v2.0.0-rc.1 release candidate
The API is frozen and later candidates carry fixes only, except the receipt-free and Safe create surface of /fhe-airdrop, which is @beta. Published on the next dist-tag; latest stays on 1.6.0 until 2.0.0.Airdrop v2 · Events · 51@tokenops/sdk/fhe-airdrop
Airdrop v2 event reference.
The SDK parses three contract events plus the ACL event. Everything else here is vendored, unparsed - decode it yourself.
Parsed by the SDK· 4
| Event | Args | Emitted on |
|---|---|---|
| ConfidentialAirdropCreated | (indexed airdrop, indexed token, airdropType, mode, indexed creator, userSalt) | factory.createEcdsaAirdrop / createMerkleAirdrop / createAndFund* succeeds. The create parses exactly this event to recover the deployed instance address, and the three compliance fields of CreateAirdropResult from the same receipt's ComplianceManagerCloned log rather than a follow-up registry call. A receipt that lacks or repeats either event throws ReceiptEventNotFoundError / ReceiptEventAmbiguousError. With waitForReceipt: false nothing is parsed - read both events from the executed transaction yourself. |
| ComplianceManagerCloned | (indexed airdrop, indexed managerClone, indexed complianceDelegate, managerImplementation) | Same create call. Names the per-instance compliance clone, its wired platform delegate (zero address means the compliance policy was off), and managerImplementation. The create parses it for those three CreateAirdropResult fields, and throws ReceiptEventNotFoundError when the receipt lacks it. |
| ClaimedAndUnwrapInitiated | (indexed claimant, beneficiary, indexed claimKey, unwrapRequestId) | claimAndUnwrap succeeds. parseUnwrapRequest (over a receipt you hold), readUnwrapRequest and useUnwrapRequest decode this instance's copy into an UnwrapRequest; pass its unwrapRequestId to the wrapper's finalizeUnwrap. |
| Allowed | (indexed caller, indexed account, indexed handle) | The FHEVM ACL grants a handle. Not part of any fhe-airdrop ABI - extractGrantedHandle filters the receipt for this event on the chain's ACL contract address. |
Factory - not parsed, decode yourself· 20
| Event | Args | Emitted on |
|---|---|---|
| ConfidentialAirdropFunded | (indexed airdrop, indexed token, amount) | factory.fundAirdrop / createAndFund* succeeds. |
| FeeCollectorSet | (indexed feeCollector) | factory.setFeeCollector succeeds. |
| SetDefaultGasFee | (gasFee) | factory.setDefaultGasFee succeeds. |
| SetMaxGasFee | (maxGasFee) | factory.setMaxGasFee succeeds (DEFAULT_ADMIN_ROLE) - the ceiling on every configurable fee. |
| NativeTokenRescued | (indexed recipient, amount) | Declared in the factory ABI through a shared interface, but the factory has no rescue entrypoint - it never fires here. Watch the instance's copy instead. |
| SetCustomFee | (indexed creator, gasFee) | factory.setCustomFee succeeds for a specific creator. |
| CustomFeeDisabled | (indexed creator) | factory.disableCustomFee succeeds. |
| EcdsaImplementationSet | (indexed implementation) | factory.setEcdsaImplementation succeeds. Affects new creates only - clones hardcode their impl in bytecode. |
| MerkleImplementationSet | (indexed implementation) | factory.setMerkleImplementation succeeds. |
| ComplianceManagerImplSet | (indexed implementation) | factory.setComplianceManagerImpl succeeds. |
| ComplianceDelegateSet | (indexed delegate) | factory.setComplianceDelegate succeeds - the platform delegate wired into future clones. |
| DefaultDelegateToComplianceSet | (on) | factory.setDefaultDelegateToCompliance succeeds - a chain-wide default, not a per-creator override. |
| CompliancePolicySet | (indexed creator, delegateToCompliance) | factory.setCompliancePolicy succeeds for a specific creator. |
| CompliancePolicyCleared | (indexed creator) | factory.clearCompliancePolicy succeeds - the creator reverts to the chain-wide default. |
| DefaultUpgradeableSet | (allowed) | factory.setDefaultUpgradeable succeeds - chain-wide UUPS eligibility default. |
| UpgradeabilityPolicySet | (indexed creator, allowed) | factory.setUpgradeabilityPolicy succeeds for a specific creator. |
| UpgradeabilityPolicyCleared | (indexed creator) | factory.clearUpgradeabilityPolicy succeeds. |
| RoleAdminChanged | (indexed role, indexed previousAdminRole, indexed newAdminRole) | Admin role for one of the factory's own five roles is reassigned (AccessControl). |
| RoleGranted | (indexed role, indexed account, indexed sender) | factory.grantRole succeeds for one of FEE_MANAGER_ROLE / IMPL_MANAGER_ROLE / COMPLIANCE_WIRING_ROLE / UPGRADE_MANAGER_ROLE / DEFAULT_ADMIN_ROLE. |
| RoleRevoked | (indexed role, indexed account, indexed sender) | factory.revokeRole / renounceRole succeeds on one of the factory's five roles. |
Airdrop instance - shared base, not parsed· 9
| Event | Args | Emitted on |
|---|---|---|
