Revokepad — Every key you handed out still opens the door.

tool

Scan a wallet for live approvals

Paste the Solana wallet. Revokepad reads the approvals and delegates still attached to it.

sampleno wallet connection
lock cylinder

idle · awaiting address

sample data
sample · fee percentiles from /api/tips

Sample wallet. The approvals below are sample data computed in your browser — no wallet is connected and nothing is signed.

That is not a Solana address: a wallet is base58 and decodes to exactly 32 bytes.

Nothing scanned yet. The two rails below fill as each program returns.
tray

0 tags selected

Revoke must be signed by the account owner. Revokepad builds the instructions and never holds a key.

procedure
01 · Paste address

Lock cylinder input with base58 validation before any request fires.

Address checked as a valid 32-byte public key.

02 · Read both rails

Two hook rows filling as each program returns.

getTokenAccountsByOwner with encoding jsonParsed, once for TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA and once for TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb.

03 · Hang the tags

One tag per account with a delegate; accounts with no delegate are skipped, zero delegatedAmount is marked as nothing outstanding.

Parsed delegate, delegatedAmount, mint and token program per account.

04 · Flag the locks you cannot change

A black tag with a red bar on Token-2022 mints carrying PermanentDelegate, labelled not revocable.

PermanentDelegate extension read from the mint account.

05 · Take keys off

Selected tags move to a tray; preview marks rows cleared, then the Revoke transaction opens in the wallet.

Revoke instructions (discriminator 5) built with @solana-program/token, fee estimated via getFeeForMessage.

06 · Confirm empty hooks

Hooks re-read after confirmation; cleared tags are gone, any failures stay hung with the error.

Re-fetched delegate field after the confirmed signature.

what this read is
  • getTokenAccountsByOwner with jsonParsed, once per token program, over the site RPC proxy.
  • delegate and delegatedAmount are read per account, both programs.
  • PermanentDelegate extension is read from the Token-2022 mint account.
  • No address is sent anywhere except the same origin RPC route.
Pre-launch — the Solana contract address is published on this page first.
Independent project. Not affiliated with pump.fun, Solana Foundation, Backed Finance, Jupiter or Raydium. Nothing here is financial advice; numbers labeled illustrative are sample data.