Skip to content

safe:confirm-offline

Sign a Safe transaction or Safe message as an owner, or through an owner Safe, and bind the signed JSON to a variable without posting it to the Safe Transaction Service.

⚗️ Experimental — available at next.evmcrispr.com.

Smart blocks: cannot be nested. This command performs an immediate wallet, RPC, external-service or control-flow operation and cannot run inside an atomic batch.

safe:confirm-offline <variable> <safe> <signable>
NameTypeEvaluationDescription
variablevariableBuild timeVariable that receives the signed JSON
safeaddressBuild timeSafe address
signablebytes32 | stringBuild timeSafe transaction or Safe message JSON, or the hash of one queued on the service (exported with its confirmations)
NameTypeEvaluationDescription
--messageboolBuild timeThe hash is a safeMessageHash, not a safeTxHash
--viaaddressBuild timeOwner Safe to sign through, when you own several owner Safes
--allow-delegate-call-toaddress | arrayBuild timeContracts the transaction may delegatecall besides MultiSendCallOnly, SafeMigration, SignMessageLib and fully decoded MultiSend or ERC-8211 batches
--allow-new-ownersaddress | arrayBuild timeOwners the transaction may add
--allow-removed-ownersaddress | arrayBuild timeOwners the transaction may remove
--allow-change-threshold-tonumberBuild timeThreshold the transaction may leave the Safe with
--allow-new-modulesaddress | arrayBuild timeModules the transaction may enable
--allow-guard-toaddress | stringBuild timeTransaction guard the transaction may leave the Safe with (none removes it)
--allow-module-guard-toaddress | stringBuild timeModule guard the transaction may leave the Safe with (none removes it)
--allow-fallback-handler-toaddress | stringBuild timeFallback handler the transaction may leave the Safe with (none removes it)
--allow-gas-refundboolBuild timeSign or execute despite a gas refund (gasPrice, gasToken or refundReceiver set)
--allow-competingboolBuild timeSign or execute although other transactions are queued at the same nonce

Adds the connected owner's signature to a Safe transaction or Safe message and binds the signed JSON to the variable, without posting anything. Pass the JSON on to the next owner, merge parallel signatures with @safe:merge, and finally execute it, or post it to the queue with safe:propose.

Before your wallet prompts, it reviews the item like safe:confirm: it refuses on a blocking finding until the matching --allow-* option names what you reviewed. Competing transactions are only checked for a hash fetched from the service, since JSON does not reach it.

The Safe commands are named after where their result goes: the Safe Transaction Service (propose, confirm), a variable holding JSON (propose-offline, confirm-offline), or the chain (confirm-onchain, execute). See Offline Safe transactions for the complete flows.

Given a hash instead of JSON, the queued transaction (or, with --message, message) is fetched from the Safe Transaction Service, checked against the hash, and exported with its owner confirmations plus your signature. That is how a queued transaction moves to the JSON flow, for example to add contract signatures the service cannot hold.

The connected account must be a current owner, directly or through owner Safes, and the Safe must be >=1.3.0. Read the hashes your wallet will show with @safe:verify before signing. Signing needs a real wallet, so it is refused during simulation.

When your wallet owns the Safe through an owner Safe — a Safe that is itself an owner — the command finds it and signs for it, up to three levels deep. A direct owner is used first; if you own several owner Safes at the same depth, pick one with --via <ownerSafe>. Your signature is stored under the owner Safe inside the JSON. Each of the owner Safe's owners runs the same command, and the owner Safe's signature is complete once its threshold is met; @safe:verify shows the progress (1 of 2). The message the owner Safe signs follows the Safe's version: the hash for Safe >=1.5.0, the EIP-712 preimage below it.

safe:confirm-offline $tx $mySafe $tx
load safe
set $mySafe 0x5afe3855358e112b5647b952709e6165e1c1eeee
safe:confirm-offline $tx $mySafe 0x2c9c1f8f2a816f9ffe3ee902e08c02e01e9060e353fa892ee7d1cf27454935cb

This follows the prepare/sign/execute separation in the Agglayer Safe multisig tools.