Skip to content

Invoise wallet

A shop pays out either to an address you own or to the Invoise wallet of an account member. The wallet is a Safe smart account owned by three keys with a 2-of-3 threshold:

Owner Held by Role
Merchant key You, in the browser only Signs every withdrawal and setting change. Never leaves your device unencrypted.
Invoise co-signer Invoise signer service Adds the second signature to what you signed. Cannot move funds alone.
Delegate (optional) Your own cold wallet Together with you: exit without Invoise. Alone: queue a withdrawal through a delay module.

One wallet per account, the same address on every supported EVM network, deployed on a network the first time a withdrawal runs there. Funds stay in the network and token they arrived in; nothing is converted on receipt.

  1. Create a shop with the payout target Invoise wallet. The setup opens at once and cannot be skipped while a shop waits for the wallet.
  2. Choose how to unlock the key: a six-character code, a password (10+ characters) or a passkey. Codes and passwords are hardened by the signer with an oblivious PRF and locked after ten wrong attempts; a passkey uses its PRF extension where the platform supports it.
  3. Without a delegate you also save a recovery key: the only way to recover funds if you lose the code or password. Add a delegate later on the wallet tab.

Withdraw any supported token to any supported network in one confirmation. Invoise gathers USDC from other networks through Circle’s CCTP, swaps on the destination when the payout token differs, then transfers to the payee. The fee is twice the gas of every step at the current price, charged in the token of each network; nothing is charged for steps that did not run. A failed final step leaves the funds on the wallet in the destination network.

Protections you can turn on: a daily limit in USD, a cooldown that pauses withdrawals after a security change and makes new payee addresses wait, and a second factor on every operation. Loosening a protection takes effect only after the current cooldown.

  • Delegate alone: queues a transfer through the Zodiac Delay module; it executes after a three-day cooldown and expires after a further week. You receive an email and a cabinet banner and can cancel it before it executes.
  • You and the delegate: sign a Safe transaction directly with the recovery key and the delegate wallet; it executes immediately.

Both work on the standalone emergency page (/emergency.html), which needs only a public node and your wallet. Download the memo with the wallet and module addresses from the security tab and keep it with the recovery key.

Invoise cannot move funds without your signature, cannot read your code or password, cannot open your envelopes without the signer’s per-wallet key, and cannot stop the delegate path.