Control accounts on EVM, Solana, Bitcoin, Aptos, Sui and TON from NEAR - via a SputnikDAO or a plain account - with MPC chain signatures. Interactive prompts guide every step; the CLI echoes the full command to script and share.
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/near/omni-cli-rs/releases/latest/download/omni-cli-rs-installer.sh | sh
irm https://github.com/near/omni-cli-rs/releases/latest/download/omni-cli-rs-installer.ps1 | iex
cargo binstall --git https://github.com/near/omni-cli-rs omni-cli-rs
cargo install --git https://github.com/near/omni-cli-rs
omni self-update
# Portable archives for macOS, Linux and Windows on the Releases page
https://github.com/near/omni-cli-rs/releases/latest
Retire the Gnosis Safe, Squads, Petra Vault and xDAO you keep per chain. One SputnikDAO on NEAR approves; the MPC signs; anyone broadcasts.
The proposal description carries the exact unsigned transaction as readable JSON. omni proposal review recomputes the signing payloads and byte-compares them with what the DAO would sign.
EVM (Ethereum, Base, Arbitrum, BNB, Polygon, HyperEVM, Abstract), SVM (Solana, Fogo), Bitcoin, Aptos, Sui and TON - out of the box.
No foreign private key ever exists. A foreign address is derived from your NEAR account plus a derivation path, and the MPC network signs on request.
Type omni and follow the prompts. Every run ends by echoing the full non-interactive command - paste it into a script or share it with your DAO.
Same network connections, same keychain, same signing options. If near already works on your machine, so does omni.
Add any chain of a supported family with omni config add-chain. Endpoints resolve from the NEAR network you pick - mainnet or testnet.
A broadcast that fails after the MPC signed is never lost: omni transaction broadcast reassembles it from the NEAR transaction hash.
A single static binary for macOS, Linux and Windows. omni self-update pulls the latest release in place.
Describe the action on the destination chain; the sign request is wrapped in a SputnikDAO proposal with a reviewable envelope.
omni transaction construct evm base contract-call 0xLocker '0 ETH' function-signature 'pause()' '[]' derivation-path locker-admin sign-as-dao dao.sputnik-dao.near 'Pause locker' proposer.near network-config mainnet sign-with-keychain send
Receiver, method, derivation path, key domain and the signing payloads are checked byte-for-byte against the envelope. Any mismatch is a hard stop.
omni proposal review dao.sputnik-dao.near 42 network-config mainnet
The deciding vote executes the MPC sign call inside the same NEAR transaction and prints the finalize command for you.
omni proposal vote dao.sputnik-dao.near 42 approve voter.near network-config mainnet sign-with-keychain send
The signature lives in the NEAR receipts. Reassemble the destination-chain transaction from the deciding vote's hash and broadcast it.
omni transaction broadcast <NEAR-TX-HASH> voter.near network-config mainnet
A plain NEAR account skips the proposal: sign-as-account signs and broadcasts in one go.
A free-form label. The foreign address is a function of (owner NEAR account, derivation path), so dao.near + treasury and alice.near + treasury are unrelated addresses on every chain. One DAO can run many independent foreign accounts just by using different paths. The default is omni-1.
The proposal description holds the exact unsigned transaction as readable JSON - not a hash. omni proposal review rebuilds the signing payloads from it and byte-compares them against the sign arguments the DAO would actually send to the MPC, after checking the receiver contract, the method, the derivation path and the key domain. If anything differs, it refuses with do NOT approve.
No - omni is a standalone binary. It does reuse the near-cli-rs configuration on your machine (network connections and the system keychain), so an existing near setup works as-is and omni creates a default one otherwise.
Six families: EVM (eth, base, arb, bnb, pol, hyperevm, abs), SVM (solana, fogo), UTXO (btc), Aptos, Sui and TON. Any other chain of a supported family is a config entry - omni config add-chain - not a new release. Endpoints resolve from the NEAR network you select: mainnet to the chain's mainnet, testnet to its testnet.
A Solana recent blockhash expires in about a minute - far shorter than a DAO vote. Governance transactions therefore use a durable nonce account owned by the derived address. Create the deterministic one once with omni transaction construct svm solana setup-nonce (account-owned paths), or pass an externally created one with --nonce-account (DAO-owned paths).
Yes. Every interactive run ends by echoing the complete non-interactive command, and all arguments can be passed directly. --quiet trims the output for pipelines.