internal/core library

Classes

ApiClient
AuthClient
Authentication: email OTP login, session lifecycle. (SMS/social/passkeys follow the same shapes.) Instances share the root client's state. NOTE: not yet thread-safe.
BtcFeeAndChange
Fee, change, and whether to add a change output. Dust change is folded into the fee.
BtcFeeEstimate
Fee estimate normalized to target blocks and satoshis per virtual byte.
BtcFeePlan
Pure fee arithmetic over input values, counts, rates, and targets. Native services handle UTXO selection and PSBT serialization.
BtcNetwork
Bitcoin REST configuration resolved by a chain provider. The API endpoint is separate from dashboard RPC metadata.
BtcService
Creates Bitcoin network providers and performs reads and broadcast. Signing remains with WalletSigner.
BtcUtxo
An unspent Bitcoin output used as an input when building a transaction.
CaptchaSettings
CAPTCHA provider settings. Supports hcaptcha and cloudflareTurnstile; defaults to hcaptcha.
CaptchaSettingsResult
The active captcha provider and site key to hand the captcha widget — returned by getCaptchaSettings; null overall means captcha is not enabled. provider is one of 'hcaptcha' | 'cloudflareTurnstile'.
ChainConfiguration
One chain's embedded-wallet config. name is a short code ('EVM', 'SOL', 'BTC'...), NOT a verifiedCredential chain name ('eip155', 'solana'...) — those are a different wire vocabulary entirely.
ClientState
Shared session state mutated by the domain clients.
DeleteDeviceRegistrationResponse
Whether revocation ended the current session.
DeviceRegistration
A registered sign-in device.
DeviceRegistrationsResponse
Registered sign-in devices.
DeviceSigner
P-256 device key for signed-nonce request authentication. Backed by Secure Enclave / Android Keystore / platform crypto; raw key material never leaves the host.
DynamicClient
Root SDK object: composes the domain clients over shared state and hosts the extension registry.
DynamicConfig
Client configuration — the DSL mirror of createDynamicClient's config.
DynamicConstants
Shared numeric/time constants — not JSON-specific, so kept out of DynamicJson.
DynamicExtension
Pluggable extension (chain support etc.) — the Dart mirror of the JS SDK's add*Extension pattern. Extensions self-register on install.
DynamicJson
EarnExecutionService
Executes a generated yield payload through the installed EVM extension.
ElevatedAccessToken
In-memory scoped token. Never log or persist it.
EmailVerificationCreateResponse
Email verification ID and optional destination address.
EmbeddedWalletSigner
Embedded-wallet signer implemented by WaasExtension. Adds no methods; lets a wallet select the WaaS provider explicitly.
EmbeddedWalletsSettings
Embedded-wallet version, supported chains, and automatic creation settings.
EventSignal<T>
Future-only event stream backing a domain event getter: a listener receives occurrences after it subscribes; a past event is never replayed.
Evm7702Authorization
A signed EIP-7702 delegation authorization.
EvmContractFunction
A contract function name and its canonical Solidity input and output types.
EvmGaslessRelayerResponse
The relayer address for an EVM chain.
EvmGaslessSponsor
Internal embedded-wallet capability used by the EVM gasless flow.
EvmNetwork
An EVM network target the extension can talk to: numeric chain id, JSON-RPC endpoint, and a display name.
EvmReceipt
The subset of an EVM transaction receipt the unified surface exposes.
EvmService
Injectable EVM JSON-RPC and transaction-serialization service.
EvmSponsoredCall
One call in a sponsored EVM batch.
EvmSponsoredTransactionStatusResponse
The current state of an EVM gasless relay request.
EvmTxRequest
A unified EVM (EIP-1559) transaction request. Unset gas/fee/nonce fields are auto-filled from the RPC.
ExportPrivateKeyCapability
Wallet-scoped export capability, separate from the injected WaaS engine.
ExportPrivateKeyEngine
Opens a separate screenshot-protected export UI with the elevated token. Never returns key material; failures throw.
ExternalAuthAssertionResponse
Scoped BYOA assertion result, verified with the configured JWKS. Requires scope and jti claims; distinct from the session VerifyResponse.
ExternalWalletProvider
Pairs with and signs through an external wallet app (MetaMask, ...) over its own connect protocol.
ExternalWalletSigner
WalletSigner provided by a wallet the user already has (MetaMask, ...), which signs under its own UI. Implemented by ExternalWalletExtension. Adds no methods to WalletSigner, for the same reason as EmbeddedWalletSigner.
FlowScope
Cancels stale work and orders local writes with session cleanup.
