Squads multisig configuration
Configure the Solana cluster, multisig identity, member signing, fee limits and optional coordinator.
MultisigSquadsWalletConfig combines read-only connection/identity options with signing options. A read-only account accepts MultisigSquadsWalletReadOnlyConfig without a seed.
Connection and Identity
| Option | Type | Default and behavior |
|---|---|---|
provider | string or string[] | Optional. Solana RPC URL or failover list. Without it, only address derivation works. |
commitment | Solana Commitment | confirmed. Commitment used for cluster reads and submissions. |
retries | number | 3. Retry setting for the failover provider. |
programId | string | Exported SQUADS_PROGRAM_ADDRESS. Override only for the Squads deployment you intend to use. |
multisigPdaOrCreateKey | string | Existing multisig PDA or the public create key from which it derives. |
createKeySecret | string or Uint8Array | Required for deployment. Base58 or raw bytes, either a 32-byte private key or a 64-byte keypair. |
Supply an identity before querying a vault. An off-curve address is interpreted as a multisig PDA; an on-curve public key is interpreted as a create key. If no explicit identity is supplied, the account derives it from createKeySecret. Deployment rejects a configured identity that differs from the secret-derived multisig.
A create key is separate from the member seed. Store both securely; do not log either. Existing-multisig users can supply its public address and avoid distributing the creation secret.
Signing Options
| Option | Type | Behavior |
|---|---|---|
coordinator | MultisigCoordinatorFactory | Optional factory called with { signerAddress }. Without one, every approval is the member's own transaction. Its implementation must verify each received signature before merging it; see coordinator requirements. |
rentPayer | string | Defaults to the member signer. A different payer must also sign, but this package does not provide a way to collect that extra signature. Keep the default for these examples. |
createMaxFee | number or bigint | Caps the deployment quote in lamports before submission. |
transferMaxFee | number or bigint | Caps the proposeTransfer() quote in lamports. |
approveMaxFee | number or bigint | Caps the coordinator bundle's quoted fee before this member signs it. |
Limits reject when the quote is greater than the configured amount; equality passes. They are operation-specific checks, not a general payment-value cap or a cap on every execution. Prefer bigint to preserve integer precision. The package has no universal execution-fee limit.
Proposal Options
MultisigSquadsTransactionOptions has optional vaultIndex (integer 0–255, default 0), memo (on-chain string) and autoExecute (boolean).
propose()andproposeTransfer()use the selected vault. Auto-execution requires threshold one, no time lock, and a member with vote and execute permissions as well as initiate.approveProposal()can auto-execute when that approval reaches the threshold, there is no time lock, and the voter also has execute permission.vaultIndexhas no effect on a vote.rejectProposal()uses onlymemo; it never uses the coordinator or auto-executes.- A coordinator's compiled bundle fixes its actions. These per-call options do not modify it.
When auto-execution cannot apply, the call stays pending instead of throwing just because the flag was set.
Fees, Rent and Units
All module fees and native values are lamports. SPL transfer amounts and balances use the mint's base units.
quoteDeploy(memberCount) includes the program's creation fee, multisig-account rent and network fee. Proposal quotes and propose().transaction.fee include network fee and rent for the stored transaction/proposal accounts. These values do not represent the vault's payment amount. A token transfer may also require the vault to fund a recipient token account.
quotePropose() and quoteTransfer() quote vault 0 in beta.2; their second argument is a wallet config override, not proposal options. quoteExecuteProposal() returns a fixed base fee of 5000n, not a full execution simulation or a guarantee of the eventual total cost. Allow for priority fees and operation-specific rent changes.
Runtime Setup
The package exports native ESM and a conditional Bare entrypoint. These guides use Node.js ESM. Browser, React Native and Bare applications need their own runtime configuration, RPC access and secure secret storage.