DEX Executor
The DEX Executor is a Smart Policy for swaps. 6.1m = named pair. 6.1a = Heat scan. Tokens stay in your wallet.
The Chatito DEX Executor is a Smart Policy for swaps: a signed, capped rule that can trade for you without taking your tokens.
Your wallet stays the wallet. The policy records who opened the grant, what it may spend, how much is left, and when it expires. When a buy runs, one transaction swaps and sends 100% of the output back to you.
This is the DEX analog of a trade-only exchange API key. It is not a vault. It is not "deposit into a smart contract." You stay the custodian.
Three doors: 6.1m, 6.2h, 6.2a
The letter is the job, not a quality score. The app picks the door from the book you create. You do not mix them.
| 6.1m (named pair) | 6.2h (MetaMask Heat) | 6.2a (Chatito Agent Heat) | |
|---|---|---|---|
| For | A named pair. You pick the spend token and the exit token. | A Heat roster. One Sign. The book may buy names in the signed box. | A Heat scan via Chatito Agent on this wallet. |
| What it may sell | Only the exit token you named. | Bags this grant bought, inside the signed roster. | Bags this grant bought. Not a prior bag. Not an airdrop. |
| Wallet | Any common EVM wallet. You approve a capped Permit2 allowance. | Wallets that can atomic batch Sign (wallet_sendCalls). MetaMask today: yes. Rabby today: no. |
Needs Chatito Agent (EIP-7702 type-4 to Chatito). MetaMask will not attach that agent. Rabby cannot yet. |
| Where the rule runs | Chatito executor pulls, swaps, and sends 100% back to you. | Chatito 6.2h executor. No 7702. Base only. Sibling Heat chains stay parked. | The agent runs as your same wallet, inside the grant box. Still not a vault. Tokens never move to a Chatito pocket. |
Same Smart Policy rules on all three: cap, expiry, revoke, recipient is you, grant is not Live.
Heat on MetaMask is 6.2h, not Chatito Agent. 6.1a is a leftover AUTO Heat-scan contract. Do not treat it as the current Heat door.
Why We Built It This Way
Most "leave it running" DEX products pick one of the bad options. We refused them.
| Shortcut | Why we will not do it |
|---|---|
| Deposit into a company vault | That is custody. Chatito is not a bank. |
| Unlimited token approve | Blast radius is your whole balance. |
| Paste a private key or seed | Never. Not for Live. Not for support. |
| Tiny dedicated hot wallet | Extra wallet, extra drain risk, extra trust. |
Instead you sign a Smart Policy: a capped, expiring spend grant. Chatito may then spend only inside that policy, and only send the result to your address.
How A Swap Works
6.1m
You (once per strategy)
sign a Permit2 allowance to the Executor
+ open a grant (spend token, exit token, caps, expiry)
|
v
Tokens stay in YOUR wallet.
The Smart Policy stores the rule. Nothing to withdraw later.
|
When the strategy wants a buy or sell
|
A Chatito keeper calls executeSwap
|
Same transaction:
pull the grant amount
swap on an allowlisted router
send every output token (and leftover) to YOU
6.2h (MetaMask Heat, Base)
You (once per strategy)
atomic wallet_sendCalls batches of <=10
Permit2 home + each Heat name in the snapshot + openGrant
|
v
Tokens stay in YOUR wallet. Roster is the signed box.
|
When Heat wants a buy or a sell of inventory this grant bought
|
A Chatito keeper calls executeSwap on the 6.2h executor
|
Same transaction:
pull the grant amount
swap on an allowlisted router
send every output token (and leftover) to YOU
Sibling Heat chains stay parked. MetaMask will not attach Chatito Agent (that door is 6.2a).
6.2a / leftover 6.1a (Chatito Agent Heat)
You (once per strategy)
attach Chatito Agent on THIS wallet (EIP-7702), if the wallet will
+ open a grant (spend token, cap, expiry)
|
v
Tokens stay in YOUR wallet. No pocket. No second address.