GetUserPasskeysResponse
Wire response of getUserPasskeys — the getPasskeys flow unwraps .passkeys, mirroring the real JS SDK.
HCaptchaSettings
Legacy hCaptcha settings. Used only when security.captcha is absent.
HttpHeader
One request header.
HttpRequest
Raw HTTP request with an absolute URL. Transport adds no headers; only ApiClient supplies credentials, never spec flows.
HttpResponse
One HTTP response, unparsed. A non-2xx status is NOT an error at this layer — the caller decides, because some hosts report failures in a 200 body (Sui GraphQL) and some in the status.
HttpService
Host-injected HTTP transport. Accepts absolute URLs and adds no headers. Only ApiClient supplies Dynamic credentials; flows may use this service for public endpoints only.
Instrumentation
Sends bounded batches of operation metadata through the injected transport.
InstrumentedLogger
Filters local logs and forwards only error metadata to instrumentation.
JwtClaims
Decoded JWT claims; this model does not verify signatures. Unknown claims are ignored. Expiry and scope checks do not establish token authenticity.
Logger
Fire-and-forget logging. The generated core never passes token or key material to this boundary.
MergeConflicts
Account merge choices. Contains personal data; do not log.
MergeField
A profile field that needs a merge decision.
MergeUserConflict
Both values for a conflicting profile field.
MergeUserConflictResolution
The user-selected value for a conflicting field.
MergeUserValue
A user and their value for a conflicting field.
MfaActionSettings
MFA requirements for an action.
MfaDevice
A registered MFA device.
MfaDevicesResponse
Registered MFA devices.
MfaMethodsResponse
Available verified MFA methods.
MfaRecoveryCodesResponse
Recovery-code response shared by fetch and regeneration endpoints.
MfaSettings
Environment MFA requirements.
MfaTotpRegistration
TOTP setup data. Never log the secret or URI.
NetworkChainConfiguration
A dashboard network group. getNetworksData flattens these groups into normalized NetworkData values.
NetworkConfiguration
One network's configuration, within a NetworkChainConfiguration group — either read from the dashboard (getNetworksData) or host-registered (e.g. getEvmHostNetworks, built from a UseEvm EvmNetwork). iconUrls/nativeCurrency/blockExplorerUrls are optional even though the upstream wire schema always populates them for a dashboard entry: a host-registered one has no such guarantee (EvmNetwork carries only chainId/rpcUrl/name), and a wrong guess (e.g. assuming ETH as every EVM chain's native currency, which is false for many L2s) is worse than an absent field — see each field's own doc for which entries actually populate it.
NetworkData
Normalized dashboard metadata consumed by chain providers. An RPC URL does not identify its protocol.
NetworkNativeCurrency
Deliberately narrow subset of dynamic-labs sdk-api-core's NativeCurrency — omits pricingProviderTokenId, which nothing here reads yet.
NetworkRpcUrls
Ordered RPC endpoints. Customer endpoints precede public endpoints.
NonceResponse
Server nonce for a device or session signature.
NoncesResponse
A pool of one-time wallet sign-in nonces (getWalletNonces) — distinct from NonceResponse's single device-signature nonce.
OAuthBrowser
Opens provider consent in a system auth session and returns the callback deep link. Core service, not an extension.
OAuthResult
Outcome of an OAuth browser session.
OperationScope
PasskeyAssertionResponse
The authentication ceremony's response sub-object. clientDataJson is this DSL's OWN consistent internal name for the field — see this file's header doc for the register-vs-signin wire-casing asymmetry this deliberately sidesteps.
PasskeyAttestationResponse
The registration ceremony's response sub-object. clientDataJson is this DSL's OWN consistent internal name for the field — see this file's header doc for the register-vs-signin wire-casing asymmetry this deliberately sidesteps.
PasskeyAuthenticationOptions
Server WebAuthn request options shared by sign-in and MFA endpoints. Serialized as JSON before PasskeyProvider.authenticate.
PasskeyAuthenticationResult
Parsed PasskeyProvider.authenticate result. Flows map clientDataJson to the server's clientDataJSON key.
PasskeyAuthenticatorSelection
Creation-options-only: narrows which kind of authenticator (platform biometric vs. roaming/security-key) may fulfill the ceremony.
PasskeyClientExtensionResults
Authenticator extension outputs. Keeps appid and hmacCreateSecret; omits opaque credProps because the IR cannot represent its untyped object.
PasskeyCredentialDescriptor
Credential to exclude during registration or allow during authentication. The server omits type in allowCredentials; flows add public-key before the platform ceremony.
