PDAs as Authorities
PDAs commonly act as mint authorities, freeze authorities, vault owners, and escrow custodians. The program enforces when the PDA may sign via business logic.
Search across all documentation pages
PDAs commonly act as mint authorities, freeze authorities, vault owners, and escrow custodians. The program enforces when the PDA may sign via business logic.
// Mint authority PDA seeds: [b"mint_auth", mint.key.as_ref()]When to reach for this:
// Conceptual: program verifies escrow conditions then signs token transfer from escrow PDA
pub fn release_escrow(bump: u8, /* accounts */) -> ProgramResult {
// validate expiry, signatures, state machine
// transfer_checked CPI with invoke_signed seeds &[&[b"escrow", &[bump]]]
// (spl_token::instruction::transfer is deprecated and rejects Token-2022)
Ok(())
}What this demonstrates:
| Role | Typical seeds |
|---|---|
| Vault | [b"vault", user] |
| Mint auth | [b"mint", mint] |
| Escrow | [b"escrow", order_id] |
Program bug = full authority compromise.
// Never expose arbitrary invoke_signed wrapper without checks.| Alternative | Use When | Don't Use When |
|---|---|---|
| Multisig authority | Human ops | Full automation |
| Wallet-owned vault | User custody | Protocol escrow |
| NFT escrow programs | Specialized | SPL token only |
Program code at program id.
CPI set_authority.
Recommended after fixed supply.
PDA holds lamports; program signs transfers.
Same patterns with metadata checks.
Malicious upgrade steals authority.
Off-chain ops pattern.
Derive associated token address.
Possible with token program.
Return rent; zero state.
Critical tier finding target.
Supports PDA authorities.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 19, 2026