Skip to main content
Cross-chain permits define the cross-chain bridging scope available to a session. Set them at the session level via crossChainPermits, not per function. Each entry allows source and destination legs and defines the limits the session has to stay within.
A permit restricts bridging authority; it does not enable the session on another chain. For a transaction that uses the account on several chains, also configure Multi-chain sessions.

Basic usage

Restrict a session to only bridge USDC from Base to Arbitrum: Examples on this page use @rhinestone/sdk, where rhinestone is the RhinestoneSDK instance from Create a session with a custom setup.
Pass each token’s address on its corresponding chain. Pass a single leg or an array, and omit a side entirely to leave it unrestricted — the settlement-layer allowlist, deadlines, and recipient rules still apply.

Guardrails

Tighten a permit with optional bounds:
  • maxAmount on a source leg caps how much of that token the session can pull (a spending limit).
  • validAfter / validUntil bound the permit deadline. Both accept a Date.
  • fillDeadline bounds the fill window per destination chain.

Recipient safety

By default a cross-chain permit enforces bridge-to-self on-chain: the destination recipient must be the smart account itself. This stops a leaked session key from routing funds to an attacker-controlled address. Opt out explicitly only when you need to bridge to a different recipient:

Settlement layers

A permit allows any supported settlement layer by default. Pass settlementLayers to narrow it to a subset:
In @rhinestone/sdk 2.16.1, "ECO" authorizes only the legacy Standard ECO arbiters. Eco solver-network routes use a different adapter and are intentionally blocked because the built-in claim policy cannot yet verify their encoded destination, token, recipient, and deadline. A quote that requires a solver-network ECO route cannot use this session; use another supported settlement layer or the account owner until route-aware authorization is available.