Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia Ethereum · Entry 13

Token approvals: what a spender can do after you authorize it

Theme
Ethereum
Sources
7 cited records
Reading time
About 3 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Token approvals: what a spender can do after you authorize it
FactDetailSource
ERC-20 allowanceThe remaining amount a spender is authorized to transfer[1]
NFT scopeA token or an operator-wide permission, depending on the method[2]
RevocationChanges permission; it does not reverse a completed transfer[1][2]
01

Connection does not grant the same authority as approval

Connecting an account to a site and granting an on-chain token allowance are separate actions. ERC-20 approval identifies a spender and an amount under the token’s rules. The spender later uses transferFrom to act within the allowance.

A supported permit can authorize an allowance by signature, with another party paying to submit it. The ERC-2612 deadline limits accepting that permit; it does not automatically expire the allowance already established. Disconnecting the site does not change this on-chain state.

02

Example: authorizing 100 units is not the same as paying 100 units

Suppose a token balance is 300 units and an account approves a spender for 100. The approval itself need not change the 300-unit balance. If the spender then transfers 40 under an ordinary decreasing-allowance implementation, 60 remains authorized.

The example assumes that implementation’s allowance behavior. A very large or specially handled allowance can leave continuing authority. Read the amount and spender, not simply the name of the application displaying the request.

03

NFT operators can receive broader permissions

ERC-721 distinguishes one-token approval from approval-for-all for an operator. ERC-1155’s standard operator approval covers the owner’s token types within that contract.

Those permissions do not map neatly to an ERC-20 numerical allowance. A wallet should describe whether the request authorizes a quantity, a specific token or an operator across a collection.

04

Closing a tab and revoking permission affect different systems

Disconnecting a site changes its wallet connection or account access. An onchain allowance lives in contract state and requires the appropriate state change to alter it. Closing a browser does not edit that state.

Revocation also cannot undo assets already transferred. A pending revocation may compete with other transactions before inclusion. ERC-20 additionally warns about changing an existing nonzero allowance and recommends an interface flow through zero.

Direct answers

Questions people ask

Is an approval itself always a transfer?

No. It commonly updates permission so a spender can perform a separate transfer later. The approval transaction can still consume gas.

Does disconnecting an application revoke its allowance?

No. Provider connection state and token-contract permission are separate. The relevant onchain allowance or approval must be changed.

Can revocation recover tokens already moved?

No. Revoking permission limits subsequent use once effective; it is not a reversal of a completed token transfer.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

A token approval gives another address or contract permission to move specified assets under the token’s rules. ERC-20 uses spending allowances; NFT standards offer token-specific or operator-wide permissions. Disconnecting a website is different from changing an onchain approval, and an approval can remain after the original interaction ends.

Scope: Ethereum. Verification: verified · 2026-10-02T18:16:35.976Z.

Link to this claim
ERC-20 allowance: The remaining amount a spender is authorized to transfer

Scope: Ethereum. Verification: verified · 2026-10-02T18:16:35.976Z.

Link to this claim
NFT scope: A token or an operator-wide permission, depending on the method

Scope: Ethereum. Verification: verified · 2026-10-02T18:16:35.976Z.

Link to this claim
Revocation: Changes permission; it does not reverse a completed transfer

Scope: Ethereum. Verification: verified · 2026-10-02T18:16:35.976Z.

Link to this claim
Revision history
  1. — First publication after primary-source research and independent automated verification.
  2. — Expanded explanation: Connection does not grant the same authority as approval. Worked examples are illustrative; source checks and independent verification are recorded separately.

On the Know who controls the funds path · Learn next: Protocol upgrades and admin powers: who can change what

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. ERC-20: Token StandardEthereum Request for Comments

    Defines fungible token balances, optional display metadata and spending allowance behavior.

    Locator: Methods: decimals, balanceOf, transfer, approve, transferFrom, allowance · Version / scope: 583335b7912e51b1ea515bb662532dd29b27e786 · Retrieved: 2026-10-02T14:35:55.037727+00:00Open source
  2. ERC-721: Non-Fungible Token StandardEthereum Request for Comments

    Defines token-specific ownership, transfer approvals, metadata pointers and receiving-contract checks.

    Locator: Specification; metadata extension; transfer and operator methods · Version / scope: 583335b7912e51b1ea515bb662532dd29b27e786 · Retrieved: 2026-10-02T14:35:55.241155+00:00Open source
  3. ERC-1155: Multi Token StandardEthereum Request for Comments

    Defines per-ID balances, batched transfers, receiver checks and operator-wide approval.

    Locator: Abstract; specification; safe transfer rules; metadata; approval · Version / scope: 583335b7912e51b1ea515bb662532dd29b27e786 · Retrieved: 2026-10-02T14:35:55.247570+00:00Open source
  4. EIP-1193: Ethereum Provider JavaScript APIEthereum Improvement Proposals

    Defines wallet provider requests, account/chain changes and the boundary between provider communication and wallet permission.

    Locator: request; events; security considerations; user account exposure · Version / scope: ac912ca6a9685590345dd8e5736cda75976d0131 · Retrieved: 2026-10-02T14:35:55.037764+00:00Open source
  5. Gas and feesethereum.org contributors

    Supports gas units, ETH/gwei units, base/priority fees, resource limits and charges for executed failed transactions.

    Locator: How are gas fees calculated; base fee; gas limit · Version / scope: dcc900ff125891da5b6c723b905a7113cf1bd864 · Retrieved: 2026-10-02T14:35:40.393022+00:00Open source
  6. ERC-20 Token StandardEthereum Improvement Proposals

    Token supply, displayed units and balance accounting.

    Locator: totalSupply; balanceOf; transfer; decimals; approve; allowance; transferFrom; Transfer · Version / scope: ERC-20 · Retrieved: 2026-10-02T17:03:45.826ZOpen source
  7. Permit Extension for EIP-20 Signed ApprovalsEthereum Improvement Proposals

    Signed token allowances, deadlines, nonces and domain checks.

    Locator: Specification; Security Considerations · Version / scope: EIP/ERC-2612; retrieved document hash recorded · Retrieved: 2026-10-02T17:03:42.295ZOpen source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Token approvals: what a spender can do after you authorize it.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/ethereum-token-approvals/