Overwing Preflight
Should the agent sign this? Ask before it does.
An agent with a Solana wallet signs whatever it is handed: a swap route from an API, a transaction built from a prompt. Preflight is one call in the signing path. It simulates the unsigned transaction, works out what it would take from your wallet, and answers allow or refuse against limits you set. It never sees a key and never sends anything to the chain.
Live on Solana mainnet. One check counts as one evaluation on any Overwing plan, or $0.01 in USDC over x402 with no account.
How it works
Four steps, about a fifth of a second.
Read
Preflight decodes the transaction itself: who signs, which accounts it can write to, which programs it calls, and the lookup tables it loads more accounts from.
Simulate
It runs the transaction against the chain as it is now, without sending it, and compares your wallet's accounts before and after.
Judge
SOL out, tokens out, tokens in, every program that ran, and any change of control over your token accounts are held to your policy. Anything the policy does not allow is refused.
Publish
The verdict is signed and added to a public record. If an allow turns out wrong, the chain shows it, and that is published too.
The policy
You set the limits. Everything else is refused.
wallet (required). The address to protect. It must sign the transaction.
max_sol_out (required). The most SOL the transaction may take, fees included. Zero allows none.
max_token_out. Atomic units that may leave, by mint. A mint you do not list may not leave at all.
min_token_in. Atomic units that must arrive, for a swap.
allowed_programs. When given, every program the transaction runs, top-level or inner, must be on the list.
allow_delegation. Off by default: a spending approval on one of your token accounts is refused.
A token account handed to another owner, or the wallet itself assigned to a program, is always refused. A field Preflight does not recognize is an error, so a misspelled limit cannot pass silently.
POST /api/v1/preflight/checks
Authorization: Bearer ow_live_…
{ "transaction": "AQAAAAAAAAAAAAAA…",
"policy": {
"wallet": "<the wallet that signs>",
"max_sol_out": 0.0005,
"allowed_programs": ["11111111111111111111111111111111"] } }
200 OK
{ "id": "pfc_aBcDeFgHiJkLmNoP",
"decision": "refuse",
"reasons": [
{ "code": "sol_out_exceeds_limit",
"detail": "1005000 lamports would leave the wallet; the policy allows 500000" } ],
"effects": { "sol_out_lamports": "1005000", "token_out": {}, "token_in": {}, "control": [] },
"programs": ["11111111111111111111111111111111"],
"covered": false,
"valid_for_seconds": 120,
"receipt": { "payload_hash": "…", "signature": "…", "signing_key_id": "…" } }Every reason a transaction is refused
- sol_out_exceeds_limit
- More SOL would leave the wallet than policy.max_sol_out allows, fees included.
- token_out_exceeds_limit
- More of a token would leave than policy.max_token_out allows. A mint the policy does not list may not leave at all.
- token_in_below_minimum
- Less of a token would arrive than policy.min_token_in requires.
- program_not_allowed
- The transaction runs a program, top-level or inner, that policy.allowed_programs does not list.
- delegate_approved
- Someone would be approved to spend from one of the wallet's token accounts. Allowed only with policy.allow_delegation.
- token_account_owner_changed
- One of the wallet's token accounts would be handed to another owner.
- wallet_reassigned
- The wallet itself would be assigned to a program.
- wallet_not_a_signer
- policy.wallet does not sign the transaction, so the check would say nothing about it.
- simulation_failed
- The transaction would fail if sent now.
- simulation_incomplete
- The node did not return the accounts after the transaction.
- lookup_table_unreadable
- The transaction loads accounts from a lookup table that is missing or too short.
- too_many_accounts
- The transaction can write to more accounts than one check reads.
- program_unresolved
- An instruction names a program outside the transaction's own accounts.
What it cannot do
A simulation is a prediction. Here is where it ends.
- It describes one moment. A verdict covers a transaction that lands within 120 seconds. Sign and send at once, or check again.
- A program can behave differently on chain. One whose author controls it can pass a simulation and act otherwise when it lands. That is what the guarantee is for, and why it is limited to programs we name.
- It tracks SOL and token accounts. Stake accounts and positions a program holds for your wallet are not followed.
- It is advice to whoever holds the key. An agent that signs without asking is not protected. Put the call where the signature is made, and pair it with an on-chain spending limit if the agent itself is not trusted.
The guarantee
A wrong allow is ours to pay for. Within small limits, for now.
What a miss is. Preflight answered allow, the same transaction landed within 120 seconds, and it took more SOL or tokens from the wallet than your policy permits, or took one of its token accounts. Anyone can check that from the chain, so anyone may report one, with no account: POST /api/v1/preflight/checks/{id}/reports with the landed signature.
When a miss is covered. The verdict was an allow and every program the transaction ran is one we name: System, Compute Budget, SPL Token, Token-2022, Associated Token Account, Jupiter v6, PumpSwap, PumpSwap fees. A transaction that runs anything else is still checked and still published; it is not covered.
What is paid. The amount taken beyond your policy, valued in dollars when the miss is confirmed, in USDC to the wallet in the verdict. Never to whoever reported it.
What is not. A shortfall in what arrives, which is slippage and belongs in the swap’s own minimum. A transaction changed after the check. One that landed outside the window. Anything we find was arranged to produce a claim. We review every covered miss before paying and publish the reason when we do not.
Whose money. Overwing’s alone. Nobody else has money in the reserve and nobody earns a return from it. This is a service guarantee from the company that gives the verdict, not insurance, and it is limited to what the reserve holds.
- $100the most paid for one verdict
- $200the most paid to one wallet in a calendar month
- Not funded yetUntil the reserve is funded, misses are recorded and published and nothing is paid. This page will name the reserve's address when it is.