Skip to main content
The production web application uses Next.js 16, React 19, Privy React Auth, Privy’s wagmi integration, wagmi, viem, TanStack Query, Zod, and Lightweight Charts.

Wallet architecture

PrivyProvider supports google, twitter, and wallet login and exposes only Base Mainnet. embeddedWallets.ethereum.createOnLogin is users-without-wallets, so a social user receives an embedded EVM wallet only when no wallet is already associated with that user. External-wallet users can keep Rabby, MetaMask, or another EVM wallet as their signer. The provider order is Privy, TanStack Query, Privy’s wagmi provider, ActiveWalletProvider, then application providers. wagmiConfig is built with @privy-io/wagmi, keeps SSR enabled, exposes only Base (8453), and preserves the browser-safe Base RPC transport. ActiveWalletProvider keeps the existing connected, activeAddress, activeChainId, and walletClient contract and adds explicit readiness and account actions. It matches the current wagmi connector to the exact Privy wallet, requires explicit selection when a multi-wallet session is ambiguous, and withholds transaction readiness unless the displayed address, wallet client signer, and Base chain agree. Authentication restoration and wallet hydration never masquerade as a logged-out state. NEXT_PUBLIC_PRIVY_APP_ID is required public browser configuration and is validated before Privy renders. A missing or placeholder value produces an actionable development error instead of a broken login control. No Privy secret, delegated signer, server wallet, or backend transaction path is used.

Writes

  1. Read an onchain quote and balances.
  2. Derive a minimum output from configured slippage.
  3. Bind the quote to wallet, token, side, network, state, and deadline.
  4. Simulate the exact request.
  5. Append the ERC-8021 Builder Code suffix.
  6. Ask the connected wallet to send.
  7. Wait for and validate the receipt.
  8. Refresh onchain and indexed queries.
Immediately before each write, the application rechecks the wallet client’s selected account and live chain. If the wallet disconnects, changes account, rejects Base switching, or no longer matches the address in the review modal, the write fails closed and the user must review again. The transaction modal identifies Base (8453), active wallet, reviewed amounts, hash, and current phase. BaseScan links use the confirmed or submitted transaction hash.

Indexed reads

Zod schemas fail closed on malformed API responses. ETH remains the authoritative displayed denomination; optional USD reference values depend on a validated API oracle response and render unavailable when missing or stale.