Multi-step Action Plans
Combine approved swap and vault steps into one action with a final output minimum.
How a plan works#
A plan adapter executes a deployed sequence of external steps under one private action. It can combine supported swaps and vault conversions. The Pool authorizes the plan through its input asset, final output asset and adapter.
Plans are curated test routes. Their targets and calldata choices are set at deployment; the caller cannot build an arbitrary route at runtime.
What deployment fixes#
Deployment sets the ordered steps, token chain, targets, market identities and guards. planDigest commits to that configuration. The publisher admits its adapter, operation and asset tuple with the adapter's runtime hash.
The proof covers the input amount, final minimum and output owner. A relayer must use the deployed steps; it cannot replace an intermediate market.
Supported steps#
A plan has at most four steps. They can be Uniswap V3 exact-input single-hop or bounded multihop swaps, or ERC-4626 deposits and redemptions. Tokens throughout the path are distinct. Each step must consume and return the quantities the adapter measures.
The user approves one final output floor. If later steps are deterministic vault conversions, the adapter can work backwards from it to derive earlier floors. For other intermediates, the final output check determines whether the action succeeds.
| Step type | Measure |
|---|---|
| V3 exact-input swap | Output tokens returned by the configured path |
| ERC-4626 deposit | Shares minted for the next step |
| ERC-4626 redeem | Underlying assets returned to the next step |
| Final step | Output received directly by the Pool |
If a step fails#
A failure reverts the entire action, including reserve changes and consumed nullifiers. The adapter reports which step failed because of short output, changed identity, a missing floor or a venue revert.
Before returning successfully, it checks its starting balances, Pool token deltas, cleared allowances and contract identities. The output then follows immediate or two-stage note settlement.
Quote a plan#
Approve the manifest's digest through a separate review, not by trusting the same API response that serves it. Quote and proof preparation must check every dependency and capacity at a consistent block and use the final minimum the user approved.
All venue calls and intermediate amounts are public. Executing them in one transaction helps with atomicity; it does not hide the market activity.