API ReferenceSetup and configurationInterface
LOCConfig
Per-instance policy for LOC creation and redemption, passed as locConfig on
AnvilDependencies. Two kinds of field live here: creation constraints the
SDK enforces (locBeneficiaryAllowList, staticLOCTokenAddressAllowlist, and the hardcoded
beneficiary / expiration), and presentation defaults only the @anvil/sdk/react components read
(disableLOCExtension, the redeem-destination fields, allowedCreatorAddressFilter).
Remarks
Every enforced field is client-side defense-in-depth against integration bugs, not a protocol rule:
it guards calls made through this SDK instance only. Check a config for shape errors with
validateUserProvidedLOCConfig. The hardcoded beneficiary / expiration fields are checked by
the validate* functions but not by the workflow builders themselves, so call validate* before
building.
Example
const locConfig: LOCConfig = { // Enforced by the SDK: builders and validate* reject other values. locBeneficiaryAllowList: [ '0x3333333333333333333333333333333333333333', ], staticLOCTokenAddressAllowlist: [ testnetProfile.contracts.USDC.address, ], // Enforced by validate* only; the React create form pre-fills and // hides it. beneficiary: { value: '0x3333333333333333333333333333333333333333', hidden: true, }, // Read by the React components only. disableLOCExtension: true, defaultDestinationAddress: '0x3333333333333333333333333333333333333333', destinationAddressReadOnly: true,};
// Shape check; resolves to undefined when the config is clean.const errors = await validateUserProvidedLOCConfig(locConfig);if (errors) throw new Error(JSON.stringify(errors));
return new AnvilSDK({ profile: testnetProfile, publicClient, locConfig,});Properties
allowedCreatorAddressFilter?
optional allowedCreatorAddressFilter?: `0x${string}`[];Creator addresses whose LOCs the beneficiary experience lists; the React beneficiary views pass it as the creators filter of the outstanding-LOC query, and empty or unset lists LOCs from every creator. Read scoping only — not a creation gate and never checked on a write.
beneficiary?
optional beneficiary?: HardcodedField<`0x${string}`>;Fix a single beneficiary for every LOC this instance creates: validate* reports
BeneficiaryMustUseConfigured when the supplied beneficiary differs, and the React create form
pre-fills it (hiding the field when hidden is true). Not checked by the builders themselves —
only the allowlist is — so call validate* first.
cancelAuthorization?
optional cancelAuthorization?: CancelLOCAuthorizationSource;Default beneficiary authorization for cancellation UI. A component prop overrides this source as a
whole; null deliberately disables it for one surface, while resolver functions receive the
selected LOC at click time.
createLOC?
optional createLOC?: CreateLOCComponentConfig;Provider-level creation policy and reference config for the beta UI.
defaultDestinationAddress?
optional defaultDestinationAddress?: `0x${string}`;Address the React redeem form pre-fills as where redeemed funds go; unset pre-fills the LOC’s beneficiary. Core redeem builders take the destination from their params and do not read this.
destinationAddressReadOnly?
optional destinationAddressReadOnly?: boolean;When true, the React redeem form does not let the user edit the destination
(defaultDestinationAddress, or the LOC’s beneficiary when that is unset). UI only; defaults to
false.
disableLOCExtension?
optional disableLOCExtension?: boolean;Hide the “extend” action in the @anvil/sdk/react LOC components. UI only:
sdk.loc.buildExtendWorkflow and validateExtend ignore it; defaults to false.
dynamicLOCCollateralTokenAddressAllowlist?
optional dynamicLOCCollateralTokenAddressAllowlist?: `0x${string}`[];Token addresses permitted to collateralize dynamic LOCs through this SDK instance. Empty or unset permits any protocol-enabled collateral token.
dynamicLOCCreditedTokenAddressAllowlist?
optional dynamicLOCCreditedTokenAddressAllowlist?: `0x${string}`[];Token addresses permitted as dynamic-LOC credited assets through this SDK instance. Empty or unset permits any protocol-enabled credited token.
expiration?
optional expiration?: HardcodedField<Date>;Fix a single expiration for every LOC this instance creates: validate* reports
ExpirationMustUseConfigured when expirationTimestampSeconds does not equal this date to the
second, and the React create form pre-fills it (hiding the field when hidden is true). Not
checked by the builders — call validate* first.
extendLOC?
optional extendLOC?: ExtendLOCComponentConfig;Provider-level defaults for the beta extension UI.
locBeneficiaryAllowList?
optional locBeneficiaryAllowList?: `0x${string}`[];Beneficiary addresses LOCs may be created for. When non-empty, the creation builders
(build*Workflow, buildCreateStaticLOCTransaction) and the validate* functions reject any other
beneficiary with InvalidArgumentError / a validation issue.
Remarks
This is client-side defense-in-depth against integration bugs, not a security boundary: it only
guards calls made through this SDK instance. A party who controls the client — e.g. by calling the
LetterOfCredit contract directly, or by using a modified build of this SDK — is not stopped by
it, and the protocol itself does not restrict LOC beneficiaries.
modifyLOCCollateral?
optional modifyLOCCollateral?: ModifyLOCCollateralComponentConfig;Provider-level defaults for the beta collateral-modification UI.
redeemLiquidation?
optional redeemLiquidation?: RedeemLiquidationSource;Default liquidator selection for the React redeem form. A fixed selection is reused as-is; a
resolver is called at submission time with the current LOC, amount, and destination; null
explicitly selects self-liquidation. A redeemLiquidation prop on RedeemLOCFlow or
RedeemLOCForm replaces this setting as a whole.
Core builders do not read this presentation setting. They receive the resolved liquidator and
liquidatorParams in RedeemLOCParams.
staticLOCTokenAddressAllowlist?
optional staticLOCTokenAddressAllowlist?: `0x${string}`[];Token addresses a static LOC may be denominated in (a static LOC’s collateral and credited token are
the same asset); empty or unset means any protocol collateral token. When non-empty, creation
builders reject any other token with InvalidArgumentError, with the same “not a security boundary”
caveat as LOCConfig.locBeneficiaryAllowList.