Every key you handed out still opens the door.
Revokepad reads every delegate and delegated amount hanging off a Solana wallet, across both token programs, then builds the Revoke you sign. Drainers reuse old approvals, so check before they do.
Validated as a 32 byte public key before any request fires. No wallet connection.
rails
Two rails, one per token program
An approval on a Token-2022 account is invisible to a scan that only queries the classic program. Revokepad runs getTokenAccountsByOwner against both program IDs and hangs the result on the rail it came from.
Classic SPL Token. Every delegate and delegatedAmount on these accounts reads the same way it has since 2020.
Token-2022. Same delegate fields, plus mint extensions that can override them entirely.
exposure
Hooks you forgot
Three shapes of exposure show up over and over. Two of them you can take off the hook yourself. The third one you cannot.
The app you approved once for a swap
A delegate can move tokens out of that account whenever it wants, with no further prompt from you. The approval does not expire.
The number was larger than you read
delegatedAmount is the ceiling, and most wallets approve the whole balance rather than the trade. The tag prints the amount, in full.
The lock with no key on your side
A Token-2022 mint extension that grants an address authority over every account of that mint. Revoke cannot touch it, so it gets a black tag instead of a button.
procedure
How the key comes off
Four steps from paste to signed Revoke. Reads cost nothing and never touch a wallet.
Paste the address
Any Solana address. It is validated as a real public key before a single RPC call is made. No wallet connection.
Read both rails
getTokenAccountsByOwner runs once per token program with jsonParsed encoding, returning delegate and delegatedAmount for every account.
Sort the tags
Accounts with no delegate are skipped. Live delegates hang as tags with their amount. Permanent delegates are flagged as not revocable.
Sign the Revoke
Pick the tags to clear. Revokepad builds the Revoke instructions and your wallet signs. The account is re-read to confirm the hook is empty.
Fee percentiles are read from getRecentPrioritizationFees when this page loads. Until then the axis shows a labelled sample.
What $REVOKEPAD is for
What $REVOKEPAD is for
Reading your approvals costs nothing and Revokepad will keep it that way. Clearing forty of them is where cost lives: forty instructions, priority fees, a relayer to pay them. $REVOKEPAD is designed as the prepaid credit for that work and the funding for a public flag list of delegates that keep turning up in drain reports. Early access is capped while the relayer is tested. The reason to move now is not the token. It is the delegate still sitting on your account.
One prepaid credit, not forty fee prompts
The designed role is a single prepaid balance that covers relayer and priority fees for a sweep. You still sign as owner, because Revoke requires it. You just stop topping up fees per transaction.
Many Revokes, one signature
The batch relayer packs multiple Revoke instructions into as few transactions as size limits allow and acts as fee payer. A wallet with dozens of stale delegates signs once per batch, not once per account.
A funded flag list of repeat delegates
The plan is a public, append-only registry of delegate addresses that reappear in drain reports, readable by any wallet before it approves. Token funding pays for curation and hosting. It does not exist yet.
Alert windows on new approvals
Paid tiers are designed to re-scan watched wallets using incremental reads where the RPC supports changedSinceSlot, and alert when a new delegate appears. Window length and wallet count scale by tier.
What this token will never claim
No holder returns, no revenue share, no integrated partners, no partner data. Every clearance is priced in SOL because the network accepts nothing else. If any line here reads like an investment, the line is wrong.
access rails
Key rails
Four rails of increasing length. The first one is free and full, and scanning never moves behind a rail.
Unlimited scans of both token programs, PermanentDelegate flags, and single Revokes you sign and pay for yourself. Free, permanently.
rail 01Batch builder plus a prepaid relayer credit that covers fees for a capped number of Revoke instructions per month, with standard priority fee.
rail 02Larger batch quota, raised priority fee budget, and a new-approval alert window across several watched wallets.
rail 03API calls for scans and Revoke transaction building, the longest alert window, highest batch quota, and early read access to the flag registry.
rail 04Pre-launch. No tier is purchasable, no price is set, and no token role here is running.
sign-out sheet
Asked at the counter
01Do I need to connect a wallet to scan?+
No. Paste any Solana address. The scan reads public account state over RPC. A wallet only opens when you choose to sign a Revoke.
02Why scan two programs?+
Classic SPL Token and Token-2022 are separate program IDs. An approval on a Token-2022 account is invisible to a scan that only queries the classic program, so Revokepad queries both.
03Can Revokepad revoke for me?+
No. Revoke must be signed by the account owner. Revokepad builds the transaction and, on paid tiers, can pay the fee. The signature is always yours.
04What is a permanent delegate?+
A Token-2022 mint extension that gives an address authority over every account of that mint. You cannot revoke it. Revokepad flags it separately so you are never told a Revoke will fix it.
05What does a revoke cost?+
The network base fee of 5,000 lamports per signature plus any priority fee, paid in SOL. Batching several Revokes into one transaction reduces the number of signatures.
06Is $REVOKEPAD live?+
No. It is pre-launch and every token role described here is a design, not a running feature. Scanning and single revokes work without it.
plate
A small tool for one job
Revokepad is a small tool for one job: showing which addresses can still move your tokens, and taking that power back. It reads SPL Token and Token-2022 accounts directly, builds Revokes from the canonical program library, and never holds keys. It is pre-launch, it has no partners, and it does not pretend a revoke can undo a drain that already happened.