Ethereum Attestation Service
An EAS attestation is an on-chain record somebody else wrote about you. Attesting one shows that a party other than you vouched for an address you have already proven you control. An attestation you wrote about yourself is dropped outright rather than merely counted for less, because something you authored is never evidence about you.
What pairing does not authorise
Pairing this connector is a read commitment, not delegation. Specifically, ~Alter cannot use this pairing to:
- •Write, revoke, or modify any attestation, yours or anyone else’s.
- •Attest anything on your behalf, to any schema, on any chain.
- •Move funds from the recipient address. No signing power is involved.
- •Read attestations naming an address you have not attested.
- •Surface your EAS pairing to any third party without a separate consent row scoped to that recipient.
The OAuth or attestation scope we request is the minimum required to recognise the pattern described in What we read. Anything beyond that is structurally refused at the connector boundary, not promised by trust. How pairing works.
What we read
- The attestation you point at, including its schema, attester, recipient and revocation state.
- Your existing wallet attestation, read only to confirm you control the address named as recipient.
What we don't read
~Alter explicitly refuses these fields even when the OAuth scope or API permits them. Every refusal is enforced at the connector boundary, not by trust.
- Self-attestations, where attester and recipient are the same address. These never enter the set at all.
- Revoked or expired attestations, treated the same way.
- The rest of your attestation history beyond the one you point at.
- Token balances, NFT holdings, or transaction history of the recipient address.
- Private keys or signing material of any kind.
Where it lives
The attestation reference, its schema and a tier badge sit in ~alter's pairing ledger keyed to your ~handle. If the attestation is later revoked on chain, the pairing stops counting on its next check. Revoking removes it from your pairing surface immediately.
How to revoke
Revocation is immediate. Ask the AI client you paired through to revoke this connector, or revoke it from your consent surface over the same connection. Either path revokes the provider token, stops all further reads, and purges the derived signals this connector fed into your identity vector. An audit row records the revocation.
One thing is kept on purpose. The connector retains a record that this account was paired and when it was disconnected, so the same account cannot be unpaired and re-paired in quick succession to churn your identity vector. That cooldown record holds the raw profile snapshot until the window passes. It is never read into a new signal while disconnected, and it is not shared with anyone.
Prefer the command line? The CLI is the optional deeper path and revokes the same connector:
CLI (optional)
alter unpair easPairing this connector does not enrol you in any matching, ranking, or matching surface. Every downstream use requires its own consent row. See the consent model.