Revokepad — Every key you handed out still opens the door.
tool
Scan a wallet for live approvals
Paste the Solana wallet. Revokepad reads the approvals and delegates still attached to it.
idle · awaiting address
Sample wallet. The approvals below are sample data computed in your browser — no wallet is connected and nothing is signed.
That is not a Solana address: a wallet is base58 and decodes to exactly 32 bytes.
classic SPL Token · awaiting read
Token-2022 · awaiting read
0 tags selected
Revoke must be signed by the account owner. Revokepad builds the instructions and never holds a key.
Lock cylinder input with base58 validation before any request fires.
Address checked as a valid 32-byte public key.
Two hook rows filling as each program returns.
getTokenAccountsByOwner with encoding jsonParsed, once for TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA and once for TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb.
One tag per account with a delegate; accounts with no delegate are skipped, zero delegatedAmount is marked as nothing outstanding.
Parsed delegate, delegatedAmount, mint and token program per account.
A black tag with a red bar on Token-2022 mints carrying PermanentDelegate, labelled not revocable.
PermanentDelegate extension read from the mint account.
Selected tags move to a tray; preview marks rows cleared, then the Revoke transaction opens in the wallet.
Revoke instructions (discriminator 5) built with @solana-program/token, fee estimated via getFeeForMessage.
Hooks re-read after confirmation; cleared tags are gone, any failures stay hung with the error.
Re-fetched delegate field after the confirmed signature.
- getTokenAccountsByOwner with jsonParsed, once per token program, over the site RPC proxy.
- delegate and delegatedAmount are read per account, both programs.
- PermanentDelegate extension is read from the Token-2022 mint account.
- No address is sent anywhere except the same origin RPC route.
Pre-launch — the Solana contract address is published on this page first.