Integration engineering

Track permit expiry and nonce independently

Track permit nonce consumption, signature deadline and allowance expiration separately when diagnosing invalid signatures.

A mathematically valid signature can be unusable because its nonce was consumed or its deadline passed. Signature verification is only one part of permission validity.

Different protocols have different clocks

ERC-2612 binds a signed approval to an owner nonce and deadline. Permit2 AllowanceTransfer additionally distinguishes stored allowance expiration from the deadline for presenting a signature. Treating both as a generic expires field loses information.

SignatureTransfer has a different nonce design. The module documentation describes unordered nonces tracked through a bitmap. Do not increment a presumed sequential nonce when the chosen protocol uses an unordered one.

Diagnose before asking for another signature

  1. Identify the exact permit type and deployed verifier.
  2. Read current nonce or nonce availability using that protocol.
  3. Check signature submission deadline against chain time.
  4. Check any separate allowance expiration.
  5. Confirm owner, spender, token and amount still match the trade.

If an earlier submission may have succeeded, reconcile it before generating a replacement. The same nonce failing can be evidence that the original permission was already used rather than evidence that the wallet signed incorrectly.

Store deadlines with their units. Unix seconds and JavaScript milliseconds are easy to confuse, and a local wall-clock countdown should not override actual chain state. On a refresh, retain the original signature with the original message or discard it; never modify the message's deadline and reuse its signature.

A useful test set includes an unused but expired permit, a consumed nonce with a future deadline and an unexpired stored allowance whose new signature deadline has elapsed. Each represents a different state transition.

Sources & verification (3)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. ERC-2612

    Signed token approvals, nonces and deadline

    https://eips.ethereum.org/EIPS/eip-2612
  2. Allowance Transfer

    Persistent time-bound spender permissions

    https://developers.uniswap.org/docs/protocols/permit2/concepts/allowance-transfer
  3. Signature Transfer

    One-use signature nonce model

    https://developers.uniswap.org/docs/protocols/permit2/concepts/signature-transfer

Continue reading

Swap API integration: quote, approve, simulate, submit