Revokepad — Every key you handed out still opens the door.

plate

A small tool for one job

Revokepad is a small tool for one job: showing which addresses can still move your tokens, and taking that power back. It reads SPL Token and Token-2022 accounts directly, builds Revokes from the canonical program library, and never holds keys. It is pre-launch, it has no partners, and it does not pretend a revoke can undo a drain that already happened.

stamped on the cabinet
  • Reads only. No key is ever requested, held, or transmitted.
  • No wallet connection. The scan is a public account read over RPC.
  • Both programs. Classic SPL Token and Token-2022, every time.
  • Pre-launch. No partners, no audit, no token sale.
  • Honest limits. A Revoke stops future movement. It does not undo a drain that already happened.

stack

What it is built on

Reads go through the same-origin RPC proxy. Instruction building uses the canonical program library. Credits where they are due.

The stack

Two token programs, one list of what is still open

A revoke is only as good as the read behind it. These are the programs and calls a production build reads before it shows you a single approval.

SPL Token programon-chain program

Source of the per-account delegate and delegatedAmount state, and of the TokenInstruction::Revoke (discriminator 5) that clears them — the instruction Revokepad builds for classic accounts.

github.com/solana-program/token

@solana-program/token (0.13.0, Apache-2.0)on-chain program

Builds getRevokeInstruction and getApproveCheckedInstruction so the revoke transaction is constructed from the canonical client rather than hand-rolled instruction data.

www.npmjs.com/package/@solana-program/token

@solana/wallet-adapter-react (+ react-ui)SDK

Lets the user connect and sign the revoke transaction in their own wallet; Revokepad never holds keys and the scan works on a pasted address with no connection at all.

www.npmjs.com/package/@solana/wallet-adapter-react

simulateTransactionRPC method

Preflights the multi-revoke transaction before the user signs, so a bad instruction is caught and the real compute/fee is shown. Documented example returns fee: 5000.

solana.com/docs/rpc/http/simulatetransaction

getFeeForMessageRPC method

Produces the exact base cost of the revoke message (5000 lamports in the docs example), which is the honest core of the 'what clearing costs' figure.

solana.com/docs/rpc/http/getfeeformessage

getRecentPrioritizationFeesRPC method

Adds a current priority-fee estimate on top of the base fee so the quoted clearing cost reflects mainnet congestion rather than a stale number.

solana.com/docs/rpc

getAccountInfo (jsonParsed) on the mintSDK

Reads the mint's extension TLV to detect PermanentDelegate and other mint-level authorities that a token-account Revoke cannot touch.

www.helius.dev/docs/rpc/http/get-accounts

getSignaturesForAddress / getParsedTransactionRPC method

Optional provenance pass that dates an approval and attributes it to the dApp that requested it, so the ranking can consider age.

solana.com/docs/rpc

getLatestBlockhashRPC method

Stamps the revoke transaction with a fresh, unexpired blockhash so it lands on the first attempt.

solana.com/docs/rpc
Checked against the docs (12)
  • Classic SPL Token program ID is TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA; Token-2022 is TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb; the Associated Token Account program is ATokenGPvbdGVxr1b2hvZbsiqW5xWH25efTNsLJA8knL.
  • A classic SPL token account is 165 bytes and stores the owner, delegate and delegatedAmount fields; the Revoke instruction clears the delegate and resets the delegated amount to zero.
  • TokenInstruction::Revoke packs to the single byte [5], i.e. discriminator 5 in the Token program's instruction set.
  • A token account has at most one delegate; a new Approve replaces the previous one, and Revoke is signed only by the account owner (no delegate signature needed).
  • getTokenAccountsByOwner with encoding jsonParsed returns the parsed delegate and delegatedAmount for each account; Helius adds a changedSinceSlot parameter for incremental syncing.
  • The documented getFeeForMessage example returns a value of 5000 lamports, and simulateTransaction's documented example returns fee: 5000 for a token instruction.
  • Revoke creates and closes no token account, so it returns no rent and costs only the network fee — SOLTidy puts that at roughly 0.000005 SOL per base-fee transaction, with many revokes batched into one transaction.
  • Token-2022's PermanentDelegate is a mint-level authority that can transfer or burn any holder's balance and, per Solana's own docs, cannot be revoked by the token account owner.
  • SIMD-0266's p-token rewrote the classic SPL Token implementation under the same program ID, cutting a transfer from about 4,645 CU to 76 CU while keeping instruction set and account layouts byte-for-byte compatible
  • Classic SPL Token and Token-2022 accounts are not interchangeable: program ID, ATA derivation seeds and instruction sets must all match, and a production scanner must query both.
  • Token-2022 PermanentDelegate is extension type 12 in the canonical ExtensionType enum, readable from the mint account's extension data via getAccountInfo.
  • The read-and-revoke pattern is established on Solana by existing tools including solrevoker.com and SOLTidy (plus Revoke.cash for EVM); Revokepad is pre-launch and claims no partner data or live integrations.

Under the hood

  • Paste any Solana address with no wallet connection: the scan calls getTokenAccountsByOwner with encoding: jsonParsed, once per token program ID.
  • Read each parsed token account's delegate and delegatedAmount; accounts with no delegate are skipped, and a delegatedAmount of zero means nothing is outstanding.
  • Scan two program IDs — classic SPL Token (TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA) and Token-2022 (TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb) — because an approval is stored per token account under its own program.
  • For every mint found, read the mint account (jsonParsed) and flag Token-2022 PermanentDelegate as a mint-level authority the token account owner cannot revoke.
  • Rank approvals by blast radius: delegatedAmount versus the account's current balance (full-balance or near-full approvals first), then token value, then the age dated from getSignaturesForAddress.
  • Assemble one transaction containing many createRevokeInstruction calls; preflight it with simulateTransaction and price it with getFeeForMessage + getRecentPrioritizationFees.
  • State the cost honestly in SOL — base fee (5,000 lamports per signature) plus priority — and note plainly that Revoke creates and closes no account, so it reclaims zero rent; the ~0.00204 SOL token-account rent stays locked either way.
  • The user signs in their own wallet via wallet-adapter (signAndSendTransaction); Revokepad builds and simulates but holds no keys.
  • Scope note kept in the UI: most Solana drains move tokens outright or hand over ownership with SetAuthority rather than through a delegation, so revoking is wallet hygiene, not a recovery tool.
voice

A locksmith's key cabinet in a back office: sage pegboard, red-orange key tags, stamped serials. Voice is a terse locksmith: names the key, names the door, takes it off the hook.

surface

pegboard: 4px holes on a 28px grid at 10% ink, plus 2% matte grain

what this page will not do

No glowing shields, no padlock stock icons, no fake security scores, no counter of wallets protected, no partner logo strip, no gradient blobs, no promise that a revoke undoes a drain that already happened.

Pre-launch — the Solana contract address is published on this page first.
account

Reads every delegate on your Solana token accounts, both programs, and builds the Revoke you sign. Reads are free. Pre-launch.

That delegate you approved for a mint months ago can still move the tokens. Paste your address, see every live delegate across SPL Token and Token-2022, take the keys off the hook.

revokepad

Independent project. Not affiliated with pump.fun, Solana Foundation, Backed Finance, Jupiter or Raydium. Nothing here is financial advice; numbers labeled illustrative are sample data.