Revokepad — Every key you handed out still opens the door.
procedure
How the key comes off
Reading an account costs nothing and touches no wallet. The only moment a wallet opens is the moment you sign a Revoke, and only you can do that.
hook 01Paste the addressAny Solana address. It is validated as a real public key before a single RPC call is made. No wallet connection.
hook 02Read both railsgetTokenAccountsByOwner runs once per token program with jsonParsed encoding, returning delegate and delegatedAmount for every account.
hook 03Sort the tagsAccounts with no delegate are skipped. Live delegates hang as tags with their amount. Permanent delegates are flagged as not revocable.
hook 04Sign the RevokePick the tags to clear. Revokepad builds the Revoke instructions and your wallet signs. The account is re-read to confirm the hook is empty.
both rails
Why two reads, not one
Classic SPL Token and Token-2022 are separate program IDs with separate account layouts. A scan against one says nothing about the other, so Revokepad queries both and reports each on its own rail.
TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DAclassic SPL Token · delegate + delegatedAmount
TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEbToken-2022 · same fields, plus mint extensions
| # | step | live call |
|---|---|---|
| 01 | Paste address Lock cylinder input with base58 validation before any request fires. | Address checked as a valid 32-byte public key. |
| 02 | Read both rails Two hook rows filling as each program returns. | getTokenAccountsByOwner with encoding jsonParsed, once for TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA and once for TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb. |
| 03 | Hang the tags One tag per account with a delegate; accounts with no delegate are skipped, zero delegatedAmount is marked as nothing outstanding. | Parsed delegate, delegatedAmount, mint and token program per account. |
| 04 | Flag the locks you cannot change A black tag with a red bar on Token-2022 mints carrying PermanentDelegate, labelled not revocable. | PermanentDelegate extension read from the mint account. |
| 05 | Take keys off Selected tags move to a tray; preview marks rows cleared, then the Revoke transaction opens in the wallet. | Revoke instructions (discriminator 5) built with @solana-program/token, fee estimated via getFeeForMessage. |
| 06 | Confirm empty hooks Hooks re-read after confirmation; cleared tags are gone, any failures stay hung with the error. | Re-fetched delegate field after the confirmed signature. |
checked against the docs
- Classic SPL Token program ID is TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA; Token-2022 is TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb; the Associated Token Account program is ATokenGPvbdGVxr1b2hvZbsiqW5xWH25efTNsLJA8knL.
- A classic SPL token account is 165 bytes and stores the owner, delegate and delegatedAmount fields; the Revoke instruction clears the delegate and resets the delegated amount to zero.
- TokenInstruction::Revoke packs to the single byte [5], i.e. discriminator 5 in the Token program's instruction set.
- A token account has at most one delegate; a new Approve replaces the previous one, and Revoke is signed only by the account owner (no delegate signature needed).
- getTokenAccountsByOwner with encoding jsonParsed returns the parsed delegate and delegatedAmount for each account; Helius adds a changedSinceSlot parameter for incremental syncing.
- The documented getFeeForMessage example returns a value of 5000 lamports, and simulateTransaction's documented example returns fee: 5000 for a token instruction.
- Revoke creates and closes no token account, so it returns no rent and costs only the network fee — SOLTidy puts that at roughly 0.000005 SOL per base-fee transaction, with many revokes batched into one transaction.
- Token-2022's PermanentDelegate is a mint-level authority that can transfer or burn any holder's balance and, per Solana's own docs, cannot be revoked by the token account owner.
- SIMD-0266's p-token rewrote the classic SPL Token implementation under the same program ID, cutting a transfer from about 4,645 CU to 76 CU while keeping instruction set and account layouts byte-for-byte compatible
- Classic SPL Token and Token-2022 accounts are not interchangeable: program ID, ATA derivation seeds and instruction sets must all match, and a production scanner must query both.
- Token-2022 PermanentDelegate is extension type 12 in the canonical ExtensionType enum, readable from the mint account's extension data via getAccountInfo.
- The read-and-revoke pattern is established on Solana by existing tools including solrevoker.com and SOLTidy (plus Revoke.cash for EVM); Revokepad is pre-launch and claims no partner data or live integrations.
what a revoke costspaid in SOL only
The network base fee is 5,000 lamports per signature, plus any priority fee the network is asking for at that moment. Batching several Revoke instructions into one transaction reduces the number of signatures. Revokepad never quotes a price as a promise, only the current network numbers it read.