ReadonlyactivityResolvers that group/label getActivityHistory rows.
ReadonlycontractReadonlyidentitySigning identity associated with the wallet.
A real signer, not a ReadonlyIdentity that structurally fits: contract
corridors need all four members — sign, signMessage, signerSession
and xOnlyPublicKey — and signerSession is the one a watch-only
identity lacks. isSigningIdentity is the check; a wallet that fails it
is refused as WalletCannotSignError before anything is funded, rather
than at the push that discovers there is no signer.
ReadonlyserviceReadonlywalletAsset manager bound to this wallet instance.
This tells the service worker to wipe all locally persisted wallet data.
Wallet history grouped into logical activities with signed net amounts.
Arkade address used for offchain funds.
An ArkadeBroadcaster proxied to the worker, which holds the
provider. Only ServiceWorkerWallet offers one: a readonly worker
refuses SUBMIT_TX/FINALIZE_TX outright, so exposing it on the
readonly class would promise something the boundary rejects.
Delegated to the worker, which holds the wallet that owns the connection. The payload crosses raw — see ResponseGetArkadeInfo for why.
Optionalopts: GetArkadeInfoOptionsAn ArkadeReader that speaks to the worker rather than to the server. The page holds no provider, so a caller that built its own from a URL would open a second connection outside the worker's rate gate and caches — this proxy is what keeps chain reads in one place.
The wallet's combined onchain and offchain balance.
Onchain boarding address used to move funds into Arkade.
Onchain boarding inputs tracked by the wallet.
Get the contract manager associated with this wallet. This is useful for querying contract state and watching for contract events.
Contract manager instance
Delegation manager, when configured.
Optionalopts: GetNewAddressesOptionsWallet.getNewAddresses
Proxied as a single request rather than rebuilt page-side out of getNextSigningDescriptor: the worker owns the HD watermark and the contract repository, so splitting the operation would let a page burn an index and then fail to register the script, leaving an address nothing watches.
Note the error shape — WalletCannotAllocateAddressError is thrown
worker-side and cannot cross the message boundary as a class, so a
forceNew refusal surfaces here as a plain Error carrying its message
(and the worker-side error as cause). Callers that must branch on the
refusal match the message rather than instanceof.
Wallet-level provider-connection freshness, delegated to the worker via
GET_STATUS. Async by necessity (the worker boundary is asynchronous); no
synchronous variant is offered because it would have the same transport
mismatch as the contract-manager proxy's cached getSyncState().
The gate has to run inside the worker (no plugin object or contract row
metadata exists on this side), so this is its own message rather than a
post-filter over GET_VTXOS.
A worker predating this message answers "Unknown message" and the call
throws. That is deliberate: service workers activate asynchronously, so
new page code runs against a stale worker for a window on every deploy,
and falling back to GET_VTXOS there would silently spend ungated coins.
Fail closed — loud and recoverable — rather than make the gate advisory.
Optionalfilter: GetVtxosFilterReturn service-worker wallet status, including connectivity and sync state.
Current service-worker wallet status payload including walletInitalized and xOnlyPublicKey
Wallet transaction history derived from boarding and Arkade activity.
Get virtual outputs tracked by the wallet.
Optionalfilter: GetVtxosFilterOptional filtering flags
virtual outputs with tapscript and witness data, normalized: every canonical fact the capability predicates read is populated, whatever the underlying repository stored
Trigger a wallet reload inside the service worker.
true when the wallet was reloaded
Explicitly recover this wallet's contracts and balance on a fresh repo.
Mirrors Wallet.restore but drives the scan inside the service
worker — the materialize() callback used by scanContracts cannot
cross the postMessage boundary, so the entire flow runs worker-side
and only the gapLimit / outcome cross the wire.
Uses the streaming send path so the bus deadline does not race a
long indexer-bound scan. AggregateError thrown by the worker is
reconstructed here so callers can inspect .errors.
Optionalopts: { gapLimit?: number }Send bitcoin and/or assets to one or more Arkade recipients, passed
either as variadic Recipients or as a single SendParams object —
the latter also carries the inputs to spend.
Recipients, or a SendParams object
Arkade transaction id
Settle boarding inputs and/or preconfirmed virtual outputs into settled virtual outputs.
Optionalparams: SettleParamsOptional explicit settlement inputs and outputs
Optionalcallback: (event: SettlementEvent) => voidArkade transaction id
HDWalletCapable.signerForDescriptor
Runs page-side: an Identity cannot cross the message bus, and it does
not need to — the page owns the signing identity, and resolving a
descriptor reads no allocation state. Shares
resolveDescriptorSigner with Wallet.signerForDescriptor
so the two sides of the bus cannot answer differently for one
descriptor.
No provider is passed, and none is needed: HDDescriptorProvider's
isOurs and signing members all delegate to the identity, which the
page holds. Building one here would only add a page-side read of the
wallet state the worker allocates from — shared mutable state on a path
that has no business touching it.
StaticcreateCreate a readonly service-worker wallet bound to an already-registered worker.
Service worker, identity, and backend configuration
Initialized readonly service-worker wallet
StaticsetupSimplified setup method that handles service worker registration and wallet initialization automatically.
Core wallet interface for Bitcoin transactions with Arkade protocol support.
This interface defines the contract that all wallet implementations must follow. It provides methods for address management, balance checking, virtual output operations, and transaction management including sending, settling, and unrolling.
See
IReadonlyWallet