The grant records inventory of bags it bought.
|
When the scanner wants a buy or a sell of that inventory
|
A Chatito keeper calls executeSwap on YOUR wallet
|
Same transaction:
spend only inside the grant box
swap on an allowlisted router
output stays in YOUR wallet
If the swap reverts, nothing is left sitting in a Chatito contract.
Hard Rules (On Purpose)
These are product rules, not marketing.
- No deposit. There is no "send tokens to Chatito" step.
- No withdraw-to-Chatito. Admin cannot sweep user assets.
- Not an upgradeable vault. A Smart Policy is a thin rule, not a proxy you have to trust forever.
- Recipient is you. The wallet that opened the grant is the immutable recipient.
- Rescue only to the owner. If something lands by accident, it can be sent only to the grant owner.
- Routers are gated on-chain. The keeper cannot call a random contract.
- On-chain remaining + expiry. Our database is a cache for the UI. The lock lives on the chain.
Grant Is Not Live
Opening a grant does not arm the strategy.
Live is a separate, human-only switch. Wizards, AI Lab, and agent keys cannot turn Live on for you.
You can revoke the grant (or wait for expiry). After that the bot cannot spend. Tokens never left your wallet in the first place.
Revoke does not turn Live off. The strategy stays Live (if it was) and falls back to manual Sign — you Sign each action yourself.
Where The Policy Lives
These are Chatito-owned executor contracts. One per chain, shared. Grants are per strategy. Do not send tokens to these addresses.
| Chain | Address |
|---|---|
| Base 6.1m | 0xff7e881E39DE1264418a81d720EE5D5a6b612a25 |
| Base 6.1a (leftover AUTO) | 0xDa7eF3a04AC737c490948e18618418974dD86B19 |
| Base 6.2h (MetaMask Heat) | 0xC3a71C6AfaB930090D3e73ffEBAA5dc0186E070B |
| BNB Smart Chain | 0x858B6CCC5BaF112931aDe314ca298d79748F0643 |
| Arbitrum One | 0x858B6CCC5BaF112931aDe314ca298d79748F0643 |
| Ethereum | 0x858B6CCC5BaF112931aDe314ca298d79748F0643 |
| Polygon | 0x721C32F40121f351D601A2D4d83939C83c7B7309 |
| Robinhood Chain | 0x858B6CCC5BaF112931aDe314ca298d79748F0643 |
| HyperEVM | 0x858B6CCC5BaF112931aDe314ca298d79748F0643 |
| Solana | Jupiter spend-grant program (same Smart Policy). Program id is shown in the app at Sign. Do not send SOL to the EVM addresses above. |
EVM chains use Permit2 + the Executor. Solana uses the same product (cap, expiry, revoke, 100% back to you) with a native spend-grant program and Jupiter. It is not an EVM clone.
Machine facts and deploy hashes: chatito.ai/executor.md.
A listed contract is not a claim that Live or Sign is open for every account on that chain. Trust the app.
What You Control
| You set | Meaning |
|---|---|
| Cap | Maximum the grant can spend |
| Expiry | After this time the grant is dead |
| Token | 6.1m: spend + exit you named. 6.1a: spend token + inventory this grant bought |
| Revoke | Instant stop. Remaining goes to zero. |
One grant per strategy. Revoking book A does not kill book B. 6.1m holds spend + exit in that one grant. 6.1a holds spend + inventory of bags it bought.
DEX practice is open in the app. Trust the app, not this page, for whether Live is on. DEX Live and new executor Signs stay closed to the public until a third-party audit.
What This Is Not
- Not a place to send tokens
- Not a seed-phrase product
- Not a promise of profit
- Not "set and forget forever" without your revoke and Live switch
- Not a claim that DEX Live is open for every account today
Related
Ready to run a strategy?
Open App