MetaMask Snap In testing
MetaMask Snap

XE for MetaMask

Your MetaMask. An XE account in it.

A Snap is an add-on that runs inside MetaMask. This one gives you XE accounts from the recovery phrase you already have, and asks before every signature.

In testing. Not on npm and not reviewed by MetaMask, so regular MetaMask cannot install it yet.

Run it in MetaMask Flask

The Snap is not published yet, so regular MetaMask cannot install it. MetaMask Flask, the developer build, can run it from your own computer.

  1. Install MetaMask Flask in a separate browser profile and create a new wallet in it. MetaMask's advice: never import a phrase that holds funds.

  2. Download the Snap's files. macOS or Linux; on Windows use WSL or Git Bash.

    mkdir -p xe-snap/dist xe-snap/images && cd xe-snap
    curl -O https://snap.xe.marketized.io/snap/0.1.0/snap.manifest.json
    curl -O https://snap.xe.marketized.io/snap/0.1.0/package.json
    curl -O https://snap.xe.marketized.io/snap/0.1.0/serve.mjs
    curl -o dist/bundle.js https://snap.xe.marketized.io/snap/0.1.0/dist/bundle.js
    curl -o images/icon.svg https://snap.xe.marketized.io/snap/0.1.0/images/icon.svg
  3. Serve them on this computer. Needs Node 18 or newer. It listens on 127.0.0.1 only.

    node serve.mjs
  4. Connect. Flask shows the Snap's permissions, installs it, then asks whether to connect this site.

    Nothing asked yet

    This page never sees your recovery phrase or password.

Reference

What it signs, and what MetaMask shows firstPayments, shared accounts, delegated keys and messages.

It signs payments you send and receive, the opening of a shared account and changes to its signers, limits granted to another key and their removal, and text messages such as a sign-in. Anything else is refused before a window opens.

A payment's window is titled "Send XE" and lists:

  • Requested by, the site asking, and Network.
  • Pay to, Amount and Memo. Memos are public.
  • Balance after and Network fee, which is none.
  • From account and the block's hash as the Snap computed it.

"New address: check it" appears when the address has never been used on that network. XE addresses have no typo check, so a mistyped one is still valid.

"Not the site in the message" appears when a site asks you to sign a sign-in that names a different site.

Connecting a site is its own window, "Connect to XE". It never lets the site sign without asking.

What it asks MetaMask for8 permissions, read from the manifest, in plain words.
PermissionWhat that means here
Take requests from websitesendowment:rpcWebsites can send it requests; other Snaps cannot. A site sees an account only after you connect it.
Reach the internetendowment:network-accessTo read balances from XE's test networks and send the blocks you sign. The addresses it uses are fixed when it is built.
Run WebAssemblyendowment:webassemblyThe signing code shared with XE's other signers is a WebAssembly module, with no access to anything outside the Snap.
Have a page inside MetaMaskendowment:page-homeBalance, pending payments, your address, a send form and recent activity.
Run once when installedendowment:lifecycle-hooksIt shows a welcome window with your first XE address.
Show confirmation windowssnap_dialogEvery signature goes through one. So does connecting a site.
Store its own datasnap_manageStateYour XE account list, the network last viewed and the sites you connected, encrypted by MetaMask. No key is stored.
Derive keys from your Secret Recovery Phrasesnap_getBip32EntropyOnly under m/44'/22597' (ed25519), the branch used for XE. It cannot derive your Ethereum keys or any other network's.
What it cannot do yetTest networks and XE only.
  • No main network: XE Sim and the XE testnet only. XE on them has no value.
  • XE only. It refuses other assets, leases and burns.
  • It will not sign as another account's delegated key, or change your representative, the account your voting weight follows.
  • XE accounts do not appear in MetaMask's own account list. They are on the Snap's page: Menu, Snaps, XE Network.
  • No alert when a payment arrives. The Snap's page reads the network when you open it.
The build and its filesVersion 0.1.0, its checksums, and every file to download.
Version
0.1.0, "XE Network"Built 2026-10-12 from source commit 6b7d5bd.
Manifest checksum
i+0TrIz/JanHpfU5G7EB8hwNlLWCHEVp1Et7AwPgAkI=
MetaMask's shasum over the manifest, the code and the icon. MetaMask refuses a Snap whose files do not give the checksum in its manifest.
SHA-256 of bundle.js
618d1c82a99089a1b24c4ab7947e515eb0e2115be1e019d98446614ba3873b88
shasum -a 256 bundle.js on macOS, sha256sum bundle.js on Linux, certutil -hashfile bundle.js SHA256 on Windows.
For sites that want to use itThree calls, the same ones this page makes.

Find MetaMask through EIP-6963, the standard by which wallets announce themselves to a page. Call wallet_requestSnaps with the Snap's id, then wallet_invokeSnap with xe_connect to ask for an account. xe_getAccounts returns the accounts already connected, without a window.

Status in fullNo audit, source not public yet, and the key path.
  • Not on npm. MetaMask installs a Snap from the npm registry or, in MetaMask Flask, from your own computer. It takes no Snap from a website's address, this one included.
  • Not reviewed by MetaMask. After publishing, MetaMask must review the Snap and allow that version.
  • No security audit. MetaMask requires one for a Snap that derives keys.
  • Source not public yet. It will be published with the first public release. You can download the code MetaMask would run, but not yet compare it with its source.
  • Tested with automated tests, and by hand in MetaMask Flask from a local build.
  • Key path m/44'/22597'/n', where n is the account number. 22597 is provisional: XE has no registered coin type.
  • No new phrase. The keys come from MetaMask's Secret Recovery Phrase and never leave the Snap. The XE app for Ledger devices derives the same accounts from the same phrase.