WDK logoWDK documentation

Squads multisig configuration

Configure the Solana cluster, multisig identity, member signing, fee limits and optional coordinator.

MultisigSquadsWalletConfig combines read-only connection/identity options with signing options. A read-only account accepts MultisigSquadsWalletReadOnlyConfig without a seed.

Connection and Identity

OptionTypeDefault and behavior
providerstring or string[]Optional. Solana RPC URL or failover list. Without it, only address derivation works.
commitmentSolana Commitmentconfirmed. Commitment used for cluster reads and submissions.
retriesnumber3. Retry setting for the failover provider.
programIdstringExported SQUADS_PROGRAM_ADDRESS. Override only for the Squads deployment you intend to use.
multisigPdaOrCreateKeystringExisting multisig PDA or the public create key from which it derives.
createKeySecretstring or Uint8ArrayRequired for deployment. Base58 or raw bytes, either a 32-byte private key or a 64-byte keypair.

Supply an identity before querying a vault. An off-curve address is interpreted as a multisig PDA; an on-curve public key is interpreted as a create key. If no explicit identity is supplied, the account derives it from createKeySecret. Deployment rejects a configured identity that differs from the secret-derived multisig.

A create key is separate from the member seed. Store both securely; do not log either. Existing-multisig users can supply its public address and avoid distributing the creation secret.

Signing Options

OptionTypeBehavior
coordinatorMultisigCoordinatorFactoryOptional factory called with { signerAddress }. Without one, every approval is the member's own transaction. Its implementation must verify each received signature before merging it; see coordinator requirements.
rentPayerstringDefaults to the member signer. A different payer must also sign, but this package does not provide a way to collect that extra signature. Keep the default for these examples.
createMaxFeenumber or bigintCaps the deployment quote in lamports before submission.
transferMaxFeenumber or bigintCaps the proposeTransfer() quote in lamports.
approveMaxFeenumber or bigintCaps the coordinator bundle's quoted fee before this member signs it.

Limits reject when the quote is greater than the configured amount; equality passes. They are operation-specific checks, not a general payment-value cap or a cap on every execution. Prefer bigint to preserve integer precision. The package has no universal execution-fee limit.

Proposal Options

MultisigSquadsTransactionOptions has optional vaultIndex (integer 0–255, default 0), memo (on-chain string) and autoExecute (boolean).

  • propose() and proposeTransfer() use the selected vault. Auto-execution requires threshold one, no time lock, and a member with vote and execute permissions as well as initiate.
  • approveProposal() can auto-execute when that approval reaches the threshold, there is no time lock, and the voter also has execute permission. vaultIndex has no effect on a vote.
  • rejectProposal() uses only memo; it never uses the coordinator or auto-executes.
  • A coordinator's compiled bundle fixes its actions. These per-call options do not modify it.

When auto-execution cannot apply, the call stays pending instead of throwing just because the flag was set.

Fees, Rent and Units

All module fees and native values are lamports. SPL transfer amounts and balances use the mint's base units.

quoteDeploy(memberCount) includes the program's creation fee, multisig-account rent and network fee. Proposal quotes and propose().transaction.fee include network fee and rent for the stored transaction/proposal accounts. These values do not represent the vault's payment amount. A token transfer may also require the vault to fund a recipient token account.

quotePropose() and quoteTransfer() quote vault 0 in beta.2; their second argument is a wallet config override, not proposal options. quoteExecuteProposal() returns a fixed base fee of 5000n, not a full execution simulation or a guarantee of the eventual total cost. Allow for priority fees and operation-specific rent changes.

Runtime Setup

The package exports native ESM and a conditional Bare entrypoint. These guides use Node.js ESM. Browser, React Native and Bare applications need their own runtime configuration, RPC access and secure secret storage.

Next Steps


Need Help?

On this page