PasskeyExtensionsInput
Authenticator extension request flags, distinct from clientExtensionResults. credProps is a boolean input flag, not its object-shaped output.
PasskeyProvider
Runs platform WebAuthn ceremonies. Takes full options and returns full results as JSON strings. Cancellation must throw a distinct error, not resolve normally or use the generic ceremony-failure error.
PasskeyPubKeyCredParam
One acceptable public-key algorithm for the new credential (COSE algorithm identifier, e.g. -7 for ES256).
PasskeyRegistrationOptions
Server WebAuthn creation options, serialized as JSON before PasskeyProvider.register because the IR has no generic object type.
PasskeyRegistrationResult
Parsed PasskeyProvider.register result, sent to the registration endpoint using clientDataJson.
PasskeyRelyingParty
The relying party (this app/environment) a passkey is scoped to. id is the domain the OS's Associated Domains / Digital Asset Links config must match — never the app's own name.
PasskeyStorageInfo
Which password manager / platform keychain a passkey is stored in (e.g. iCloud Keychain, Google Password Manager).
PasskeyUser
The account a NEW passkey is being registered for (creation options only — there is no equivalent on sign-in/auth options, since the whole point of allowCredentials there is that the user hasn't been identified yet).
ProjectSettings
Environment security, wallet, provider, and network configuration.
Provider
A dashboard provider entry for social, SMS, ramp, or ZeroDev settings. Select the relevant fields by providerKind.
SdkFeatureFlags
Deliberately narrow subset of dynamic-labs sdk-api-core's FeatureFlags — only the one flag isExternalWalletScreeningEnabled reads. Add fields here as this DSL needs to read more of them.
SdkSettings
Environment wallet configuration and SDK feature flags.
SdkUser
The authenticated user, as returned by signin/users endpoints.
SecureStorage
Persistent key-value storage. Implementations MUST be hardware/OS-backed (Keychain, EncryptedSharedPreferences, DPAPI...); auth tokens land here.
SecuritySettings
Environment CAPTCHA settings, including the legacy hCaptcha configuration.
SendEmailOtpResult
Email address and verification ID used to complete OTP sign-in.
SendSmsOtpResult
Phone details and verification ID for SMS sign-in. phoneCountryCode is the dialing code, distinct from isoCountryCode.
SessionSigner
P-256 session key, distinct from the device key. Signs privileged payloads; its public key binds API requests to the session through x-dyn-session-public-key. Rotates at sign-out.
SmsVerificationCreateResponse
Verification ID returned after sending an SMS code.
SocialAccount
A linked social identity.
SolanaNetwork
A Solana cluster target the extension can talk to: JSON-RPC endpoint, display name, and the cluster moniker (mainnet-beta / devnet / testnet) used for explorer links.
SolanaReceipt
The subset of a Solana transaction status the unified surface exposes.
SolanaService
Injectable Solana cluster JSON-RPC and transaction-serialization service.
SolanaSplTransfer
An SPL token transfer. The service derives associated token accounts and creates the recipient account when needed.
SolanaTransactionSponsor
Optional capability that replaces a Solana transaction fee payer.
SolanaTxRequest
A native SOL transfer request. Unset recentBlockhash is fetched from the RPC.
SponsorEvmTransactionRequest
A signed EVM gasless intent sent to the Dynamic relayer.
SponsorEvmTransactionResponse
The identifier of an accepted EVM gasless relay request.
StateSignal<T>
Hot state stream backing a <field>Changed getter: a new listener immediately receives the current value, then every update. Dependency-free mirror of the flutter-sdk BehaviorSubject.seeded store.
StellarAccount
A loaded Horizon account: sequence number (for building a transaction) and native XLM balance. Non-native asset balances are not modeled — checkTrustline reads them off the real platform SDK response StellarExtension already holds.
StellarNetwork
A Stellar network target: its passphrase (what a transaction signs against), Horizon RPC URL, a display name, and the WaaS engine's own chain id.
StellarPaymentRequest
A native-XLM or custom-asset payment, in the form buildPaymentTransaction takes.
StellarService
Horizon reads and XDR transaction building/submission for a single Stellar network. Implemented by a concrete SDK per platform; StellarExtension is constructed with one and never talks to Horizon directly.
StepUpCheckResponse
Whether step-up is required for a scope, and which credentials can satisfy it.
StepUpCredential
One credential available for step-up authentication.
StoredSession
Persisted session token and expiry; excludes the user profile.
SuiAddressBalance
The address node of a getBalance response. Null balance = the address holds none of that coin.
SuiBalanceEnvelope
getBalance's whole response.
SuiBalanceResponse
getBalance's data.
