{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "eip-712-typed-data",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/eip-712-typed-data/",
  "collection": "ethereum",
  "title": "Typed-data signatures: reading EIP-712 messages",
  "description": "Read Ethereum typed-data signatures by checking the domain, requested action and replay controls, rather than assuming a readable message is harmless.",
  "aliases": [],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T18:12:41.505Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "EIP-712 defines how structured typed data is hashed and signed, including a domain that separates signing contexts. It can make wallet requests more interpretable, but does not make their requested permissions safe. Applications must still implement replay controls, and a signature may authorize valuable actions without an immediate on-chain fee.",
    "claimId": "eip-712-typed-data-quick-answer",
    "sourceIds": [
      "eip712",
      "eip2612"
    ]
  },
  "keyFacts": [
    {
      "label": "Structure",
      "value": "The signed digest commits to typed message data and a domain separator.",
      "sourceIds": [
        "eip712"
      ],
      "id": "structure",
      "claimId": "eip-712-typed-data-fact-structure"
    },
    {
      "label": "Domain",
      "value": "Domain fields can include name, version, chainId and verifyingContract.",
      "sourceIds": [
        "eip712"
      ],
      "id": "domain",
      "claimId": "eip-712-typed-data-fact-domain"
    },
    {
      "label": "Replay",
      "value": "EIP-712 explicitly leaves application replay handling to implementers.",
      "sourceIds": [
        "eip712"
      ],
      "id": "replay",
      "claimId": "eip-712-typed-data-fact-replay"
    }
  ],
  "prerequisites": [
    "ethereum-wallet-requests"
  ],
  "sections": [
    {
      "id": "read",
      "heading": "Read both the domain and the action",
      "sourceIds": [
        "eip712"
      ],
      "paragraphs": [
        "The domain identifies the signing context, while the typed message describes the requested operation. A familiar application name does not replace checking the verifying contract, chain and message fields.",
        "Look for the recipient or spender, asset, amount, deadline and nonce where the application defines them. Not every typed message uses the same field names or permissions."
      ]
    },
    {
      "id": "authority",
      "heading": "A signature can be submitted later by someone else",
      "sourceIds": [
        "eip2612"
      ],
      "paragraphs": [
        "A token permit can let a relayer submit a signed allowance authorization. The user may pay no gas when signing, yet the accepted permit can create spending authority.",
        "“No gas” describes the signing step, not the absence of financial consequences. Do not classify every off-chain signature as a harmless login."
      ]
    },
    {
      "id": "replay",
      "heading": "Readable fields do not enforce themselves",
      "sourceIds": [
        "eip712"
      ],
      "paragraphs": [
        "The verifying application must check the domain and implement appropriate one-time-use, deadline or idempotency rules. Including a field in a display is insufficient if the verifier does not enforce it.",
        "A security review therefore examines both the message a wallet signs and the contract logic that accepts it."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does EIP-712 automatically prevent a signature from being used twice?",
      "answer": "No. The standard specifies typed signing and domain separation. The application must reject unwanted repeats or make repeated execution harmless.",
      "sourceIds": [
        "eip712"
      ]
    }
  ],
  "claims": [
    {
      "id": "eip-712-typed-data-quick-answer",
      "articleSlug": "eip-712-typed-data",
      "statement": "EIP-712 defines how structured typed data is hashed and signed, including a domain that separates signing contexts. It can make wallet requests more interpretable, but does not make their requested permissions safe. Applications must still implement replay controls, and a signature may authorize valuable actions without an immediate on-chain fee.",
      "sourceIds": [
        "source-c78d0f0c60a42b2d",
        "source-1f53bb744ddddb6b"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c78d0f0c60a42b2d",
          "locator": "Specification; Security Considerations"
        },
        {
          "sourceId": "source-1f53bb744ddddb6b",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Checked EIP-712 domainSeparator, typed message hashing, optional domain fields and explicit lack of replay protection. Security Considerations permits rejection or idempotent replay handling.",
          "ERC-2612 verifies the example of a later submitted gasless-signing allowance. No readable-message safety or mandatory universal field list is asserted."
        ]
      }
    },
    {
      "id": "eip-712-typed-data-fact-structure",
      "articleSlug": "eip-712-typed-data",
      "statement": "Structure: The signed digest commits to typed message data and a domain separator.",
      "sourceIds": [
        "source-c78d0f0c60a42b2d"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c78d0f0c60a42b2d",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Checked EIP-712 domainSeparator, typed message hashing, optional domain fields and explicit lack of replay protection. Security Considerations permits rejection or idempotent replay handling.",
          "ERC-2612 verifies the example of a later submitted gasless-signing allowance. No readable-message safety or mandatory universal field list is asserted."
        ]
      }
    },
    {
      "id": "eip-712-typed-data-fact-domain",
      "articleSlug": "eip-712-typed-data",
      "statement": "Domain: Domain fields can include name, version, chainId and verifyingContract.",
      "sourceIds": [
        "source-c78d0f0c60a42b2d"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c78d0f0c60a42b2d",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Checked EIP-712 domainSeparator, typed message hashing, optional domain fields and explicit lack of replay protection. Security Considerations permits rejection or idempotent replay handling.",
          "ERC-2612 verifies the example of a later submitted gasless-signing allowance. No readable-message safety or mandatory universal field list is asserted."
        ]
      }
    },
    {
      "id": "eip-712-typed-data-fact-replay",
      "articleSlug": "eip-712-typed-data",
      "statement": "Replay: EIP-712 explicitly leaves application replay handling to implementers.",
      "sourceIds": [
        "source-c78d0f0c60a42b2d"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c78d0f0c60a42b2d",
          "locator": "Specification; Security Considerations"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:12:41.505Z",
        "reviewer": "Codex independent automated reviewer /root/verify_ethereum_100",
        "notes": [
          "Checked EIP-712 domainSeparator, typed message hashing, optional domain fields and explicit lack of replay protection. Security Considerations permits rejection or idempotent replay handling.",
          "ERC-2612 verifies the example of a later submitted gasless-signing allowance. No readable-message safety or mandatory universal field list is asserted."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "eip712",
      "label": "Typed structured data hashing and signing",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-712",
      "locator": "Specification; Security Considerations",
      "note": "Typed-data encoding and domain fields; replay protection is application-specific.",
      "version": "EIP/ERC-712; retrieved document hash recorded",
      "checkedAt": "2026-10-02T17:03:42.239Z",
      "contentSha256": "0951c36c432c48e281bd131331bdd5f4426706417e0d38fa3e667c0b7f84a530",
      "recordId": "source-c78d0f0c60a42b2d"
    },
    {
      "id": "eip2612",
      "label": "Permit Extension for EIP-20 Signed Approvals",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-2612",
      "locator": "Specification; Security Considerations",
      "note": "Signed token allowances, deadlines, nonces and domain checks.",
      "version": "EIP/ERC-2612; retrieved document hash recorded",
      "checkedAt": "2026-10-02T17:03:42.295Z",
      "contentSha256": "aa208d281cac5dbb182656bc7a3feab982df5c5df9e2f6dfa9b9efb5fc578ed1",
      "recordId": "source-1f53bb744ddddb6b"
    }
  ],
  "related": {
    "articles": [
      "permit-signatures",
      "signature-replay-attacks",
      "ethereum-token-approvals",
      "sign-in-with-ethereum"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and independent automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Typed-data signatures: reading EIP-712 messages.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/eip-712-typed-data/"
}
