WalletLocalizations class abstract

Callers can lookup localized strings with an instance of WalletLocalizations returned by WalletLocalizations.of(context).

Applications need to include WalletLocalizations.delegate() in their app's localizationDelegates list, and the locales they support in the app's supportedLocales list. For example:

import 'l10n/wallet_localizations.dart';

return MaterialApp(
  localizationsDelegates: WalletLocalizations.localizationsDelegates,
  supportedLocales: WalletLocalizations.supportedLocales,
  home: MyApplicationHome(),
);

Update pubspec.yaml

Please make sure to update your pubspec.yaml to include the following packages:

dependencies:
  # Internationalization support.
  flutter_localizations:
    sdk: flutter
  intl: any # Use the pinned version from flutter_localizations

  # Rest of dependencies

iOS Applications

iOS applications define key application metadata, including supported locales, in an Info.plist file that is built into the application bundle. To configure the locales supported by your app, you’ll need to edit this file.

First, open your project’s ios/Runner.xcworkspace Xcode workspace file. Then, in the Project Navigator, open the Info.plist file under the Runner project’s Runner folder.

Next, select the Information Property List item, select Add Item from the Editor menu, then select Localizations from the pop-up menu.

Select and expand the newly-created Localizations item then, for each locale your application supports, add a new item and select the locale you wish to add from the pop-up menu in the Value field. This list should be consistent with the languages listed in the WalletLocalizations.supportedLocales property.

Implementers

Constructors

WalletLocalizations(String locale)

Properties

hashCode → int
The hash code for this object.
no setterinherited
localeName → String
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
securityCustodyBestEffort → String
Security screen: the honest erase line for a tier whose key is not held by secure hardware (ADR-0571).
no setter
securityCustodyHardwareKey → String
Security screen: the honest erase line for a hardware-held key tier (no permanence claim, ADR-0571).
no setter
securityCustodyProbeError → String
Security screen: shown when the custody-tier probe fails (e.g. a locked device).
no setter
securityCustodySectionTitle → String
Security screen: section header for where the wallet keys are protected.
no setter
securityCustodyTierKeychain → String
Security screen: custody tier name for the raw Apple keychain fallback.
no setter
securityCustodyTierNone → String
Security screen: custody tier name when the platform has no key vault (desktop).
no setter
securityCustodyTierSecureEnclave → String
Security screen: custody tier name for Apple Secure Enclave.
no setter
securityCustodyTierSoftware → String
Security screen: custody tier name for a software-rooted keystore.
no setter
securityCustodyTierStrongBox → String
Security screen: custody tier name for Android StrongBox.
no setter
securityCustodyTierTee → String
Security screen: custody tier name for an Android TEE-backed keystore.
no setter
securityCustodyTierUnknown → String
Security screen: custody tier name for an unrecognised (newer-core) tier.
no setter
securityDeleteDialogBody → String
Delete-wallet confirmation dialog: body warning.
no setter
securityDeleteDialogBodyWatchOnly → String
Delete-wallet confirmation dialog body for a WATCH-ONLY wallet (#397 §3.7 D5): no recovery phrase, so the copy must not warn about backing one up — it re-imports from its viewing key.
no setter
securityDeleteDialogCancel → String
Delete-wallet confirmation dialog: the cancel action.
no setter
securityDeleteDialogConfirm → String
Delete-wallet confirmation dialog: the destructive confirm action.
no setter
securityDeleteDialogTitle → String
Delete-wallet confirmation dialog: title.
no setter
securityDeleteFailedSnack → String
Security screen: snackbar shown when a delete fault recovered the wallet (no data lost).
no setter
securityDeleteWalletButton → String
Security screen: the destructive button that opens the delete confirmation.
no setter
securityDeleteWalletSubtitle → String
Security screen: subtitle under the delete-wallet button.
no setter
securityDeleteWalletSubtitleWatchOnly → String
Security screen delete subtitle for a WATCH-ONLY wallet (#397 §3.7 D5): it has no recovery phrase, so the copy must not claim 'restorable from your recovery phrase' — it re-imports from its viewing key instead.
no setter
securityTitle → String
Security screen: app bar title.
no setter
securityUnavailableBody → String
Security screen: honest body when the host app owns wallet custody (no package provisioner is wired), so the package's custody probe and delete-wallet actions are not available here.
no setter
walletActivityCatchingUp → String
Short activity-section cue shown in place of the empty card on the durable catch-up arm (#380) — the wallet is provably still filling in but the rescan choice is unknown (post-relaunch / post-dismiss / a restore's first sync). HEDGED (review): a fresh create's first sync shares this cue, so it must not assert a history that doesn't exist — 'anything you've received will show up here' is true on the rebuilt, restored, AND empty-new arms.
no setter
walletActivityEmpty → String
Empty-state line when the wallet has no transaction history.
no setter
walletActivityError → String
Honest error line when the transaction-history read fails or times out.
no setter
walletActivityExpired → String
Status of an unmined transaction past its expiry — funds returned to spendable.
no setter
walletActivityFailed → String
Status of a transaction the endpoint rejected.
no setter
walletActivityLoadMore → String
Button at the bottom of the activity list that fetches the next keyset page.
no setter
walletActivityPending → String
Status of a broadcast-but-unmined history row.
no setter
walletActivityPublicBadge → String
Screen-reader words for the activity row’s transparency badge (the visual is a small globe icon), and the value of the tx-detail Visibility row. Direction-neutral: covers sent AND received transparent legs.
no setter
walletActivityQueued → String
Status of a send saved offline, waiting to broadcast.
no setter
walletActivityRebuilding → String
Short activity-section cue shown in place of the empty card while a rescan repopulates.
no setter
walletActivityReceived → String
Title of an incoming (positive net amount) history row.
no setter
walletActivityRetrying → String
Status of a wallet-created, unmined history row the wallet still OWES a broadcast (TxSummary.delivery == retryPending, stage S8 obligation): no endpoint has accepted it yet; the same signed bytes go out again on the next sync pass and after a relaunch. Replaces 'Pending' for that row in the activity list and the detail sheet.
no setter
walletActivityRowHint → String
Screen-reader tap hint on a history row (the row opens the transaction-detail sheet).
no setter
walletActivitySaved → String
Status of a wallet-created, unmined history row whose signed bytes are kept but which the wallet is NOT broadcasting on its own right now (TxSummary.delivery == persisted — a swap deposit held past its quote's window). No promise of automatic sending.
no setter
walletActivitySent → String
Title of an outgoing (negative net amount) history row.
no setter
walletActivitySyncNotRunning → String
Activity-section note replacing 'No activity yet' when history exists but cannot repopulate because no sync pass will run (UX HIGH; #405 widened it from the host policy to the SSOT so a FAILED start is covered too). States the pending fill and its condition; CAUSE-AGNOSTIC — the badge above it names why sync isn't running.
no setter
walletActivityTitle → String
Heading above the transaction-history list on the wallet screen.
no setter
walletAppearanceMenuItem → String
Wallet overflow-menu item that opens the host app's own settings page (the route the host wires; the example puts its theme, Tor and device-log choices there).
no setter
walletArrivingLabel → String
New incoming money that is not yet confirmed. Used in two places: the synced balance card's foot, shown OUTSIDE the balance with a '+' before the amount (maintainer: 'show the actual amount that we have now and pending is a separate part'), and the status of an incoming activity row that is not yet mined. Never for money the user already has.
no setter
walletAutoShieldIncomplete → String
Balance-card cue under the transparent line when the auto-shield loop failed or was denied; the manual Shield button sits right below it.
no setter
walletAutoShieldToggleLabel → String
The auto-shield switch label (default ON; only changeable behind the expert gate).
no setter
walletBackupBody → String
Explanation on the backup screen of what the recovery phrase is and the rules for handling it.
no setter
walletBackupConfirmCheckbox → String
Deliberate confirmation the user toggles before the wallet can become deposit-ready (the money-safety gate).
no setter
walletBackupContinue → String
Action that confirms the backup and opens the wallet for deposits; enabled only once the confirmation box is checked.
no setter
walletBackupDone → String
Action that closes the recovery-phrase backup screen after the words have been viewed (view-only; nothing is saved).
no setter
walletBackupManagedBody → String
Explanation shown when the wallet has no local recovery phrase (a host-managed / raw seed); tells the user their recovery lives with the installing app's account.
no setter
walletBackupManagedTitle → String
Heading of the managed-by-host state, shown when the wallet was set up from a host-supplied seed and has no recovery phrase of its own.
no setter
walletBackupReauthFailed → String
Honest error when the host re-authentication step failed (e.g. a wrong passphrase) before the recovery words were shown; distinct from a device-locked read failure, so it does not tell the user to unlock their device.
no setter
walletBackupRetryReveal → String
Retry action after a failed recovery-phrase reveal.
no setter
walletBackupReveal → String
Deliberate-action button to reveal the recovery words (shoulder-surfing mitigation: words are hidden until tapped).
no setter
walletBackupRevealFailed → String
Honest, plain-language error when the recovery words can't be read (e.g. device locked); no error code.
no setter
walletBackupRevealing → String
Busy label while the recovery words are read from the wallet.
no setter
walletBackupSaveFailed → String
Honest error when persisting the backup confirmation fails; the wallet stays not-yet-ready (the gate stays closed).
no setter
walletBackupScreenTitle → String
App-bar title of the post-onboarding recovery-phrase backup screen.
no setter
walletBackupSectionTitle → String
Section header on the Security settings screen for the recovery-phrase backup entry.
no setter
walletBackupSecureNoteAndroid → String
Security note on Android, where the screen is marked secure (no screenshots).
no setter
walletBackupSecureNoteOther → String
Security note on platforms with no screenshot-block; advises a private setting.
no setter
walletBackupStartOver → String
Understated escape action on the forced-backup screen (#356-F2): deletes the not-yet-backed-up wallet (after a confirm dialog) and returns to the create/restore start, so a user who mis-tapped Create is never cornered into falsely confirming a backup.
no setter
walletBackupStartOverConfirm → String
Destructive confirm action of the Start-over dialog (rendered in the destructive color).
no setter
walletBackupStartOverConfirmBody → String
Body of the Start-over confirmation dialog. Must stay honest for EVERY way of reaching forced backup: a fresh create (nothing deposited via this app), the rare restore stranded here by a confirm-persist failure, AND the residual lost-flag edge on a wallet that was briefly active (review) — hence the hedged 'if this wallet ever held funds' phrase-warning instead of an absolute 'never received anything' claim.
no setter
walletBackupStartOverConfirmTitle → String
Title of the Start-over confirmation dialog on the forced-backup screen.
no setter
walletBackupStartOverKeep → String
Safe cancel action of the Start-over dialog — says what it keeps rather than a bare 'Cancel', so a mis-tap defaults to no loss.
no setter
walletBackupTileSubtitle → String
Subtitle of the settings tile that opens the recovery-phrase backup screen.
no setter
walletBackupTileTitle → String
Title of the settings tile that opens the post-onboarding recovery-phrase backup screen.
no setter
walletBackupTitle → String
Heading on the recovery-phrase backup screen.
no setter
walletBalanceHiddenAmount → String
What a screen reader says in place of an amount the user has hidden with the eye button (the screen shows dots).
no setter
walletBalanceLabel → String
Label above the total wallet balance.
no setter
walletBalanceStale → String
Honest staleness cue shown when the last-known balance is rendered through a failed refresh.
no setter
walletCatchUpBanner → String
Top-of-wallet reassurance banner on the durable catch-up arm (#380): the wallet has never completed a sync pass and is below the chain tip — a relaunch mid-rescan catch-up, a dismissed rescan notice over a rebuilt wallet, or a restore/create's first sync. Generic: unlike the walletRescanRebuilding* family it cannot name what the user chose (the choice does not survive a relaunch). HEDGED funds claim (review, the #356-F7 precedent): a fresh create's first sync — possibly offline, so unbounded — shares this cue, and 'your funds are safe' would assert funds that provably don't exist; 'anything you've received' is conditionally true on every arm.
no setter
walletCatchUpRescanBanner → String
Top-of-wallet reassurance banner on the durable rescan arm (#377 s357b-2): the core's rescan-rebuilding breadcrumb says a rescan rebuild is still catching up, but the in-session choice (which range) did not survive the relaunch — so the copy names the RESCAN (the user's own deliberate action, the stronger 'did I lose funds?' reassurance) without naming the range the walletRescanRebuilding* family can. Same HEDGED funds claim as walletCatchUpBanner ('anything you've received' — a zero-balance wallet rescans too).
no setter
walletCheckOneTimeMenuItem → String
Wallet app-bar overflow-menu item that runs the manual one-time (ephemeral) address check/recovery — always available, covering returns the automatic windowed detect can no longer see (an old return past the detect window, or a re-used one-time address).
no setter
walletCountdownUnderMinute → String
Screen-reader-only countdown magnitude used in the {time} slot of the quote/deposit countdown sentences once under 60 seconds (#364 F9): a per-second live-region announcement was a 1 Hz storm, so the accessible label goes coarse while the visual text keeps ticking.
no setter
walletCreateButton → String
Primary action on the welcome screen: start creating a brand-new wallet.
no setter
walletDeepScanBannerChecking → String
#390 C1 — a dismissible banner on the wallet home while a deep scan the user ran is still surfacing money (pending > 0). Sync-NEUTRAL wording (‘as it’s found’, not ‘as your wallet syncs’) so it stays honest while offline; survives closing the sheet.
no setter
walletDeepScanBody → String
#390 deep-scan sheet explanation. Honest: it CHECKS (does not itself find); results appear via the normal balance as sync proceeds.
no setter
walletDeepScanCheckButton → String
#390 sheet primary action — start (or continue) the deep scan.
no setter
walletDeepScanCheckDeeperButton → String
#390 sheet primary action once a range is already fully checked (covered > 0 and nothing pending) — each run goes deeper.
no setter
walletDeepScanChecking → String
#390 in-flight label — on the sheet button while a scan runs, and on the disabled overflow-menu entry (says why it is disabled).
no setter
walletDeepScanClose → String
#390 sheet dismiss button (the scan continues in the background once started).
no setter
walletDeepScanCoverage → String
#390 sheet coverage line when a range is fully checked (covered > 0, pending == 0). NO count — the address index is not a swap tally, so any number would be false (B2). Offers going deeper.
no setter
walletDeepScanCoveragePending → String
#390 sheet coverage line while the current range is still registering + polling (pending > 0). Sync-NEUTRAL — no ‘while your wallet syncs’ claim, which is false when offline/stalled (B3).
no setter
walletDeepScanCoverageUnknown → String
#390 sheet coverage line fallback while the read is loading or unavailable (never a scary error over a recovery sheet).
no setter
walletDeepScanFailed → String
#390 snackbar when the scan could not start (a transient fault). Reassures nothing changed.
no setter
walletDeepScanMenuItem → String
#390 overflow-menu entry (adjacent to Rescan) opening the deep-scan sheet. CHECK verb, never ‘recover’ — the scan can’t know funds exist. ‘addresses’ not ‘refunds’ — it recovers swap deliveries too.
no setter
walletDeepScanRan → String
#390 inline confirmation after an accepted scan. Honest: it does NOT claim ‘found X’ — money surfaces via the normal balance. Sync-NEUTRAL (no ‘as your wallet syncs’, false when offline; B3).
no setter
walletDeepScanRefusedDisabled → String
#390 snackbar for the swapDisabled refusal (a host kill switch stopped the polling the check depends on).
no setter
walletDeepScanRefusedOutstanding → String
#390 inline message for the checkOutstanding refusal (a prior check is still registering/polling — at most one per ~48h settlement window). B4: names the real horizon (‘up to a couple of days’) instead of ‘a little while’.
no setter
walletDeepScanRescanBusy → String
#390 sheet note while a rescan is running/rebuilding — the deep scan and a rescan both re-poll the transparent set, so they are mutually exclusive.
no setter
walletDeepScanRestoreNoteBody → String
#390 one-time post-restore note body — educates that the situation can happen and how to resolve it, without alarming (‘most wallets need nothing’).
no setter
walletDeepScanRestoreNoteCheck → String
#390 post-restore note action — open the deep-scan sheet.
no setter
walletDeepScanRestoreNoteDismiss → String
#390 post-restore note dismiss action (the note never shows again once displayed).
no setter
walletDeepScanRestoreNoteTitle → String
#390 one-time post-restore note title, shown once after the first restore’s catch-up finishes.
no setter
walletDeepScanSlow → String
#390 rel-H1 inline message when the check exceeds the FFI wedge timeout. The widen MAY have committed (a durable local write), so this must NOT claim 'nothing changed' — it's neutral and says money appears in the balance if it did.
no setter
walletDeepScanTitle → String
#390 deep-scan sheet title.
no setter
walletDeepScanTorHint → String
#390 sheet privacy hint shown when Tor was requested but fell back to clearnet (or is unavailable) — the scan is elective, so recommend deferral. Never blocks the action.
no setter
walletDeepScanTorUnknownHint → String
#390 B5 — softer privacy nudge shown when the connection/transport state hasn’t loaded yet (Tor status unknown), so the privacy hint is never silently dropped. Distinct from walletDeepScanTorHint (a CONFIRMED Tor fallback).
no setter
walletExpertToggleDescription → String
Subtitle under the expert-gate switch. Plain-factual.
no setter
walletExpertToggleDescriptionNoAutoShield → String
The expert-gate description when the HOST declared auto-shield unsupported (#383 R2): walletExpertToggleDescription with ONLY the 'turning automatic shielding off' clause removed — that switch never renders there, so advertising it would promise a control that doesn't appear. Keep the shared clause identical to the sibling key so the two never drift.
no setter
walletExpertToggleLabel → String
The expert-gate switch label (default OFF). Turning it on reveals the auto-shield switch and the move-to-transparent entry in the sheet.
no setter
walletExportViewingKeyCopied → String
Confirmation shown after the viewing key is copied to the clipboard.
no setter
walletExportViewingKeyCopy → String
Button that copies the exported viewing key to the clipboard.
no setter
walletExportViewingKeyDone → String
Action that closes the export-viewing-key screen.
no setter
walletExportViewingKeyFailed → String
Honest error line shown when reading the viewing key for export failed transiently.
no setter
walletExportViewingKeyQrLabel → String
Accessibility label for the QR tile encoding the exported viewing key.
no setter
walletExportViewingKeyRetry → String
Retry action after a failed re-auth or a failed viewing-key read on the export screen.
no setter
walletExportViewingKeyReveal → String
Button that triggers re-authentication and then reveals the viewing key on the export screen.
no setter
walletExportViewingKeyRevealing → String
Loading line shown while the viewing key is being read for export.
no setter
walletExportViewingKeySecureNoteAndroid → String
Note shown on the export-viewing-key screen when screenshot blocking is active.
no setter
walletExportViewingKeySecureNoteOther → String
Note shown on the export-viewing-key screen when screenshot blocking is not available (non-Android).
no setter
walletExportViewingKeyTileSubtitle → String
Subtitle of the export-viewing-key settings tile, summarizing that the exported key is view-only.
no setter
walletExportViewingKeyTileTitle → String
Settings → Security list-tile that opens the viewing-key export screen.
no setter
walletExportViewingKeyTitle → String
App-bar title of the UFVK export screen (#397): the sanctioned surface that reveals the wallet's unified full viewing key for a watch-only or accounting use.
no setter
walletExportViewingKeyWarning → String
The #397 D9 warning copy shown on the export-viewing-key screen. Must state all four facts: (1) it reveals all history in and out, past and future; (2) it cannot spend or recover; (3) share only with someone trusted; (4) the only un-share is moving funds to a new wallet. No softening.
no setter
walletExportViewingKeyWarningWatchOnly → String
The #397 D9 warning for a WATCH-ONLY wallet exporting its own viewing key (UX-M3): identical to walletExportViewingKeyWarning but its final clause states the honest 'once shared it cannot be un-shared', since a watch-only wallet cannot 'move your funds to a new wallet' (no spending keys). Keep the same four facts, no softening.
no setter
walletGeneratingLabel → String
Busy label while the wallet seed is generated and sealed (a local step, no network).
no setter
walletHideBalance → String
Screen-reader label and tooltip of the eye button in the wallet header while amounts are SHOWN: pressing it replaces every amount with dots (FR-49 W-7; maintainer FD-6).
no setter
walletInFlightReadError → String
#308a (S2 §3.5d): shown in place of the in-flight cue (walletInFlightNote) when the in-flight-sends read FAILS, instead of the cue silently vanishing — a vanished cue reads exactly like 'nothing is mid-flight'. The read retries on its own and on every sync/resume edge, so 'Retrying' is true. It must not claim anything IS in flight (we don't know), and must keep the don't-double-pay caution by pointing at the activity list, where the payment's first leg shows as a pending transaction.
no setter
walletLoadingLabel → String
Screen-reader name of a spinner that stands alone, with no label beside it (the wallet's first load, the activity list's first load, the swap token list). S13 §2, maintainer.
no setter
walletMenuSyncNotRunningHint → String
Sub-label under the disabled Rescan / Check-older-swap-addresses menu entries: no sync pass will run, so neither op can ever finish (#405 — widened from the host policy alone to the SSOT walletSyncPassesRunProvider, which also covers a FAILED sync start). CAUSE-AGNOSTIC ON PURPOSE: 'turn syncing on in settings' is the right instruction for a host-off policy and the WRONG one for a failed start, so this states the CONDITION only; the sync badge and the start-failed notice on the same screen own the cause and its remedy. Needed because the explaining badge is occluded behind the open menu and a screen reader would otherwise hear only 'dimmed'.
no setter
walletMenuTooltip → String
Tooltip / screen-reader label for the wallet app-bar overflow menu.
no setter
walletMoveAlreadyBody → String
Body for an already-submitted move (precise: the prior submission moved the funds; never sent twice).
no setter
walletMoveAlreadyTitle → String
The one-shot proposal was already consumed (a double-tap); the funds are never sent twice.
no setter
walletMoveAutoShieldNote → String
Orange note on the move-to-transparent confirm when auto-shield is ON — without it the loop silently reverts the deliberate unshield and burns a second fee.
no setter
walletMoveBackButton → String
Return from the review screen to the amount-entry form.
no setter
walletMoveCancel → String
Dismiss the move-to-transparent sheet from the amount-entry phase.
no setter
walletMoveClose → String
Close the move-to-transparent sheet from a terminal state.
no setter
walletMoveConfirmButton → String
Confirm button that signs + broadcasts the de-shield transaction.
no setter
walletMoveCouldNotLoad → String
The own-address fetch failed or timed out; retryable.
no setter
walletMoveDeshieldBody → String
The §5.1 de-shield warning body, move-specific: the funds + the user's own t-address go public on-chain (no third-party 'recipient' framing).
no setter
walletMoveDeshieldTitle → String
The §5.1 de-shield warning title, move-specific (a self-transfer, not a payment to a third party).
no setter
walletMoveDestinationLabel → String
Label for the read-only destination — the wallet's own transparent address.
no setter
walletMoveDoneBody → String
Body for a successful de-shield broadcast.
no setter
walletMoveDoneTitle → String
Terminal success: the de-shield tx was broadcast.
no setter
walletMoveFailedTitle → String
Terminal failure: nothing was sent; the user can try again.
no setter
walletMoveLoading → String
Transient state while the wallet's own transparent address is loaded.
no setter
walletMoveMenuItem → String
Overflow-menu entry for the Send expert layer's de-shield action (the mirror of Shield).
no setter
walletMoveNothingBody → String
Honest explanation that there is no spendable shielded balance to de-shield.
no setter
walletMoveNothingCatchingUpBody → String
Variant of walletMoveNothingBody while the wallet is still catching up (#381, hardware-proven): the missing shielded balance is UNSCANNED, not unconfirmed, so the default body's 'Once funds confirm' would misattribute the cause. Hedged ('anything you've received') — it must not assert funds exist (#356-F7 precedent).
no setter
walletMoveNothingTitle → String
Shown when there is no shielded balance available to de-shield.
no setter
walletMoveOwnAddressNote → String
Honest, move-specific note: it's the user's own t-addr; the funds can be re-shielded, but the on-chain history of this move is permanent (no self-contradiction).
no setter
walletMoveOwnAddressNoteStaysPublic → String
Variant of walletMoveOwnAddressNote shown when the move leaves the public balance under the shield floor (stage S14): it drops 'You can shield these funds again later', which would be false there.
no setter
walletMovePreparing → String
Transient state while the de-shield proposal is computed (local, no network).
no setter
walletMoveRetry → String
Re-run the move after a recoverable failure.
no setter
walletMoveReviewButton → String
Button that proposes the de-shield and advances to the review screen.
no setter
walletMoveReviewTitle → String
Title of the de-shield confirmation/review screen.
no setter
walletMoveSavedBody → String
Body for a de-shield that was persisted but not yet broadcast. Same #401 R1b posture as walletSendSavedBody: already signed ⇒ the promise holds at every custody tier; pass-dependent ⇒ the render site appends walletSyncPausedMoneyNote when no sync pass will run.
no setter
walletMoveSavedTitle → String
The de-shield tx is persisted but not yet broadcast; it re-sends on a later sync (money-safe). NOT 'when you're online' — the #399 reconnect-promptness rule, folded in by #401 R1b. Mirrors walletSendSavedTitle.
no setter
walletMoveSheetSubtitle → String
Explains what move-to-transparent is for (exchange deposits that reject shielded sources).
no setter
walletMoveSheetTitle → String
Title of the move-to-transparent (de-shield to own address) sheet.
no setter
walletMoveSubmitting → String
Transient state while the de-shield tx is signed and broadcast.
no setter
walletMoveUnknownBody → String
Body for walletMoveUnknownTitle. Must never say whether funds moved. Points at Activity, where the move's real state is shown.
no setter
walletMoveUnknownTitle → String
Title of the move-to-transparent sheet's terminal when the move ran but its answer was lost (MoveOutcomeUnknown): the transaction may already be saved. Neither 'moved' nor 'nothing happened' is true. Body: walletMoveUnknownBody. Only Close is offered, never a retry.
no setter
walletMoveWalletEnded → String
Body for the defensive walletUnavailable terminal — the session dropped mid-sheet (rare).
no setter
walletNotSetUpBody → String
Honest-degradation body for the not-set-up wallet state; states the money-safety reason setup is gated. Only for builds that genuinely ship without the wallet — a failed boot wiring renders walletStartupFailed* instead (#356-F1).
no setter
walletNotSetUpTitle → String
Heading shown when no wallet is provisioned in this build.
no setter
walletNotSpendableYetLabel → String
Balance card breakdown row while the wallet is NOT synced: money the user already has, inside the balance, that cannot be spent until the sync finishes (the wallet cannot yet build what spending it needs). Not new or incoming money — never translate as 'arriving' or 'incoming'.
no setter
walletOnboardingFailedAlreadyOpen → String
Onboarding failure: the wallet's single-instance lock is held (retryable). Honest for BOTH causes — a real second window AND a transient internal straggler finishing up (the device-proven case, where no other window exists).
no setter
walletOnboardingFailedConfiguration → String
Onboarding failure: the host app supplied an invalid wallet configuration (e.g. a rejected data directory). A developer error, not a device/user condition — NON-retryable, and deliberately without an action button (a Retry here would loop the same failure; security review N1).
no setter
walletOnboardingFailedDeviceLocked → String
Onboarding failure: device locked, or the key store did not answer within the SDK's bound (retryable; a wedge clears only on restart).
no setter
walletOnboardingFailedInterruptedSetup → String
Onboarding failure: an interrupted create (remnant); retrying re-probes and resumes the repair via create (open cannot repair it). Retryable, reassuring (the sealed seed is intact).
no setter
walletOnboardingFailedNeedsRecovery → String
Onboarding failure: damaged seal / destroyed key / corrupt storage — restore is the path, not retry. Funds are recoverable from the phrase.
no setter
walletOnboardingFailedNetwork → String
Onboarding failure: a network condition during setup (retryable).
no setter
walletOnboardingFailedNoVault → String
Onboarding failure: no device key vault at all (fail-closed; permanent for this device).
no setter
walletOnboardingFailedRestoreAction → String
Primary action on the needsRecovery failure screen: clears the unreadable wallet and routes to the restore flow (#251 escape hatch).
no setter
walletOnboardingFailedStorageFull → String
Onboarding failure: out of disk space (retryable).
no setter
walletOnboardingFailedTitle → String
Heading on the onboarding failure screen.
no setter
walletOnboardingFailedUnknown → String
Onboarding failure: anything else / a forward-compat kind (retryable; the stable code rides logs).
no setter
walletOnboardingRecoverConfirmBody → String
Body of the confirm dialog: WARN the user they must have their recovery phrase in hand, then reassure funds are safe (phrase-controlled), before the irreversible force-clear.
no setter
walletOnboardingRecoverConfirmCancel → String
Cancel action in the restore-confirm dialog.
no setter
walletOnboardingRecoverConfirmTitle → String
Title of the confirm dialog before the deliberate force-clear + restore.
no setter
walletOnboardingRetry → String
Retry action shown for recoverable onboarding failures.
no setter
walletOnboardingWelcomeBody → String
Body on the wallet onboarding welcome screen; states the money-safety reason backup comes first.
no setter
walletOnboardingWelcomeTitle → String
Heading on the wallet onboarding welcome screen.
no setter
walletOpeningLabel → String
Busy label for the boot probe / open phase — usually brief, but the open lawfully waits out a transiently-held wallet lock for up to ~27.5s, so the wait must be labeled, not a mute spinner.
no setter
walletParkedAlreadyInProgress → String
The notFound outcome of the FR-23-b authorize verb (#401 R2b), split off from walletParkedRetryStale. notFound means the row is no longer QUEUED — which is EITHER gone (cancelled, completed) OR claimed by the background drain that won the race. In the claimed case the previous copy ('isn't waiting anymore') contradicted the screen itself: the same payment re-renders as PREPARING two lines above, so the user was told a visible row does not exist. The expired outcome keeps walletParkedRetryStale, where 'isn't waiting anymore' is exactly true (the row was deleted). Hedged with 'may' because the surface cannot tell the two apart; points at the two surfaces that can. NEVER invites a re-send — the funds are committed either way and a second send would pay twice.
no setter
walletParkedAuthorizeFailed → String
Snackbar when the authorize call itself threw (busy / closed wallet / the host's signing credential was unavailable). The saved payment is untouched — same reassurance shape as the other 'unchanged, try again' faults.
no setter
walletParkedAuthorizeRearmed → String
The same not-ready outcome as walletParkedAuthorizeStillWaiting, but for a row that was PAUSED when the user tapped (#400 R5). The authorization re-arms a paused row's retry budget before signing, so even when nothing is signed the row DID change: it is no longer paused, its icon and label change, the paused hint disappears and the reopen-sending prompt may vanish with it. Telling that user their payment is 'unchanged' while the row visibly re-shapes reads as a bug and is simply untrue — so state the re-arm, which is what actually happened. THE SIXTH QUEUE-DRAIN STRING (#403 R3): the previous ending, 'it will be tried again', is the same automatic-drain promise #401 R1(a) swept from five siblings and missed here. A re-armed row is a QUEUED intent, so a background retry needs a sync pass AND a signing credential, and at host custody the unattended pass holds neither. It is the ONLY member of that family a user reaches BY TAPPING THE MONEY BUTTON, and it lands on top of a section whose own note may say these do not send on their own — a promise and its negation four lines apart about one payment. Same rule as walletSendQueuedBody / walletSendQueueHint: promise NO schedule, name the two real actions. Both are on screen by construction here (the re-arm leaves the row Queued, so it renders Send now and Cancel). 'Send now' must match walletParkedSendNow verbatim.
no setter
walletParkedAuthorizeSent → String
Snackbar after a parked send was signed in the authorization bracket (FR-23-b): it is now a real transaction on its way. It leaves the pending-payments list and appears in activity. Present progressive on purpose — reaching the network is still in progress. Used when a sync pass WILL run (walletSyncPassesRunProvider); otherwise — host policy off OR a failed sync start — use walletParkedAuthorizeSentSyncPaused (#407 R10d: this line said 'the host's sync policy is ON', which stopped being the gate at #401 R5).
no setter
walletParkedAuthorizeSentSyncPaused → String
The signed-outcome snackbar when NO background sync pass will run (#400 R1, the reliability HIGH; re-keyed by #401 R5). The transaction is signed and the wallet is broadcasting it — but if the broadcast never reaches the network, the wallet's durable re-send only runs on a completed sync pass: without passes the payment would sit signed and unsent with no correction. So the plain 'Sending your payment now.' is not the whole truth here. Renamed from ...SyncOff and made cause-agnostic because it is keyed on the sync DRIVE: a FAILED sync start strands the residual exactly as the host's sync-off policy does, and 'turn syncing back on' is the wrong instruction for it — the screen's own sync notice carries the remedy either way. Never phrase it as a failure (nothing failed) and never invite re-entering the payment — the funds are already committed and a second send would pay twice.
no setter
walletParkedAuthorizeStillWaiting → String
Snackbar when the authorization signed NOTHING and the payment stays saved (not enough spendable balance at this moment, a full one-time-address window, or the wallet's own background pass claimed the row first). MONEY-CRITICAL COPY RULE: this is NOT a failure — never translate it as one. A user who believes the payment failed re-enters it and BOTH send: a double pay. Deliberately promises no retry timing (background retries ride sync passes, which a host may have turned off). Only for a row that was NOT paused — see walletParkedAuthorizeRearmed.
no setter
walletParkedBlockedByNetworkUpgrade → String
Parked-send row detail when ParkedSend.signingBlock is SigningBlock.networkUpgrade — and ONLY then (GRACE-1 §4p G-6): the drain will not sign this row until the app is updated. MUST NOT say 'will send when ready' (it will not, on this version) and MUST NOT say 'failed' (the money is untouched and the intent is intact). Cancel stays offered; retry does not, since retrying changes nothing until the app is updated. A server that merely stopped reporting its network is walletParkedBlockedByServerSilent, never this.
no setter
walletParkedBlockedByServerSilent → String
Parked-send row detail when ParkedSend.signingBlock is SigningBlock.graceExpired (GRACE-1 §4p): this server will not say which network it is on and the wallet's grace for it has run out (or never began), so the drain will not sign this row until a server that reports its network is used. The next step is SWITCH SERVERS. MUST NOT say 'upgraded' or 'update the app' (nothing was upgraded and an update fixes nothing — that is walletParkedBlockedByNetworkUpgrade), MUST NOT say 'will send when ready' and MUST NOT say 'failed'. Cancel stays offered; retry does not.
no setter
walletParkedBlockedByServerSilentClock → String
walletParkedBlockedByServerSilent's variant when the grace ran out on the DEVICE CLOCK (GraceExpiry.clock). The next step is the SAME as the sibling's — a server that reports the network version — and the device clock is a PRECONDITION of it, never an alternative to it (§4p-run fold review row 6, §4r U-5): a corrected clock alone re-permits nothing (the latch holds until a branch-reporting server), so the copy MUST read 'if the date and time are wrong, fix them FIRST — then switch' and MUST NOT read 'switch servers, OR check the date and time'. Same prohibitions as the sibling: never 'upgraded', 'update the app', 'will send when ready' or 'failed'.
no setter
walletParkedCancel → String
Per-row button to cancel (discard) a parked send. The safe counter-affordance — never a re-send.
no setter
walletParkedCancelAlreadySending → String
Snackbar when cancel returned false. The SDK can't yet distinguish 'already gone' from 'began sending', so the copy is hedged ('may') — honest in BOTH cases. NEVER present as cancelled; never invite a re-send — direct the user to the activity list (double-pay safety).
no setter
walletParkedCancelConfirmBody → String
Body of the cancel-parked confirm dialog. Reassures that a queued (not-yet-sent) send moves no funds, while flagging the action is irreversible.
no setter
walletParkedCancelConfirmDiscard → String
Cancel-parked confirm dialog: the irreversible confirm that discards the queued send.
no setter
walletParkedCancelConfirmKeep → String
Cancel-parked confirm dialog: keep the pending payment (dismiss the dialog).
no setter
walletParkedCancelConfirmTitle → String
Title of the confirm dialog before discarding a parked send.
no setter
walletParkedCancelDone → String
Snackbar after a parked send was successfully cancelled.
no setter
walletParkedCancelFailed → String
Snackbar when the cancel call threw (e.g. wallet busy / closed). The queued send is untouched.
no setter
walletParkedError → String
Honest error line when the parked-sends read fails. The surface is shown (not silently hidden) because a parked send is money the user is waiting on.
no setter
walletParkedErrorRetry → String
Inline retry button under the parked-sends read-error line: re-pulls the pending-payments list in place (the home has no pull-to-refresh). SECTION-level, not row-level: the per-row affordance is walletParkedSendNow, which signs one saved payment (#401 R7c — this line named walletParkedRetry, retired by #400). Same 'try again' wording as the other read-error retries (walletReceiveRetry, walletShieldRetry).
no setter
walletParkedErrorRetryInProgress → String
The parked-sends read-error retry button's label WHILE the re-pull is in flight (#407 R5). Load-bearing for a11y, not decoration: the surrounding Semantics(liveRegion:) is flagged on THIS label, so the label CHANGING is what re-fires the announcement when the identical error re-lands. The pre-#407 shape flagged an outer container whose SemanticsData was byte-identical across the flip — measured, it never re-announced, while the code comment claimed it did. Same shape as walletParkedSendNowInProgress. Keep it SHORT — it replaces 'Try again' inside a button beside a spinner.
no setter
walletParkedPausedHint → String
Hint line under a PAUSED parked-send row (#315): the wallet stopped auto-retrying (each retry of a one-time-address send permanently uses up one of a small number of address slots). Must state (a) it will NOT send by itself, (b) funds are safe, (c) the two actions THAT ARE ON SCREEN. #400 R3: the old text said 'Retry it or cancel it' and rendered directly above a button labelled 'Send now' — since FR-23-b that one button both re-arms the row AND signs it, and the separate Retry button no longer exists. Name the visible buttons verbatim (walletParkedSendNow, walletParkedCancel). Never 'will send when ready'.
no setter
walletParkedPreparingHint → String
Hint line under a MID-SIGNATURE parked row (#400 R2) when a sync pass WILL run (walletSyncPassesRunProvider — #407 R10d corrected this line, which still said 'the host's sync policy is ON' after #401 R5 / #403 R4 re-keyed the site onto the drive-aware SSOT; a FAILED sync start reads policy-ON and runs no passes). Must state (a) work is in progress, (b) the amount may ALREADY be out of the spendable balance — unlike every other row in this section, whose amount is an earmark over the balance, this row can be past the point where the wallet committed the transaction locally and marked its notes spent, so the section's 'their amounts are still part of your balance' is not true of it — (c) funds are safe, (d) it self-recovers: the wallet re-queues an unfinished claim on its next completed sync pass, so the user has nothing to do and must NOT re-enter the payment. Deliberately unspecific about WHEN. Normally NO action is offered on this row (every verb that could act on it requires a still-queued row), so the copy must not name one — with ONE exception (#403 R9e, correcting a claim this file stated absolutely): while the user's OWN authorization bracket is what claimed the row, the section keeps rendering its spinnered Send now, because deleting the cue mid-proof is the dead-app shape the cue exists to prevent. When no pass will run — host policy off OR a failed start — use walletParkedPreparingHintSyncPaused.
no setter
walletParkedPreparingHintSyncPaused → String
The MID-SIGNATURE row's hint when NO background sync pass will run (#400 R2, re-keyed by #401 R5). Its sibling promises the row 'returns to the list on its own' — true only where sync passes happen, because that self-recovery IS a sync pass. Without passes the row sits there indefinitely and a user told to wait for a self-heal that cannot come re-enters the payment: the double pay this whole section exists to prevent. Renamed from ...SyncOff because it is keyed on the sync DRIVE, not the host policy: a FAILED sync start has the same consequence and 'turn syncing back on' would be the wrong instruction there — so the promise is replaced by a cause-agnostic condition and the screen's own notice carries the remedy. Keep the same first two clauses as the sibling (work in progress; the amount may already be set aside; funds safe). Never phrase it as a failure — nothing failed.
no setter
walletParkedRetryStale → String
Snackbar when retry returned false (the row is gone / began sending / changed). Mirrors the cancel-false contract: never invite a re-send; point at the surfaces.
no setter
walletParkedSendNow → String
Per-row button on a parked send (FR-23-b, #361): sign and send the already-saved payment now, instead of waiting for the wallet's next background pass. A host that authorizes each spend individually prompts here. ONE LABEL FOR BOTH ROW STATES — healthy AND paused (#361 M4): on a paused row it re-arms the retry budget and signs, so it does strictly MORE than on a healthy row and 'Retry' understated it. (The description previously said 'HEALTHY (not paused)' and 'a paused row shows walletParkedRetry instead'; that Retry key is retired — #400 R9 corrects the drift.) Not shown on a row that is already mid-signature (ParkedSend.sending).
no setter
walletParkedSendNowInProgress → String
The Send now button's label while the authorization is in flight (#400 R4): the button is disabled and shows a spinner. Load-bearing, not decoration — at held custody there is no host prompt to look at, and the call runs an unbounded proving step (tens of seconds on a fragmented wallet), so without a cue the user sees a dead button and taps elsewhere or re-enters the payment. Mirrors walletReclaimInProgress.
no setter
walletParkedSubtitle → String
Sub-heading for the parked-sends section. Deliberately NEUTRAL about whether a row will send on its own (#315): a healthy row sends when ready, a PAUSED row never sends until the user retries — the per-row copy carries that split, so this shared line must be true for both. The amounts are an earmark over the balance (still spendable), never added on top nor deducted. Never invite a re-send.
no setter
walletParkedSubtitlePreparing → String
The parked-sends sub-heading when AT LEAST ONE row is mid-signature (#401 R2a). The plain sibling asserts the earmark unconditionally — 'their amounts are still part of your balance' — and that is FALSE for a claimed row: past the engine's create the notes are already locally spent, so the amount has left the spendable set. THE OPENER MUST STAY NEUTRAL (#407 R6 reverted #401 R8a's change to it): this heading renders over the WHOLE section whenever ANY row is sending, and that list may also hold PAUSED rows that never send on their own — 'haven't finished sending' told those users progress was underway and invited them to WAIT instead of tapping Send now, the abandoned-funds harm the paused copy exists to prevent. The progress claim belongs in the except-clause, scoped to the rows it is true of.
no setter
walletParkedSyncPausedNote → String
The parked-sends pause note, replacing the shared walletSyncPausedMoneyNote on THIS surface (#401 R2d + R5). Two changes. (1) It names the ESCAPE: the shared note says only 'paused', and it sits directly above a Send now button that #400 R9 deliberately left working at every custody tier — a user who reads 'paused' and stops looking has abandoned funds they could release with one tap. (2) It is CAUSE-AGNOSTIC and keyed on the sync DRIVE, not the host policy: a failed sync start freezes the queue exactly as a sync-off policy does, and 'in this app's settings' is the wrong instruction for it — the screen's own sync notice carries whichever remedy applies. RENDERED ONLY WHILE THAT ESCAPE EXISTS (#403 R2): Send now is suppressed on a mid-signature row, so a section whose rows are ALL mid-signature falls back to the affordance-free walletSyncPausedMoneyNote instead — a note naming a control that is not on screen is worse than the plain pause it replaced. 'Send now' must match walletParkedSendNow verbatim. Two full standalone sentences; never claims failure.
no setter
walletParkedTitle → String
Heading above the parked-sends section: EVERY queued send that has no on-chain transaction yet and so doesn't appear in the activity list — one-time-address (TEX) sends awaiting their window AND plainly-queued offline sends (#331). The copy is deliberately shape-agnostic; keep it honest for both.
no setter
walletPendingChangeLabel → String
Label for our own change in flight (normal right after a send); shown so the breakdown reconciles to the total.
no setter
walletPoolAllShielded → String
Balance-card pool-clarity line (#389) when the transparent balance is zero: a positive affirmation that EVERY coin is in the shielded (private) pool. Always-on so an all-private wallet gets explicit reassurance, not merely the absence of a transparent line. The '·' (U+00B7 middot) separates the two clauses; keep a real middot with a space on each side. 'shielded' and 'private' as elsewhere on the card.
no setter
walletPoolIronwood → String
The Ironwood shielded pool's name (NU6.3), as the {pool} placeholder of the walletSyncPool* lines. A proper noun: keep it in Latin script unless the locale's Zcash community writes it otherwise.
no setter
walletPoolOrchard → String
The Orchard shielded pool's name, as the {pool} placeholder of the walletSyncPool* lines. A proper noun: keep it in Latin script unless the locale's Zcash community writes it otherwise.
no setter
walletPoolSapling → String
The Sapling shielded pool's name, as the {pool} placeholder of the walletSyncPool* lines. A proper noun: keep it in Latin script unless the locale's Zcash community writes it otherwise.
no setter
walletPoolTapHint → String
Screen-reader tap hint (#389) for the balance-card pool line: read after the button role as 'double tap to
no setter
walletReceive → String
Wallet-surface button + receive screen title.
no setter
walletReceiveCopied → String
Receive screen: snackbar confirmation after copying the address.
no setter
walletReceiveCopy → String
Receive screen: copy-to-clipboard button label.
no setter
walletReceiveError → String
Receive screen: address lookup failed; paired with a Try again button.
no setter
walletReceiveFreshAddress → String
Receive screen (shielded tab): button that mints a fresh diversified address — a new unlinkable address for a contact or invoice that still pays into this wallet.
no setter
walletReceiveFreshBusy → String
Receive screen: snackbar when the fresh-address mint timed out because the wallet is briefly busy (e.g. signing a payment); a retry normally succeeds.
no setter
walletReceiveFreshCaption → String
Receive screen: note shown with a freshly minted diversified address. Must convey all four facts: unlinkable; funds arrive in this wallet; earlier addresses stay valid; the display is one-time (copy before leaving).
no setter
walletReceiveFreshCopyNow → String
Receive screen: the fresh-address note's on-screen state, the last sentence of walletReceiveFreshCaption verbatim; the whole caption moved behind the note's (i) (S13 §1.7: the 'copy it now' state stays on screen).
no setter
walletReceiveFreshError → String
Receive screen: snackbar shown when minting a fresh diversified address fails; the previous address stays on screen.
no setter
walletReceivePreparing → String
Receive screen: honest loading headline while the address derivation is in flight (replaces a bare spinner).
no setter
walletReceivePreparingHint → String
Receive screen: reassuring sub-line under the loading headline. CAUSE-HONEST since #385 (E2E-1): the derivation is LOCAL — the old 'catches up with the network' blamed the network on a fully-synced wallet; the honest cause is the derive queueing behind other wallet work (a heavy sync being one example, not the only one). Avoids 'first sync' since a restore also hits this on a fresh device.
no setter
walletReceiveQrLabel → String
Receive screen: accessibility label for the address QR image.
no setter
walletReceiveQrLabelTransparent → String
Receive screen: accessibility label for the transparent address QR image.
no setter
walletReceiveRequestAmount → String
Receive screen: button that opens the optional amount field; with an amount, the QR, Copy and Share carry a payment request for it (S13, maintainer).
no setter
walletReceiveRequestAmountLabel → String
Receive screen: label of the requested-amount field, in ZEC (S13, maintainer).
no setter
walletReceiveRetry → String
Receive screen: button that re-attempts the address load after a failure.
no setter
walletReceiveShare → String
Receive screen: button that opens the host's share sheet with the address, or the payment request when an amount is set (S13, maintainer). Shown only when the host supplies a share hook.
no setter
walletReceiveSubtitle → String
Receive screen: explains the address is public and shareable.
no setter
walletReceiveSubtitleTransparent → String
Receive screen: subtitle shown when the transparent address is selected.
no setter
walletReceiveTransparentWarning → String
Receive screen: the honest public-address warning shown above the transparent receive address.
no setter
walletReceiveTypeShielded → String
Receive screen: the address-type toggle segment for the private shielded address (the default).
no setter
walletReceiveTypeTransparent → String
Receive screen: the address-type toggle segment for the public transparent address.
no setter
walletReceiveUnavailable → String
Receive screen: shown when there is no live wallet session.
no setter
walletReclaimButton → String
The account-level button that runs the #315 reclaim (reopen a bricked one-time-address send window). Shown only when a send is paused.
no setter
walletReclaimConfirmAction → String
Confirm the reclaim (proceed to authorize + run it).
no setter
walletReclaimConfirmBody → String
Body of the reclaim confirm dialog — the honest-cost disclosure. Must state: the amount is your own and returns; the real cost is a couple of network fees; the moved amount is recovered via the existing action once it confirms. Never imply the funds are lost, and never promise the window reopens instantly. #400 R3: the action is named 'Recover now' (walletRecoverNow) — the old 'Recover funds' was never a button label anywhere in the app.
no setter
walletReclaimConfirmCancel → String
Dismiss the reclaim confirm dialog without acting.
no setter
walletReclaimConfirmTitle → String
Title of the honest-cost disclosure dialog shown before the #315 reclaim runs.
no setter
walletReclaimExplainer → String
#315 slice 2: the line above the 'Reopen sending' button, shown under the parked list when a send is paused. Explains that reopening moves a small amount (your own, returned) — never a fee-only framing that hides the round-trip.
no setter
walletReclaimFailed → String
Snackbar when the reclaim threw a typed error (e.g. seed required / busy / closed handle). The funds are untouched and it is retryable.
no setter
walletReclaimInProgress → String
The reclaim button's label while the reclaim is in flight (button disabled + spinner).
no setter
walletReclaimNeedsFunds → String
Snackbar when the reclaim failed because the shielded balance can't fund the small self-mint (InsufficientFunds).
no setter
walletReclaimNotBroadcast → String
Snackbar when the reclaim mint's broadcast was not acknowledged (ReclaimOutcome.NotBroadcast). Money-safe, but do NOT claim 'nothing was moved': a lost acknowledgement can mean the mint actually landed. Honest about that ambiguity and paces the retry so a rapid re-tap can't double-mint (an extra fee). The principal always returns via the sweep.
no setter
walletReclaimNothing → String
Snackbar when the reclaim found no abandoned reservation to reclaim (ReclaimOutcome.NothingToReclaim) — the window is transient / already clear. No money moved.
no setter
walletReclaimStarted → String
Snackbar after a successful reclaim mint (ReclaimOutcome.Minted). It is INITIATED, not done: the window reopens once the mint confirms (a few minutes) — never claim it is already working. Names the TWO manual follow-ups the user must still do so the flow is not a dead-end. #400 R3: BOTH names were wrong — 'retry the paused send' pointed at a Retry button that FR-23-b replaced with walletParkedSendNow, and 'Recover funds' was never the button's label (it is walletRecoverNow, 'Recover now' — 15 locales had already translated the correct label; EN was the outlier). Every affordance named here must match the visible button label verbatim.
no setter
walletReclaimUnknown → String
Neutral snackbar for a forward-compat reclaim outcome the app does not recognise (ReclaimOutcome.Unknown, only under core/bridge version skew). Never claim success or failure: state it finished and point to the sends + the recover action. Hedge with 'any' since whether an amount moved is unknown. #400 R3: the action is 'Recover now' (walletRecoverNow), matching the visible button.
no setter
walletRecoverConfirmAction → String
Recover confirm dialog: the confirm action that runs the recovery.
no setter
walletRecoverConfirmBody → String
Body of the recover confirm dialog. The action is privacy-positive (into shielded) and idempotent (re-runnable).
no setter
walletRecoverConfirmCancel → String
Recover confirm dialog: dismiss without recovering.
no setter
walletRecoverConfirmTitle → String
Title of the confirm dialog before running the one-time-address recovery (sweep).
no setter
walletRecoverFailed → String
Snackbar when the recovery call threw (e.g. seed required / closed handle). The funds are untouched and re-runnable.
no setter
walletRecoverInProgress → String
The recover button's DISABLED in-progress label while a sweep signs + broadcasts per address (it can take a moment on a slow link). Doubles as the single-flight in-progress cue, so a re-tap can't launch a second concurrent sweep.
no setter
walletRecoverNothing → String
Snackbar when recovery found nothing sweepable (e.g. already recovered on a prior run).
no setter
walletRecoverNow → String
Button to recover funds sitting on one-time (ephemeral) transparent addresses into the shielded balance. Shown only when a successful read reports recoverable funds.
no setter
walletRecoverRetry → String
Snackbar when recovery had per-address faults or hit the per-run cap. The funds stay on-chain and re-runnable — never a loss.
no setter
walletRecoverTruncated → String
Sweep outcome when the per-invocation cap left addresses UNCHECKED and nothing was swept or failed — honest 'incomplete check', never a claim that funds exist (distinct from walletRecoverRetry, which is for per-address faults).
no setter
walletRescanBlockedSettlingNotice → String
Cue shown when the SDK refused a rescan because a broadcast send has not settled yet (rebuilding under it could double-pay); resolution takes hours of online sync.
no setter
walletRescanBlockedSyncNotRunningNotice → String
Rescan refusal notice (#405): the commit-point fence turned the confirm away because no sync pass will run (host policy off OR a failed sync start), so the wipe would strand a zeroed wallet behind a rebuild that cannot execute. Nothing destructive ran, which is why this is the one rescan refusal entitled to say 'your wallet is unchanged' outright (#379 softened walletRescanFailedNotice because a post-rename fault leaves a REBUILT wallet). CAUSE-AGNOSTIC — the badge and the start-failed notice above it carry the cause and the way out.
no setter
walletRescanBody → String
Body of the rescan sheet: what rescan does + the money-safety reassurance.
no setter
walletRescanCancel → String
Dismiss the rescan sheet without rescanning.
no setter
walletRescanChange → String
Button to change an already-chosen rescan start date.
no setter
walletRescanConfirm → String
Confirm button that starts the rescan.
no setter
walletRescanDatePick → String
Help text on the rescan date picker dialog.
no setter
walletRescanFailedDismiss → String
Dismiss the rescan-failed cue.
no setter
walletRescanFailedNotice → String
Honest cue shown when a rescan failed but the wallet was recovered by re-opening. Claims funds-safety only, never 'unchanged' (#379): a fault AFTER the rebuild's atomic rename recovers into the REBUILT lower-birthday wallet, whose balance/history repopulate via the auto-restarted sync.
no setter
walletRescanMenuItem → String
Wallet app-bar overflow-menu item that opens the rescan-recovery sheet.
no setter
walletRescanNeedsSpaceNotice → String
Cue shown when a rescan failed because the device is out of disk space; retrying without freeing space will fail again, so the copy asks for space instead of a retry. Claims funds-safety only, never 'unchanged' (#379): a DiskFull after the rebuild's atomic rename recovers into the REBUILT lower-birthday wallet.
no setter
walletRescanPick → String
Button to choose a rescan start date.
no setter
walletRescanRangeAll → String
Description shown when the rescan will scan the full history (no date).
no setter
walletRescanRangeDefault → String
Description of the DEFAULT rescan range when it is the wallet's own birthday (a wallet younger than a year, where scanning earlier would only cover empty pre-wallet blocks). Does NOT claim completeness of the USER's funds — a too-high restore birthday can leave real deposits below this floor — so it points the recovery user at the earlier-date / scan-all escape hatch (the same nudge the chosen-date arm carries).
no setter
walletRescanRangeResolving → String
Transient description while the wallet's scan-floor read is in flight (sub-millisecond normally; up to the FFI timeout on a wedged bridge). Pick-a-date and Scan-all stay available; only Start waits.
no setter
walletRescanRangeTitle → String
Heading of the date-range control in the rescan sheet.
no setter
walletRescanRebuildingAll → String
Activity-section cue while a full-history rescan repopulates.
no setter
walletRescanRebuildingDefault → String
Activity-section cue while the default rescan (from the wallet's own birthday) repopulates.
no setter
walletRescanRunning → String
Label while the rescan rebuild FFI call is in progress.
no setter
walletRescanScanAll → String
Button to clear the rescan start date and scan the full history.
no setter
walletRescanSettlingAdvisory → String
Rescan sheet advisory shown while in-flight sends exist (#364 M3): the engine's settling-send fence will likely refuse the rescan, and the refusal costs a full quiesce — say so BEFORE Start. Advisory only; the engine stays authoritative, so the copy must hedge ('usually', 'expect') and never promise refusal.
no setter
walletRescanSwapPointer → String
#390 cross-pointer on the Rescan sheet: a rescan re-scans compact blocks (no transparent outputs) and keeps the restore ceiling, so it cannot surface old-swap funds; point the affected user at the deep scan.
no setter
walletRescanTitle → String
Title of the rescan-recovery confirm sheet.
no setter
walletRescanWarning → String
Honest expectation-setting note in the rescan sheet — the duration scales with how far back the chosen date reaches (the ~1-year default measured hours on emulator-class hardware, so 'a few minutes' over-promised).
no setter
walletRestoreBack → String
Secondary action on the restore screen: return to the welcome screen.
no setter
walletRestoreBirthdayChange → String
Action to change an already-chosen creation date.
no setter
walletRestoreBirthdayClear → String
Action to clear the chosen creation date and scan the whole chain instead (money-safe, slower).
no setter
walletRestoreBirthdayNone → String
Shown when the user chose a full scan (no date): money-safe but slower.
no setter
walletRestoreBirthdayPick → String
Action to choose the approximate wallet-creation date.
no setter
walletRestoreBirthdayTitle → String
Heading of the restore starting-point (wallet-creation date) control.
no setter
walletRestoreBody → String
Body on the restore screen explaining what to enter, with an honest note that passphrase-protected ('25th word') wallets can't be imported (a wrong/absent passphrase silently restores a different, empty wallet).
no setter
walletRestoreButton → String
Secondary action on the welcome screen: restore an existing wallet from its recovery phrase.
no setter
walletRestoreFaultAlreadyExists → String
Inline restore error when a completed wallet is already provisioned here.
no setter
walletRestoreFaultBirthdayTooRecent → String
Inline restore error when the chosen creation date is past the chain tip.
no setter
walletRestoreFaultInvalidPhrase → String
Inline restore error when the phrase fails validation with no single offending word (e.g. a checksum failure).
no setter
walletRestoreFaultSeedMismatch → String
Inline restore error when a different phrase is supplied over an interrupted-create remnant.
no setter
walletRestoreLengthHint → String
Hint shown beside the word count when it isn't yet a valid phrase length.
no setter
walletRestorePhraseHint → String
Placeholder hint inside the recovery-phrase field, showing words are space-separated.
no setter
walletRestoreSubmit → String
Primary action on the restore screen: validate the phrase and restore the wallet.
no setter
walletRestoreTitle → String
Heading on the restore (recovery-phrase entry) screen.
no setter
walletScanOpenSettings → String
Scanner, camera refused: opens the app's system settings through the host (S13, maintainer).
no setter
walletScanOpenSettingsFailed → String
Scanner, camera refused: the host's settings opener failed (maintainer).
no setter
walletSecurityMenuItem → String
Wallet overflow menu: opens the Security screen (key custody + delete wallet).
no setter
walletSendAlreadyBody → String
Result body for a re-consumed proposal token (no double-spend).
no setter
walletSendAlreadyTitle → String
Result: the one-shot proposal was already consumed (double-tap).
no setter
walletSendAmountHint → String
Placeholder for the amount field.
no setter
walletSendAmountLabel → String
Label for the amount field.
no setter
walletSendAnother → String
Return to a fresh form after a completed send.
no setter
walletSendBackButton → String
Confirm-screen action that returns to the editable form.
no setter
walletSendButton → String
Entry button on the active wallet surface that opens the send flow.
no setter
walletSendChangeLabel → String
Confirm line: change returned to the wallet (informational).
no setter
walletSendConfirmButton → String
Confirm-screen action that signs + broadcasts.
no setter
walletSendDeshieldBody → String
§5.1 de-shield disclosure body — honest about the public, linkable de-shield.
no setter
walletSendDeshieldTitle → String
§5.1 de-shield disclosure heading: a transparent recipient makes the payment public.
no setter
walletSendDone → String
Leave the send screen after a completed/queued send.
no setter
walletSendExpiredBody → String
Body for walletSendExpiredTitle. States the limit the user hit (the five-second mount grace — keep the number in step with WalletSendEntry's grace if it is ever re-priced), why the wallet refuses (the app already holds a final "nothing was sent" for this request, and paying under it would put a payment on chain with no record of it in the app), and the ONE next step. Never promises the wallet will pay it later; nothing was signed.
no setter
walletSendExpiredTitle → String
Full-screen title when a send screen opened by the app's own entry point (WalletSendEntry.push) appears AFTER the entry's mount grace ran out (stage S8 deadline, R05). The app was already told that nothing was sent, and that answer is final for this request: the screen offers no form and no way to pay it. Terminal, not transient — the user starts again from the app.
no setter
walletSendFailedBody → String
Result body for a sign/build failure (re-propose needed).
no setter
walletSendFailedTitle → String
Result: signing/build failed; no money moved.
no setter
walletSendFaultAddressInvalid → String
Form fault: the recipient address failed to parse.
no setter
walletSendFaultAmountDecimals → String
Form fault: more than 8 fractional digits.
no setter
walletSendFaultAmountEmpty → String
Form fault: the amount field is empty.
no setter
walletSendFaultAmountNotANumber → String
Form fault: the amount isn't a plain decimal number.
no setter
walletSendFaultAmountNotPositive → String
Form fault: the amount parses to zero.
no setter
walletSendFaultAmountOutOfRange → String
Form fault: the amount exceeds max money.
no setter
walletSendFaultAmountsExpired → String
Form fault on the SEND path: the reviewed proposal's anchor went stale between confirm and send (the wallet IS synced; the numbers aged out) — re-propose for fresh figures. Distinct from walletSendFaultNotSynced (the propose-path not-anchorable case).
no setter
walletSendFaultCouldNotPrepare → String
Form fault: a prepare failure with no finer mapping that is DETERMINISTIC on the input (retrying unchanged re-fails), so the honest next step is to check the details. The retryable class has its own key, walletSendFaultCouldNotPrepareTransient — never render this one for it (INC-018 (b)).
no setter
walletSendFaultCouldNotPrepareTransient → String
Form fault: a prepare failure the wallet's OWN state will clear without the user changing anything — a note whose witness the scan has not completed, an anchor not yet recorded, an input a concurrent proposal holds (WalletErrorKind.proposeTransient, INC-018 (b), phase-2 P2-2, maintainer decision 4). MUST NOT say 'check the details': on the device proof the details were correct and the identical send prepared fine two minutes later. 'Just now' + 'in a moment' — a short wait, not a sync-length one (that is walletSendFaultNotSynced).
no setter
walletSendFaultInsufficientCatchingUp → String
Form fault detail under the insufficient-funds message while the wallet is still catching up (#381): the 'you have X' figure is the partial repopulating balance, not a final verdict. Hedged ('may') — it must not promise funds exist.
no setter
walletSendFaultMemoConflict → String
Form fault: the app supplied BOTH a text memo and machine bytes on one payment. A programming error, not a user mistake — the copy must not tell the user to fix or remove their memo, and must say plainly that no money moved.
no setter
walletSendFaultMemoNotSendable → String
Form fault: a reserved/invalid memo.
no setter
walletSendFaultMemoTooLong → String
Form fault: the memo exceeds its length bound.
no setter
walletSendFaultMemoToTransparent → String
Form fault: a memo was given to a transparent recipient.
no setter
walletSendFaultNetworkMismatch → String
Form fault: the address belongs to the other Zcash network.
no setter
walletSendFaultNetworkUpgrade → String
Send fault body under the shared walletSendFailedTitle, for RW-SYNC-002 (networkUpgradeUnsupported): the network is running consensus rules this app version cannot build a valid transaction for, so signing is refused before any proving time is spent. MUST NOT blame the user, MUST NOT imply funds are at risk (they are untouched), MUST NOT promise a timeline we do not control, and MUST NOT promise that receiving still works (INC-016: a build that predates the upgrade can be blind to incoming payments as well). Never shown for a wallet that is merely behind on sync — that is walletSendFaultInsufficientCatchingUp.
no setter
walletSendFaultNotSynced → String
Form fault: not anchorable yet (proposal stale) — offers the queue path. Shown ONLY where the queue affordance actually renders; otherwise walletSendFaultNotSyncedNoQueue.
no setter
walletSendFaultNotSyncedNoQueue → String
The same not-anchorable fault WITHOUT the queue invitation — for surfaces with no offline-queue affordance (the move-to-transparent sheet always; the send form when the host's custody disables the queue, #327). Must stay walletSendFaultNotSynced with ONLY its trailing ', or queue this to send later' clause removed (grammar-mandated closes allowed, e.g. ja 待つ→待ってください) so the two never drift.
no setter
walletSendFaultNotSyncedSyncNotRunning → String
The not-anchorable send fault when no sync pass will run (#405 → the SSOT, so a FAILED start no longer falls through to 'wait for sync to catch up'). The queue clause is gated off by the host policy separately. CAUSE-AGNOSTIC and points at the wallet screen's sync status rather than naming one cause's remedy — the send screen has no ambient badge of its own.
no setter
walletSendFaultOneTimeAddressLimit → String
Send fault: the one-time (ephemeral) address gap-limit ceiling for a multi-step (TEX) send. DUAL-NATURED (#315): slots held by confirming transfers free up on their own; slots used up by sends that never confirmed do NOT — so the copy must promise neither 'just wait' nor doom. Routed back to the form (orange-transient), never the red dead-end.
no setter
walletSendFaultQueueFull → String
Form fault: the durable offline-send queue is at capacity.
no setter
walletSendFaultStorageFull → String
Send fault: the device is out of disk space, so persisting the send hit DiskFull (#373). Retrying without freeing space fails again, so the copy asks for space instead of a plain retry. Funds are untouched — nothing was written or broadcast. Sibling of walletRescanNeedsSpaceNotice and walletOnboardingFailedStorageFull.
no setter
walletSendFaultUriInvalid → String
Form fault: the composed payment URI was rejected.
no setter
walletSendFaultWalletBusy → String
Form fault: the wallet is mid-lifecycle (busy/closing).
no setter
walletSendFaultWatchOnly → String
Inline send-form fault when a watch-only wallet somehow reaches propose/send (defense-in-depth; the SDK refuses the spend).
no setter
walletSendFeeLabel → String
Confirm line: the ZIP-317 fee.
no setter
walletSendInMotionBody → String
Honest in-motion body for a partial TEX two-step send. Must NOT promise auto-completion (the forwarding step can expire into a recoverable strand); only the permanently-true 'don't re-send' plus pointing at the shipped wallet-screen recovery.
no setter
walletSendInMotionTitle → String
Result title for a TEX two-step send with some but not all legs accepted (either order) — funds are in motion on a wallet-controlled one-time address.
no setter
walletSendKeptBody → String
Result body for walletSendKeptTitle. Deliberately makes NO claim either way about automatic sending: it is shown both when the wallet reported a held state (a swap deposit past its quote) and when the reading could not be taken, and must be true in both. Points at Activity, where TxSummary.delivery is rendered.
no setter
walletSendKeptTitle → String
Result: a transaction was signed and kept, but the wallet did NOT report that it will retry it on its own (stage S8 obligation, row 10 — the core's per-transaction delivery state was not retry-pending, or could not be read). No promise of automatic sending; Activity shows the live state. Shared by the send, shield and move result surfaces.
no setter
walletSendLargeConfirmBoth → String
Large-send dialog body when both the relative and absolute large-amount triggers fired (both, and the forward-compat unknown arm).
no setter
walletSendLargeConfirmCancel → String
The cancel action in the large-send dialog — returns to the confirm screen without sending.
no setter
walletSendLargeConfirmNearTotal → String
Large-send dialog body when the amount is a high fraction of the available balance (nearTotalBalance).
no setter
walletSendLargeConfirmOverThreshold → String
Large-send dialog body when the amount is over the absolute large-amount threshold (overAbsoluteThreshold).
no setter
walletSendLargeConfirmTitle → String
Title of the deliberate large-amount confirmation dialog shown before signing when the proposal trips the money-safety check.
no setter
walletSendLeaveBody → String
Dialog body for walletSendLeaveTitle (S13 H2, maintainer).
no setter
walletSendLeaveConfirm → String
Dialog action: leave the send screen; sending continues (S13 H2, maintainer).
no setter
walletSendLeaveStay → String
Dialog action: stay on the send screen (S13 H2, maintainer).
no setter
walletSendLeaveTitle → String
Dialog title when the user presses Back while a payment is being sent (S13 H2, maintainer).
no setter
walletSendMachineMemoLimit → String
The honest limit under the machine-memo disclosure: a purpose label is accountability, not verification. The wallet cannot confirm the sentence describes the bytes.
no setter
walletSendMachineMemoTitle → String
Heading of the per-send disclosure shown at the authorization step when the host attached opaque machine-memo bytes. Never shows the bytes themselves.
no setter
walletSendMemoHint → String
Helper under the memo field — memos can't go to transparent addresses.
no setter
walletSendMemoLabel → String
Label for the optional memo field.
no setter
walletSendMemoMachineDisabled → String
Note under the disabled memo field when the host attached opaque machine-memo bytes (FR-28). One memo per payment, so the written memo field is unavailable.
no setter
walletSendMemoTransparentDisabled → String
Note shown under the memo field when it is disabled because the recipient is a transparent (public) address that cannot receive a memo.
no setter
walletSendNoSpendableYet → String
Honest reason shown under a disabled Send button when the wallet is fully synced but has no spendable funds.
no setter
walletSendPartialBody → String
Result body when some (not all) pool-crossing transactions broadcast. Same #401 R1b posture as walletSendSavedBody: already signed, so the completion promise holds at every custody tier, and the render site appends walletSyncPausedMoneyNote when no sync pass will run.
no setter
walletSendPaste → String
Send form: fills the recipient from the clipboard (S13, maintainer).
no setter
walletSendPreparing → String
Busy label while proposing (local note-selection + fee).
no setter
walletSendPrivacyShielded → String
Send-review visibility statement for a fully shielded payment.
no setter
walletSendPrivacyTransparent → String
Send-review visibility statement when any output is transparent; compact restatement of the de-shield warning.
no setter
walletSendPublicAckLabel → String
Checkbox under the 'not private' warning on a payment to a transparent address, on the review and beside Queue; Send now / Queue stay disabled until it is ticked (maintainer: 'add the Send acknowledgement like Swap', this wording).
no setter
walletSendQueueButton → String
Offline-first secondary action: durably queue the send for the next online sync.
no setter
walletSendQueuedBody → String
Result body for a queued (offline-first) send. It must be true at EVERY custody tier (#400 R9): the previous 'we'll send this automatically the next time your wallet syncs online' is FALSE wherever the wallet holds no signing credential of its own — a host that authorizes each spend individually cannot sign on an unattended background pass at all, and that is exactly the host the offline queue was widened for (FR-23-b). So promise no schedule; name the surface the payment now lives on (keep the wording in step with walletParkedTitle) and the two things the user can actually do there. Never 'as soon as you're online' (the retry schedule can lag a reconnect), and never anything that invites re-entering the payment (a double pay).
no setter
walletSendQueuedTitle → String
Result: the offline send intent was durably stored.
no setter
walletSendQueueHint → String
Honest note under the queue action (#399, retold by #401 R1). NEVER asserts the user is offline (the wallet may be unsynced, or the SERVER may be the unreachable side). It also PROMISES NO SCHEDULE: the previous 'prepared and sent automatically the next time your wallet syncs online' is FALSE at host custody, where the background pass holds no signing credential at all — and that is exactly the host the queue was widened for (FR-23-b). Same rule and same wording family as walletSendQueuedBody, which the user meets ONE TAP LATER: name the surface the payment lives on and the two things they can do there. Keeps the fee-preview honesty (queuing skips it; the fee is computed at signing).
no setter
walletSendQueuing → String
Busy label while durably persisting the queued send intent.
no setter
walletSendRecipientGetsLabel → String
Send review: the amount the recipient receives, fee and change excluded (S13, maintainer).
no setter
walletSendRecipientHint → String
Placeholder for the recipient address field.
no setter
walletSendRecipientInvalid → String
Live recipient-field status: the entered text is not a parseable Zcash address.
no setter
walletSendRecipientLabel → String
Label for the recipient address field / confirm line.
no setter
walletSendRecipientLocked → String
Helper text AND screen-reader label for the recipient field when it is opened read-only (locked) by a prefilled request (from a scanned payment code or the app), so the address can't be edited. Sentence case, no period. Generic — the lock applies whether or not the prefill came from a payment URI.
no setter
walletSendRecipientShielded → String
Live recipient-field status: the entered address is a shielded address, so the payment is private.
no setter
walletSendRecipientTransparent → String
Live recipient-field status: the entered address is a transparent address, so the payment is publicly visible on-chain.
no setter
walletSendRecipientWrongNetwork → String
Live recipient-field status: the address is well-formed but for the wrong network (e.g. a testnet address in a mainnet wallet).
no setter
walletSendReviewButton → String
Primary form action: prepare the send and show the confirm screen.
no setter
walletSendReviewTitle → String
Heading on the confirm screen.
no setter
walletSendSavedBody → String
Result body when no transaction was accepted this attempt — cause-agnostic: a transport miss OR a mempool reject (which can be the already-known race shape with money actually in motion; the wallet-screen in-flight cue owns that window). Money-safe; auto-retry. The automatic promise is TRUE at every custody tier (#401 R1b): this transaction is already SIGNED, and the §6.1 ReBroadcast arm re-sends the raw bytes with no seed — unlike a QUEUED intent, which needs a credential the background pass may not have. It is PASS-dependent though, so the render site appends walletSyncPausedMoneyNote when no pass will run. 'On a later sync' — never 'as soon as you're online' (the #399 reconnect-promptness rule).
no setter
walletSendSavedTitle → String
Result: nothing was accepted this attempt (transport miss or mempool reject); the payment is persisted and will retry.
no setter
walletSendScanQr → String
Send form: opens the camera to scan an address or a zcash: payment request (S13, maintainer).
no setter
walletSendSelfSendNote → String
Passive info note on the confirm screen when the recipient is the wallet's own address — money-safe, just usually unintended. Never a blocker.
no setter
walletSendSentBody → String
Result body for a fully-broadcast send.
no setter
walletSendSentTitle → String
Result: every transaction broadcast successfully.
no setter
walletSendSubmitting → String
Busy label while signing + broadcasting.
no setter
walletSendSyncNotRunning → String
Honest reason under a disabled Send when no sync pass will run (#405 → the SSOT). Wins over any retained status arm: nothing is syncing, stalling, or catching up. CAUSE-AGNOSTIC — the badge names the cause. No trailing period (it renders as a reason line).
no setter
walletSendSyncUnavailable → String
Honest reason shown under a disabled Send button when sync is stalled or offline (so it won't progress until connectivity/the fault is resolved) and nothing is spendable.
no setter
walletSendTitle → String
App-bar title of the send screen.
no setter
walletSendTotalLabel → String
Confirm line: total debited (recipient amount + fee).
no setter
walletSendTryAgain → String
Action on a failed-send result that returns to a fresh form.
no setter
walletSendUnavailable → String
Honest state when the send screen has no live wallet session (defensive).
no setter
walletSendUnknownBody → String
Body for walletSendUnknownTitle on the SEND path (S7 U1). Must never say whether money moved: the transaction may have been signed and broadcast. Points at Activity, where the payment's real state is shown.
no setter
walletSendUnknownQueuedBody → String
Body for walletSendUnknownTitle on the offline QUEUE path (S7 U1): the payment may have been durably queued to send later. Points at the wallet's pending (parked) payments list.
no setter
walletSendUnknownTitle → String
Title of the send screen's terminal when the payment ran but its answer was lost (S7 U1, SendOutcomeUnknown): the host's own authorization code threw or declined after the spend ran. Neither 'sent' nor 'nothing was sent' is true. Bodies: walletSendUnknownBody / walletSendUnknownQueuedBody. No retry is offered.
no setter
walletSendWaitingForFunds → String
Honest reason shown under a disabled Send button while sync is still catching up and nothing is spendable yet (spend-before-sync). Neutral wording (#356-F7): a zero-fund wallet has no funds for sync to 'reach', so the copy must not imply funds are known to exist.
no setter
walletSendWatchOnly → String
Honest full-screen state when the send screen is reached on a watch-only wallet (no spending keys). Permanent fact, not transient.
no setter
walletSettingsSaveFailed → String
Snackbar shown when persisting a settings toggle failed; the switch stays at its saved value.
no setter
walletSheetLeaveBody → String
Shield / Move sheet: dialog body when Back is pressed while it submits; title walletSendLeaveTitle, actions walletSendLeaveStay / walletSendLeaveConfirm (maintainer).
no setter
walletShieldAlreadyTitle → String
The one-shot shield token was already consumed (a double-tap) — never broadcast twice.
no setter
walletShieldAmountLabel → String
Label for the gross transparent amount being shielded.
no setter
walletShieldButton → String
Action button next to the unshielded balance — moves transparent funds into the private shielded pool (Recv-3).
no setter
walletShieldClose → String
Dismiss the shield sheet after a terminal outcome.
no setter
walletShieldConfirmButton → String
Confirm button that signs + broadcasts the shield transaction.
no setter
walletShieldDoneBody → String
Body for a successful shield broadcast.
no setter
walletShieldDoneTitle → String
Terminal success: the shield tx was broadcast.
no setter
walletShieldFailedTitle → String
The shield could not be prepared or signed; no funds moved.
no setter
walletShieldFeeLabel → String
Label for the ZIP-317 fee on the shield transaction.
no setter
walletShieldNetLabel → String
Label for the net amount that ends up in the shielded balance (gross minus fee).
no setter
walletShieldNote → String
Privacy-positive framing of the shield action (the inverse of a de-shield warning).
no setter
walletShieldNothingBody → String
Honest explanation that the transparent balance is below the shielding threshold.
no setter
walletShieldNothingTitle → String
Shown when the transparent balance is below the shieldable minimum.
no setter
walletShieldPreparing → String
Transient state while the shield proposal is computed (local, no network).
no setter
walletShieldRetry → String
Re-run the shield after a recoverable failure.
no setter
walletShieldSavedBody → String
Honest body for the unbroadcast (saved-for-retry) shield — confirmation is NOT imminent; it re-sends on a later sync. Same #401 R1b posture as walletSendSavedBody (already signed ⇒ custody-independent, pass-dependent ⇒ the render site appends walletSyncPausedMoneyNote), and no 'next time you're online' reconnect promise.
no setter
walletShieldSavedTitle → String
The shield tx is persisted but not yet broadcast; it re-sends on a later sync (money-safe). NOT 'when you're online' (#401 R1b): that is the reconnect-promptness shape #399 forbids — the re-send rides a completed sync pass, which can lag a reconnect and never comes at all while sync is paused. Mirrors walletSendSavedTitle.
no setter
walletShieldSheetTitle → String
Title of the shield confirmation sheet.
no setter
walletShieldStaleBody → String
The wallet isn't synced far enough to anchor the shield yet — retry after sync.
no setter
walletShieldStorageFullBody → String
Shield fault: the device is out of disk space, so preparing/persisting the shield hit DiskFull (#373 follow-up). Retrying without freeing space fails again, so the copy asks for space instead of a plain retry. Funds are untouched. Sibling of walletSendFaultStorageFull.
no setter
walletShieldSubmitting → String
Transient state while the shield tx is signed and broadcast.
no setter
walletShieldTransientBody → String
Shield fault body for the retryable prepare refusal (WalletErrorKind.proposeTransient, INC-018 (b)): a condition the wallet's own state clears — an anchor not yet recorded, an input a concurrent proposal holds, a witness the scan has not completed. The shield sibling of walletSendFaultCouldNotPrepareTransient; MUST NOT claim the wallet is 'still syncing' (that is walletShieldStaleBody — a locked input is not a sync matter) and MUST NOT be title-only (the couldNotPrepare arm's dead-end). No funds moved.
no setter
walletShieldUnknownBody → String
Body for walletShieldUnknownTitle. Must never say whether funds moved. Points at Activity, where the shield's real state is shown.
no setter
walletShieldUnknownTitle → String
Title of the shield sheet's terminal when the shield ran but its answer was lost (ShieldOutcomeUnknown): the transaction may already be saved. Neither 'shielded' nor 'nothing happened' is true. Body: walletShieldUnknownBody. Only Close is offered, never a retry.
no setter
walletShieldWalletEnded → String
Body of the shield sheet’s failure terminal when the wallet session ended mid-sheet; mirrors walletMoveWalletEnded.
no setter
walletShowBalance → String
Screen-reader label and tooltip of the eye button while amounts are HIDDEN: pressing it shows them again (FR-49 W-7; maintainer FD-6).
no setter
walletSnapshotUnavailable → String
Honest, recoverable message when the cold snapshot read fails.
no setter
walletSpendableLabel → String
Label for the confirmed, spendable portion of the balance.
no setter
walletStallBirthdayInFuture → String
Stall reason: the wallet's configured starting height (birthday) is above the chain tip THIS SERVER reports and above the newest height the app's bundled data vouches for (StallReason.birthdayInFuture, T0-1c-R2). The wallet cannot tell a server that is behind the chain from a starting height set above the real chain tip, so the copy MUST name BOTH next steps: check the starting block this wallet is set to, or try another server. That height has TWO producers (§4n-review row 7, §4r U-5): the birthday typed at restore AND a rescan from a chosen height (rescan_from) — so the copy says 'the starting block this wallet is set to' and MUST NOT say 'you entered when restoring' (the rescan user typed nothing at restore). MUST NOT say 'check your connection' (the server answered — that is walletStallEndpoint) and MUST NOT suggest restoring from the recovery phrase (nothing on the device is at fault — that is walletStallInternal). The wallet keeps retrying on its own; it clears when the server catches up or the starting block is lowered.
no setter
walletStallEndpoint → String
Stall reason: endpoint unreachable — the normal-offline (caution) arm since #399. Hedged on purpose: a refused dial can mean the SERVER is down while the user's internet is fine, so it must not assert the user's connection is the problem. The wallet retries on its own. Since P3-13 the server IS user-switchable (the sync sheet's Server row opens the picker); the copy still does not promise a switch, because a refused dial cannot say whether it is this server or the user's link that is down.
no setter
walletStallEndpointMisbehaving → String
Stall reason: the server ANSWERED and the answer was wrong (StallReason.endpointMisbehaving — malformed or impossible data, a required pool it does not know, or a root/height that conflicts with what an EARLIER server told this wallet). The mirror image of walletStallInternal: the problem is on the SERVER, so the next step IS 'switch servers'. MUST NOT say 'check your connection' (that is walletStallEndpoint — the link works) and MUST NOT suggest restoring from the recovery phrase (nothing on the device is at fault; the seed is not involved). MAY name a RESCAN as the last resort, after other servers (T0-1d): one member of the class is a conflict with the wallet's own cached record — written from an earlier server — and the conflict alone cannot say which server lied; a rescan rebuilds that record and is the only exit when every server is refused. Uses the same 'rescan your history' vocabulary as walletRescanMenuItem. The wallet keeps retrying on its own.
no setter
walletStallInternal → String
Stall reason: a CORRUPT wallet store, or a local fault the wallet could not diagnose (StallReason.internal; R10 narrowed it) — repair/restore, never switch servers. A busy or briefly unreadable store is walletStallStorageUnavailable, which must never offer the restore.
no setter
walletStallReorg → String
Stall reason: chain reorganization in progress.
no setter
walletStallStorage → String
Stall reason: device storage full.
no setter
walletStallStorageUnavailable → String
Stall reason: a TRANSIENT local storage fault (StallReason.storageUnavailable, R10) — the wallet's database was busy past its timeout, or an I/O fault such as a locked iPhone's Data Protection. The store is intact and the wallet retries by itself; the SDK's background sync shows this only at the second local fault before a pass completes. MUST NOT suggest restoring from the recovery phrase (that is walletStallInternal, a corrupt store). MUST NOT say 'check your connection' or 'switch servers' (the network is not involved). Keep it short.
no setter
walletStallTor → String
Stall reason: the private path is GENUINELY DOWN — a dial that failed (refused, unreachable, a dial timeout), nothing registered, a registrant that declared its transport FAILED, or a runtime the SDK cannot drive. TRANSPORT-NEUTRAL by construction (FR-30 (a), C1): this string is rendered from a StallReason, which carries no transport name — every other failing arm names the host's transport, this one cannot, so it names none. It must never say "Tor": a host that registered Shadowsocks reads it too (ADR-0547). TWO CLAIMS IT MAY NOT MAKE (FR-32 (b), stage S1 copy): a StallReason carries no POLICY, so a Preferred wallet reads this sentence too — it can neither say the private path "is required" (a setting that user may never have chosen) nor promise that "nothing was sent in the clear" (only Required fails closed; its dial plan has no fallback arm at all). Both were in this string until stage S1. NARROWED at stage S1 truth: a path that ACCEPTED the dial and then carried nothing no longer reaches this reason — it reads TorState.unanswered, whose sentence claims nothing about which side is at fault.
no setter
walletStallUnknown → String
Stall reason: forward-compatibility arm — still a stall, never healthy.
no setter
walletStartupFailedBody → String
Body of the boot-wiring failure screen. Must reassure that a boot failure never means fund loss (funds are on-chain), and point at the retry.
no setter
walletStartupFailedTitle → String
Heading of the boot-wiring failure screen (WalletStartupFailedScreen): the app ships the wallet but its startup work (native library load / data directory) failed.
no setter
walletSwapAckLabel → String
Blocking acknowledgment checkbox label — gates the Start swap action (§2.6 disclosures-as-blocking-UX).
no setter
walletSwapAmountHint → String
Placeholder for the swap amount field.
no setter
walletSwapAmountLabel → String
Label for the exact ZEC-in amount field.
no setter
walletSwapAssetLabel → String
Label for the destination-asset dropdown (what the user swaps their ZEC into).
no setter
walletSwapBackButton → String
Review-screen action that returns to the editable form.
no setter
walletSwapBackToWallet → String
Primary button on NON-terminal tracking cards (pending/detected/processing/unknown/not-found), the establish-failure card, and the swap-unavailable screen (#364 F12). 'Done' there read as 'the swap is done' — this label states the navigation honestly. Terminal outcome cards (success/refunded/failed) keep 'Done'.
no setter
walletSwapButton → String
Entry button on the active wallet surface that opens the swap flow (shown only when the host has enabled swap).
no setter
walletSwapConfirmButton → String
Review-screen action that executes the swap (registers intent + queues the deposit).
no setter
walletSwapDepositAddressLabel → String
IntoZec deposit screen: the deposit-address field label.
no setter
walletSwapDepositAmountCopied → String
Snackbar after Copy amount (S13, maintainer).
no setter
walletSwapDepositBackBody → String
IntoZec deposit screen: back-press guard dialog body (the in-flight reassurance).
no setter
walletSwapDepositBackBodyExpired → String
Leave-screen dialog body ONCE THE DEPOSIT WINDOW HAS EXPIRED (#364 F11): the live-window body invites copying the address 'to pay', which post-expiry is exactly what the user must not do — this variant warns off sending instead. HEDGED (review MED): 'should refund', never 'will' — same rule as walletSwapDepositExpired.
no setter
walletSwapDepositBackLeave → String
IntoZec deposit screen: back-press guard — confirm leaving.
no setter
walletSwapDepositBackStay → String
IntoZec deposit screen: back-press guard — stay on the screen.
no setter
walletSwapDepositBackTitle → String
IntoZec deposit screen: back-press guard dialog title.
no setter
walletSwapDepositCopied → String
IntoZec deposit screen: snackbar after copying the deposit address.
no setter
walletSwapDepositCopy → String
IntoZec deposit screen: copy-to-clipboard button.
no setter
walletSwapDepositCopyAmount → String
Swap deposit screen: copies the exact amount to send (S13, maintainer).
no setter
walletSwapDepositExactNote → String
IntoZec deposit screen: the exact-amount honesty note (§4.4).
no setter
walletSwapDepositExpired → String
IntoZec deposit screen: the expired-window message. HEDGED (review MED): 'should refund', never 'will' — a below-minimum/dust late deposit or a GC'd order can make an unconditional promise false on a money screen.
no setter
walletSwapDepositMemoCopied → String
IntoZec deposit screen: snackbar after copying the deposit memo.
no setter
walletSwapDepositMemoCopy → String
IntoZec deposit screen: copy-the-memo-to-clipboard button.
no setter
walletSwapDepositMemoLabel → String
IntoZec deposit screen: label for the required deposit memo value.
no setter
walletSwapDepositMemoRequired → String
IntoZec deposit screen: heading of the required-memo section (some source chains, e.g. XRP/Cosmos, require a destination tag or memo on the deposit).
no setter
walletSwapDepositMemoWarning → String
IntoZec deposit screen: the funds-loss warning above the required deposit memo.
no setter
walletSwapDepositQrLabel → String
IntoZec deposit screen: accessibility label for the deposit-address QR.
no setter
walletSwapDepositSent → String
IntoZec deposit screen: advance-to-tracking affordance.
no setter
walletSwapDepositTitle → String
IntoZec deposit screen: title (§3.3b D7).
no setter
walletSwapDeshieldBody → String
§2.6 disclosure body — honest about the de-shield and the public provider legs.
no setter
walletSwapDeshieldTitle → String
§2.6 disclosure heading: swapping out de-shields ZEC and exposes the provider legs.
no setter
walletSwapDestinationHint → String
Placeholder for the destination address field.
no setter
walletSwapDestinationLabel → String
Label for the foreign receive-address field (where the swapped asset is delivered).
no setter
walletSwapDestinationScanTooltip → String
OutOfZec form: tooltip on the destination-address QR scan button (mobile only).
no setter
walletSwapDirectionBuy → String
Swap form: the IntoZec direction segment (the default) — buy ZEC with another asset.
no setter
walletSwapDirectionSell → String
Swap form: the OutOfZec direction segment — sell ZEC for another asset.
no setter
walletSwapDiscloseAmounts → String
Disclosure item: provider sees both amounts.
no setter
Disclosure item: provider links the two assets to one intent.
no setter
walletSwapDiscloseDestination → String
Disclosure item: provider sees the destination address.
no setter
walletSwapDiscloseGeneric → String
Disclosure item: a forward-compat disclosure line this build can't name.
no setter
walletSwapDiscloseIp → String
Disclosure item: provider sees the caller IP unless on Tor.
no setter
walletSwapDiscloseProviderLegsPublic → String
Disclosure item shown when providerLegsTransparent: the provider's chain legs are public (distinct from our de-shield).
no setter
walletSwapDiscloseSource → String
Disclosure item: provider sees the source address.
no setter
walletSwapDiscloseTitle → String
Heading above the §2.6 provider-disclosure list.
no setter
walletSwapDone → String
Action that leaves the swap screen and returns to the wallet.
no setter
walletSwapExecuteStillWorking → String
Snackbar when the user tries to leave (back gesture/button) while the swap execute is still running — the screen blocks leaving for this bounded step (#367 execute pop-guard). Money is being committed; every outcome screen is leavable.
no setter
walletSwapExecuting → String
Busy label while registering the swap and queuing the deposit.
no setter
walletSwapFaultAlreadyInFlight → String
Form fault: the SDK's one-deposit-in-flight guard refused a second swap while one is still queued/signing/sending/settling. Deliberately does NOT invite a re-quote (re-quoting is the double-deposit door). 'Fully settles … can take a while' is honest about the settlement tail: the guard clears at reorg-final burial (~2 h after the deposit mines) or after quote expiry + tx expiry (review NIT — the earlier copy implied an immediate clear).
no setter
walletSwapFaultConnection → String
Form fault: the swap request to the 1Click service timed out / the connection broke (host-side timeout) — the user's connectivity is the likely cause, distinct from the provider itself being down.
no setter
walletSwapFaultCouldNotQuote → String
Form fault: a generic quote/execute failure with no finer mapping.
no setter
walletSwapFaultDepositFailed → String
Form fault: our side couldn't queue the deposit (no ZEC moved; re-quote).
no setter
walletSwapFaultDestinationInvalid → String
Form fault: the destination was rejected by the SDK.
no setter
walletSwapFaultDestinationRequired → String
Form fault: the destination address was empty (OutOfZec requires it).
no setter
walletSwapFaultDestinationUnavailable → String
Form fault: our side couldn't mint a fresh swap receiving address (IntoZec — the #382 mirror of walletSwapFaultRefundUnavailable; pre-#382 this kind fell through to the generic could-not-quote). Same pre-first-sync dominant cause, same wait-for-sync remedy. 'Receiving address' means the wallet-side ZEC delivery address, NOT the user's typed destination.
no setter
walletSwapFaultExecuteTimeout → String
IntoZec execute overran the host-side timeout (#367, F5): the cause may be transport OR a local stall (a busy store consuming most of the window), so this HEDGES both — unlike walletSwapFaultConnection, it must not firmly blame the user's connection. Money-safe: an IntoZec execute moves no wallet funds; re-quoting is the remedy.
no setter
walletSwapFaultExpired → String
Form fault: the quote deadline lapsed — re-quote.
no setter
walletSwapFaultForeignAmountRequired → String
IntoZec form fault: the source amount was empty.
no setter
walletSwapFaultOutOfBounds → String
Form fault: the quote fell outside the user-anchored bound (protective).
no setter
walletSwapFaultProviderMisbehaved → String
Form fault: the provider broke the protocol contract.
no setter
walletSwapFaultProviderUnavailable → String
Form fault: provider unreachable/erroring (retryable).
no setter
walletSwapFaultRefundAddressRequired → String
IntoZec form fault: the refund address was empty.
no setter
walletSwapFaultRefundUnavailable → String
Form fault: our side couldn't mint a fresh refund address (#382 rewrite). The DOMINANT real cause since #368 is a pre-first-sync Sell — the refund mints through the engine, which needs the lazily-provisioned account, and the swap surface is activation-gated — so the copy names the wait-for-sync remedy instead of the pre-#382 bare 'try again' (which looped false hope while lightwalletd was down and the swap provider up). 'Usually' keeps the rare structural tail honest.
no setter
walletSwapFaultRequestInvalid → String
Form fault: not-issued/already-executed/malformed request — re-quote.
no setter
walletSwapFaultSlippageTooHigh → String
Form fault: requested slippage above the SDK ceiling (defensive).
no setter
walletSwapFaultStateUnavailable → String
Form fault: our side couldn't persist durable swap state (fail-closed).
no setter
walletSwapFaultStoreBusyRetry → String
Retryable fault (#367): the wallet's own store was momentarily busy and NOTHING was consumed — re-running the same action works. On the review screen it renders inline and Start swap is the retry (the quote is still valid); on the form, tapping Get quote again is the retry. Distinct from walletSwapFaultStateUnavailable (whose remedy is a re-quote).
no setter
walletSwapFaultSwapOff → String
Form fault: swap disabled at this instance (defensive). Also the classifier verdict for the defensively-unreachable watchOnly kind — if that kind ever becomes reachable at quote/execute, promote it to a dedicated permanent-framing key (walletSwapUnavailableWatchOnly is the model).
no setter
walletSwapFaultTermsDiffer → String
Stage S8 (R01): the quote handed to execute names a quote the wallet issued but its terms (address, amounts, memo, refund target, binding) differ from the wallet's own durable record — refused BEFORE the quote's single-use claim, so nothing was consumed and nothing left the wallet. Must state that nothing was sent (true by construction) and point at a fresh quote; must not accuse the provider (the DTO was altered on the way back through the host, not by the provider).
no setter
walletSwapFaultWalletUnavailable → String
Form fault: no live wallet session (defensive).
no setter
walletSwapForeignAmountLabelGeneric → String
IntoZec form: the foreign amount field label before an asset is picked.
no setter
walletSwapInFlightRowGeneric → String
In-flight swap row line for an unrecognized direction (forward-compat) — neutral, never a guess about who sends what.
no setter
walletSwapInFlightRowIntoZec → String
In-flight swap row line when the USER sends the deposit externally (IntoZec).
no setter
walletSwapInFlightRowOutOfZec → String
In-flight swap row line when the WALLET sends the deposit (OutOfZec).
no setter
walletSwapInFlightRowOverdue → String
In-flight swap row line for an UNRESOLVED record past its settlement window (#382 — such rows now list indefinitely instead of vanishing at 48 h; the wallet keeps watching every sync while unresolved), OUT-OF-ZEC + unknown-direction arm since #385 ('coming back' is refund-shaped, which is exactly the OutOfZec ZEC leg; the IntoZec row has its own delivery-shaped line). MUST stay outcome-neutral ('hasn't reached a confirmed outcome HERE' — review): the swap may in fact have SUCCEEDED unobserved, so 'taking longer than expected' would assert a falsehood over a completed swap. The second sentence is the money promise and covers only ZEC legs — it must not claim anything about a foreign-asset refund, which happens provider-side. ACCEPTED OVERCLAIM (#386, shared with the not-found body): for a pre-#368 upgrade-era record with no recorded watch leg, 'after a sync' is true only of a user-initiated full rescan — upgrade-era-only, shrinking population, documented rather than gated.
no setter
walletSwapInFlightRowOverdueIntoZec → String
The IntoZec arm of the overdue row line (#385 — 'any ZEC coming back' read refund-shaped for a swap whose ZEC leg is the incoming DELIVERY; delivered ZEC never left this wallet's side). Same outcome-neutrality contract as the OutOfZec arm; the money promise covers the ZEC delivery leg only — the foreign deposit's refund, if any, happens provider-side on the source chain. Shares the #386 accepted overclaim documented on the OutOfZec arm (a watchless pre-#368 record's late ZEC is full-rescan-only).
no setter
walletSwapInFlightRowPastWindow → String
In-flight swap row line once the record's deposit window has lapsed (#367, both directions): the present-tense motion lines ('on its way' / 'waiting for your deposit') would be false for the rest of the record's ~48 h life. Neutral — the swap may have settled, refunded, or expired; View swap shows the live truth.
no setter
walletSwapIntoZecEndsShielded → String
IntoZec review: the pinned ends-shielded honesty copy (§3.3b D1).
no setter
walletSwapIntoZecShieldTitle → String
IntoZec review: the positive end-state card title.
no setter
walletSwapNetworkFeeLabel → String
Review line label (OutOfZec only, #367 fee disclosure): the Zcash network fee the deposit transaction will pay ON TOP of the 'You send' amount — without this line the review implied the deposit was the whole debit.
no setter
walletSwapNetworkFeeValue → String
Review line value for the network fee: the exact ZIP-317 fee is computed only when the deposit transaction is signed at execute (there is no swap fee-preview round-trip), so the review honestly discloses the fee's EXISTENCE and timing — never a fabricated number.
no setter
walletSwapPayoutVerifyAck → String
OutOfZec review: the distinct payout-verification acknowledgment (separate from the privacy ack).
no setter
walletSwapPayoutVerifyTitle → String
OutOfZec review: the payout-address verification step title — the user's own foreign address where the swapped asset is sent.
no setter
walletSwapPendingWindowPassedIntoZec → String
Tracking detail when the pending-deposit window already lapsed and the USER was the deposit sender (IntoZec). No refund promise — a deposit that arrived late is the provider's refund flow, handled by other states.
no setter
walletSwapPendingWindowPassedOutOfZec → String
Tracking detail when the pending-deposit window already lapsed and the WALLET was the deposit sender (OutOfZec) — the honest dead-quote line replacing an eternal 'swap started'. Hedged: a late-sent deposit is refunded provider-side, so the claim is only about the not-sent case.
no setter
walletSwapPickerEmpty → String
Token picker: the honest empty state (no assets after filtering).
no setter
walletSwapPickerError → String
Token picker: a first-ever fetch failure with no cache.
no setter
walletSwapPickerRetry → String
Token picker: retry button after a load error.
no setter
walletSwapPickerSearchHint → String
Token picker: placeholder in the search field.
no setter
walletSwapPickerStale → String
Token picker: the L6 serve-stale banner (the live fetch failed; cached data shown).
no setter
walletSwapPickerTitle → String
Token picker sheet title for the IntoZec (Buy) direction — the SOURCE asset the user swaps FROM.
no setter
walletSwapPickerTitleReceive → String
Token picker sheet title for the OutOfZec (Sell) direction — the TARGET asset the user receives (the shared picker is direction-neutral; the caller supplies the framing).
no setter
walletSwapQuoteButton → String
Primary form action: request a bounds-checked quote.
no setter
walletSwapQuoteExpired → String
Review screen: shown when the quote countdown reaches zero; Start swap is disabled.
no setter
walletSwapQuoteExpiresUnderMinute → String
Screen-reader label for the review quote countdown once under 60 seconds (review M4): a dedicated sentence — composing 'less than a minute' into the {time} slot of walletSwapQuoteExpiresIn double-hedged ('about less than a minute') in every locale at the most time-critical spoken moment.
no setter
walletSwapQuoting → String
Busy label while requesting a quote.
no setter
walletSwapRefundHelper → String
IntoZec form: helper text clarifying the refund address is a foreign-chain address.
no setter
walletSwapRefundHint → String
IntoZec form: the refund address field hint.
no setter
walletSwapRefundInfoBody → String
IntoZec form: body of the refund-address explainer dialog (§3.3b D6).
no setter
walletSwapRefundInfoTitle → String
IntoZec form: title of the refund-address explainer dialog.
no setter
walletSwapRefundLabel → String
IntoZec form: the source-chain refund address field label.
no setter
walletSwapRefundScanTooltip → String
IntoZec form: tooltip on the refund-address QR scan button (IZ-4; mobile only).
no setter
walletSwapRefundVerifyAck → String
IntoZec review: the distinct refund-verification acknowledgment (separate from the privacy ack).
no setter
walletSwapRefundVerifyBody → String
IntoZec review: the refund-address verification instruction.
no setter
walletSwapRefundVerifyTitle → String
IntoZec review: the refund-address verification step title (§3.3b D6).
no setter
walletSwapRemove → String
Tooltip/semantics label of the per-row remove affordance on the in-flight swap list (#367).
no setter
walletSwapRemoveBodyDone → String
Confirm-dialog body when the row being removed already shows its pinned terminal outcome (#367) — plain list hygiene, nothing is lost.
no setter
walletSwapRemoveBodyInFlight → String
Confirm-dialog body when the row being removed has NO observed terminal yet, OUT-OF-ZEC arm ONLY since #385 (#367 origin, hedge extended by #382): the watched leg IS this wallet's refund address, so 'stop watching for its refund' and the rescan-recovery claim are true. Removing drops the only re-attach handle AND stops the unresolved-swap watch (the per-sync re-arm keys off this record); a later refund is still recoverable by rescan — never silently lost (the refund address stays registered with the wallet's own engine). The IntoZec/unknown rows use their own bodies — every claim here is FALSE for IntoZec (UX HIGH-1).
no setter
walletSwapRemoveBodyInFlightIntoZec → String
Confirm-dialog body for removing an UNRESOLVED IntoZec row (#385, UX HIGH-1 — the shared body lied to IntoZec users): the watched leg is the DELIVERY destination (this wallet's own engine-minted address), so the watch/rescan claims are about the incoming ZEC delivery; an IntoZec refund is the user's FOREIGN deposit returned on the source chain — this wallet never sees it and rescanning here can never find it, so the copy says where it happens instead.
no setter
walletSwapRemoveBodyInFlightUnknown → String
Confirm-dialog body for removing an UNRESOLVED row whose direction this build doesn't recognize (forward-compat, #385): makes only the direction-independent claims — a watched leg is always one of this wallet's own engine-registered addresses (so the rescan claim holds), and no refund-location claim is made (it differs per direction).
no setter
walletSwapRemoveCancel → String
Confirm-dialog dismiss action for the swap-row remove (#367).
no setter
walletSwapRemoveConfirm → String
Confirm-dialog confirming action for the swap-row remove (#367).
no setter
walletSwapRemoveTitle → String
Confirm-dialog title for removing an in-flight swap row (#367).
no setter
walletSwapReviewTitle → String
Heading on the swap review/confirm screen.
no setter
walletSwapRowOutcomeFailed → String
In-flight swap row line once a FAILED terminal was observed and pinned (#367). Soft wording — a deposited amount settles or refunds provider-side; the row must not assert loss.
no setter
walletSwapRowOutcomeRefunded → String
In-flight swap row line once a REFUNDED terminal was observed and pinned (#367). A named outcome, not an error — details (where the refund went) are on the tracking view.
no setter
walletSwapRowOutcomeSuccess → String
In-flight swap row line once a SUCCESS terminal was observed and pinned (#367) — the row stays until the user removes it or opens tracking and taps Done.
no setter
walletSwapScanCameraUnavailable → String
Address QR scanner screen: honest message when the camera can't start (permission denied / no camera) (shared brick).
no setter
walletSwapScanCancel → String
Address QR scanner screen: the close-button tooltip (shared brick).
no setter
walletSwapScanInstruction → String
Address QR scanner screen: the aiming hint / accessible label (shared brick).
no setter
walletSwapScanManualEntry → String
Address QR scanner screen: the always-present escape button that returns to the type/paste field (shared brick).
no setter
walletSwapScanTitle → String
Address QR scanner screen: app-bar title (shared by the IntoZec refund + OutOfZec destination scans).
no setter
walletSwapsInFlightError → String
Honest error line when the durable in-flight swap list can't be read — never a silent hide (this list is the only wallet-side witness of a mid-flight swap).
no setter
walletSwapsInFlightRetry → String
Inline retry button under the in-flight-swaps read-error line: re-pulls the list in place (the home has no pull-to-refresh, and this list is a swap's only wallet-side witness). Same 'try again' wording as the other read-error retries (walletReceiveRetry, walletSwapPickerRetry).
no setter
walletSwapsInFlightRetryInProgress → String
The in-flight-swaps read-error retry button's label WHILE the re-pull is in flight (#407 R5) — the twin of walletParkedErrorRetryInProgress, and load-bearing for the same reason: the label change is what re-announces the retry to a screen reader. Keep it SHORT (it replaces 'Try again' inside a button beside a spinner).
no setter
walletSwapSlippageCustom → String
Swap form: the custom-slippage chip.
no setter
walletSwapSlippageCustomLabel → String
Swap form: the custom-slippage percent field label.
no setter
walletSwapSlippageLabel → String
Swap form: the slippage control label (§3.3b D4).
no setter
walletSwapSlippageMayFail → String
Swap form: advisory for a too-tight slippage tolerance.
no setter
walletSwapSlippageNormal → String
Swap form: advisory for a normal slippage tolerance.
no setter
walletSwapSlippageRisky → String
Swap form: advisory for a wide slippage tolerance.
no setter
walletSwapSlippageTooHigh → String
Swap form: advisory for a slippage beyond the SDK hard ceiling.
no setter
walletSwapSourceAssetHint → String
IntoZec form: the source-asset picker placeholder before an asset is chosen.
no setter
walletSwapSourceAssetLabel → String
IntoZec form: the source-asset picker field label.
no setter
walletSwapStartAnother → String
Secondary action on a still-tracking swap card (W-swap-5): return to the swap form to begin a new swap. The swap being tracked is NOT cancelled — it stays listed on the wallet screen — so the wording is 'another', not 'cancel' or 'new'.
no setter
walletSwapStatusCheckingTitle → String
Tracking: the COLD-attach / first-load busy title, shown while the swap's status is being established and no answer has arrived yet — a fresh re-attach after process death (no carried state), or the moment just after execute before the first poll returns. Neutral BY DESIGN: 'Swap started' (walletSwapStatusPendingTitle) over-claims a state we have not confirmed (the swap may already be further along, or not yet started). The '…' is a real U+2026 ellipsis. (#347, cold-attach label)
no setter
walletSwapStatusDetectedBody → String
Tracking body for the deposit-detected state.
no setter
walletSwapStatusDetectedTitle → String
Tracking: the provider detected the deposit.
no setter
walletSwapStatusFailedBody → String
Tracking body for the failed state (funds-safety honest).
no setter
walletSwapStatusFailedTitle → String
Tracking: terminal failure.
no setter
walletSwapStatusNotFoundBody → String
Tracking body for the not-found terminal (#367; last sentence added by #385, hedge sharpened by #386). Must NOT assert loss: a deposit that landed on an expired order is refunded provider-side to the recorded refund address; 'most likely expired' stays hedged (the provider can no longer tell us anything definitive). Since #385 this card's Done does NOT dismiss the still-unresolved record (MED-1ux — not-found is a heuristic, never pinned, and a silent dismiss voided the watch the overdue row had just promised), so the copy says the swap stays listed + watched and points at the list's Remove (which carries the full disclosure dialog). The watching claim is hedged 'in case it still arrives' (M-1, precision-fixed by #386: 'until it has arrived' PRESUPPOSED an arrival, but this card's own headline case — an expired order whose foreign-coin deposit is refunded provider-side on the source chain — never delivers ZEC here at all); a served leg (money arrived, then shielded/moved) stops the per-pass watch. ACCEPTED OVERCLAIM (#386, documented rather than gated): a pre-#368 upgrade-era record with no recorded watch leg (NULL watch columns, its one-shot backfill window spent) is NOT per-pass watched — its late ZEC is engine-registered and surfaces on a user-initiated full rescan only. That population is upgrade-era-only and shrinking; gating this sentence on watch presence would need a new DTO bit for a corner that retires itself. HEDGED (review M5): 'should refund' — this card's own premise is a GC'd order, the exact case that makes an unconditional refund promise false.
no setter
walletSwapStatusNotFoundTitle → String
Tracking: the SDK's poll policy concluded the provider no longer recognizes this swap (#367 — several consecutive definitive not-found answers; most likely the order expired and was cleaned up provider-side).
no setter
walletSwapStatusPendingBodyIntoZec → String
Tracking body for the pending-deposit state when the USER sends the deposit externally (IntoZec — a foreign coin from their own wallet, never ZEC from this one). Used ONLY within the issuing app run, where the deposit screen showed the instructions; a re-attached swap uses walletSwapStatusPendingBodyIntoZecReattached.
no setter
walletSwapStatusPendingBodyIntoZecReattached → String
Tracking body for a RE-ATTACHED IntoZec pending-deposit swap (#367 — opened from the wallet-screen row after a restart or re-entry). The original body's 'send them before the quote expires' is impossible to follow here: the deposit address/memo are deliberately not stored, and they must NOT be re-shown (a memo-less deposit can lose funds on memo chains). Honest about both arms: already-sent (will be detected) and never-sent (let it expire, start fresh).
no setter
walletSwapStatusPendingBodyOutOfZec → String
Tracking body for the pending-deposit state when the WALLET sends the deposit (OutOfZec). Honest across every state this screen can cover, tightened by #367 (UX MED-4 + reliability MED-2): 'briefly offline' + 'window is short' replace the old unbounded 'once you're back online' promise (false past ~11 min of the 15-min window), and 'stays yours … up to an hour to show as spendable' replaces 'stay in your wallet' (the locked-notes balance dip after a gate-caught miss). Keep both hedges.
no setter
walletSwapStatusPendingTitle → String
Tracking: provider is waiting for the deposit.
no setter
walletSwapStatusProcessingBody → String
Tracking body for the processing state.
no setter
walletSwapStatusProcessingTitle → String
Tracking: the provider is processing the swap.
no setter
walletSwapStatusRefundedBody → String
Tracking body for the refunded state when the USER sent the deposit (IntoZec, #367): the refund goes to the user's own refund address on the SOURCE chain — this wallet never sees it, so the body says where to look instead of the old placeless 'your funds were refunded'.
no setter
walletSwapStatusRefundedBodyOutOfZec → String
Tracking body for the refunded state when the WALLET sent the deposit (OutOfZec; #368 replaced the #367 'may not appear yet' interim): the refund address is watched (refund-index registration), viewing this screen re-arms the watch, and since #382 EVERY sync pass re-arms it while the swap is unresolved — so 'shows up in your balance after the wallet next syncs' is mechanical for ANY absence length, not only within 48 h of executing. Keep the timing hedge ('can take a little while') — the provider's refund transaction must mine and a sync pass must run before the balance moves; never promise instant.
no setter
walletSwapStatusRefundedTitle → String
Tracking: terminal refund (a named outcome, not an error).
no setter
walletSwapStatusSuccessBody → String
Tracking body for the success state.
no setter
walletSwapStatusSuccessTitle → String
Tracking: terminal success.
no setter
walletSwapStatusUnderBody → String
Tracking body for the under-deposited state when the WALLET sent the deposit (OutOfZec) — the user cannot top up a wallet-sent deposit, so the body stays passive (completing or refunding provider-side).
no setter
walletSwapStatusUnderBodyIntoZec → String
Tracking body for the under-deposited state when the USER sends the deposit externally (IntoZec, #367): unlike the OutOfZec arm the user CAN act — top up the missing amount — so the body says so, with the honest refund fallback.
no setter
walletSwapStatusUnderTitle → String
Tracking: only a partial deposit has been received.
no setter
walletSwapStatusUnknownBody → String
Tracking body for the unknown state.
no setter
walletSwapStatusUnknownTitle → String
Tracking: a forward-compat status this build can't name (neutral, never alarming).
no setter
walletSwapTargetAssetHint → String
OutOfZec form: the target-asset picker placeholder before an asset is chosen.
no setter
walletSwapTitle → String
App-bar title of the swap screen.
no setter
walletSwapTrackingError → String
Tracking: an establish-time typed failure (the stream can't be opened).
no setter
walletSwapTrackingErrorBody → String
Body of the tracking ESTABLISH-failure card (review M1): its own body — the failed-status body ('The swap couldn't be completed') contradicted the title on a money claim; an establish failure says nothing about the swap's outcome and must not read as a failure verdict.
no setter
walletSwapTrackingUnavailableBody → String
Tracking body when the host has killed swap (§3.5 — funds-safety honest). SINCE #382 UNREFERENCED by the package (both directions render their own honest kill body — the IntoZec/OutOfZec siblings); retained for the #347 l10n review to prune rather than churn 16 locales mid-GA.
no setter
walletSwapTrackingUnavailableBodyIntoZec → String
IntoZec tracking: the §3.3b L8 honest killed-swap message (delivery arrives on the next sync).
no setter
walletSwapTrackingUnavailableBodyOutOfZec → String
OutOfZec tracking: the honest killed-swap message (#382 — the OutOfZec mirror of the IntoZec L8 body). Pre-#382 this arm said funds 'settle or refund on the provider's side' — a misdirect once #368 made refunds land at THIS wallet's own address (the provider would truthfully answer 'we already sent it back'). Mechanics: the kill clears the detection watch, but the refund address stays engine-registered and the unresolved-swap re-arm restores the watch on the first sync after swap is re-enabled — so the promise is mechanical, conditioned on swap being turned back on.
no setter
walletSwapTrackingUnavailableTitle → String
Tracking: swap was turned off, so live tracking stopped (§3.5 host kill state).
no setter
walletSwapUnavailableOff → String
Honest state when swap is turned off at this build/instance (§3.5 host kill state).
no setter
walletSwapUnavailableWallet → String
Honest state when the swap screen has no live wallet session (defensive).
no setter
walletSwapUnavailableWatchOnly → String
Swap screen reached (host deep-link) on a watch-only wallet (#397 §3.7 D3): the condition is PERMANENT for this wallet, so no 'right now' transience — view-only framing, no retry invitation.
no setter
walletSwapViewSwap → String
Action label that re-opens live tracking for an in-flight swap — on the wallet-screen row and on the 'a swap is already in progress' fault (W-swap-5 #366).
no setter
walletSwapYouReceiveLabel → String
Review line: the minimum guaranteed amount of the destination asset.
no setter
walletSwapYouSendLabel → String
Review line: the exact ZEC amount leaving the wallet.
no setter
walletSyncBadgeHint → String
Screen-reader tap hint on the sync badge row (the row opens the sync-detail sheet; the ⓘ icon carries the same affordance visually).
no setter
walletSyncCatchingUp → String
Shown under the Scanning status during the opaque early phase (percent still rounds to 0) so the wallet reads as actively working, not stuck — explains WHY the sync is slow. No trailing period: it can precede another detail line in the joined a11y label. Says 'a deep initial sync' (not 'first sync') since a restore also hits this on a fresh device.
no setter
walletSyncConnecting → String
Sync status: connecting, no bootstrap percent available.
no setter
walletSyncDisabled → String
Sync badge headline when the HOST app's sync policy is off (#383 R1) — syncing is deliberately not running by the embedding app's own setting. Short; state, not an error.
no setter
walletSyncDisabledDetail → String
Next step under the sync-off badge — points at the HOST app's settings (the package has no sync switch of its own). Keep 'this app's settings' generic; hosts name the screen differently.
no setter
walletSyncEndpointBehind → String
Sync-status headline for SyncStatus.endpointBehind (T0-1c): the wallet scanned to THIS SERVER's reported tip, but that tip is below a block height the network had already passed before this version of the app was built — the server is behind the chain (a node still syncing, stuck or forked, or a server under-reporting its height). MUST NOT read as a plain 'Up to date': the balance shown alongside is current only as of that older block. Distinct from walletSyncUpToDateLimited (this app VERSION — says update) and walletSyncUpToDateDegraded (this server's POOLS — says switch); this one is about this server's HEIGHT and also says switch.
no setter
walletSyncExplainConnecting → String
Sync-detail sheet explanation: the Connecting arm (incl. Tor bootstrap).
no setter
walletSyncExplainDisabled → String
Sync sheet explanation for the sync-off state (#383 R1): says WHO turned it off (the app's settings, deliberately), carries the funds-safe reassurance its not-running siblings (ExplainStartFailed/ExplainOffline) carry, and is honest that the figures are the last synced state — never implies an error or that the package can turn it back on.
no setter
walletSyncExplainEndpointBehind → String
Sync-detail sheet explanation paired with walletSyncEndpointBehind. The next step MUST be 'switch servers': never 'check your connection' (the link works — the pass completed) and never 'update the app' (that is the UpToDateLimited pair). Names both money consequences honestly and without claiming the user holds any: incoming payments after that block are not visible from this server, and a send built against this server's tip carries an expiry the real chain may already be past (it would expire and the funds return, not be lost). MUST NOT say the funds are lost or that anything needs restoring.
no setter
walletSyncExplainIdle → String
Sync-detail sheet explanation: genuinely idle (loop not running, no start failure).
no setter
walletSyncExplainOffline → String
Sync-detail sheet explanation: offline; leads with the funds-are-safe reassurance. The queued-sends clause names the SURFACE, never a drain schedule (#401 R1 — host custody cannot drain on a background pass); keep 'Saved & pending' in step with walletParkedTitle.
no setter
walletSyncExplainScanning → String
Sync-detail sheet explanation: scanning. Reassures the user the app stays usable (maintainer: 'what's going on' behind the badge).
no setter
walletSyncExplainStalled → String
Sync-detail sheet explanation: stalled; the typed walletStall* reason renders as its own paragraph underneath. The endpointUnreachable stall gets walletSyncExplainStalledOffline instead (#399).
no setter
walletSyncExplainStalledOffline → String
Sync-detail sheet explanation for the endpointUnreachable stall only (#399): the calm normal-offline story — funds-safe reassurance, queued-sends-are-normal, automatic retry. Carries BOTH hedges itself ('if you're offline' conditional + the server-side possibility) because the sheet suppresses the walletStallEndpoint detail under this explanation (the near-identical-pair rule); the detail still rides the badge a11y label. The queued-sends clause names the SURFACE and no schedule (#401 R1 — host custody cannot drain on a background pass), and the retry sentence says CONNECTION explicitly so it can never be read as a promise about the send. Hard stalls keep walletSyncExplainStalled.
no setter
walletSyncExplainStartFailed → String
Sync-detail sheet explanation when the sync START command itself failed (#356-F8): replaces the idle arm's 'starts automatically — no action needed', which would contradict the retry notice. Shown above the sheet's Try-again button.
no setter
walletSyncExplainStarting → String
Sync-detail sheet explanation: the loop is up but hasn't reported a batch yet (the silent prep phase).
no setter
walletSyncExplainUnknown → String
Sync-detail sheet explanation: the forward-compat arm — neutral syncing framing, never healthy or alarming.
no setter
walletSyncExplainUnverified → String
Sync-detail sheet explanation paired with walletSyncUnverified; the grace's own line (walletSyncGraceLeft*/walletSyncGraceEnded*) renders beside it and OWNS the sending claim (running: a countdown; ended: a refusal) — this body makes NO claim about sending (fold of the security and crypto angles: it used to say 'sending keeps working for a short grace period', false once the grace has ended). The next step MUST be 'switch servers': never 'check your connection' (the link works — the pass reached the tip) and never 'update the app' (that is the UpToDateLimited pair; nothing was upgraded here). States honestly that the balance IS current (this server serves blocks; only its network claim is missing) — unlike the Limited and Degraded pairs, this is not a balance-is-a-floor state. Under a reported rewinding streak the sheet shows walletSyncExplainUnverifiedStreak instead. MUST NOT say 'upgraded' or 'update'.
no setter
walletSyncExplainUnverifiedStreak → String
Sync-detail sheet explanation paired with walletSyncUnverified when the SDK reports streakReported: true on the grace claim (P3-12, maintainer): the loop has judged this server misbehaving (repeated rewinds — the endpointMisbehaving stall the grace outranks, P2-6). MUST NOT say the balance is current; names the rewinds and their consequence for the balance; makes NO claim about sending (the grace line beside it owns that — fold). The next step MUST be 'switch servers': never 'check your connection', never 'update the app'. MUST NOT say 'upgraded' or 'update'.
no setter
walletSyncExplainUpToDate → String
Sync-detail sheet explanation: up to date.
no setter
walletSyncExplainUpToDateDegraded → String
Sync-detail sheet explanation paired with walletSyncUpToDateDegraded. The next step MUST be 'switch servers': never 'check your connection' (the link works — the pass reached the tip) and never 'update the app' (that is the UpToDateLimited pair). Names the money consequence honestly (unspendable funds in that pool, balance is a floor) without claiming the user holds any. WHICH pool, and how, is the detail line under it — walletSyncPoolUnsupported / walletSyncPoolWithheld / walletSyncPoolHeightViolation / walletSyncPoolUnknown, one per affected pool (§4r U-3).
no setter
walletSyncExplainUpToDateLimited → String
Sync-detail sheet explanation paired with walletSyncUpToDateLimited. Names both consequences honestly — possibly-invisible funds and unavailable memos — because either alone would understate it.
no setter
walletSyncGraceEndedClock → String
The grace ENDED by the DEVICE CLOCK rule (GraceExpiry.clock; GRACE-1 §4p G-6): a day passed on this device's clock since the last confirmation, whatever the server's block height did — the axis a server that freezes its height cannot hold still — or the clock was set back after that day was seen (which does not re-open the grace). Shared by the sync detail line and the send-fault body. ONE next step — a server that reports the network version — with the device clock as its PRECONDITION, never an alternative (§4p-run fold review row 6, §4r U-5): a wrong clock is the one benign cause, but a corrected clock alone re-permits nothing (the latch holds until a branch-reporting server), so the copy MUST read 'if the date and time are wrong, fix them FIRST — then switch' and MUST NOT read 'switch, OR check the date and time'. MUST NOT say 'upgraded' or 'update the app'.
no setter
walletSyncGraceNeverConfirmed → String
The grace never BEGAN (GraceExpiry.neverConfirmed; GRACE-1 §4p): every server this wallet has met withheld the network version, so the app has never confirmed it can send at all. Shared by the sync detail line and the send-fault body; also the forward-compat fallback for a grace shape this UI does not know. NOT the never-synced case (that is walletSendFaultNotSynced — wait for sync). Next step: SWITCH SERVERS. MUST NOT say 'upgraded' or 'update the app'.
no setter
walletSyncIdle → String
Sync status: wallet open, loop about to start (transient — sync auto-starts).
no setter
walletSyncIdleDetail → String
Next step under the idle sync status — sync runs on its own, there is no manual start.
no setter
walletSyncOffline → String
Sync status: no connectivity.
no setter
walletSyncOfflineDetail → String
Next step under the offline sync status; queued sends are normal, not errors. Promises no drain schedule (#401 R1 — the automatic-drain family): a host-custody background pass cannot sign at all, so this names the surface the send is safe on instead. Keep 'Saved & pending' in step with walletParkedTitle.
no setter
walletSyncPausedMoneyNote → String
Shared money-surface qualifier appended to the SAVED-FOR-RETRY result bodies (send / partial / shield / move) when no background sync pass will run (#401 R1b + R5). Those bodies promise the wallet finishes the send on a later sync — true at every custody tier (the transaction is already signed) but only where passes HAPPEN. Deliberately CAUSE-AGNOSTIC: the drive is not running under BOTH the host's sync-off policy AND a failed sync start, and naming one remedy would be wrong for the other — the screen already carries the cause-specific line (the sync-off settings note, or the start-failed retry notice). Plural-safe and standalone (a full sentence); never claims failure, only the pause. Appended through walletSyncPausedJoin, never by a Dart string interpolation. It has a SECOND render site since #403 R2: the parked-sends section falls back to it when every row is mid-signature, because its own note names a Send now that is suppressed on those rows — this one names no affordance, which is exactly why it fits there.
no setter
walletSyncRetry → String
Button on the sync-start-failed notice that re-attempts starting the sync loop.
no setter
walletSyncScanningEarly → String
Sync status: the opaque early phase of a deep first sync where the note-fraction is still ~0 — a number-less headline (paired with an indeterminate bar + the catching-up detail) so a stuck-looking 'Scanning 0%' is never shown.
no setter
walletSyncServerAppDefault → String
Picker: the row label for the host app's default server when it is not among the offered entries (choosing it forgets the remembered choice).
no setter
walletSyncServerBusy → String
Picker refusal copy for WalletErrorKind.walletBusy in another phase (a rescan or a close in flight): retryable, nothing changed.
no setter
walletSyncServerCancel → String
The switch and trust notice dialogs' dismiss action — nothing changes.
no setter
walletSyncServerCheck → String
Picker: the action that probes the typed custom server (one round trip under the wallet's own Tor policy) WITHOUT switching.
no setter
walletSyncServerChecking → String
Picker: the Check button's label while the probe is in flight (15 s budget).
no setter
walletSyncServerContinue → String
The switch notice dialog's confirm action.
no setter
walletSyncServerCustom → String
Picker: the expander that reveals the custom-address field (the maintainer's expert-user path — a regular user never opens it).
no setter
walletSyncServerCustomHint → String
Picker: the custom-address field's hint — the shape the SDK's door accepts (https; http only for a local development server).
no setter
walletSyncServerInUse → String
Picker: the trailing marker on the server row the wallet currently dials.
no setter
walletSyncServerInvalidUrl → String
Picker refusal copy for WalletErrorKind.invalidEndpoint on a custom address (not https, a username or password in it, a path, too long, no host). ONE copy for every reason: the SDK's reason string is a static code the UI never echoes (the FFI rule — no matching on error text).
no setter
walletSyncServerKeyHeaderLabel → String
Picker (ADR-0568): the label of the field for the header name the key goes in (e.g. x-api-key) — shown once a key is typed.
no setter
walletSyncServerKeyHeaderNeeded → String
Picker (ADR-0568): inline copy when a key is typed without its header name.
no setter
walletSyncServerKeyHide → String
Picker (ADR-0568): the key field's toggle — hide the typed key.
no setter
walletSyncServerKeyInvalid → String
Picker refusal copy for WalletErrorKind.invalidEndpointAuth (ADR-0568): the SDK refused the key or its header (a header the transport owns, too long, not printable, padded, or a key for an http:// server). Never the address's copy — the kind tells them apart.
no setter
walletSyncServerKeyLabel → String
Picker (ADR-0568): the label of the optional key field under a custom server's address — the key the user's own server needs. Obscured; never logged.
no setter
walletSyncServerKeySaved → String
Picker (ADR-0568): shown beside the in-use custom server's host when the wallet holds a key for it. The key itself is never shown or returned.
no setter
walletSyncServerKeyShow → String
Picker (ADR-0568): the key field's toggle — show the typed key.
no setter
walletSyncServerNotOffered → String
Picker refusal copy for WalletErrorKind.syncServerNotOffered — a host bug (the picker renders only offered entries), kept honest rather than silent.
no setter
walletSyncServerSheetTitle → String
Title of the sync-server picker sheet (P3-13) and of the switch notice dialog.
no setter
walletSyncServerSwitching → String
Picker: the progress row while the switch runs (the sync loop stops and joins, the choice is written, the session is rebuilt over the same data).
no setter
walletSyncServerSwitchNotice → String
The in-flight notice body while CONNECTING or SCANNING (before ANY switch): the cost (the pass in progress restarts on the new server), the reassurance (no rescan — balance, history and queued sends are untouched), and the honest caveat (the card may read pending until the new server's scan catches up — fold of the walk). At an up-to-date status the sheet shows walletSyncServerSwitchNoticeAtTip instead.
no setter
walletSyncServerSwitchNoticeAtTip → String
The in-flight notice body at an UP-TO-DATE status (nothing is in progress): the switch reconnects; balance and history stay. fold of the walk's observation 2.
no setter
walletSyncServerTrustNotice → String
The trust notice's body: what a sync server LEARNS and what it is TRUSTED with. Shown BEFORE the first probe of a custom server (the probe itself discloses the IP — the crypto audit's MEDIUM moved it from the switch to the Check step), never again for the same host in one picker session. Names the privacy consequence the sync guards cannot judge (IP unless Tor, the birthday range, the transparent addresses the wallet polls — the most wallet-identifying item, even under Tor — the txids it fetches for memo enhancement, the broadcasts; the security review widened it from three items to five) and the honesty consequence they do (balance and history as reported). MUST NOT claim the server can move funds — it cannot (no keys).
no setter
walletSyncServerTrustNoticeKey → String
Trust notice addition (ADR-0568), shown when the user gives a key: a personal key lets the server tie every request, including payments sent on a fresh Tor circuit, to one account. MUST say it links payments to the wallet even over Tor.
no setter
walletSyncServerTrustTitle → String
Title of the trust notice shown before a CUSTOM server is used for the first time (maintainer ruling 1: validate access, then tell the user they are trusting that server).
no setter
walletSyncServerUnreachable → String
Picker refusal copy for WalletErrorKind.syncServerUnreachable when the user TYPED this address (the custom-URL field): the probe could not dial, timed out, or was refused — a gated server rejecting the key lands here too. Hedged like walletStallEndpoint: it MUST NOT say 'check your connection' alone — the server may be the down side. Nothing changed: the wallet stays on its current server. WHY IT NO LONGER STOPS AT 'check the address' (stage S1 copy, from the truth re-adjudication): probe_oracle (wallet.rs) maps everything that is not a FAILED private dial onto this kind, and since stage S1 a private path that ACCEPTS the dial and then carries nothing no longer reports TorUnavailable — deliberately, because blaming the path for what cannot be separated from a wedged server is the over-claim the stage removed. So a censored path and a wedged server arrive here as the same error and the SDK cannot tell them apart; the address stays the first step (this reader typed it) but it is no longer the ONLY one. Its sibling walletSyncServerUnreachableOffered serves the reader who typed nothing.
no setter
walletSyncServerUnreachableOffered → String
Picker refusal copy for WalletErrorKind.syncServerUnreachable when the address came from the APP'S OWN LIST (a predefined or default choice) rather than from the user — stage S1 copy. Same error, different reader: 'check the address' is dead advice for someone who typed nothing, and it is the sentence that would meet a Required wallet whose private path is being censored, where the address is the one thing that is certainly fine. The either/or is the point and must survive translation — the SDK cannot separate a wedged server from a path that accepts connections and carries nothing, and it does not guess; it names both causes and the two steps the reader can actually take. Names no transport (ADR-0547) and no policy (FR-32 (b)).
no setter
walletSyncServerUse → String
Picker: the action that switches onto a custom server the probe verified; also the trust dialog's confirm action.
no setter
walletSyncServerWrongNetwork → String
Picker refusal copy for WalletErrorKind.networkMismatch: the server answered and claims another network (testnet under a mainnet wallet). Not recoverable for THAT server; nothing changed.
no setter
walletSyncSheetBlocksLeft → String
Label of the live remaining-blocks row in the sync-detail sheet (exact grouped count — the sheet is WHERE the big number belongs; the badge keeps the compact form).
no setter
walletSyncSheetClose → String
Dismiss button of the sync-detail sheet (sibling of walletShieldClose/walletMoveClose). 'Close', not 'Done' (#356-NIT): the sheet is purely informational — 'Done' implies a completed action.
no setter
walletSyncSheetConnection → String
Sync sheet: section header for HOW the wallet talks to the network (transport privacy + server).
no setter
walletSyncSheetProgress → String
Label of the live scan-percent row in the sync-detail sheet.
no setter
walletSyncSheetServer → String
Sync sheet Connection section: row label for the lightwalletd host the wallet connects to. Since P3-13 the row is a BUTTON when a session exists — it opens the sync-server picker (walletSyncServerRowSemantics is its a11y label).
no setter
walletSyncSheetSyncedTo → String
Label of the tip row in the sync-detail sheet on EVERY reached-tip state (§4r U-2): plain up to date, and the qualified siblings — limited (this app version), degraded (this server's pools), unverified (this server's network claim) and behind (this server's height). The value is the exact grouped height the pass reached; on the behind state it is THIS SERVER's tip, and walletSyncSheetBehindBy follows it.
no setter
walletSyncSpendableReady → String
Shown while scanning when funds are already spendable (spend-before-sync).
no setter
walletSyncStalled → String
Sync status headline for a stalled (typed, renderable) state.
no setter
walletSyncStartFailed → String
Honest, recoverable notice when the background sync loop's start command itself fails (rare); shown with a retry.
no setter
walletSyncStarting → String
Sync status headline when the loop is started but hasn't reported a batch yet (the silent prep phase: reaching the server + fetching the commitment-tree roots and chain tip). Shown instead of the bare Idle 'Not syncing yet' so the wallet reads as actively connecting. NOTE: intentionally identical to walletSyncConnecting in English but a SEMANTICALLY DISTINCT state (host-side driving-Idle prep vs. the SDK's Connecting/Tor-bootstrap arm) — do not merge the two keys in translations.
no setter
walletSyncStartingDetail → String
Detail line under the connecting/starting sync status explaining the prep phase before scanning begins.
no setter
walletSyncTryNow → String
Button on the sync sheet's stalled arm (#399): retry the connection immediately instead of waiting out the automatic retry schedule (restarts the sync loop, which resets its backoff).
no setter
walletSyncUnknown → String
Sync status: forward-compatibility arm rendered as a neutral syncing state.
no setter
walletSyncUnverified → String
Sync-status headline for SyncStatus.upToDateUnverified (GRACE-1 §4p): the wallet scanned to the chain tip, but THIS SERVER will not say which version of the Zcash network it is on, so the app cannot confirm a payment it signs will be accepted; sending works for a short grace and is then refused. MUST NOT read as a plain 'Up to date'. Distinct from walletSyncUpToDateLimited (this app VERSION — says update; MUST NOT be conflated: nothing was upgraded here), walletSyncUpToDateDegraded (this server's POOLS) and walletSyncEndpointBehind (this server's HEIGHT); this one is about the server's NETWORK CLAIM and, like the last two, says switch. MUST NOT contain 'upgraded' or 'update'.
no setter
walletSyncUnverifiedStreakDetail → String
Sync-detail line rendered directly under the grace line when the SDK reports streakReported: true on the grace claim (P3-12 fold, security review MEDIUM 1): the badge's screen-reader label is the headline plus the detail lines, so the streak the grace outranks reaches a user who never opens the sheet. Same next step, 'switch servers'; MUST NOT say 'update' or 'upgraded'.
no setter
walletSyncUpToDate → String
Sync status: fully synced to the chain tip.
no setter
walletSyncUpToDateDegraded → String
Sync-status headline for SyncStatus.upToDateDegraded (T0-1b): the wallet scanned to the chain tip, but THIS SERVER refused, withheld or misreported the subtree roots of one of Zcash's shielded pools, so funds received in that pool cannot be spent through it. MUST NOT read as a plain 'Up to date' — the balance shown alongside is a floor for that pool. Distinct from walletSyncUpToDateLimited (that one is about this app VERSION and says update; this one is about the SERVER and says switch).
no setter
walletSyncUpToDateLimited → String
Sync-status headline for SyncStatus.upToDateLimited: the wallet scanned to the chain tip but this app version could not fully interpret every block, because the network runs consensus rules it does not implement. MUST NOT read as a plain 'Up to date' — the balance shown alongside is a floor, not a total.
no setter
walletTitle → String
Wallet screen title.
no setter
walletTorActive → String
Tor state chip: wallet traffic is riding Tor.
no setter
walletTorActiveUnattested → String
Transport chip for TorRuntimeKind.dialer — an arbitrary byte-stream dialer a Rust host injected, which the SDK (net/dialer.rs) "never knows or names". FR-32 (a): this arm read "Tor active" in the PROTECTED tone until stage S1 copy, asserting onion routing for a path the SDK cannot attest (ADR-0547: the SDK has no predefined transport kinds and renders only what the host declared). It says what IS true — wallet traffic is riding the path the app supplied — and refuses the privacy claim; paired with walletTransportExplainUnverified in the caution tone. A Rust host that KNOWS what it injected says so through WalletHostTransport (label + protection), which wins over any SDK TorState.
no setter
walletTorActiveUnverified → String
Tor state chip: traffic is on Tor but via a runtime this binding can't attribute; qualified, not a confident protected framing.
no setter
walletTorBootstrapping → String
Transport chip: the private path is starting and wallet traffic waits for it. The NEUTRAL variant, used when the SDK has no name to show (nothing registered, or a runtime with no registry) — walletTorBootstrappingNamed carries the host's own name when there is one. Never says "Tor": the wallet names no transport the host did not name (ADR-0547, FR-30 (a)).
no setter
walletTorFellBack → String
Tor state chip: policy preferred and Tor degraded to clearnet (visible, never silent).
no setter
walletTorHostDirect → String
Transport chip: the host app's registered dialer declared its path EXPOSED (ADR-0547 exposure = exposed: a plain direct connection, or a forward proxy that passes the client address) — not private, the server sees the IP, whatever the host named it and whatever the isolation says. Neutral tone, paired with walletTransportExplainDirect.
no setter
walletTorHostOtherTransport → String
The transport name substituted into walletTorHostPath / walletTorHostPathLinkable when the SDK has NO host name to show (the SDK's own unattributed rendering — an empty name never comes from a host, the crossing refuses it): the wallet never names a transport the host did not name (ADR-0547). Lower-case fragment that reads inside the parentheses.
no setter
walletTorOff → String
Tor state chip: off by configuration.
no setter
walletTorUnanswered → String
Transport CHIP for TorState.unanswered (stage S1 truth, FR-36): the path took the connection and no RPC has come back over it for the maintainer's minute while the wallet was trying. It states the two attested facts — the dial was accepted, nothing has answered — and blames neither side: the SDK cannot tell a blackholed path from a wedged server and never guesses (the either/or is spelled out in the sheet, walletTransportExplainUnanswered). The NEUTRAL variant, used when the SDK has no name to show; walletTorUnansweredNamed carries the host's own name when there is one. Never says "Tor" (ADR-0547). Deliberately NOT walletTorUnavailable's wording: that one means the path is genuinely down.
no setter
walletTorUnansweredDirect → String
Transport chip for TorState.unanswered on a registered dialer whose descriptor declared its path EXPOSED (ADR-0547 exposure = exposed: the server sees the device's address). FR-44: the unanswered arm inherited Active's payload and not its honesty — it read the plain "connected — nothing coming back" sentence for an exposed path, so a state change silently dropped a privacy loss the Active chip had been disclosing (walletTorHostDirect). The name is discarded here exactly as it is on walletTorHostDirect: what matters is that the path is not private, whatever the host called it and whatever the isolation says. Paired with walletTransportExplainUnansweredDirect, caution tone.
no setter
walletTorUnansweredUnattested → String
Transport chip for TorState.unanswered on the runtimes that declared NOTHING to branch on — TorRuntimeKind.dialer (an arbitrary byte-stream dialer a Rust host injected, which net/dialer.rs says the SDK "never knows or names") and TorRuntimeKind.unknown. It is walletTorUnanswered plus the refusal that walletTorActiveUnattested already makes for the SAME runtime while traffic is flowing. WHY IT EXISTS (crypto audit HIGH + the product pass, found independently): the unanswered arm sent these two runtimes to the bare walletTorUnanswered, so a path the SDK cannot attest read "Private path in use (privacy not verified)" while it carried and the STRONGER "Private path connected" once it went quiet — a user checking privacy at the moment the path stopped carrying read a bigger claim than while it was working. That is FR-44's defect class, sign-identical, on a different runtime; FR-32 (a) is the rule it breaks. Paired with walletTransportExplainUnansweredUnverified, caution tone. ExternalSocks5 keeps the unqualified walletTorUnanswered (the host named Tor by choosing that variant), as does the attested empty-name hostDialer. STILL OPEN, deliberately: whether the noun "private path" over-claims even with the parenthetical — that question is the same for this string and for walletTorActiveUnattested, and they must change together or not at all.
no setter
walletTorUnavailable → String
Transport chip: zero traffic — the path is GENUINELY DOWN. NARROWED at stage S1 truth to a dial that FAILED (refused, unreachable, a dial timeout, a NotReady/Retired/FAILED descriptor) plus the cases where there is no path at all (nothing registered, a registrant that declared its transport FAILED — ABI v3 health, ADR-0549). A dial the transport ACCEPTED and then carried nothing is NOT this state: it reads TorState.unanswered, because the SDK cannot separate a blackholed path from a wedged server and this chip would blame the path. The NEUTRAL variant, used when the SDK has no name to show; walletTorUnavailableNamed carries the host's own name when there is one. Never says "Tor" (ADR-0547, FR-30 (a)); names no policy (FR-32 (b)).
no setter
walletTorUnknown → String
Tor state chip: forward-compatibility arm; privacy rule renders it as not protected.
no setter
walletTransparentFundsAutoDenied → String
The sheet’s automation sentence while the host authorizer has declined automatic shielding for this session (the switch is ON but the loop is paused). Plain-factual; the manual Shield button on the balance card remains the recovery.
no setter
walletTransparentFundsAutoOff → String
The sheet’s conditional automation sentence while auto-shield is OFF (shown even when the expert gate hides the switch, so a persisted OFF is never invisible).
no setter
walletTransparentFundsIntro → String
Plain-factual intro of the transparent-funds sheet: the visibility facts ONLY. The auto-shield claim is the separate CONDITIONAL sentence (walletTransparentFundsAutoOn/Off) so the sheet never states automation that is switched off.
no setter
walletTransparentFundsMenuItem → String
Overflow-menu entry opening the transparent-funds policy sheet (expert gate + auto-shield).
no setter
walletTransparentFundsTitle → String
Title of the transparent-funds policy sheet.
no setter
walletTransparentLabel → String
Label for the transparent (unshielded) portion of the balance — privacy-relevant, shown only when nonzero.
no setter
walletTransparentNote → String
Honest note under a nonzero unshielded balance: BOTH the spendability truth (transparent funds count toward the total but not the spendable figure until shielded — the 'why is my total bigger than spendable' question must be answerable from the card itself, maintainer) AND the privacy truth (publicly visible until shielded).
no setter
walletTransparentNoteWatchOnly → String
The transparent-funds note for a WATCH-ONLY wallet (#397 §3.7 D5): it keeps only the privacy truth (public on-chain) and drops the 'shield these to spend' framing, which a watch-only wallet cannot follow (no spending keys).
no setter
walletTransportExplainBootstrapping → String
Sync sheet Connection explanation: the private path is starting. The NEUTRAL variant (no name to show); walletTransportExplainBootstrappingNamed names the host's transport when the descriptor does.
no setter
walletTransportExplainDirect → String
Sync sheet Connection explanation: no privacy transport — a direct (clearnet) connection.
no setter
walletTransportExplainFellBack → String
Sync sheet Connection explanation: Tor-preferred policy fell back to clearnet.
no setter
walletTransportExplainHostProxy → String
Sync sheet Connection explanation: generic copy for a HOST-provided protective transport (e.g. xray/vless/VPN) when the host supplies no detail of its own.
no setter
walletTransportExplainTor → String
Sync sheet Connection explanation: verified built-in Tor is active.
no setter
walletTransportExplainUnanswered → String
Sync sheet Connection explanation for TorState.unanswered (stage S1 truth, FR-36). The either/or is the POINT and must survive translation: the SDK reports what its own RPCs saw over a connection whose arm it knows, and it never says WHY a ready path is not carrying — a blackholed transport and a wedged server look identical from here. TWO next steps for the two causes (the walletStallBirthdayInFuture discipline): another server for a wedged server, the app's network settings for the path. MUST NOT promise that nothing left in the clear — a Preferred wallet reads this too, and its next dial leaves for clearnet. The NEUTRAL variant (no name to show).
no setter
walletTransportExplainUnansweredDirect → String
Sync sheet Connection explanation for TorState.unanswered on an EXPOSED registered path (FR-44). Two facts, in this order: the privacy verdict the descriptor decides (walletTransportExplainDirect's sentence, verbatim — the server sees the device's address) and then the unanswered either/or with its two next steps, which survive here unchanged because the state means the same thing whatever the exposure. The subject is "the connection", never "the private path": naming this path private is the FR-44 defect.
no setter
walletTransportExplainUnansweredUnverified → String
Sync sheet Connection explanation for TorState.unanswered on a registered path whose EXPOSURE the host did not declare, or declared with a value this binding cannot read (FR-44). walletTransportExplainUnverified's verdict, verbatim, then the unanswered either/or with its two next steps. The Active family renders walletTransportExplainUnverified alone on the same payload; this is the same verdict with the state's own sentence after it.
no setter
walletTransportExplainUnavailable → String
Sync sheet Connection explanation: zero traffic — the path is unreachable, unregistered or declared FAILED. Carries the NEXT STEP (ADR-0549 D3) — a failed path is no longer a wait, so the sentence must not read as one. The NEUTRAL variant (no name to show). It says "IS REQUIRED" NOWHERE (FR-32 (b), stage S1 copy): TorState.Unavailable carries no policy and a Preferred wallet reaches it too — a registrant that declared its transport FAILED is a frequent producer — so the sentence states what is true (the path is not available and nothing is connecting) without asserting a setting the user may not have chosen. It makes no claim about clearnet either: since stage S1 a Preferred wallet leaves a FAILED path after the minute, so "nothing was sent in the clear" would be a promise this state cannot keep.
no setter
walletTransportExplainUnverified → String
Sync sheet Connection explanation: an unverifiable/unknown transport state (privacy rule: never claim protection).
no setter
walletTxDetailClose → String
Dismiss button of the transaction-detail sheet (sibling of walletShieldClose/walletMoveClose).
no setter
walletTxDetailCopied → String
Snackbar confirmation after copying the transaction id.
no setter
walletTxDetailCopyTxid → String
Button that copies the FULL transaction id (the row shows a shortened form).
no setter
walletTxDetailDate → String
Label of the date row in the transaction-detail sheet (absolute, locale-aware).
no setter
walletTxDetailFee → String
Label of the fee row in the transaction-detail sheet (shown only when the fee is known).
no setter
walletTxDetailHeight → String
Label of the mined-height row in the transaction-detail sheet (shown only when mined).
no setter
walletTxDetailMemo → String
Label of the memo row in the transaction-detail sheet (shown only when the tx carries one).
no setter
walletTxDetailMemoAttached → String
Value of the memo row: the tx carries an encrypted memo (content is not yet fetchable through the SDK, so only its presence is shown).
no setter
walletTxDetailStatus → String
Label of the status row in the transaction-detail sheet.
no setter
walletTxDetailTxid → String
Label of the transaction-id row in the transaction-detail sheet.
no setter
walletTxDetailVisibility → String
Label of the tx-detail row stating the transparency fact (value: walletActivityPublicBadge). Rendered only for transactions with a publicly visible output.
no setter
walletTxExplainConfirmed → String
Plain-language explanation of the Confirmed status in the transaction-detail sheet (the depth rides the status row).
no setter
walletTxExplainExpired → String
Plain-language explanation of the Expired status: cancelled, nothing withdrawn (the maintainer's 'what does expired mean' ask). The banner (walletTxFundsKept) carries the headline reassurance; this adds the mechanism.
no setter
walletTxExplainFailed → String
Plain-language explanation of the Failed status: endpoint-rejected, nothing withdrawn.
no setter
walletTxExplainPending → String
Plain-language explanation of the Pending status in the transaction-detail sheet (also the forward-compat Unknown arm, which renders as Pending). Shown for an unmined wallet-created row only once an endpoint ACCEPTED it (TxSummary.delivery accepted/null); a row the wallet is still retrying gets walletTxExplainRetrying instead, because 'sent to the network' is false for it.
no setter
walletTxExplainQueued → String
Plain-language explanation of the Queued status in the transaction-detail sheet. Never 'waiting for a connection' (a send can be queued while ONLINE via the not-synced-yet path, and a queued row can be viewed during a non-network stall). Names NO drain schedule at all (#401 R1): at host custody the background pass holds no signing credential, so it points at the surface and the two real actions instead — the walletSendQueuedBody wording family. LATENT today: history.rs maps Queued rows out of the chain view, so this arm is unreachable; it is kept true so it cannot go live wrong.
no setter
walletTxExplainRetrying → String
Plain-language explanation for a wallet-created, unmined row the wallet still owes a broadcast (TxSummary.delivery == retryPending, stage S8 obligation). Cause-agnostic (a transport miss, a blackholed private path, a kill between signing and sending). 'On each sync' — never 'as soon as you're online' (the #399 reconnect-promptness rule). The expiry clause is true: a transaction past its expiry height is never rebroadcast and the funds free again.
no setter
walletTxExplainRetryingExpired → String
Detail-sheet explanation for a wallet-created row that reads Expired while the wallet still owes the payment (TxSummary.delivery == retryPending, S7 C1): the old transaction expired unmined and the wallet will re-send it once the expiry is safely buried. The row label stays 'Retrying'. The 'don't send it again yourself' clause is the point: a manual re-send pays twice.
no setter
walletTxExplainSaved → String
Plain-language explanation for a wallet-created, unmined row whose bytes are kept without a retry promise (TxSummary.delivery == persisted — a swap deposit held past its quote's window). Makes no claim about automatic sending either way.
no setter
walletTxExplainUnknown → String
Plain-language explanation of the forward-compat Unknown status: neutral — must never AFFIRM a broadcast (unlike walletTxExplainPending) nor claim cancellation, since the binding cannot interpret the state (security review).
no setter
walletTxFundsKept → String
Prominent reassurance for an expired/failed transaction: the money-honest core fact (TxStatus.expired ⇒ funds returned to spendable; failed ⇒ endpoint rejected, nothing spent). Used in the detail-sheet banner and appended to the history row's screen-reader label.
no setter
walletWatchOnlyAboutBody → String
Security-screen explanation for a watch-only wallet: it has no spending keys and nothing to back up.
no setter
walletWatchOnlyBack → String
Return from the watch-only import screen to the welcome screen.
no setter
walletWatchOnlyBadge → String
Short header badge marking a watch-only wallet (no spending keys).
no setter
walletWatchOnlyBirthdayChange → String
Button to change the chosen watch-only start date.
no setter
walletWatchOnlyBirthdayPick → String
Date-picker help text on the watch-only import screen.
no setter
walletWatchOnlyBirthdayTitle → String
Heading of the required creation-date control on the watch-only import screen.
no setter
walletWatchOnlyBody → String
Intro on the watch-only import screen: explains a viewing key gives view-only access and that a start date is needed.
no setter
walletWatchOnlyButton → String
Welcome-screen action (#397) to import a watch-only wallet from a viewing key — it can see balance and history but cannot spend.
no setter
walletWatchOnlyFaultAlreadyExists → String
Inline fault when a wallet already exists and a watch-only import was attempted over it.
no setter
walletWatchOnlyFaultBirthdayTooRecent → String
Inline fault when the chosen watch-only start date is above the chain tip.
no setter
walletWatchOnlyFaultInvalidKey → String
Inline fault when the entered string is not a valid unified viewing key. MODE-NEUTRAL wording: the key may have been pasted OR scanned from a QR, so it must not say 'paste again'.
no setter
walletWatchOnlyFaultNetworkMismatch → String
Inline fault when a well-formed viewing key is for the wrong network (mainnet vs testnet).
no setter
walletWatchOnlyKeyHint → String
Placeholder hint showing the expected viewing-key prefix.
no setter
walletWatchOnlyKeyLabel → String
Label for the text field where the user pastes the unified viewing key.
no setter
walletWatchOnlyScanCameraUnavailable → String
Shown on the QR reader when the camera cannot start (permission denied / no camera); the manual-entry escape button is always present. Mirrors walletSwapScanCameraUnavailable.
no setter
walletWatchOnlyScanFilled → String
Screen-reader announcement (not visible on screen) made after a QR scan fills the viewing-key field, so a non-sighted user knows the scan landed. NEVER contains the key itself. Keep it short and past-tense.
no setter
walletWatchOnlyScanHint → String
A muted one-line hint under the viewing-key input field, shown only on camera platforms (Android/iOS). Points the user at the scan icon so the QR-scan affordance is discoverable when the body copy is paste-first. Keep it short.
no setter
walletWatchOnlyScanInstruction → String
Aiming hint overlaid on the camera preview when scanning a viewing key. Mirrors walletSwapScanInstruction.
no setter
walletWatchOnlyScanManualEntry → String
The always-present escape button on the viewing-key QR reader — returns to the import form to PASTE the key. The viewing-key counterpart of walletSwapScanManualEntry ('Enter manually'); a viewing key is pasted, not typed, so this must say paste, matching walletWatchOnlyScanCameraUnavailable.
no setter
walletWatchOnlyScanTitle → String
App-bar title of the full-screen QR reader when scanning a viewing key.
no setter
walletWatchOnlyScanTooltip → String
Tooltip/a11y label of the camera-scan icon button on the viewing-key field (mobile only).
no setter
walletWatchOnlySectionTitle → String
Security-screen section header shown instead of the backup section for a watch-only wallet.
no setter
walletWatchOnlySubmit → String
Confirm action that imports the watch-only wallet from the pasted viewing key.
no setter
walletWatchOnlyTitle → String
Heading on the watch-only import screen.
no setter

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
securityDeleteRefusedBusySnack(int seconds) → String
Security screen: snackbar shown when a delete is REFUSED because a sync-server switch is still in flight (S2 M01 — a delete never races a switch). Names the wait: {seconds} is the switch timeout, after which a delete is accepted again.
toString() → String
A string representation of this object.
inherited
walletActivityConfirmations(int count) → String
Confirmation depth of a mined history row.
walletAmount(String amount) → String
A ZEC amount with its unit; amount is pre-formatted by integer math (never a float).
walletAutoShieldToggleDescription(String minZec) → String
Subtitle under the auto-shield switch. {minZec} is the already-formatted minimum amount (e.g. "0.001").
walletBalanceHeaderAsOf(String height) → String
Balance card header when the chain height the balance reflects is known — the as-of block rides IN the header (maintainer), never a separate floating row. The height arrives PRE-GROUPED (exactBlockCount — same format as the sheet's figure rows).
walletBalanceHeaderAsOfAt(String height, String time) → String
Balance card header when BOTH the as-of height and its stamp time are known — one line, never a second row (maintainer: no per-state layout shift). Height arrives pre-grouped; time pre-formatted.
walletBalanceHeaderAt(String time) → String
Balance card caption (maintainer): the time the balance is as of — just the time when today, date and time otherwise. One short line on a small phone; the block height lives in the sync sheet.
walletCountdownHoursMinutes(int hours, String minutes) → String
Countdown magnitude past an hour (e.g. '1h 05m'; {minutes} arrives zero-padded). Localize the unit forms per locale (review F2).
walletCountdownMinutes(int minutes) → String
Countdown magnitude at minute granularity, composed into the countdown sentences' {time} slot (review F2: unit forms live in the ARB so each locale renders its own — the first cut hardcoded Latin 'min' into all 16 locales' spoken labels). Floored minutes — never overstates a money window.
walletCountdownSeconds(int seconds) → String
Countdown magnitude under a minute (visual; the a11y label uses walletCountdownUnderMinute / the dedicated quote sentence). Localize the unit per locale (review F2).
walletInFlightNote(num count, String amount) → String
The durable in-flight two-step cue (#309): first leg broadcast, send not complete — money in motion through a wallet-controlled one-time address. Repeats the permanently-true 'don't re-send' after the result screen is dismissed; cause-agnostic + locational; NO auto-completion promise. Plural: each in-flight send uses its OWN one-time address, so N>=2 must not say 'a one-time address' / 'it'. amount is the pre-formatted aggregate and annotates the same pending payments the activity list shows. TERM (D2, #347): 'set aside for' / 'are set aside' replaced 'committed' — the safety term must NEVER read as blockchain-CONFIRMED, and never as STUCK; the 15 locales were already normalized to reserved/allocated, so EN now ratifies them.
walletInFlightNoteSyncPaused(num count, String amount) → String
walletInFlightNote's variant when NO background sync pass will run (re-keyed and renamed by #403 R4). The second leg forwards only on sync passes, so 'still completing' would claim progress and then negate it — this variant says 'partway through … paused' as one coherent story. Renamed from ...SyncOff and made CAUSE-AGNOSTIC for the same reason as its three re-keyed siblings (walletParkedPreparingHintSyncPaused, walletParkedAuthorizeSentSyncPaused, walletParkedSyncPausedNote): the drive is also not running after a FAILED sync start, where the host policy still reads on and 'syncing is off in this app's settings' is simply the wrong remedy — the screen's own sync notice carries the cause. Match walletSyncPausedMoneyNote's condition wording. Keep the D2 'set aside' term and the identical don't-send-again instruction; same plural rule and placeholders as the sibling.
walletInfoButtonLabel(String label) → String
Screen-reader name of the (i) button after a label; opens the explanation that used to sit on screen (S13). label = the label the button follows, verbatim.
walletMoveAvailable(String amount) → String
Spendable shielded-balance hint above the move amount field; integer-formatted (never a float).
walletMoveAvailableCatchingUp(String amount) → String
Variant of walletMoveAvailable while the wallet is still catching up (#381, the #380 swap-line rule): the spendable figure is the partial repopulating balance, so a low/zero figure must not read as final.
walletMoveBelowFloorNote(String amount, String floor) → String
Orange note on the move-to-transparent review when the move leaves the PUBLIC balance (what is already public at the shield source plus this move) under the core's shield floor (stage S14, maintainer copy): no Shield, manual or automatic, can take it until more arrives. Replaces the auto-shield note in that case.
walletParkedCancelSemanticTimed(String amount, String time) → String
Screen-reader label for a parked row’s Cancel button — binds the action to its amount AND save time so same-amount rows never read identically.
walletParkedRowPausedTimed(String amount, String time) → String
One PAUSED parked-send row (#315): the committed amount plus the locale-formatted save time. The 'paused' word is the row-level honesty split from the healthy 'saved & pending' — a paused payment never sends on its own (walletParkedPausedHint carries the explanation).
walletParkedRowPreparingTimed(String amount, String time) → String
One MID-SIGNATURE parked-send row (#400 R2, ParkedSend.sending): the wallet claimed this payment and is building the transaction — or was, until the app was killed during that step (an OOM while proving is the common mobile case). Before this row existed such a payment was on NO surface at all, which is the double-pay shape the whole section exists to prevent. Say PREPARING: nothing failed (never 'failed') and nothing was broadcast (never 'sent'/'on its way'). walletParkedPreparingHint carries the rest.
walletParkedRowTimed(String amount, String time) → String
One saved & pending (parked) send row: the committed amount plus the locale-formatted save time (the discriminator between two same-amount rows).
walletParkedSendNowInProgressSemanticTimed(String amount, String time) → String
Screen-reader label for the Send now button WHILE its spend bracket is open (#401 R3c). The visible label shortens to 'Sending…', and the in-flight semantic label used to fall back to that bare string — which re-introduces exactly the collision the timed labels exist to prevent: two parked rows with the same amount become two identical 'Sending…' nodes, and the one the user actually authorized is no longer identifiable. Keep the amount + save-time binding through the in-flight state. Present tense, because the signature is happening now.
walletParkedSendNowSemanticTimed(String amount, String time) → String
Screen-reader label for a row’s Send now button — binds the action to its amount AND save time so same-amount rows never read identically (mirrors the Cancel semantic label). Used on healthy AND paused rows alike (see walletParkedSendNow).
walletPaymentReceived(int count) → String
Transient arrival cue (SnackBar; also announced by screen readers) shown when the live incoming-funds stream reports new confirmed arrivals (maintainer decision — the minimal option). DELIBERATELY amount-free: the event payload carries no amount by design (ADR-0536); details are one tap away in the activity list.
walletPoolShielded(String amount) → String
Balance-card pool-clarity line (#389), private-pool segment: the shielded (private) portion of the total, shown always-on directly under the headline so 'how much of my ZEC is private?' is answerable at a glance. amount is a pre-formatted BARE ZEC figure (NO unit) — the unit rides the headline right above, and shielded + transparent sum EXACTLY to it (shielded = total − transparent), so the bare numbers can never disagree with the total. Keep it short: it shares ONE line with the transparent segment. 'Shielded' is the same privacy term used across the card; translate it as the sibling walletTransparentLabel does.
walletPoolTransparent(String amount) → String
Balance-card pool-clarity line (#389), public-pool segment: the transparent (unshielded, publicly-visible-on-chain) portion, rendered in the same privacy-orange the rest of the card uses for transparent funds. amount is pre-formatted BARE ZEC (unit on the headline). Keep it short (shares one line with the shielded segment). Match the 'transparent/unshielded' wording of the sibling walletTransparentLabel.
walletRecoverableEphemeralConfirmingNote(String amount) → String
As walletRecoverableEphemeralNote, but the amount is not yet reorg-final (still confirming) — shown as pending recovery, never settled/ready. amount is pre-formatted.
walletRecoverableEphemeralNote(String amount) → String
Note under the transparent line: part of the unshielded funds sits on a wallet-controlled one-time (ephemeral) address and is reorg-final/recoverable. SUBSET of the balance, never added on top. Cause-agnostic (an exchange return as much as an expired transfer), so never 'stranded'/'bounced'. amount is pre-formatted.
walletRecoverableEphemeralNoteWatchOnly(String amount) → String
The recoverable-ephemeral note for a WATCH-ONLY wallet (#397 §3.7 D3): keeps the locational fact but DROPS the '(recoverable)' claim — recovery mints a self-send (a spend) a watch-only wallet cannot do, and its reclaim affordance is hidden. amount is pre-formatted.
walletRecoverDone(String amount) → String
Snackbar after recovery accepted ALL funds cleanly. The amount is provisional (accepted, not yet confirmed) so the copy says 'recovering'. amount is pre-formatted.
walletRecoverDonePartial(String amount) → String
Snackbar after recovery accepted SOME funds but had per-address faults or hit the per-run cap (swept > 0 AND (failed > 0 OR truncated > 0)). Reports the provisional recovered amount AND honestly flags that work remains — never hides the remainder. amount is pre-formatted.
walletRescanEstimate(String blocks) → String
Size cue under the rescan range control — the approximate number of blocks the chosen range covers, so the duration warning has a visible magnitude. Pre-formatted compact count (e.g. "1.6M").
walletRescanRangeChosen(String date) → String
Description shown when a rescan start date is chosen.
walletRescanRebuildingFrom(String date) → String
Activity-section cue while a dated rescan repopulates.
walletRestoreBirthdayChosen(String date) → String
Shown when a creation date is set (the ~6-months-ago default). States the exclusion as a FACT and names both escape hatches (earlier date / full scan).
walletRestoreFaultInvalidWord(int index) → String
Inline restore error when one word isn't in the BIP39 list; index is 1-based.
walletRestorePillSemantics(int index, String word) → String
Screen-reader label for a recovery-word pill (valid word).
walletRestorePillSemanticsInvalid(int index) → String
Screen-reader label for a recovery-word pill that isn't a BIP39 word. Deliberately OMITS the typed value: an invalid token carries no verification value to read back, and keeping it out of the OS accessibility tree avoids echoing a mistyped recovery word to assistive/automation services (security HARDENING).
walletRestoreRemoveWord(int index) → String
Screen-reader label for the × that removes a recovery-word pill.
walletRestoreSomeWordsInvalid(int count) → String
Live cue when one or more entered words aren't in the BIP39 list (shown as error-coloured pills).
walletRestoreWordCount(int count) → String
Live count of recovery words entered.
walletSendAvailable(String amount) → String
Spendable-balance hint above the send form; amount is integer-formatted (never a float).
walletSendAvailableCatchingUp(String amount) → String
Variant of walletSendAvailable while the wallet is still catching up (#381, the #380 swap-line rule): the spendable figure is the partial repopulating balance, so a low/zero figure (incl. the post-'Send another' refresh) must not read as final.
walletSendFaultInsufficient(String available, String required) → String
Form fault: insufficient funds. Figures are integer-formatted; never logged (§5.4).
walletSendFaultInsufficientPending(String pending) → String
Form fault detail: pending-incoming funds shown alongside an insufficient-funds error. 'Once the wallet catches up', NOT 'once it confirms': the amount is most often a note with thousands of confirmations that is held only until more of the chain is scanned (witness unavailable), so 'confirms' was false for the common case (phase-2 P2-4, maintainer decision 3).
walletSendFaultOverCeiling(String limit) → String
Form fault: the amount exceeds the HOST's policy send ceiling (walletSendCeilingZatProvider, e.g. an alpha roll-out cap). Honest app-policy phrasing — the amount itself is valid.
walletSendLargeConfirmAction(String amount) → String
The irreversible confirm action in the large-send dialog; carries the exact amount so it is unmistakable at the moment of confirming.
walletSendMachineMemoPurpose(String purpose) → String
The host-supplied purpose sentence, rendered verbatim in the machine-memo disclosure.
walletSwapAvailable(String amount) → String
Spendable-balance hint above the swap form; amount is integer-formatted.
walletSwapAvailableCatchingUp(String amount) → String
Variant of walletSwapAvailable while the wallet is still catching up (#380): the spendable figure is the partial repopulating balance, so a low/zero figure must not read as final.
walletSwapDepositExpiresIn(String time) → String
IntoZec deposit screen: the live deadline countdown.
walletSwapDepositInstruction(String amount, String asset, String chain) → String
IntoZec deposit screen: the send instruction.
walletSwapDestinationHelperChain(String chain) → String
OutOfZec form: chain-aware helper for the destination field once a target asset is picked (cross-chain mistakes lose funds).
walletSwapDestinationLabelChain(String chain) → String
OutOfZec form: the destination field label once a target asset is picked, naming its chain.
walletSwapFaultInsufficient(String needed, String spendable) → String
Spendable pre-check refusal at quote review (#367): the deposit plus a conservative network-fee allowance exceeds what is spendable. 'about' is load-bearing — the needed figure includes an allowance, not the exact fee. Amounts are locale-formatted ZEC decimals.
walletSwapFaultInsufficientCatchingUp(String needed, String spendable) → String
The catching-up variant of walletSwapFaultInsufficient (#367): the wallet is mid catch-up/rescan, so the spendable figure may be partial — the closing hedge stops the refusal reading as a final verdict over a partial figure. Keep the hedge conditional ('may'), never a promise.
walletSwapFaultOverCeiling(String limit) → String
Swap form: the host's FR-23 alpha ceiling bounds the swap deposit; stated as an app restriction, never as an invalid amount (#364 S6 — its own key: the send form's 'limits sends' copy misread on a swap form).
walletSwapForeignAmountLabel(String symbol) → String
IntoZec form: the foreign amount field label once an asset is picked.
walletSwapForeignValue(String amount, String asset) → String
Review: a foreign amount + asset, e.g. the IntoZec 'you send' line.
walletSwapInFlightStarted(String time) → String
In-flight swap row time stamp. {time} is a locale-formatted DATE AND TIME (month, day, and clock time — since #382 an UNRESOLVED row is unbounded in age, no longer capped at ~48h, so the date matters), so keep the sentence grammatical with a full datetime, NOT a bare clock time (no preposition that only reads for a time-of-day). Known display bound (#377): the compact format carries no YEAR, so a >1-year-old unresolved row reads year-less — the shared Activity-row idiom.
walletSwapIntoZecFloorNote(String zec, String slippage) → String
IntoZec review: the honest guaranteed-minimum / max-cost line (§3.3b L8).
walletSwapPayoutVerifyBody(String asset) → String
OutOfZec review: the payout-address verification instruction. {asset} is the asset label, e.g. "USDC on Ethereum".
walletSwapPendingWindowEndsAt(String time) → String
Tracking detail under the pending-deposit body (W-swap-5 #366-e): the quote's deposit window, so a pending swap is never open-ended on screen. {time} is a locale-formatted DATE AND TIME (month, day, and clock time — a swap window can cross a day boundary), so keep the sentence grammatical with a full datetime, NOT a bare clock time (e.g. no preposition that only reads for a time-of-day).
walletSwapPickerNoMatch(String query) → String
Token picker: shown when the search query matches no asset.
walletSwapQuoteExpiresIn(String time) → String
Review screen: the live quote countdown while time remains. Since #367 the SDK's expiresAt is the ACTIONABLE deadline (display and the execute gate share one number), so the sentence may promise confirmability up to it; 'about' hedges only device-clock skew. Do NOT use wording that guarantees the quote past the shown time.
walletSwapReceiveValue(String amount, String asset) → String
Formatted receive figure: the provider's decimal min-out amount and the asset label.
walletSwapRefundHelperChain(String chain) → String
IntoZec form: chain-aware helper for the refund field once a source asset is picked.
walletSwapRefundLabelChain(String chain) → String
IntoZec form: the refund field label once a source asset is picked, naming its chain.
walletSwapsInFlightTitle(int count) → String
Wallet-screen section header for the durable in-flight swap list (W-swap-5 #366).
walletSwapSlippagePercent(String value) → String
Swap form: a slippage preset/value rendered as a percent.
walletSwapStatusUnderDetail(String received, String missing, String time) → String
Tracking detail under the under-deposited body (#367 — these DTO fields existed and were never rendered): the provider's received/missing amounts as DECIMAL STRINGS in the deposit asset's units (render verbatim — never re-computed host-side) and the top-up deadline. {time} is a locale-formatted DATE AND TIME (month, day, and clock time — the window can cross a day boundary), so keep the sentence grammatical with a full datetime, NOT a bare clock time (no preposition that only reads for a time-of-day).
walletSwapTokenLabel(String symbol, String chain) → String
Token picker: a source asset's display label (symbol + chain, both uppercased).
walletSyncConnectingPercent(int percent) → String
Sync status: connecting with a Tor bootstrap percent.
walletSyncGraceEndedBlocks(String blocks) → String
The grace ENDED by the block rule (GraceExpiry.blocks; GRACE-1 §4p G-6): the chain advanced a day's worth of blocks since the app last confirmed, with a server that reports its network, that it can send — and this server never said. ONE sentence shared by the sync-status detail line, the send-fault body (RW-SYNC-003) and nothing else, so the three never disagree. blocks is the count since that confirmation, pre-formatted compactly. The next step is SWITCH SERVERS. MUST NOT say 'upgraded' or 'update the app' (that is walletSendFaultNetworkUpgrade — a different fault with a different fix) and MUST NOT imply funds are at risk.
walletSyncGraceLeftBlocks(String blocks) → String
walletSyncGraceLeftHours's variant when the SDK hands NO time — the device clock cannot be trusted for the grace (it reads before the last confirmation), so the block rule alone decides and only the blocks are shown (GRACE-1 §4p G-4; this is the same string set, not a new case). blocks is pre-formatted compactly (e.g. "1.2K"). MUST NOT say 'upgraded' or 'update'.
walletSyncGraceLeftHours(int hours) → String
Detail line under walletSyncUnverified while the grace RUNS and the device clock can be trusted for it: how long sending keeps working. hours is the whole hours left on whichever of the two grace rules (blocks, device clock) runs out FIRST — the SDK already converted the blocks through the network's block spacing, so this is one figure; 0 renders as 'less than an hour'. The next step ('then switch servers') rides in the sentence. MUST NOT say 'upgraded' or 'update'.
walletSyncPausedJoin(String body, String note) → String
THE JOINER, and the separator is the locale's business (#403 R6). walletSyncPausedQualified appends walletSyncPausedMoneyNote to a money body, and doing it with a Dart '$body $note' inserts a U+0020 after a fullwidth full stop (。) in ja and zh, which is wrong typography in both — this package already ADJUDICATED that exact pattern once, in, and abandoned it. TRANSLATORS: this string contains NO words. Emit the two placeholders verbatim in the order the locale's sentence flow requires, with whatever separator that language uses between two complete sentences: a single space for the space-delimited languages, and NOTHING AT ALL for ja/zh (both fragments already end in their own 。). Never add punctuation of your own — both fragments are already terminated. RTL (ar/he) keeps the single space: both fragments are strong-RTL and period-terminated, so the plain join is correct there.
walletSyncPoolHeightViolation(String pool) → String
Sync-detail line for ONE shielded pool whose service was PoolService.heightViolation — this server served subtree completion heights that cannot be true and the wallet refused to record them; the server ANSWERED and the answer was wrong (§4r U-3). Same placement and rules as walletSyncPoolUnsupported. 'Misreporting', matching the explanation's 'misreporting'. MUST NOT say 'empty' or 'unknown pool'.
walletSyncPoolUnknown(String pool) → String
Sync-detail line for ONE shielded pool whose service is PoolService.unknown — the bridge's forward-compatibility arm (a state this version of the UI does not know; only under core/bridge version skew). Rendered as unknown, NEVER as healthy (spec §3.3 unknown handling) — the pool still counts as degraded. Same placement as walletSyncPoolUnsupported.
walletSyncPoolUnsupported(String pool) → String
Sync-detail line (and badge a11y label) for ONE shielded pool whose service on the last pass was PoolService.unsupported — this server does not know the pool at all (an older lightwalletd), so funds received in it cannot be spent through this server (§4r U-3, closing §4j row 8 by rendering). One line per affected pool, under the explanation of walletSyncUpToDateDegraded, walletSyncEndpointBehind or walletSyncUnverified; NO line for a pool served normally. pool is the pool's name (walletPoolSapling / walletPoolOrchard / walletPoolIronwood). 'Refuses', matching walletSyncExplainUpToDateDegraded's 'refusing'. MUST NOT say the pool is empty and MUST NOT say funds are lost; the next step (switch servers) is in the explanation above it.
walletSyncPoolWithheld(String pool) → String
Sync-detail line for ONE shielded pool whose service was PoolService.withheld — this server served FEWER completed subtree roots than the wallet can prove the pool already has (from the signed data the app ships with), so funds received in the part it did not serve cannot be spent through this server (§4r U-3). Same placement and rules as walletSyncPoolUnsupported. 'Withholding', matching the explanation's 'withholding'. MUST NOT say the pool is empty.
walletSyncScanning(int percent) → String
Sync status: scanning blocks, monotonic percent complete.
walletSyncScanRemaining(String count) → String
Compact blocks-left count shown on the SAME ROW as the Scanning percent once a real percent exists (counts down). count is pre-formatted compactly, e.g. "1.6M".
walletSyncServerFallbackNotOffered(String host) → String
Banner on the sync sheet's Server row and the picker when the REMEMBERED choice names a server this app version no longer offers (SyncServerFallback.choiceNotOffered): the default is in use, said, never silent. host = the server now in use.
walletSyncServerFallbackRefusedByTransport(String host) → String
Banner for SyncServerFallback.choiceRefusedByTransport (FR-29 E12): the remembered CUSTOM server is an unencrypted http:// address, which only the SDK's own direct connection may carry — under the app's private path the default is in use, the choice is kept. host = the server now in use.
walletSyncServerFallbackUnreadable(String host) → String
Banner for SyncServerFallback.choiceUnreadable (a malformed remembered choice): the wallet is usable on the default; pick again to replace it. host = the server now in use.
walletSyncServerRowSemantics(String host) → String
Screen-reader label of the sync sheet's Server row when it opens the picker (P3-13). host is the lightwalletd HOST in use (never a full URL).
walletSyncServerSwitchFailedRecovered(String host) → String
Picker notice after a switch failed PAST the point of no return and the wallet was recovered by re-opening (the rescan's recover-by-reopen). Names the server actually in use after the re-open (the new one if the choice landed, the previous one otherwise). Funds and history are untouched either way.
walletSyncSheetBehindBy(int count, String blocks) → String
One-cell figure row in the sync-detail sheet under walletSyncSheetSyncedTo on SyncStatus.endpointBehind (§4m #5, §4r U-2): how far behind the network this server is, AT LEAST. count is newestKnown - tip — the newest height this wallet knows the chain reached (a public constant of the app, or its own last scanned height less the reorg allowance) less this server's tip — which is a LOWER BOUND on the server's lag, never the gap itself, so the copy MUST keep 'at least' in every plural case. blocks is the same number pre-formatted as an exact grouped count (e.g. "12,345" — the sheet's vocabulary; the badge keeps compact forms); count selects the plural case only. Rendered only when count >= 1. MUST NOT read as an error or say the funds are lost: the explanation beside it already names the next step (switch servers).
walletTorBootstrappingNamed(String transport) → String
Transport chip: as walletTorBootstrapping, for a REGISTERED transport whose descriptor names it. transport = the HOST'S OWN name for its transport, verbatim ("Tor", "Shadowsocks", "VLESS via Cloudflare") — the wallet never interprets or translates it.
walletTorHostPath(String transport) → String
Transport chip: wallet traffic rides the dialer the host app registered (FR-29), whose path hides the device's address and honours per-purpose isolation. transport = the HOST'S OWN name for its transport, verbatim (ADR-0547: the wallet has no list of transport kinds), or walletTorHostOtherTransport when the SDK has no name to show. Protected tone.
walletTorHostPathLinkable(String transport) → String
Transport chip: as walletTorHostPath, but the host declared isolation unsupported (or did not declare it) — the wallet's connections can be linked to each other at the proxy — or the host did not declare whether the path hides the device's address (exposure unknown). Caution tone; the state never promises what the host did not declare (ADR-0545, ADR-0547). transport = the host's own name, verbatim.
walletTorUnansweredLinkable(String transport) → String
Transport chip for TorState.unanswered on a registered dialer that is NOT the plainly-private case: the host declared isolation unsupported (or did not declare it), so the wallet's connections can be linked to each other at the proxy — or the host did not declare whether the path hides the device's address (exposure unknown), where the weaker sentence is the honest one (the §3.3 privacy rule: never inherit a benign framing for something the binding cannot attest). The twin of walletTorHostPathLinkable on the Active family. transport = the host's own name, verbatim, or walletTorHostOtherTransport when the SDK has none to show — the sentence leads with the state, not the name, so the unattributed fragment reads inside it. Caution tone.
walletTorUnansweredNamed(String transport) → String
Transport chip: as walletTorUnanswered, for a REGISTERED transport whose descriptor names it — and ONLY for a path the host declared HIDDEN and isolating, since it is the variant that carries no privacy qualifier. transport = the HOST'S OWN name for its transport, verbatim — the wallet never interprets or translates it (ADR-0547).
walletTorUnavailableNamed(String transport) → String
Transport chip: as walletTorUnavailable, for a REGISTERED transport whose descriptor names it. transport = the host's own name, verbatim.
walletTransparentFundsAutoOn(String minZec) → String
The sheet’s conditional automation sentence while auto-shield is ON. {minZec} is the already-formatted minimum (e.g. "0.001").
walletTransportExplainBootstrappingNamed(String transport) → String
Sync sheet Connection explanation: as walletTransportExplainBootstrapping, naming the host's own transport verbatim.
walletTransportExplainUnansweredNamed(String transport) → String
Sync sheet Connection explanation: as walletTransportExplainUnanswered, naming the host's own transport verbatim. Only the FIRST clause takes the name — the either/or still says "the path", because naming the host's transport a second time would read as an accusation of it.
walletTransportExplainUnavailableNamed(String transport) → String
Sync sheet Connection explanation: as walletTransportExplainUnavailable, naming the host's own transport verbatim.
walletWatchOnlyBirthdayChosen(String date) → String
The chosen watch-only start month/year, carrying the honest warning that older funds won't appear (a watch-only import always scans from a floor — no full-scan arm — so the auditor importing an older wallet must not silently see an understated balance). Mirrors walletRestoreBirthdayChosen without the 'Scan all history' clause.

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

of(BuildContext context) → WalletLocalizations

Constants

delegate → const LocalizationsDelegate<WalletLocalizations>
localizationsDelegates → const List<LocalizationsDelegate>
A list of this localizations delegate along with the default localizations delegates.
supportedLocales → const List<Locale>
A list of this localizations delegate's supported locales.