SuiCheckpoint
The checkpoint a transaction landed in.
SuiCoinBalance
One coin type's total balance, in that coin's base units (MIST for native SUI).
SuiCoinContents
A coin object's contents.
SuiCoinFields
A coin object's Move fields, as JSON — only balance is read.
SuiCoinNode
One owned coin object. address is the OBJECT id here (the GraphQL field for an object's id is address), and digest is base58, not hex.
SuiCoinsEnvelope
getCoins's whole response.
SuiCoinsResponse
getCoins's data.
SuiEpoch
The current epoch, as far as a gas price is concerned.
SuiExecuteEffects
executeTransaction's effects — only the digest is read.
SuiExecuteEnvelope
executeTransaction's whole response.
SuiExecuteResponse
executeTransaction's data.
SuiExecuteResult
The result of a broadcast. A non-empty errors means the node rejected it; the SDK surfaces those verbatim rather than interpreting them.
SuiExecuteTransactionRequest
Broadcasts a signed transaction. Response: data.executeTransaction — errors is a non-empty list when the node rejected it, otherwise effects.transaction.digest is the landed digest.
SuiExecuteTransactionVariables
executeTransaction's variables. Both are BASE64, not hex: bcs is the serialized TransactionData and sigs the SerializedSignatures over it (flag || sig || pubkey — 97 bytes for ed25519).
SuiExecutionError
Why execution failed, when it did.
SuiGasCoinCandidate
A coin object that covers a transaction, with its balance parsed to a number so the largest can be picked. Never wire data — assembled from a getCoins response.
SuiGasPriceEnvelope
getReferenceGasPrice's whole response.
SuiGasPriceResponse
getReferenceGasPrice's data.
SuiGetBalanceRequest
One address's balance in a single coin type. Response: data.address.balance.totalBalance (a BigInt scalar).
SuiGetBalanceVariables
getBalance's variables. coinType is a fully-qualified coin type — 0x2::sui::SUI for the native coin.
SuiGetCoinsRequest
The coin objects an address owns, for gas-payment selection. Response: data.address.objects.nodes[] with address/version/digest and contents.json.balance.
SuiGetCoinsVariables
getCoins's variables. type is an OBJECT type filter, not a coin type: 0x2::coin::Coin<0x2::sui::SUI> for native SUI coins.
SuiGraphQlError
One error a GraphQL server reports alongside (or instead of) data.
SuiNetwork
A Sui network with a host-supplied GraphQL endpoint and a dashboard network ID.
SuiObjectConnection
A page of owned objects. Not paginated by this SDK: one gas coin has to cover the transfer, so the first page is either enough or the caller has to consolidate coins.
SuiOwnedObjects
The address node of a getCoins response.
SuiReceipt
The subset of a Sui transaction's execution status the unified surface exposes.
SuiService
Resolves Sui networks and performs chain I/O. WalletSigner handles signing.
SuiTransactionDigest
The digest of the transaction the node accepted.
SuiTransactionEffects
What executing a transaction did. status is the string SUCCESS or a failure — compared, never parsed, because the IR has no enums.
SuiTransactionStatusEnvelope
getTransactionStatus's whole response.
SuiTransactionStatusRequest
Whether a transaction landed. Response: data.transactionEffects — absent means the node has never seen the digest, status is SUCCESS or a failure, and executionError.message carries why.
SuiTransactionStatusResponse
getTransactionStatus's data. An absent transactionEffects means the node has never seen the digest — not that the transaction failed.
SuiTransactionStatusVariables
getTransactionStatus's variables.
SuiTxRequest
A native SUI transfer request. Gas payment coins and price are selected from the RPC at build time.
SuiUnsignedTransaction
SUI transfer and payment coins. Amounts, object versions, and gas values use decimal strings because BCS u64 can exceed Int64.
TonJettonTransfer
A Jetton token transfer.
TonMessage
One internal message in a TON transaction request.
TonNativeTransfer
A native TON transfer.
TonNetwork
A TON JSON-RPC endpoint and its network global ID.
TonPreparedTransaction
Unsigned TON V5R1 data prepared for WalletSigner.
TonSendTransactionResponse
The hash of a submitted TON external message.
TonService
Resolves TON networks and handles Wallet V5R1 encoding and JSON-RPC calls.
TonTransactionRequest
A TON transaction with one or more internal messages.
UserPasskey
One of the user's registered passkeys — metadata only, never credential secrets.
UserSession
Session token, expiry, and optional user identity fields.
VerifiedCredential
One verified credential of the user (wallet, email, social account...).
