Skip to content
Thyme Docs

Verify Roles Profiles

thyme verify roles-profile reconstructs a supported profile from pinned constants and checks a signature request or the deployed contracts. It needs your chosen RPC endpoint, profile ID, and owner address; it does not authenticate to or call the Thyme API and does not sign or broadcast transactions.

Before signing

Download the request JSON from the Console and save the allowlist you intended independently:

allowlist.json
[
  {
    "target": "0x1111111111111111111111111111111111111111",
    "selector": "0x095ea7b3"
  }
]

Replace the example target and selector with your actual intended rule. An object containing a rules array is also accepted.

thyme verify roles-profile \
  --profile PROFILE_ID --owner OWNER_ADDRESS \
  --rpc-url "$RPC_URL" \
  --request request.json --allowlist allowlist.json

The verifier checks the owner, factory proxy creation code, deterministic addresses and salts, canonical Safe initializer, Roles proxy and role key, executor Safe, typed-data structure, nonce, allowed call shapes/selectors, exact allowlist, and recomputed digest. Use the profile ID and owner you intend, not values copied blindly from an untrusted request.

For a scope update, supply both the new and previously active rules:

thyme verify roles-profile \
  --profile PROFILE_ID --owner OWNER_ADDRESS \
  --request request.json --mode scope-update \
  --allowlist new-rules.json --previous-allowlist old-rules.json

Revocation uses --mode revocation with --request and does not require an allowlist. Setup defaults to --mode setup; --ordering sign_first|deploy_first overrides the request's setup ordering.

After activation

thyme verify roles-profile \
  --profile PROFILE_ID --owner OWNER_ADDRESS \
  --rpc-url "$RPC_URL" --from-block DEPLOYMENT_BLOCK --json

Without --request, the command checks deployed state and events. It reconstructs the Safe and Roles addresses, verifies the pinned stack, checks Safe ownership and module configuration, and verifies the original SafeSetup event belongs to the proxy's creation transaction. Executor derivation uses Roles assignment events and the executor Safe's owner.

If available, pass --digest 0x... with the full 32-byte Safe transaction digest you signed. Later intentional owner, threshold, or module changes can differ from the initial template; review each failed row in context.

Options

OptionDefault / behavior
--profile <id>Required profile ID used to derive salts.
--owner <address>Required customer wallet address.
--chain <id>One of 11155111, 80002, 1301, 137, 10, 56 (default 11155111); other chains rejected.
--rpc-url <url>Explicit endpoint, then RPC_URL loaded from root .env/environment, then viem's public endpoint for --chain. Public endpoints often rate-limit the log scans the post-hoc checks need, so prefer your own node.
--request <file>Select pre-signature mode with exported request JSON.
--allowlist <file>Required for setup and scope-update request checks.
--previous-allowlist <file>Required for scope updates.
--mode <mode>setup, scope-update, or revocation; default setup.
--ordering <ordering>Setup ordering override: sign_first or deploy_first.
--digest <hex>Expected signed digest for post-activation event checking.
--from-block <n>Oldest block to search for events.
--max-blocks <n>Search depth when --from-block is absent; default 400000.
--chunk-blocks <n>Blocks per log request; default 2000.
--jsonMachine-readable output.

Logs are scanned newest first. If a profile was created before the default search window, set an older --from-block. Reduce --chunk-blocks when an RPC limits event query ranges.

Exit codes are 0 for all checks passing, 1 for verification or network failures, and 2 for usage/input errors. A result depends on the RPC responses and supplied intent; review mismatches before signing or funding the profile.