Eligibility and whitelisting
Access rules collectors can understand
See who qualifies, what they must prove, who authorizes the proof, and which Keel surface can use the rule today.
Choose from the surface you are actually using
The creator flow is deliberately small. The operator flow is broader. The contracts support more combinations than either interface.
Public or invite list
The normal release wizard publishes one Public or Allowlist stage. Holder, Claim, and Custom values exist in draft types but basic publication preparation rejects them.
- Available
- Public, Allowlist
- Not available here
- Holder, Claim, Custom, Merkle, Token Payment, Premint
- Published shape
- One ordered OneMint stage
Source · Studio available
apps/studio/src/components/launch/release-studio.tsx · apps/studio/src/lib/release-schema.ts · apps/studio/src/server/services/release-service.tsOneMint operator stages
The operator editor exposes Public, Allowlist, NFT Claim, Token Payment, Premint, Off, and End. It does not currently expose a Merkle selector.
- Collector stages
- Public, Allowlist, NFT Claim, Token Payment
- Administrator stage
- Premint
- Schedule controls
- Off, End
Source · Operator available
apps/studio/src/components/launch/mint-configurator.tsx · apps/studio/src/lib/mint-launch-schema.tsOneMint and KeelMintGate
OneMint source also supports Merkle. KeelMintGate can compose Merkle, token, custom-gate, and signed rules with All or Any logic.
- OneMint
- Off, Allowlist, Public, Token Payment, Claim, Premint, End, Merkle
- KeelMintGate
- Merkle, token, custom gate, signature, and composed rules
- Important
- Contract support is not basic Studio support
Open the door or invite exact wallets
These are the access choices available in the normal artist release flow.
Anyone may attempt the active stage
Public does not mean unconstrained. The controller still checks timing, supply, quantity, wallet limits, exact payment, and collection capacity.
- Collector proves
- Wallet and exact mint parameters
- Membership proof
- None
- Studio action
- publicMint
Keep the list private; issue a short-lived proof
The artist pastes wallet addresses into a private revision. At collection time the service rechecks the current list and live drop, then issues a typed authorization.
- Editor
- Addresses separated by lines or commas; 10,000-member limit
- Collector sees
- Eligibility result, not the private list
- Authorization
- Short-lived EIP-712 signature
- Publication requires a non-empty list and configured authorization signer.
- Authorization rechecks the active release, stage, nonce, wallet limits, minted count, and supply.
Source · Studio available
apps/studio/src/components/studio/release-access-editor.tsx · apps/studio/src/server/services/release-service.ts · apps/studio/src/app/api/releases/slug/[slug]/authorization/route.tsCarry a proof when the rule belongs onchain
Merkle, signed, token, and custom rules bind different evidence. They can be composed only where the controller supports that composition.
Prove membership and allowance
OneMint binds a wallet and allowance in a double-hashed leaf. A valid proof can narrow the effective wallet limit for that collector.
- Collector supplies
- Merkle proof and allowance
- Onchain commitment
- Merkle root
- Current UI
- Not exposed in the OneMint operator editor
Bind the whole mint promise
KeelMintGate authorization binds the campaign, collector, signer, quantity ceiling, unit price, nonce, deadline, and context. SignatureChecker supports EOAs and ERC-1271 wallets.
- Typed data
- EIP-712, Keel Mint Access v1
- Signer policy
- Creator, platform, either, or none
- Replay controls
- Nonce, deadline, context hash, digest lock
Explain every external gate
KeelMintGate can call a configured custom gate with committed data and combine it with Merkle, token, and signature rules using All or Any logic.
- Operator prepares
- Gate address and custom data
- Contract decides
- All gates or any passing gate
- Basic Studio
- Not available
Payment, ownership, claims, and administrator mints are different rules
The collector should see the exact thing being checked rather than one generic gated badge.
Pay the exact ERC-20 amount
The advanced collector checks token balance and allowance. The controller rejects fee-on-transfer behavior because received payment would not match the committed amount.
- Collector needs
- Payment-token balance and controller allowance
- Price
- Quantity multiplied by unit price
- Basic Studio
- Not available
Use ownership or balance as eligibility
KeelMintGate supports ERC-20 balance, ERC-721 balance, a specific ERC-721 token, or ERC-1155 balance. The current operator compiler exposes a narrower ERC-721-balance path.
- Purpose
- Eligibility, not payment
- Standards
- ERC-20, ERC-721, ERC-1155
- Composition
- Can join Merkle, custom, and signature rules
Consume exact entitlement IDs
A claim binds a signed authorization to eligible ERC-721 token IDs. The controller checks ownership and records consumed IDs so an entitlement cannot be reused.
- Collector supplies
- Signature and entitlement token IDs
- Checks
- Ownership, limits, signature, and prior consumption
- Contract limit
- Up to 64 claim IDs per call
Strike as an administrator
Premint consumes the drop allocation through an administrator action. It is not an early collector checkout and does not belong on a public mint button.
- Actor
- Authorized administrator
- Action
- adminStrike
- Collector mint
- Not available
Eligibility still sits beneath supply, capacity, and payment
A valid proof cannot mint outside the active stage, beyond a wallet limit, above collection capacity, or without exact payment.
Stages share the drop
Every stage in a OneMint drop shares one supply and one wallet-minted count. A stage may narrow the wallet limit, but it does not create a separate pool.
- Finite supply
- Reserves collection capacity
- Open supply
- No finite reservation; the collection maximum remains authoritative
- Permanent close
- Releases unused reserved capacity
A campaign has its own cap
A direct finite KeelMintGate campaign reserves target capacity. Adapter campaigns cannot receive the same direct capacity protection and must make their limit safe elsewhere.
- Direct target
- Finite maximum can reserve capacity
- Adapter target
- No direct reservation guarantee
- Accounting
- Per-campaign supply and wallet counters
Source · SDK / contract
../keel-contracts/src/modules/keel-mint-access/KeelMintGate.sol ↗Payment moves into pull balances
KeelMintGate accepts exact native or ERC-20 payment and credits payout and eligible platform-fee balances for withdrawal. A platform fee applies only to platform-signed authorization.
- Payment
- Exact native value or exact ERC-20 receipt
- Payout
- Pull balance
- Platform fee
- Only for platform-signed authorization
Source · SDK / contract
../keel-contracts/src/modules/keel-mint-access/KeelMintGate.sol ↗Named in code does not mean available
The guide fails closed when a stage is reserved, a signer is missing, or fresh live evidence has not been produced.
Do not offer rejected OneMint modes
ProofOfWork, Auction, NeuralPayment, Airdrop, and CustomGate are enum values, but OneMint rejects them. FRAY auctions do not make the OneMint Auction stage available.
- Rejected
- ProofOfWork, Auction, NeuralPayment, Airdrop, CustomGate
- FRAY
- A separate auction system
- Source of truth
- Controller behavior and supported-stage validation
Source · Blocked / unsupported
../keel-sdk/packages/sdk/src/one-mint.ts · ../keel-contracts/src/modules/keel-mint-access/OneMintController.sol ↗Prove the exact rule against the exact release
Source shows validation and call shape. A recorded deployment names an address. Fresh acceptance must prove the release, stage, signer, wallet, RPC state, transaction, event, and resulting counters.
- Logical receipt
- Mode and surface match documented availability
- Wallet receipt
- Expected controller, call, event, and final state
- Binding
- Receipts attach to the exact source fingerprint

