Official registry
Descriptors live in ethereum/clear-signing-erc7730-registry. This toolkit consumes that catalog. It does not accept descriptor PRs and does not ship a second catalog.
Pin a commit SHA
Section titled “Pin a commit SHA”import { createOfficialRegistry, fetchPrebuiltRegistryIndex, VENDORED_REGISTRY_COMMIT,} from '@erc7730/sdk';
// Quick start: omitted pin defaults to VENDORED_REGISTRY_COMMIT.const registryQuick = createOfficialRegistry();
// Production: pass an explicit 40-character commit SHA.const pin = VENDORED_REGISTRY_COMMIT;const indexes = await fetchPrebuiltRegistryIndex({ pin });const registry = createOfficialRegistry({ pin, indexes });VENDORED_REGISTRY_COMMIT is the SHA this repository vendors for schemas and fixtures, and the default when pin is omitted. Production wallets pick and freeze their own pin. Passing pin: "master" or pin: "main" still throws.
Passing indexes means index.calldata.json and index.eip712.json are not fetched again. You can also bundle those JSON files at build time.
Indexes
Section titled “Indexes”| Index | Lookup |
|---|---|
index.calldata.json |
CAIP-10 eip155:{chainId}:{address} (deployments and EIP-1967 / EIP-1167 implementations) |
index.eip712.json |
CAIP-10 of context.eip712.deployments, disambiguated with encodeType hash when needed |
There is no factory-clone catalog in the official indexes. Factory-only files match via extend() plus matchContext (deploy event logs), not by scanning the tree on a miss.
EIP-712 descriptors that bind only via domain / domainSeparator are not pre-indexed on GitHub. Load them through extend() (or a local overlay) and let matchContext run.
extend() is local
Section titled “extend() is local”registry.extend(myDescriptor); // local-override provenance — not an official-registry contributionLocal overrides are tagged source: "local-override". Under officialOnlyPolicy() they are rejected. Under officialOrLocalPolicy() they can be accepted with medium confidence.
Attestations
Section titled “Attestations”Optional attachAttestations: true loads ERC-8176 attestation JSON from the pinned tree (registry/<project>/sigs/). Pair with attestedPolicy({ attesters, eas }). The SDK verifies; it never issues attestations.
What is not fetched
Section titled “What is not fetched”addressMatcherURLs (v1-era) — fail closed- Arbitrary GitHub
main/masteras apin - Etherscan / Sourcify as trusted clear-signing metadata