TokenManager applies two transfer controls per token: a rate limit over a
fixed epoch window, and a per-transaction maximum transfer amount. The rate
limit tracks inbound and outbound flow; the max transfer amount applies to
outbound transfers. Both controls live on the TokenManager for the token. Use
this guide to configure them.
Attestation does not bypass destination TokenManager checks. An inbound
transfer can still be rejected by the rate limit or blocked while the token is
paused.
How the throttles behave
- Rate limit: Caps the absolute net flow (
|flowIn - flowOut|) within each fixed epoch window. It applies to inbound and outbound flow. The default window length is six hours. Setting the rate limit to0blocks both directions. After configuration, always verify the limit is non-zero before your firstcrossChainTransfer; a common mistake is configuring withrateLimit: 0and skipping this guide. - Max transfer amount: Caps the size of a single outbound transfer
transaction. Applies on top of the rate limit to prevent oversize single
transfers regardless of the headroom remaining in the rate-limit window.
Setting
maxTransferAmountto0blocks all outbound transfers. Usetype(uint256).max(or2n ** 256n - 1nin TypeScript) to disable the per-transfer cap.
1,000,000 over six hours:
- A user transfers
300,000out and100,000in during the window. Net outbound consumed is200,000. Remaining headroom:800,000. - A second user attempts to transfer
900,000out in the same window. The transfer reverts because net outbound would exceed1,000,000.
Prerequisites
Before you begin, ensure that you’ve:- Obtained the
tokenIdfor the token you want to configure. - Confirmed the wallet you’ll use holds the operator role for that token’s
TokenManager.
Steps
1
Discover the TokenManager address
Read the local
TokenManager address from the CrossChainTokenService:TypeScript
2
Set the rate limit
Call
setRateLimit with the maximum absolute net flow (|flowIn - flowOut|)
per window in the token’s smallest unit.TypeScript
3
Set the max transfer amount
Call
setMaxTransferAmount to cap the size of a single outbound transfer.TypeScript
4
Set the rate-limit window (optional)
The default window is six hours. To change it, call
setRateLimitWindow with
the new window length in seconds.TypeScript
5
Verify the configuration
Read the current values from the
TokenManager and compare them with the values
you selected for the preceding configuration steps. If you skipped the optional
window step, compare rateLimitWindow with the six-hour default. If rateLimit
is still 0, transfers revert until you call setRateLimit with a non-zero
amount (in the token’s smallest unit).TypeScript