bivvydocs
Developers / Approvals & permissions
BIVVY DOCS

A little permission.
A lot of control.

Sensitive actions are always connected to an explicit user decision.

Default behavior

ActionPermission
ConnectPasskey login and consent
Read balance, addresses, historyAllowed during the connected session
Send bitcoinFresh passkey approval per payment
Create an invoice or estimate an on-chain feeFresh passkey approval per operation
Sign or encrypt a Nostr event/messageFresh passkey approval per operation

Monthly allowances

When approving a payment, the user can set a monthly limit for that origin in sats or US dollars. Fees count toward the limit. Dollar spending is recorded at the current BTC/USD spot quote, rounded up to whole cents. Months reset at midnight UTC on the first day.

Allowances are shared across devices. Bivvy stores signed policies and atomically reserves spending in Turso before dispatching a payment. Concurrent requests cannot reserve the same budget. Uncertain or failed payments retain their reservation conservatively.

Lock and revoke

Sessions lock after 15 minutes. Disconnect removes the current app’s iframe and clears its in-memory key references. Revoke durable permissions in the wallet under connected apps. Future automatic requests must read the current server policy.

Locking the top-level wallet clears that window’s session. Separately open apps may have their own sessions until expiry. Revoke permissions to stop their future automatic operations. A payment already submitted cannot be revoked.

Accounting trust

The permission service coordinates budgets and revocation. It has no user signing key, but clients rely on its current counters. Signed policies prevent it from inventing a larger allowance; a malicious or rolled-back service could misreport spending. See the complete trust model.

Made to be understood. Built to be yours.View the source