Skip to content
Thyme Docs

Permission Manifests

A task can include permissions.json beside index.ts. Upload stores this declaration with the immutable release. Flow resolves it against the profile's chain and executable args, checks coverage during configuration, and rejects undeclared calls before transaction submission.

functions/update-value/permissions.json
{
  "calls": [
    {
      "target": { "arg": "targetAddress" },
      "function": "setValue(uint256)"
    }
  ]
}

A target may reference one top-level address argument or supply explicit addresses keyed by decimal chain ID. function accepts a Solidity signature or four-byte selector. The file has only a calls property; do not add a version property. See the manifest reference for the complete format and limits.

What the declaration means

DeclarationBehavior
No fileUndeclared release; compatibility behavior allows binding, while the profile's own authorization still applies.
{ "calls": [] }Explicitly no contract calls required; a real run returning calls is blocked.
Non-empty callsEach required target/selector must resolve and, for a scoped profile, be covered.

A declaration is not a permission grant. It describes required calls; it cannot enable a module, add a target, or sign a scope update for the owner. Legacy profiles have no comparable on-chain allowlist, but declared releases still face runtime declaration checks.

Coverage follows configuration

Flow rechecks coverage when creating or resuming an executable, editing args, switching its release, or reassigning its profile. Changing an address argument may change the required permission even when the source code stays the same. A pending release switch is checked again before commit.

If coverage is missing, review the exact target and selector, obtain the owner's scope approval through profile settings, then retry the operation. An unresolved argument or missing chain mapping blocks the operation instead of assuming access.

Webhook custom args are also subject to runtime declaration checks. A local warning about an undeclared call does not grant cloud permission.

Limits of scope

Roles scopes restrict target and selector, not token recipient or amount. The manifest likewise does not constrain calldata parameters. Read code and review inputs before authorizing asset-moving selectors. Calls without a four-byte selector cannot be represented in a declared manifest.

The manifest allows up to 50 distinct declarations and 16 KiB of UTF-8 JSON. Runtime call limits are separate and may be narrower for a particular submission route; see runtime limits.