Authorization Epoch
Each keyshare generated by the MPC nodes has an authorization epoch: a counter that advances by one on every committed policy change. A change is accepted only if it targets the key's current epoch, which prevents stale or replayed requests from overwriting newer state.
| Operation | Requirement | Epoch after success |
|---|---|---|
| Create (DKG) | policy.epoch = 1 | 1 |
| Update | policy.epoch = current + 1 | current + 1 |
| Delete | expected_authorization_epoch = current | current + 1 |
- A key generated without a policy starts at epoch
0. - Delete advances the epoch, so the next update uses the new epoch
+ 1. - A stale authorization state error is returned when the epoch is not match.
Read the Current Epoch
curl -X POST "http://<YOUR_WALLET_BACKEND_ENDPOINT>/v2/rest/getPolicy" \
-H "Content-Type: application/json" \
-d '{
"payload": { "key_id": "YOUR_KEY_ID_HERE" },
"userSignatures": { ... }
}'
{
"policy": { "version": "1.0", "epoch": 1, "description": "EIP-191 Policy", "rules": [ ... ] },
"authorization_epoch": 1
}
policy is null when the key has no policy.