| AirdropInitialized | (indexed token, airdropType, indexed admin, indexed feeCollector, gasFee, startTime, endTime, canExtendClaimWindow, unwrappable, complianceManager) | The instance's initialize() runs, called once by the factory in the create transaction. Carries the claim window, canExtendClaimWindow, unwrappable and complianceManager; the block number is a getter (deploymentBlockNumber()), and the variant-specific fields are on ECDSAAirdropInitialized / MerkleAirdropInitialized. A filter built from an earlier prerelease ABI matches nothing. |
| ClaimPreviewed | (indexed recipient, indexed claimKey) | getClaimAmount succeeds on either variant - a fee-free, non-accounting preview. Not emitted by a rejected ECDSA preview, which performs no FHE op and grants no ACL once a replay guard is consumed. |
| ClaimWindowExtended | (oldEndTime, newEndTime) | extendClaimWindow succeeds (only if canExtendClaimWindow was true at create). |
| Claimed | (indexed claimant, beneficiary, indexed claimKey) | claim succeeds on either variant. The amount never appears in clear; claimKey is the on-chain replay/leaf identifier, not the amount. |
| ComplianceBalanceDisclosed | (indexed discloser, indexed party, encryptedAmount) | adminDiscloseBalanceToParty / adminBatchDiscloseBalanceToParties succeeds (DISCLOSURE_ADMIN_ROLE). |
| GasFeeWithdrawn | (indexed recipient, amount) | withdrawGasFee succeeds (FEE_COLLECTOR_ROLE). |
| HandleDisclosedToParty | (indexed discloser, indexed party, encryptedAmount) | discloseHandleToParty / batchDiscloseHandlesToParty succeeds. |
| WithdrawnConfidential | (indexed by, indexed recipient) | withdrawConfidential succeeds (TREASURY_ROLE) - sweeps the entire encrypted pool. |
| NativeTokenRescued | (indexed recipient, amount) | rescueNativeToken succeeds (RESCUER_ROLE) on a zero-fee campaign. |
Airdrop instance - access / pause / upgrade mixins, not parsed· 7
| Event | Args | Emitted on |
|---|---|---|
| Initialized | (version) | OpenZeppelin initializer version marker, fires once during the instance's initialize(). |
| Paused | (account) | pause() succeeds (PAUSER_ROLE). |
| Unpaused | (account) | unpause() succeeds (PAUSER_ROLE). |
| RoleAdminChanged | (indexed role, indexed previousAdminRole, indexed newAdminRole) | Admin role for one of the instance's roles is reassigned. FEE_COLLECTOR_ROLE is re-parented to itself at init, not to DEFAULT_ADMIN_ROLE. |
| RoleGranted | (indexed role, indexed account, indexed sender) | grantRole succeeds for any instance role (PAUSER_ROLE, WINDOW_ADMIN_ROLE, TREASURY_ROLE, RESCUER_ROLE, FEE_COLLECTOR_ROLE, UPGRADER_ROLE, DISCLOSURE_ADMIN_ROLE, plus SIGNER_ROLE / MERKLE_ADMIN_ROLE on the matching variant). |
| RoleRevoked | (indexed role, indexed account, indexed sender) | revokeRole / renounceRole succeeds. LastAdmin and LastFeeCollector floors can block this on-chain. |
| Upgraded | (indexed implementation) | upgradeToAndCall succeeds (UPGRADER_ROLE). Reverts at the proxy layer on clone-mode instances regardless of who calls it. |
ECDSA-only, not parsed· 2
| Event | Args | Emitted on |
|---|---|---|
| ECDSAAirdropInitialized | (dedupMode) | Same initialize() call, ECDSA side - carries dedupMode, which readDedupMode() also reads. |
| EIP712DomainChanged | () | The EIP-712 domain is (re)initialized during ECDSAConfidentialAirdrop.initialize (OpenZeppelin EIP712). |
Merkle-only, not parsed· 2
| Event | Args | Emitted on |
|---|---|---|
| MerkleAirdropInitialized | (indexed merkleRoot, isMerkleRootMutable) | Same initialize() call, Merkle side - carries merkleRoot and isMerkleRootMutable. |
| MerkleRootSet | (indexed oldRoot, indexed newRoot) | setMerkleRoot succeeds (MERKLE_ADMIN_ROLE) - carries both the old and new root, so an indexer can detect a rotation versus the initial set. |
Compliance manager, not parsed· 7
| Event | Args | Emitted on |
|---|---|---|
| ClientDelegateAdded | (indexed delegate) | complianceManager.addDelegate succeeds (DELEGATION_ADMIN_ROLE), and once at the clone's initialize for complianceAdmin (the creator when left zero), unless it is the platform delegate. |
| ClientDelegateRevoked | (indexed delegate) | complianceManager.revokeDelegate succeeds (DELEGATION_ADMIN_ROLE). |
| ComplianceDelegateSet | (indexed delegate) | Fires once, at the manager clone's initialize, only if the factory's compliance policy was on for that creator at create time. Irrevocable - no function ever clears it. |
| Initialized | (version) | OpenZeppelin initializer version marker for the compliance manager clone. |
| RoleAdminChanged | (indexed role, indexed previousAdminRole, indexed newAdminRole) | Admin role for DELEGATION_ADMIN_ROLE or DEFAULT_ADMIN_ROLE on this clone is reassigned. |
| RoleGranted | (indexed role, indexed account, indexed sender) | grantRole succeeds for DELEGATION_ADMIN_ROLE or DEFAULT_ADMIN_ROLE on this clone. |
| RoleRevoked | (indexed role, indexed account, indexed sender) | revokeRole / renounceRole succeeds on this clone. No floor here - emptying DEFAULT_ADMIN_ROLE permanently freezes the delegate set. |
parseEventLogs({ abi, logs }) and persist by topic. The ACL.Allowed event from the FHE coprocessor is the canonical source for handle ownership — see the indexing events recipe (coming soon).Browse recipes