Docs

Every mechanic of the vault, what protects it and what can go wrong.

What Legato is

Legato is an inheritance vault on Robinhood Chain, a dead man's switch for tokens. You deposit Stock Tokens, USDG or WETH, name up to four heirs, and set a check-in period. As long as you make a move on the vault within each period, nothing happens. If you go silent for a full period, your heirs can claim their shares.

All vaults live in one contract, LegatoVaults, each with its own id and its own balances. There is no custodian, no keeper and no off-chain service in the path of your funds.

Opening a vault

create(heirs, shares, period, tokens, amounts) opens a vault owned by the caller. It can fund the vault in the same transaction; approve each token first (the app batches the approvals where your wallet allows it).

  • Heirs: 1 to 4 distinct addresses, not the owner, not the zero address.
  • Shares: in basis points, each above 0, together exactly 10000 (100%).
  • Period: at least 30 days, at most 3 years. The app offers 90 days, 180 days, 1 year or a custom number of days.
  • Creation fee: an optional flat fee in USDG, capped at 1 USDG in the contract. It is 0.

The clock

Every vault stores lastCheckIn. Any owner transaction on the vault sets it to the current block time: deposit, withdraw, checkIn, setHeirs, setPeriod. The claim opens at lastCheckIn + period.

The claim opening does not end the vault. Until the first heir actually claims, the owner can still check in, and the clock starts again from the full period.

Managing a vault

  • Deposit any allowlisted token. The vault books what actually arrived, so a token that takes a fee on transfer is counted correctly. Up to 32 different tokens per vault.
  • Withdraw any amount up to the vault's balance of that token, to the owner's wallet.
  • Change heirs or shares with setHeirs. Removed heirs lose any claim at once.
  • Change the period with setPeriod, within the same bounds.
  • Close sends every balance to the owner and ends the vault for good.

Claiming

After lastCheckIn + period, any listed heir can call claim(id). The first claim freezes the vault: it becomes Inherited, the owner can no longer act on it, and the balances at that moment are recorded.

Each heir then claims once and receives its share of every token from the recorded balances. The last heir to claim takes whatever is left, so rounding dust never stays behind. One heir claiming does not depend on the others; an heir that never claims simply leaves its share in the vault.

Check-in agent

The owner can name one check-in agent per vault with setAgent, and remove or replace it the same way (each change also resets the clock). The agent is any wallet, typically run by an AI agent. It can call exactly one function, agentCheckIn, which resets the clock to the full period like the owner's check-in.

It cannot deposit, withdraw, change heirs or the period, set another agent or close the vault. A typical agent watches for signs of life, such as activity on the owner's other wallets or a reply to a message, and checks in while they continue. If they stop, it stops, and the heirs claim after the period. An agent that keeps checking in for an owner who is gone delays the heirs; name only an agent you trust to stop.

The agent API (x402 style)

Legato serves a pay-per-call API for agents at 0.001 USDG a call. An agent deposits USDG credits into the AgentCredits contract from its own wallet (the app's Agent API tab) and withdraws the rest any time.

For every request it signs legato:<address in lowercase>:<METHOD>:<path>:<timestamp> with that wallet and sends x-legato-agent, x-legato-ts and x-legato-sig. The timestamp may be seconds or milliseconds and must be within 60 seconds of the server; each signature works once. Without a valid signature or credit the answer is HTTP 402 Payment Required with the price and how to pay. Served calls are charged in batches about every 10 minutes; the contract never takes more than the credit.

