Sponsored gas
A delegated agent can settle without holding SUI for gas. The gateway can
sponsor gas after the agent signs a Sui personal message that proves it
holds the registered delegated key. Sponsorship authenticates gas only,
not settlement. Settlement still requires a valid on-chain pay and a
verified payment proof.
When you need it
| Gas path | When |
|---|---|
| Agent-provided gas | The delegate address holds SUI coin objects; the SDK builds a full tx with those gas payments |
| Sponsored gas | The agent has no (or insufficient) SUI; the platform sponsors after a personal-message challenge |
The SDK payer prefers agent gas when configured, otherwise sponsored gas when a sponsor client is configured.
Personal-message challenge
BYO delegated keys must not use unbound sponsor paths. The protocol is a
personal-message challenge (signPersonalMessage / IntentScope
PersonalMessage) before the gateway attaches gas:
- Challenge. Agent requests a single-use nonce bound to the registered
delegate address and the target grant/pool
(
POST /api/sponsor/personal-message/challenge). - Signed payload. The agent signs a domain-separated personal message with
the delegated key. Domain separator:
suipay:sponsor-personal-message:v1(not a settlement digest). - Bindings. The payload covers nonce, expiry, delegate, pool id, grant id, network, package id, request id (for example the payment/challenge id), and a SHA-256 of the pre-sponsor transaction kind (not the post-sponsor executable digest the sponsor builds later).
- Sponsor. Agent calls
POST /api/sponsorwith the kind bytes plus the personal-message fields. The gateway verifies signature, address derivation, unconsumed nonce, grant registration, and that the kind is a permittedspend_account::settle_policy_payment(or refundable spend) for that grant. - Execute. Agent signs the sponsored transaction digest; gateway or client submits. Nonce is consumed so the same challenge cannot authorize another kind.
What the challenge does not do
- It does not authorize delivery of a paid resource by itself.
- It does not bypass grant policy, budgets, or
paychecks. - A valid personal message without a valid on-chain payment does not settle.
Quotas and safety
Sponsorship is rate- and quota-limited per signer, separately from token budget. Failed, aborted, and ambiguous transactions may still count against gas quota. Treat sponsorship as part of the blast radius of a leaked delegated key: an attacker can burn gas up to the remaining quota as well as spend within grant caps.
MCP OAuth
OAuth-session delegates use the platform's existing sponsor path for that connection. BYO keys always use the personal-message challenge above when requesting sponsored gas.