One NEAR DAO,
every chain

Control accounts on EVM, Solana, Bitcoin, Aptos, Sui and TON from NEAR - via a SputnikDAO or a plain account - with MPC chain signatures. Interactive prompts guide every step; the CLI echoes the full command to script and share.

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/near/omni-cli-rs/releases/latest/download/omni-cli-rs-installer.sh | sh
irm https://github.com/near/omni-cli-rs/releases/latest/download/omni-cli-rs-installer.ps1 | iex
cargo binstall --git https://github.com/near/omni-cli-rs omni-cli-rs
cargo install --git https://github.com/near/omni-cli-rs
omni self-update
# Portable archives for macOS, Linux and Windows on the Releases page
https://github.com/near/omni-cli-rs/releases/latest
omni

Why omni?

🏛️

One DAO instead of N multisigs

Retire the Gnosis Safe, Squads, Petra Vault and xDAO you keep per chain. One SputnikDAO on NEAR approves; the MPC signs; anyone broadcasts.

🔍

Verifiable proposals

The proposal description carries the exact unsigned transaction as readable JSON. omni proposal review recomputes the signing payloads and byte-compares them with what the DAO would sign.

🌐

Six chain families

EVM (Ethereum, Base, Arbitrum, BNB, Polygon, HyperEVM, Abstract), SVM (Solana, Fogo), Bitcoin, Aptos, Sui and TON - out of the box.

🔗

MPC chain signatures

No foreign private key ever exists. A foreign address is derived from your NEAR account plus a derivation path, and the MPC network signs on request.

▸

Interactive and scriptable

Type omni and follow the prompts. Every run ends by echoing the full non-interactive command - paste it into a script or share it with your DAO.

🧩

A near-cli-rs extension

Same network connections, same keychain, same signing options. If near already works on your machine, so does omni.

⚙️

Chains are config, not releases

Add any chain of a supported family with omni config add-chain. Endpoints resolve from the NEAR network you pick - mainnet or testnet.

🔁

Recoverable by design

A broadcast that fails after the MPC signed is never lost: omni transaction broadcast reassembles it from the NEAR transaction hash.

⚡

Rust, with self-update

A single static binary for macOS, Linux and Windows. omni self-update pulls the latest release in place.

The DAO route

01 / propose

Any member constructs

Describe the action on the destination chain; the sign request is wrapped in a SputnikDAO proposal with a reviewable envelope.

omni transaction construct evm base contract-call 0xLocker '0 ETH' function-signature 'pause()' '[]' derivation-path locker-admin sign-as-dao dao.sputnik-dao.near 'Pause locker' proposer.near network-config mainnet sign-with-keychain send
02 / review

Every voter verifies

Receiver, method, derivation path, key domain and the signing payloads are checked byte-for-byte against the envelope. Any mismatch is a hard stop.

omni proposal review dao.sputnik-dao.near 42 network-config mainnet
03 / vote

Approve or reject

The deciding vote executes the MPC sign call inside the same NEAR transaction and prints the finalize command for you.

omni proposal vote dao.sputnik-dao.near 42 approve voter.near network-config mainnet sign-with-keychain send
04 / broadcast

Anyone finalizes

The signature lives in the NEAR receipts. Reassemble the destination-chain transaction from the deciding vote's hash and broadcast it.

omni transaction broadcast <NEAR-TX-HASH> voter.near network-config mainnet

A plain NEAR account skips the proposal: sign-as-account signs and broadcasts in one go.

What you can do

$ omni account
  • Derived addresses on every chain
  • Native balance per chain
  • For a DAO or a plain account
  • Any derivation path
$ omni transaction
  • Native transfers on six families
  • EVM contract calls (typed or raw)
  • Sign directly or via DAO proposal
  • Broadcast / recover from a NEAR tx
$ omni proposal
  • List proposals, envelopes decoded
  • Review: byte-compare the payloads
  • Vote approve / reject
  • Get the finalize command
$ omni config
  • Show the chain registry
  • Add or remove chains
  • Sync new defaults after upgrades
  • Reset (always backed up)

See it in action

Pick a destination

◆ Select the destination chain family:
evm - EVM chains (Ethereum, Base, Arbitrum, ...)
svm - SVM chains (Solana, Fogo, ...)
utxo - UTXO chains (Bitcoin)
ton - TON (v5r1 wallet)
[↑↓ to move, enter to select, type to filter]

Choose who signs

◆ Who calls the MPC signer (the owner of the derived foreign account)?
sign-as-account - Your NEAR account calls the MPC right now
sign-as-dao - Wrap the sign request in a SputnikDAO proposal
[↑↓ to move, enter to select, type to filter]

FAQ

What is a derivation path?

A free-form label. The foreign address is a function of (owner NEAR account, derivation path), so dao.near + treasury and alice.near + treasury are unrelated addresses on every chain. One DAO can run many independent foreign accounts just by using different paths. The default is omni-1.

How can a voter trust a proposal?

The proposal description holds the exact unsigned transaction as readable JSON - not a hash. omni proposal review rebuilds the signing payloads from it and byte-compares them against the sign arguments the DAO would actually send to the MPC, after checking the receiver contract, the method, the derivation path and the key domain. If anything differs, it refuses with do NOT approve.

Do I need near-cli-rs installed?

No - omni is a standalone binary. It does reuse the near-cli-rs configuration on your machine (network connections and the system keychain), so an existing near setup works as-is and omni creates a default one otherwise.

Which chains are supported?

Six families: EVM (eth, base, arb, bnb, pol, hyperevm, abs), SVM (solana, fogo), UTXO (btc), Aptos, Sui and TON. Any other chain of a supported family is a config entry - omni config add-chain - not a new release. Endpoints resolve from the NEAR network you select: mainnet to the chain's mainnet, testnet to its testnet.

Why does the Solana DAO route need a durable nonce?

A Solana recent blockhash expires in about a minute - far shorter than a DAO vote. Governance transactions therefore use a durable nonce account owned by the derived address. Create the deterministic one once with omni transaction construct svm solana setup-nonce (account-owned paths), or pass an externally created one with --nonce-account (DAO-owned paths).

Can I use it in scripts?

Yes. Every interactive run ends by echoing the complete non-interactive command, and all arguments can be passed directly. --quiet trims the output for pipelines.