GET /v1/vaults/{id}paidStatus, owner, check-in agent, heirs and shares, seconds until the claim opens, holdings at Chainlink prices.
GET /v1/address/{address}paidEvery vault the address owns, inherits or checks in for, with its role and clock.
GET /v1/claimablepaidRecent vaults whose claim is open, largest first.
GET /v1freeThe index.
import { privateKeyToAccount } from "viem/accounts";

const agent = privateKeyToAccount(process.env.AGENT_KEY); // the wallet holding your credits

async function legato(path) {
  const ts = Date.now(); // seconds or milliseconds both work
  const msg = `legato:${agent.address.toLowerCase()}:GET:${path}:${ts}`;
  const sig = await agent.signMessage({ message: msg });
  const r = await fetch("https://uselegato.xyz" + path, {
    headers: { "x-legato-agent": agent.address, "x-legato-ts": String(ts), "x-legato-sig": sig },
  });
  if (r.status === 402) throw new Error((await r.json()).error); // add credits
  return r.json();
}

// a check-in agent: find the vaults it watches and how long each has left
const { vaults } = await legato("/v1/address/" + agent.address);

Safeguards

  • The contract owner can only allow or disallow tokens for new deposits and set the creation fee within its cap. It has no function that moves vault balances. Disallowing a token never blocks withdrawals or claims of it.
  • Only the vault owner can deposit, withdraw, check in, change or close. The check-in agent can only reset the clock. Only listed heirs can claim, only after the period.
  • API credits live in a separate AgentCredits contract. The meter can only charge served calls within each agent's credit; the owner can set the price (capped at 0.01 USDG), the meter and the treasury, and cannot move credits.
  • OpenZeppelin ReentrancyGuard on every function that moves tokens, SafeERC20 for every transfer.
  • Periods bounded at 30 days to 3 years; heirs bounded at 4; tokens per vault bounded at 32, which keeps claim and close gas bounded.
  • Tested with unit tests over every path and a fork test against Robinhood Chain mainnet with real NVDA and USDG.

Risks

  • Unaudited. The contract has tests but no external audit. Use amounts you can afford to lose.
  • A missed check-in is final once claimed. If you stay silent for the whole period, heirs can claim even while you are alive. Pick a period you will keep, and remember that any owner action counts.
  • Lost keys. If you lose your own key, you cannot withdraw; your heirs claim after the period. If an heir loses its key, its share stays in the vault; change heirs before the period ends.
  • Assets. Stock Tokens carry issuer, price, market hours and oracle risks. USDG and WETH carry their own. Values on the site use Chainlink feeds and are for display only.
  • Not a will. A vault moves tokens when a condition is met. It is not a legal instrument and covers only what is inside it.
  • Chain. Robinhood Chain availability, upgrades or token-level restrictions (such as a blocked address) are outside Legato's control.

Contracts

Robinhood Chain mainnet, chain id 4663. Explorer: robinhoodchain.blockscout.com.

LegatoVaults0x2229…42c4
AgentCredits0x0EbE…6530
API meter0xB398…1D89
USDG0x5fc5…d168
WETH0x0Bd7…AD73

Allowed assets

The allowlist at deployment: 29 tokens.

AAPL Apple0xaF3D…93f9
NVDA Nvidia0xd060…9EEC
TSLA Tesla0x322F…3b2d
MSFT Microsoft0xe932…2e74
AMZN Amazon0x12f1…bF54
META Meta0xc0D6…2f35
GOOGL Alphabet0x2e08…4FE3
COIN Coinbase0x6330…450b
MU Micron0xfF08…4afD
INTC Intel0xc72b…9681
PLTR Palantir0x894E…4F2A
DELL Dell0x941A…11Dd
SNDK Sandisk0xB90A…6400
MSTR Strategy0xec26…da09
CRCL Circle0xdF09…1CB5
BABA Alibaba0xad25…a1c4
GME GameStop0x1b0E…153E
SPCX SpaceX0x4a0E…5eEa
USAR USA Rare Earth0xd917…86a6
SPY S&P 500 ETF0x117c…4C0C
QQQ Nasdaq 100 ETF0xD5f3…de68
GLD Gold ETF0xC9a9…FC4e
SLV Silver ETF0x411e…D89f
USO Oil ETF0xa30F…D344
SGOV T-bill ETF0x92FD…F9B5
USDG Global Dollar0x5fc5…d168
WETH Wrapped Ether0x0Bd7…AD73

Questions about the product itself are answered on the home page.