2.0 RC docsView 1.x docs
v2.0.0-rc.1 release candidate
The API is frozen and later candidates carry fixes only, except the receipt-free and Safe create surface of /fhe-airdrop, which is @beta. Published on the next dist-tag; latest stays on 1.6.0 until 2.0.0.
WriteuseMutationencrypts input Curated

useDisperse

Multi-recipient confidential transfer in one tx — batch-encrypts amounts + per-recipient ACL.

Import
@tokenops/sdk/fhe-disperse/react
Return
{ mutate, mutateAsync, isPending, error, data }
Lifecycle
Write

Description

Disperse confidential tokens to multiple recipients. The SDK validates inputs, computes the wallet-mode subtotal split, encrypts all amounts + subtotals in a single proof batch, computes msg.value for gas-fee modes, and dispatches to the correct contract entry point based on mode.

Amount units: TokenOps confidential (ERC-7984) tokens use a 6-decimals convention (1 token = 1_000_000 base units), not the 18 decimals typical of ERC-20. Amount parameters are base units of the token's actual decimals: for the CTTT test token (6 decimals) 1_000_000n = 1 CTTT, while the transparent TTT test token uses 18 decimals. Every entry of amounts[] follows this convention.

Encryptor resolution. The hook-level encryptor (from DisperseHookOptions) is forwarded lazily to the SDK client. If missing when the mutation runs, the SDK throws MissingEncryptorError (code: "TOKENOPS_MISSING_ENCRYPTOR"). Capture useZamaSDK() once at the top of your component and forward () => zamaSDK - never () => useZamaSDK() inline (calls a React hook inside a mutation body, violating the rules of hooks).

With waitForReceipt: false (Safe / multisig) the mutation resolves to a PendingDisperseResult; narrow with if (data.pending) before reading distributions.

After success, invalidate useGetFees, useHasApprovedSubwallets, and any downstream token-balance queries owned by the consumer.

Silent-zero transfers. ERC-7984 transfers do not revert when the sender's encrypted balance is insufficient — the transfer succeeds and moves an encrypted zero instead. This is by design: reverting would leak balance information. The transaction receipt alone cannot tell you whether value actually moved.

Signature

@tokenops/sdk/fhe-disperse/react
ts
function useDisperse(options?: DisperseHookOptions): UseMutationResult<DisperseResult | PendingDisperseResult, Error, DisperseArgs & ReceiptMode>;

Run it

Connect your wallet and click Disperse with rc.1 — this dispatches a real Sepolia transaction through the same runner the stories use.

Interactive · live Sepolia tx
Loading editor…
Edit any input above, then press ⌘↵ to run.
Console0 lines
No output yet. Run the snippet to see logs stream in.

Example

@tokenops/sdk/fhe-disperse/react · @example
tsx
function Component() {
  const zamaSDK = useZamaSDK();
  const disperse = useDisperse({ encryptor: () => zamaSDK });
  disperse.mutate({ token, mode: "direct", recipients, amounts });
}

Pulled directly from the hook's TSDoc block — the same snippet your IDE shows on hover.

Errors

This mutation can reject with SDK-level, product-level, or generic-fallback errors. Product classes carry the offending value as fields — render them inline instead of a generic "transaction failed." See Disperse 2.0 › Errors for the per-class recovery table.

Invalidation recipe

After this mutation succeeds, invalidate the queries it affects so consumer UI re-fetches fresh state. The SDK never auto-invalidates — that's a consumer decision (different apps cache different shapes).

patterns/invalidation.ts
ts
import { useQueryClient } from "@tanstack/react-query";

const queryClient = useQueryClient();
const disperse = useDisperse(/* options */);

disperse.mutate(args, {
  onSuccess() {
    // Coarse invalidation: refresh every cached read on this product surface.
    queryClient.invalidateQueries({
      queryKey: ["tokenops-sdk", "fhe-disperse"],
    });
  },
});

See also

Other Write hooks in disperse 2.0: