Skip to content
LogoLogo

Authorize Access Key

accessKey.authorize

Authorizes an access key by signing a key authorization and sending a transaction.

Usage

import {  } from 'viem/utils'
import {  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = .('0x...')
const  = .(.(), {
  : ,
})
 
const { ,  } = await ..({
  ,
  : .((.() + 30_000) / 1000),
})
 
.('Access key:', )
.('Transaction hash:', .)
Access key: 0x742d35Cc6634C0532925a3b844Bc9e7595f0bEbb
Transaction hash: 0x1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef

Asynchronous Usage

The examples above use a *Sync variant of the action, that will wait for the transaction to be included before returning.

If you are optimizing for performance, you should use the non-sync accessKey.authorize action and wait for inclusion manually:

import {  } from 'viem/utils'
import { ,  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = .('0x...')
const  = .(.(), {
  : ,
})
 
const  = await ..({
  ,
  : .((.() + 30_000) / 1000),
})
const  = await ..({  }).
 
const {  } = ...(.)

Recipes

Issue a Checkout Access Key with Least Privilege

Combine expiry, limits, and scopes so a browser access key can only pay the merchant, up to a cap, until checkout expires.

import { ,  } from 'viem/utils'
import { ,  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = .('0x...')
const  = .(.(), {
  : ,
})
 
const  = '0x742d35Cc6634C0532925a3b844Bc9e7595f0bEbb'
 
const {  } = await ..({
  ,
  : .(1),
  : [
    {
      : .('50', 6),
      : '0x20c0000000000000000000000000000000000000',
    },
  ],
  : [
    {
      : '0x20c0000000000000000000000000000000000000',
      : [],
      : 'transfer(address,uint256)',
    },
  ],
})

Grant a Server Agent a Recurring Budget

Pass a period on a limit to give a server-side agent a budget that resets monthly, and an expiry to bound the key's lifetime.

import { ,  } from 'viem/utils'
import { ,  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = .('0x...')
const  = .(.(), {
  : ,
})
 
const {  } = await ..({
  : ,
  : .(90),
  : [
    {
      : .('5000', 6),
      : 30 * 24 * 60 * 60, // resets every 30 days
      : '0x20c0000000000000000000000000000000000000',
    },
  ],
})

Delegate Key Management to an Admin Key

Pass admin: true to authorize an unrestricted admin key, then use it as the sending account to manage other keys while the root key stays offline.

import {  } from 'viem/utils'
import { ,  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = .('0x...')
 
// 1. Authorize an unrestricted admin key for the ops service.
const  = .(.(), {
  : ,
})
await ..({
  : ,
  : true,
})
 
// 2. The admin key authorizes scoped keys without the root key.
const  = .(.(), {
  : ,
})
const {  } = await ..({
  : ,
  : ,
  : .(1),
})

Return Value

type ReturnType = {
  /** Account the key was authorized on. */
  account: Address
  /** Unix timestamp when the key expires. */
  expiry: bigint
  /** Access key address. */
  publicKey: Address
  /** Signature scheme identifier. */
  signatureType: number
  /** Transaction receipt. */
  receipt: TransactionReceipt
}

The authorized access key details and the transaction receipt.

Parameters

accessKey

  • Type: Address | AccessKeyAccount | { address: Address; type: SignatureEnvelope.Type } | { publicKey: Hex; type: SignatureEnvelope.Type }

Access key to authorize.

admin

  • Type: boolean

Whether to authorize the key as an admin key. Admin keys are unrestricted and can manage the account's other access keys; expiry, limits, and scopes are ignored. Requires the T6 hardfork.

chainId

  • Type: number | bigint

Chain ID for replay protection.

expiry

  • Type: number

Unix timestamp when the key expires.

limits

  • Type: readonly { token: Address; limit: bigint; period?: number }[]

Spending limits per token.

scopes

  • Type: readonly { address: Address; selector?: Hex | string; recipients?: readonly Address[] }[]

Call scopes restricting which contracts, selectors, and recipients the key can call.

witness

  • Type: Hex

Optional 32-byte witness bound into the authorization's signing hash.

account (optional)

  • Type: Account | Address

Account that will be used to send the transaction.

feePayer (optional)

  • Type: Account | boolean

Fee payer for the transaction (TIP-1 gas sponsorship).

Pass true to defer the fee token to an external fee payer (e.g. a relay), or a local Account to co-sign the transaction as the fee payer.

feeToken (optional)

  • Type: Address | bigint

Fee token for the transaction.

Can be an unpaused USD-denominated TIP-20 token address or ID.

gas (optional)

  • Type: bigint

Gas limit for the transaction.

keyAuthorization (optional)

  • Type: KeyAuthorization

Signed key authorization to include with the transaction, authorizing an access key to act for the sending account.

maxFeePerGas (optional)

  • Type: bigint

Max fee per gas for the transaction.

maxPriorityFeePerGas (optional)

  • Type: bigint

Max priority fee per gas for the transaction.

nonce (optional)

  • Type: number

Nonce for the transaction.

nonceKey (optional)

  • Type: 'expiring' | 'random' | bigint

Nonce key for the transaction (TIP-1009 2D nonces).

Use 'expiring' to select an expiring nonce, which enables concurrent transaction submission without nonce ordering. Use 'random' to select a random key.

throwOnReceiptRevert (optional)

  • Type: boolean
  • Default: true

Whether a Sync action throws when the receipt reports a revert.

validAfter (optional)

  • Type: number

Unix timestamp after which the transaction can be included.

validBefore (optional)

  • Type: number

Unix timestamp before which the transaction must be included.