Skip to main content

Authorization Epoch

Each keyshare generated by the MPC nodes has an authorization epoch: a counter that advances by one on every committed policy change. A change is accepted only if it targets the key's current epoch, which prevents stale or replayed requests from overwriting newer state.

OperationRequirementEpoch after success
Create (DKG)policy.epoch = 11
Updatepolicy.epoch = current + 1current + 1
Deleteexpected_authorization_epoch = currentcurrent + 1
  • A key generated without a policy starts at epoch 0.
  • Delete advances the epoch, so the next update uses the new epoch + 1.
  • A stale authorization state error is returned when the epoch is not match.

Read the Current Epoch

curl -X POST "http://<YOUR_WALLET_BACKEND_ENDPOINT>/v2/rest/getPolicy" \
-H "Content-Type: application/json" \
-d '{
"payload": { "key_id": "YOUR_KEY_ID_HERE" },
"userSignatures": { ... }
}'
{
"policy": { "version": "1.0", "epoch": 1, "description": "EIP-191 Policy", "rules": [ ... ] },
"authorization_epoch": 1
}

policy is null when the key has no policy.