VerifyResponse
Response of emailVerifications/signin and MFA step-up endpoints.
WaasEngine
Embedded-wallet MPC engine owned by WaasExtension. initialize must reuse the engine for the same authToken across all chains and rebuild it when the session changes. The reference implementation uses a hidden waas-v1 WebView.
WaasKeyShareInfo
One key share's backup metadata, as carried in VerifiedCredential.walletProperties.keyShares (dynamic-labs sdk-api-core's WalletKeyShareInfo). Deliberately narrow: only backupLocation is modeled — id/passwordEncrypted/walletShareDeveloperKeyEncrypted/externalKeyShareId/keygenId are out of scope, nothing here reads them yet.
WaasShareSet
One of a WaaS wallet's active MPC share sets — its own (VerifiedCredential.walletProperties.shareSetId/shareSetType) or another auth principal's (walletProperties.otherShareSets). shareSetType is one of 'rootUser' | 'delegated' | 'server' | 'businessAccountUser' | 'offlineRecovery' — server-defined string, not modeled as an enum here (see VerifiedCredential.format's own convention).
WaasWalletProperties
Deliberately narrow subset of dynamic-labs sdk-api-core's WalletProperties — only the fields hasDelegatedAccess/getWalletAccountShareSets (waas.flows.ts) actually read. Excludes every non-WaaS wallet-provider variant's fields (the turnkey-prefixed fields, hardwareWallet, coinbase-mpc, ...) and the WaaS-only fields nothing here reads yet (version/settings/derivationPath/isAuthenticatorAttached/...).
Wallet
A user's wallet built from a verified credential. chain is the SDK chain code; instance methods use this wallet's bound signer.
WalletAdditionalAddress
An additional address associated with a wallet (dynamic-labs sdk-api-core's WalletAdditionalAddress) — e.g. a chain that exposes more than one address format per key (BTC: legacy/segwit/taproot) or per network (mainnet/testnet). Carries the public key for that address, which VerifiedCredential itself does NOT — this is the only place a wallet's public key is available after the fact (WaasCreatedWallet's own publicKeyHex, from createWallet's result, only exists transiently at creation time and is never persisted). Confirmed against dynamic-js-sdk's getPublicKeyForWalletAccount, which reads exactly this field to build a BTC PSBT.
WalletConnectSettings
WalletConnect project ID used for public relay access and rate limits. walletProjectId is unused.
WalletsClient
Combines server primary-wallet selection with reactive client chain and network state. Instances share the root client's state. NOTE: not yet thread-safe.
WalletSigner
Chain-independent message and transaction signer for one address. Chain extensions depend on this contract, not a specific wallet provider.
ZerodevMultichainProvider
One chain's ZeroDev project client id, from Provider.multichainProviders.

Enums

EvmSponsoredTransactionStatus
Current state of an EVM gasless relay request.
SolanaSponsorshipMode
Controls automatic sponsorship for a Solana transaction.

Functions

dynBase58Decode(String value) → List<int>
dynBytesToBase58(List<int> bytes) → String
dynBytesToBase64(List<int> bytes) → String
dynBytesToHex(List<int> bytes) → String
dynCanonicalJson(Object? value, [int depth = 0]) → String
dynConcatBytes(List<List<int>> parts) → List<int>
dynHex32(String hex) → List<int>
dynHexToBytes(String hex) → List<int>
dynKeepAlphanumeric(String value) → String
Keeps ASCII letters and digits only.
dynLengthPrefixed(List<int> bytes) → List<int>
dynParseLong(String value) → int
A decimal string as an int — see the IR's parseLong for the ceiling.
dynPrefixed(String prefix, String? value) → String?
prefix + value when the value is there, null when it is not. See the IR's prefixIfPresent.
dynRandomUuid() → String
dynRankIn(List<String> list, String value) → int
dynRepeatedQuery(String path, List<(String, List<String>?)> pairs) → String
dynSortedBy<T>(Iterable<T> items, List<Comparable Function(T)> keys, [List<bool> descending = const []]) → List<T>
items ordered by the keys keys return, each ascending, the second only deciding ties in the first. A new list — a generated sortBy never sorts in place.
dynU16Le(int value) → List<int>
dynU64Le(String decimal) → List<int>
dynUleb128(int value) → List<int>
firstOrNull<T>(Iterable<T>? iterable) → T?
Returns the first item or null. Evaluates compound list expressions once.
firstWhereOrNull<T>(Iterable<T> iterable, bool test(T)) → T?
Not JSON-specific — a hand-rolled Iterable.firstWhere-or-null so the generated code doesn't need the collection package as a pub dependency.