Skip to content
LogoLogo

Revoke Access Key

accessKey.revoke

Revokes an authorized access key.

Usage

import {  } from './viem.config'
 
const { ,  } = await ..({
  : '0x742d35Cc6634C0532925a3b844Bc9e7595f0bEbb',
})
 
.('Revoked access key:', )
.('Transaction hash:', .)
Revoked access key: 0x742d35Cc6634C0532925a3b844Bc9e7595f0bEbb
Transaction hash: 0x1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef

Asynchronous Usage

The examples above use a *Sync variant of the action, that will wait for the transaction to be included before returning.

If you are optimizing for performance, you should use the non-sync accessKey.revoke action and wait for inclusion manually:

import {  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = await ..({
  : '0x742d35Cc6634C0532925a3b844Bc9e7595f0bEbb',
})
const  = await ..({  }).
 
const {  } = ...(.)

Recipes

Rotate an Access Key

Combine accessKey.authorize with revoke to bring a replacement key live before retiring the old one, avoiding a signing gap.

import {  } from 'viem/utils'
import { ,  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = .('0x...')
 
// 1. Authorize the replacement key.
const  = .(.(), {
  : ,
})
await ..({
  : ,
  : .(30),
})
 
// 2. Retire the outgoing key.
const {  } = await ..({
  : '0x8ba1f109551bD432803012645Ac136ddd64DBA72',
})

Revoke a Compromised Key with an Admin Key

Pass an admin key as account so your incident response service can revoke keys while the root key stays offline.

import {  } from 'viem/utils'
import {  } from 'viem/tempo'
import {  } from './viem.config'
 
const  = .('0x...')
 
// Admin key previously authorized with `admin: true`.
const  = .(.(), {
  : ,
})
 
const {  } = await ..({
  : ,
  : '0x742d35Cc6634C0532925a3b844Bc9e7595f0bEbb',
})

Return Value

type ReturnType = {
  /** Account the key was revoked on. */
  account: Address
  /** Revoked access key address. */
  publicKey: Address
  /** Transaction receipt. */
  receipt: TransactionReceipt
}

The revoked access key details and the transaction receipt.

Parameters

accessKey

  • Type: Address | AccessKeyAccount

Access key to revoke. Pass an access key address or an AccessKeyAccount.

account (optional)

  • Type: Account | Address

Account that will be used to send the transaction.

feePayer (optional)

  • Type: Account | boolean

Fee payer for the transaction (TIP-1 gas sponsorship).

Pass true to defer the fee token to an external fee payer (e.g. a relay), or a local Account to co-sign the transaction as the fee payer.

feeToken (optional)

  • Type: Address | bigint

Fee token for the transaction.

Can be an unpaused USD-denominated TIP-20 token address or ID.

gas (optional)

  • Type: bigint

Gas limit for the transaction.

keyAuthorization (optional)

  • Type: KeyAuthorization

Signed key authorization to include with the transaction, authorizing an access key to act for the sending account.

maxFeePerGas (optional)

  • Type: bigint

Max fee per gas for the transaction.

maxPriorityFeePerGas (optional)

  • Type: bigint

Max priority fee per gas for the transaction.

nonce (optional)

  • Type: number

Nonce for the transaction.

nonceKey (optional)

  • Type: 'expiring' | 'random' | bigint

Nonce key for the transaction (TIP-1009 2D nonces).

Use 'expiring' to select an expiring nonce, which enables concurrent transaction submission without nonce ordering. Use 'random' to select a random key.

throwOnReceiptRevert (optional)

  • Type: boolean
  • Default: true

Whether a Sync action throws when the receipt reports a revert.

validAfter (optional)

  • Type: number

Unix timestamp after which the transaction can be included.

validBefore (optional)

  • Type: number

Unix timestamp before which the transaction must be included.