Overwing

Overwing Preflight

Should the agent sign this? Ask before it does.

An agent with a Solana wallet signs whatever it is handed: a swap route from an API, a transaction built from a prompt. Preflight is one call in the signing path. It simulates the unsigned transaction, works out what it would take from your wallet, and answers allow or refuse against limits you set. It never sees a key and never sends anything to the chain.

Live on Solana mainnet. One check counts as one evaluation on any Overwing plan, or $0.01 in USDC over x402 with no account.

How it works

Four steps, about a fifth of a second.

01

Read

Preflight decodes the transaction itself: who signs, which accounts it can write to, which programs it calls, and the lookup tables it loads more accounts from.

02

Simulate

It runs the transaction against the chain as it is now, without sending it, and compares your wallet's accounts before and after.

03

Judge

SOL out, tokens out, tokens in, every program that ran, and any change of control over your token accounts are held to your policy. Anything the policy does not allow is refused.

04

Publish

The verdict is signed and added to a public record. If an allow turns out wrong, the chain shows it, and that is published too.

The policy

You set the limits. Everything else is refused.

wallet (required). The address to protect. It must sign the transaction.

max_sol_out (required). The most SOL the transaction may take, fees included. Zero allows none.

max_token_out. Atomic units that may leave, by mint. A mint you do not list may not leave at all.

min_token_in. Atomic units that must arrive, for a swap.

allowed_programs. When given, every program the transaction runs, top-level or inner, must be on the list.

allow_delegation. Off by default: a spending approval on one of your token accounts is refused.

A token account handed to another owner, or the wallet itself assigned to a program, is always refused. A field Preflight does not recognize is an error, so a misspelled limit cannot pass silently.

POST /api/v1/preflight/checks
Authorization: Bearer ow_live_…
{ "transaction": "AQAAAAAAAAAAAAAA…",
  "policy": {
    "wallet": "<the wallet that signs>",
    "max_sol_out": 0.0005,
    "allowed_programs": ["11111111111111111111111111111111"] } }

200 OK
{ "id": "pfc_aBcDeFgHiJkLmNoP",
  "decision": "refuse",
  "reasons": [
    { "code": "sol_out_exceeds_limit",
      "detail": "1005000 lamports would leave the wallet; the policy allows 500000" } ],
  "effects": { "sol_out_lamports": "1005000", "token_out": {}, "token_in": {}, "control": [] },
  "programs": ["11111111111111111111111111111111"],
  "covered": false,
  "valid_for_seconds": 120,
  "receipt": { "payload_hash": "…", "signature": "…", "signing_key_id": "…" } }

Every reason a transaction is refused

sol_out_exceeds_limit
More SOL would leave the wallet than policy.max_sol_out allows, fees included.
token_out_exceeds_limit
More of a token would leave than policy.max_token_out allows. A mint the policy does not list may not leave at all.
token_in_below_minimum
Less of a token would arrive than policy.min_token_in requires.
program_not_allowed
The transaction runs a program, top-level or inner, that policy.allowed_programs does not list.
delegate_approved
Someone would be approved to spend from one of the wallet's token accounts. Allowed only with policy.allow_delegation.
token_account_owner_changed
One of the wallet's token accounts would be handed to another owner.
wallet_reassigned
The wallet itself would be assigned to a program.
wallet_not_a_signer
policy.wallet does not sign the transaction, so the check would say nothing about it.
simulation_failed
The transaction would fail if sent now.
simulation_incomplete
The node did not return the accounts after the transaction.
lookup_table_unreadable
The transaction loads accounts from a lookup table that is missing or too short.
too_many_accounts
The transaction can write to more accounts than one check reads.
program_unresolved
An instruction names a program outside the transaction's own accounts.

What it cannot do

A simulation is a prediction. Here is where it ends.

  • It describes one moment. A verdict covers a transaction that lands within 120 seconds. Sign and send at once, or check again.
  • A program can behave differently on chain. One whose author controls it can pass a simulation and act otherwise when it lands. That is what the guarantee is for, and why it is limited to programs we name.
  • It tracks SOL and token accounts. Stake accounts and positions a program holds for your wallet are not followed.
  • It is advice to whoever holds the key. An agent that signs without asking is not protected. Put the call where the signature is made, and pair it with an on-chain spending limit if the agent itself is not trusted.

The guarantee

A wrong allow is ours to pay for. Within small limits, for now.

What a miss is. Preflight answered allow, the same transaction landed within 120 seconds, and it took more SOL or tokens from the wallet than your policy permits, or took one of its token accounts. Anyone can check that from the chain, so anyone may report one, with no account: POST /api/v1/preflight/checks/{id}/reports with the landed signature.

When a miss is covered. The verdict was an allow and every program the transaction ran is one we name: System, Compute Budget, SPL Token, Token-2022, Associated Token Account, Jupiter v6, PumpSwap, PumpSwap fees. A transaction that runs anything else is still checked and still published; it is not covered.

What is paid. The amount taken beyond your policy, valued in dollars when the miss is confirmed, in USDC to the wallet in the verdict. Never to whoever reported it.

What is not. A shortfall in what arrives, which is slippage and belongs in the swap’s own minimum. A transaction changed after the check. One that landed outside the window. Anything we find was arranged to produce a claim. We review every covered miss before paying and publish the reason when we do not.

Whose money. Overwing’s alone. Nobody else has money in the reserve and nobody earns a return from it. This is a service guarantee from the company that gives the verdict, not insurance, and it is limited to what the reserve holds.

  • $100
    the most paid for one verdict
  • $200
    the most paid to one wallet in a calendar month
  • Not funded yet
    Until the reserve is funded, misses are recorded and published and nothing is paid. This page will name the reserve's address when it is.