@arkade-os/sdk Documentation - v0.5.0-rc.11
    Preparing search index...

    Interface HDWalletCapable

    Capability a wallet exposes so descriptor-blind consumers — Boltz swaps and other plugins — can bind the artifacts they create to the wallet's current HD index and later enumerate every index that has been used.

    Probed structurally (isHDWalletCapable) rather than widening IWallet: plugins must keep working against wallets that predate it, and a static wallet answers "no HD state" through the same three methods.

    interface HDWalletCapable {
        getCurrentSigningDescriptor(): Promise<string | undefined>;
        getUsedSigningDescriptors(opts?: { lookAhead?: number }): Promise<string[]>;
        signerForDescriptor(descriptor: string): Promise<Identity>;
    }

    Implemented by

    Index

    Methods

    • The descriptor at the wallet's current receive index, or undefined for static / auto wallets and HD wallets that have never rotated. Callers fall back to the identity key.

      Returns Promise<string | undefined>

    • Every descriptor the wallet may hold keys under, ascending by index: the allocation watermark's band plus any descriptor persisted on a contract. Empty for static wallets.

      lookAhead appends that many descriptors past the watermark without advancing it, for a restore that must probe indices no local state mentions yet.

      Parameters

      • Optionalopts: { lookAhead?: number }

      Returns Promise<string[]>

    • An Identity whose keys and signatures are those of descriptor. Returns the wallet identity itself when descriptor is the identity's own key (a static wallet's descriptor, or an HD wallet's baseline key).

      Throws ForeignDescriptorError for a descriptor this wallet cannot sign for. Never silently substitutes another key: an identity handed out for a foreign descriptor signs happily with the wrong key, and that surfaces only as a rejected transaction or a dead script — far from the call that caused it.

      The returned identity must actually sign — sign, signMessage and signerSession, not just xOnlyPublicKey. A watch-only identity carrying the right key is not a signer, and contractSigner refuses it as WalletCannotSignError: returning one here would otherwise pass every check and throw at push time, after the contract is funded.

      Parameters

      • descriptor: string

      Returns Promise<Identity>