Skip to content

Per-instance policy for LOC creation and redemption, passed as locConfig on AnvilDependencies. Two kinds of field live here: creation constraints the SDK enforces (locBeneficiaryAllowList, staticLOCTokenAddressAllowlist, and the hardcoded beneficiary / expiration), and presentation defaults only the @anvil/sdk/react components read (disableLOCExtension, the redeem-destination fields, allowedCreatorAddressFilter).

Remarks

Every enforced field is client-side defense-in-depth against integration bugs, not a protocol rule: it guards calls made through this SDK instance only. Check a config for shape errors with validateUserProvidedLOCConfig. The hardcoded beneficiary / expiration fields are checked by the validate* functions but not by the workflow builders themselves, so call validate* before building.

Example

const locConfig: LOCConfig = {
// Enforced by the SDK: builders and validate* reject other values.
locBeneficiaryAllowList: [
'0x3333333333333333333333333333333333333333',
],
staticLOCTokenAddressAllowlist: [
testnetProfile.contracts.USDC.address,
],
// Enforced by validate* only; the React create form pre-fills and
// hides it.
beneficiary: {
value: '0x3333333333333333333333333333333333333333',
hidden: true,
},
// Read by the React components only.
disableLOCExtension: true,
defaultDestinationAddress:
'0x3333333333333333333333333333333333333333',
destinationAddressReadOnly: true,
};
// Shape check; resolves to undefined when the config is clean.
const errors = await validateUserProvidedLOCConfig(locConfig);
if (errors) throw new Error(JSON.stringify(errors));
return new AnvilSDK({
profile: testnetProfile,
publicClient,
locConfig,
});

Properties

allowedCreatorAddressFilter?

optional allowedCreatorAddressFilter?: `0x${string}`[];

Creator addresses whose LOCs the beneficiary experience lists; the React beneficiary views pass it as the creators filter of the outstanding-LOC query, and empty or unset lists LOCs from every creator. Read scoping only — not a creation gate and never checked on a write.


beneficiary?

optional beneficiary?: HardcodedField<`0x${string}`>;

Fix a single beneficiary for every LOC this instance creates: validate* reports BeneficiaryMustUseConfigured when the supplied beneficiary differs, and the React create form pre-fills it (hiding the field when hidden is true). Not checked by the builders themselves — only the allowlist is — so call validate* first.


cancelAuthorization?

optional cancelAuthorization?: CancelLOCAuthorizationSource;

Default beneficiary authorization for cancellation UI. A component prop overrides this source as a whole; null deliberately disables it for one surface, while resolver functions receive the selected LOC at click time.


createLOC?

optional createLOC?: CreateLOCComponentConfig;

Provider-level creation policy and reference config for the beta UI.


defaultDestinationAddress?

optional defaultDestinationAddress?: `0x${string}`;

Address the React redeem form pre-fills as where redeemed funds go; unset pre-fills the LOC’s beneficiary. Core redeem builders take the destination from their params and do not read this.


destinationAddressReadOnly?

optional destinationAddressReadOnly?: boolean;

When true, the React redeem form does not let the user edit the destination (defaultDestinationAddress, or the LOC’s beneficiary when that is unset). UI only; defaults to false.


disableLOCExtension?

optional disableLOCExtension?: boolean;

Hide the “extend” action in the @anvil/sdk/react LOC components. UI only: sdk.loc.buildExtendWorkflow and validateExtend ignore it; defaults to false.


dynamicLOCCollateralTokenAddressAllowlist?

optional dynamicLOCCollateralTokenAddressAllowlist?: `0x${string}`[];

Token addresses permitted to collateralize dynamic LOCs through this SDK instance. Empty or unset permits any protocol-enabled collateral token.


dynamicLOCCreditedTokenAddressAllowlist?

optional dynamicLOCCreditedTokenAddressAllowlist?: `0x${string}`[];

Token addresses permitted as dynamic-LOC credited assets through this SDK instance. Empty or unset permits any protocol-enabled credited token.


expiration?

optional expiration?: HardcodedField<Date>;

Fix a single expiration for every LOC this instance creates: validate* reports ExpirationMustUseConfigured when expirationTimestampSeconds does not equal this date to the second, and the React create form pre-fills it (hiding the field when hidden is true). Not checked by the builders — call validate* first.


extendLOC?

optional extendLOC?: ExtendLOCComponentConfig;

Provider-level defaults for the beta extension UI.


locBeneficiaryAllowList?

optional locBeneficiaryAllowList?: `0x${string}`[];

Beneficiary addresses LOCs may be created for. When non-empty, the creation builders (build*Workflow, buildCreateStaticLOCTransaction) and the validate* functions reject any other beneficiary with InvalidArgumentError / a validation issue.

Remarks

This is client-side defense-in-depth against integration bugs, not a security boundary: it only guards calls made through this SDK instance. A party who controls the client — e.g. by calling the LetterOfCredit contract directly, or by using a modified build of this SDK — is not stopped by it, and the protocol itself does not restrict LOC beneficiaries.


modifyLOCCollateral?

optional modifyLOCCollateral?: ModifyLOCCollateralComponentConfig;

Provider-level defaults for the beta collateral-modification UI.


redeemLiquidation?

optional redeemLiquidation?: RedeemLiquidationSource;

Default liquidator selection for the React redeem form. A fixed selection is reused as-is; a resolver is called at submission time with the current LOC, amount, and destination; null explicitly selects self-liquidation. A redeemLiquidation prop on RedeemLOCFlow or RedeemLOCForm replaces this setting as a whole.

Core builders do not read this presentation setting. They receive the resolved liquidator and liquidatorParams in RedeemLOCParams.


staticLOCTokenAddressAllowlist?

optional staticLOCTokenAddressAllowlist?: `0x${string}`[];

Token addresses a static LOC may be denominated in (a static LOC’s collateral and credited token are the same asset); empty or unset means any protocol collateral token. When non-empty, creation builders reject any other token with InvalidArgumentError, with the same “not a security boundary” caveat as LOCConfig.locBeneficiaryAllowList.