Smart Contracts
The on-chain contracts and deployed addresses across supported chains.
Network Information
Aegis contracts are deployed on Base mainnet, Base Sepolia, Sepolia testnet, and Arc Testnet
Base Mainnet
ERC-8004 agent identity registration
0xE49Eeb26346c0af54c98D82BA33DeA43174Ef7C1Key functions: registerAgent, getAgent, isAgentActive
On-chain policy and permission storage
0x1C3aA1eb29Bbe4C18Cc5C483524E18B40CF64f94Key functions: createPolicy, grantPermission, revokePermission, isPermissionValid
Per-asset, raw-amount action validation + usage accounting (no price oracle). Limits are per asset in that asset's own base units.
0x1BD9deD0e5C80C7c163D5eFD86ff552706B538a4Key functions: setConstraints (per-asset), checkAction, consumeAllowance (atomic enforce+record), recordUsage, getUsage, getRemainingQuota
Chainlink ETH/USD price — used ONLY for fee USD→wei conversion. No role in policy enforcement (limits are raw per-asset).
0x9883A48206F0e84bbaB8d8Cb93700e51A03078f7Key functions: getEthUsdPrice, setTokenFeed
Centralized fee configuration for account creation and transfer fees
0x5178098F549a3cb4eC06B036EAf4fA0c2160cC6AKey functions: getCreationFeeWei, calculateTransferFee, feeCollector
Protocol calldata resolver for DeFi adapters
0x2ef16690b9298Fb99eBc8903CC1c4d14A95793A2Registered adapter for common DeFi selectors
0x79098A54eef98364e9058d8975C1CFAf570ce7d1CREATE2 factory for deterministic smart account deployment
0xe94B60040f169D063b6E1684d683097907fC7F41Key functions: createAccount (payable), getAddress, getCreationFee
Base Sepolia
On-chain policy and permission storage
0x687D218AA8b7088e2376c9d420b8E1f3253f2d9APer-asset, raw-amount action validation + usage accounting
0x83301bd61640c9AfA6eD6eb51521D0F1299c8B03Chainlink ETH/USD price — used only for fee USD→wei conversion
0xDE3B9DAEC6BacbA69A2470058DD6B9DefC629A50Fee configuration for accounts
0x1A8a26C457f520ef61A84c8AA459ffE700BBd1f4Protocol calldata resolver for DeFi adapters
0x7A31231aC0f5263172493a01A87C40b5a61ee5F6Registered adapter for common DeFi selectors
0xF3f81D9b3E2aC251441C2E508f51eB9C2B7D8db8CREATE2 factory that deploys policy-enforced ERC-4337 smart accounts
0x421558444D2d23c5e04b20F50765ae5EC4DD0EbFSepolia Testnet
On-chain policy and permission storage
0x96d00C3b3a686a30044BAD93dbbF52540b649b18Action validation with constraints
0x989b844317f0a7f731cB2e1dB367BEd72a142aA6Chainlink-powered price feeds
0xf8d5Ed5520593187AFC950738946C6f1bf0d349dFee configuration for accounts
0x37c03a1d96D70dc60F2dde48Ebc19AC5cAD1fb88Protocol calldata resolver for DeFi adapters
0xb24F255b776179363132e870743105732b195De9Registered adapter for common DeFi selectors
0xDD990DbFAAefEa727e6B28ADA45091fbAd59FBfeCREATE2 factory that deploys policy-enforced ERC-4337 smart accounts
0x74298E689C46955696c26Ceba5BA71DA7058A231Arc Testnet
On-chain policy and permission storage
0xa89c36172D01BF33746B401f0e8C4D316B06D6ecPer-asset, raw-amount action validation + usage accounting
0x4B8C8Ef37fd7a07fAd7a8bc2Cb1ccFDc6bC68019Static USDC/USD feed for Arc testnet fee conversion
0xEAF9179C6FEBDb41f1a317D1f6287B6773312278Fee configuration for accounts
0x1ee21DB922Cf6D781497f565b33cb39822892165Protocol calldata resolver for DeFi adapters
0x195768687C95E6A09fC8D30e4909D1Fda3d76254Registered adapter for common DeFi selectors
0xb30692735F001088ad096ba3C49e55EBA2F6ed3ECREATE2 factory that deploys policy-enforced ERC-4337 smart accounts
0xF9e9BB23a0B76Ae6F85652Da7c85A16a0B6B21e8Per-Asset Limits
Limits are per asset, in that asset's own base units — there is no price-oracle conversion. A USDC cap is set in 6-decimal USDC units (e.g. 1000000000 = 1,000 USDC); native ETH (address(0)) in wei. Each asset has its own daily-rolling budget. An action moving an asset with no configured limit is denied unless the policy enables allowUnlistedAssets. Common token addresses below.
v14 decodes and caps token-input swaps plus LP position flows, and registers CommonDeFi adapters for multicall, Universal Router, Permit2, Curve, Balancer, Aave, Compound, Beefy, and V2-style router paths. Multi-asset flows enforce each input token against its own cap; collect/withdrawal-style recipient checks are restricted to the smart account where required.
| Token | Contract |
|---|---|
| ETH (native) | always supported |
| USDC | 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| WETH | 0x4200000000000000000000000000000000000006 |
| USDT | 0xfde4C96c8593536E31F229EA8f37b2ADa2699bb2 |
| DAI | 0x50c5725949A6F0c72E6C4a641F24049A917DB0Cb |
| USDbC | 0xd9aAEc86B65D86f6A7B5B1b0c42FFA531710b6CA |
| cbETH | 0x2Ae3F1Ec7F1F5012CFEab0185bfc7aa3cf0DEc22 |
| cbBTC | 0xcbB7C0000aB88B473b1f5aFd9ef808440eed33Bf |
| Token | Contract |
|---|---|
| ETH (native) | always supported |
| USDC | 0x036CbD53842c5426634e7929541eC2318f3dCF7e |
| WETH | 0x4200000000000000000000000000000000000006 |
| Token | Contract |
|---|---|
| ETH (native) | always supported |
| USDC | 0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238 |
| LINK | 0x779877A7B0D9E8603169DdbD7836e478b4624789 |
| Token | Contract |
|---|---|
| USDC (native) | always supported |
| USDC | 0x3600000000000000000000000000000000000000 |
| ETH | 0x4ccccd3220ac80c07a8B575A4cb494c0E77606Ed |
Fee Structure
Protocol-level fees enforced on-chain via GuardrailFeeManager
Fees are read on every call from GuardrailFeeManager (creationFeeUsd, transferFeeBps, transferFeeCapUsd). Both are currently set to 0 on Sepolia and Base. The contract enforces a hard cap of 10% (1000 bps) on the transfer fee so the protocol owner cannot exceed that even if fees are reintroduced.
Contract Interaction Flow
1. Factory.createAccount{value: fee}(owner, signer, agentId, mode, salt, parentId)
└── Deploys AgentSmartAccount; enforcer.registerAccount(account, agentId)
2. Agent op (ERC-4337):
EntryPoint.handleOps → Account.validateUserOp [read-only fail-fast: enforcer.checkAction]
→ Account.execute(target, value, AEGIS_MAGIC‖permissionId‖data)
├── enforcer.consumeAllowance(agentId, permissionId, ...) [atomic check + record — the real guard]
└── target.call(actualData) [a revert rolls back the reservation]
Limits are PER-ASSET in raw base units (no oracle). consumeAllowance runs
before the call, so even ops bundled in one block can't exceed a cap.
3. Owner emergency: owner EOA calls Account.execute(target, value, rawData)
└── privileged bypass — raw calldata, no policy enforcement (recovery path)