# Extrinsics: proxy

Proxies are wallets that are authorized by other wallets to perform tasks. Each Bittensor proxy type permits a fixed set of calls.

_Source: https://beta.taostats.io/docs/understanding-taostats/extrinsics/proxy-extrinsics_

_Last reviewed: 2026-10-05_

Proxies are wallets that are authorized by other wallets to perform tasks. When you add a proxy, you choose a proxy type, and the type fixes which calls the proxy can make on your behalf. A call that the type does not list is rejected.

Bittensor has 19 proxy types. Four of them are deprecated and permit nothing.

> [!NOTE]
> **Securing your wallet**
>
> For how proxies fit into an overall wallet-security setup alongside ledgers and multisig, see [Securing a wallet: ledgers, multisig & proxies](https://beta.taostats.io/docs/concepts/security/securing-a-wallet).

## ProxyType permission table

| ProxyType | Transfer TAO / alpha | Manage stake | Register | Subnet admin | Weights & serving | Child keys | Swap hotkey | Claim root | Basket trading | Coldkey swap |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| **Any** | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| **NonCritical** | ✅ | ✅ | ✅ *(PoW only)* | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| **NonTransfer** | ❌ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | ❌ | ❌ |
| **NonFungible** | ❌ | ❌ | ✅ *(PoW only)* | ✅ | ✅ | ✅ | ❌ | ✅ | ❌ | ❌ |
| **Owner** | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **SubnetLeaseBeneficiary** | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **Transfer** | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **SmallTransfer** | ✅ *(\< 0.5 TAO / 0.5 alpha)* | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **Staking** | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **Registration** | ❌ | ❌ | ✅ *(PoW + burned)* | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **ChildKeys** | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ |
| **SwapHotkey** | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ |
| **RootClaim** | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | ❌ | ❌ |
| **BasketTrading** | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | ❌ |
| **SudoUncheckedSetCode** | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **Triumvirate** *(deprecated)* | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **Senate** *(deprecated)* | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **Governance** *(deprecated)* | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |
| **RootWeights** *(deprecated)* | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ |

## What the columns mean

- **Transfer TAO / alpha**: `transfer_keep_alive`, `transfer_allow_death`, `transfer_all`, `transfer_stake` and `transfer_stake_and_hotkey`. These move value to a different coldkey.
- **Manage stake**: `add_stake`, `remove_stake`, `unstake_all`, `unstake_all_alpha`, `move_stake`, `swap_stake` (and their `_limit` variants), `stake_into_basket`, `add_collateral` and `set_min_collateral`. Stake stays on your own coldkey, but these calls can unstake it to free TAO.
- **Register**: `register` and `register_limit` (proof of work), `burned_register`, and `root_register`.
- **Subnet admin**: the subnet-owner hyperparameter calls (`sudo_set_*` in AdminUtils), `set_tempo`, `set_subnet_identity` and `update_symbol`. SubnetLeaseBeneficiary also has `start_call`.
- **Weights & serving**: `set_weights`, `commit_weights` and `reveal_weights` (with their mechanism, batch and timelocked variants), `serve_axon`, `serve_prometheus`, `set_identity`, `associate_evm_key`, and validator take changes.
- **Child keys**: `set_children` and `set_childkey_take`.
- **Swap hotkey**: `swap_hotkey` and `swap_hotkey_v2`.
- **Claim root**: `claim_root` and `claim_root_with_hotkey`.
- **Basket trading**: `swap_basket` and `swap_basket_many`, used by a root validator to rebalance its basket.
- **Coldkey swap**: announcing, executing, disputing or clearing a coldkey swap. Only `Any` can do this.

## Notes

- **NonTransfer is not value-safe.** It cannot transfer to another coldkey, but it can unstake, lock and burn stake, and register networks. Do not use it to protect an account's value.
- **NonFungible is the type that touches no value.** It cannot move, stake, lock or burn TAO or alpha, and cannot swap keys. It can still set weights and child keys, which redirect emissions, so treat it as an operations key, not a harmless one.
- **NonCritical** covers day-to-day work, including transfers, EVM and contract calls. It excludes sudo, burned and root registration, coldkey swaps and basket trading.
- **Basket trading needs an explicit grant.** No proxy type except `Any` and `BasketTrading` can call `swap_basket`. `NonCritical` and `NonTransfer` cannot.
- **Staking does not include claiming root dividends.** Pair it with a `RootClaim` proxy if the delegate needs both.
- **SmallTransfer** allows balance transfers below 0.5 TAO and stake transfers below 0.5 alpha per call.
- **SudoUncheckedSetCode** permits one call: `sudo_unchecked_weight` wrapping `System.set_code`, used for runtime upgrades by the sudo key.
- **No restricted type can call sudo**, wrap calls in a multisig, or submit MEV-shield encrypted calls, because those re-dispatch the inner call without the proxy filter.
- A proxy cannot add another proxy with a broader type than its own.
- The broad types (`Any`, `NonCritical`, `NonTransfer`, `NonFungible`) can also call Utility, Proxy, Scheduler, Commitments, Swap (liquidity positions), limit-order and other infrastructure pallets.
