEPTED · {{ kFlashMsg }}
B1 · PLATE BAY
SLOT EMPTY No key exists yet. MANIFEST etches one here.
RECEIVER_IDFUNCTION-CALL KEY
perp.near
ALLOWANCE {{ kAllow }} NEAR{{ kPkShort }}
gauge {{ kLeft }} left
✕ {{ kRefused }}
{{ tb.name }}
DELETED {{ kStamp }}
K1 · Probe keypad{{ kUsedTxt }}
SIGNING…
L1 · LedgerR30
{{ ledgerCount }}burned keys
{{ r.stamp }} {{ r.when }}
{{ r.pkShort }}
{{ r.scope }}
DeleteKey {{ r.txShort }}{{ r.calls }} ok · {{ r.refused }} ✕
Simulated rows. Hashes are illustrative, kept in this browser.
SCH-0 · Manual

How it works

Pyre Scope manages one NEAR function-call access key per trading session. The key is added to your account with a narrow permission, used for the session, and deleted when you leave. The ledger keeps the record.

Keyhole eyelet cut from copper plate, one edge scorched
U1 · 01

The permission

A NEAR access key is either full-access or function-call. A function-call key carries three limits: one receiver_id, a list of method_names, and an allowance that pays gas fees. It cannot transfer NEAR, cannot attach a deposit, and cannot add or delete keys.

An empty method_names list means every method on the receiver. The kiosk never manifests an empty list.

"permission": {
  "FunctionCall": {
    "allowance": "250000000000000000000000",
    "receiver_id": "perp.near",
    "method_names": [
      "place_order",
      "cancel_order",
      "close_position"
    ]
  }
}
U2 · 02

Manifest: AddKey

a · generate

A fresh ed25519 keypair is created for this session only.

b · sign once

Your wallet signs one AddKey action with your full-access key.

c · trade

Orders are signed by the scoped key without further wallet prompts.

U3 · 03

What the chain refuses

A transaction outside the scope fails validation and is never included in a block. The kiosk shows each refusal by its error name.

ERRORCAUSEEXAMPLE
MethodNameMismatchmethod not in method_nameswithdraw on perp.near
ReceiverMismatchcall to another contractft_transfer on wrap.near
NotEnoughAllowancegas allowance spentorder after the gauge is empty
DepositWithFunctionCallnon-zero deposit attachedany call carrying NEAR
RequiresFullAccessaction other than FunctionCallTransfer, AddKey, DeleteKey
U4 · 04

Burn: DeleteKey

Closing the session signs DeleteKey for the session public key. After that transaction, the key cannot sign anything. The ledger stores one row per burn: public key, scope, and the hash of the DeleteKey transaction.

{{ r.stamp }}{{ r.pkShort }}
U5 · 05 · THIS PROTOTYPE

The kiosk connects no wallet and signs nothing. Keys, hashes, gas costs and ledger rows are illustrative. The chain readout on the overview comes from a snapshot of NEAR taken at block 217865807, and the block head is read live from https://free.rpc.fastnear.com.

Open Kiosk
DENIED

This route is out of scope.

Return to overview