> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grapl.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Eligibility and Merkle proofs

> How the local protocol binds buying eligibility to the actual caller.

A Merkle proof demonstrates that a wallet is in the list committed by a root. It does not sign a transaction, log someone in or authorize spending. GRAPL combines membership with an authenticated router caller.

## The wallet checked by the hook

```mermaid theme={null}
sequenceDiagram
  participant Buyer as Buying wallet
  participant Router as LaunchRouter
  participant Pool as PoolManager
  participant Hook as LaunchHook
  participant Registry as LaunchRegistry
  Buyer->>Router: Swap with proof
  Router->>Pool: Unlock and swap
  Pool->>Hook: beforeSwap
  Hook->>Router: Read activeTrader
  Hook->>Registry: Check time, direction and wallet proof
  Registry-->>Hook: Accept or revert
```

The router captures its actual caller as `activeTrader`. The hook accepts only its configured PoolManager and immutable router, then reads that caller directly. `hookData` carries the proof, not a trusted buyer address. The router delivers output only to its caller; it exposes no arbitrary recipient.

## Local leaf format

The registry uses an address-only, double-hashed leaf:

```solidity theme={null}
bytes32 leaf = keccak256(bytes.concat(keccak256(abi.encode(trader))));
```

Verification uses OpenZeppelin `MerkleProof.verifyCalldata` against the root registered for that pool. Proof generation must use matching leaf encoding and pair hashing. Copying another wallet's proof does not impersonate its caller. The leaf does not bind a chain, purchase quota or nonce: reusing a list/root across pools makes those wallets eligible in each corresponding pool.

The single-wallet scheduled fixture uses that wallet's leaf as the root and an empty proof array. This is a test example, not a public proof API.

## Freezing and changing wallets

The list is finalized **before the scheduled token and pool are deployed**. Existing registry entries have no root-update method. Product decisions must define wallet verification, the linking deadline and handling of mistakes before freezing.

<Note>
  **Wallet pending** in the app is illustrative. It does not confirm onchain
  membership. Social OAuth, registration storage and proof delivery remain
  unimplemented.
</Note>

## Scope of enforcement

The gate applies to the registered pool. Launch tokens are transferable; the hook does not restrict every ERC-20 transfer or external market. Anyone can call the authorized router directly under the same rules; there is no separate app-origin signature gate.

Membership does not establish token safety, guaranteed allocation or protection against all bots and Sybil accounts. Continue with [presale timing](/concepts/public-presales) and [security](/reference/security).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.