0Pricing
Web3 & DApp Development Fundamentals · Lesson

Access Control

Ownable and Roles.

Access Control is a free Web3 & DApp Development Fundamentals lesson on CoddyKit. This is lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Web3 & DApp Development Fundamentals learning path, and your progress syncs across the web and the CoddyKit app. The Web3 & DApp Development Fundamentals course includes 4 lessons in total.

Why Access Control

Many contract functions should only be callable by certain accounts — minting tokens, pausing the system, withdrawing funds. Access control enforces who can do what.

OpenZeppelin offers two main patterns: Ownable and AccessControl.

The Ownable Pattern

Ownable gives a contract a single privileged owner. Import and inherit it:

import "@openzeppelin/contracts/access/Ownable.sol"; contract Vault is Ownable { constructor() Ownable(msg.sender) {} }

The deployer becomes the initial owner.

import "@openzeppelin/contracts/access/Ownable.sol";

contract Vault is Ownable {
    constructor() Ownable(msg.sender) {}
}

The onlyOwner Modifier

Restrict a function to the owner with the onlyOwner modifier:

function withdraw() public onlyOwner { payable(owner()).transfer(address(this).balance); }

If anyone else calls it, the transaction reverts automatically.

function withdraw() public onlyOwner {
    payable(owner()).transfer(address(this).balance);
}

Transferring Ownership

Ownable lets you hand control to another address:

// Give ownership to a new account vault.transferOwnership(newOwner); // Or give it up forever vault.renounceOwnership();

Renouncing makes onlyOwner functions permanently uncallable — use with care.

// Give ownership to a new account
vault.transferOwnership(newOwner);

// Or give it up forever
vault.renounceOwnership();

Limits of a Single Owner

One owner is simple but limiting:

  • No way to grant different permissions to different people.
  • A single key is a single point of failure.

For richer setups, use role-based access control.

The AccessControl Pattern

AccessControl supports many named roles. Inherit it and define your roles:

import "@openzeppelin/contracts/access/AccessControl.sol"; contract Token is AccessControl { bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE"); }

Roles are identified by a hashed name.

import "@openzeppelin/contracts/access/AccessControl.sol";

contract Token is AccessControl {
    bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
}

Granting Roles

The deployer typically gets the admin role and then grants others:

constructor() { _grantRole(DEFAULT_ADMIN_ROLE, msg.sender); _grantRole(MINTER_ROLE, msg.sender); }

The DEFAULT_ADMIN_ROLE can grant and revoke all other roles.

constructor() {
    _grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
    _grantRole(MINTER_ROLE, msg.sender);
}

The onlyRole Modifier

Restrict functions to holders of a role:

function mint(address to, uint256 amount) public onlyRole(MINTER_ROLE) { _mint(to, amount); }

Only accounts granted MINTER_ROLE can mint; everyone else reverts.

function mint(address to, uint256 amount)
    public onlyRole(MINTER_ROLE) {
    _mint(to, amount);
}

Managing Roles at Runtime

Admins can grant and revoke roles after deployment:

token.grantRole(MINTER_ROLE, alice); token.revokeRole(MINTER_ROLE, alice); // Check membership bool canMint = await token.hasRole(MINTER_ROLE, alice);

An account can even renounce its own role.

token.grantRole(MINTER_ROLE, alice);
token.revokeRole(MINTER_ROLE, alice);

// Check membership
bool canMint = await token.hasRole(MINTER_ROLE, alice);

Choosing a Pattern

Which to use?

  • Ownable — simple admin tasks, one trusted operator.
  • AccessControl — multiple roles, separation of duties, DAOs.

For production, consider giving the owner/admin role to a multisig rather than a single key.

Each Role Has an Admin

In AccessControl, every role has an admin role that controls who can grant or revoke it. By default that is DEFAULT_ADMIN_ROLE, but you can change it:

// Make MANAGER_ROLE the admin of MINTER_ROLE _setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);

This lets you build hierarchies of permissions.

// Make MANAGER_ROLE the admin of MINTER_ROLE
_setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);

Quick Check

Test your understanding of access control.

Recap

You learned OpenZeppelin's access control patterns.

  • Ownable gives one owner; restrict with onlyOwner and transfer or renounce ownership.
  • AccessControl supports many roles identified by hashed names.
  • Grant the admin role at deploy; protect functions with onlyRole.
  • Admins grant/revoke roles at runtime; accounts can renounce roles.
  • Use Ownable for simple cases, AccessControl (ideally behind a multisig) for complex ones.

Frequently Asked Questions

Is the “Access Control” lesson free?

Yes — the full text of “Access Control” is free to read here on the web. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Web3 & DApp Development Fundamentals course, upgrade to CoddyKit PRO. The Web3 & DApp Development Fundamentals course includes 4 lessons in total.

What will I learn in “Access Control”?

Ownable and Roles. You practise Web3 & DApp Development Fundamentals with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Web3 & DApp Development Fundamentals?

No prior experience is required. Web3 & DApp Development Fundamentals on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 2 of 4.

How long does the “Access Control” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Web3 & DApp Development Fundamentals lesson?

Yes. Every Web3 & DApp Development Fundamentals lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Why OpenZeppelin
  2. Access Control
  3. Token Extensions
  4. Upgradeable Contracts
← Back to Web3 & DApp Development Fundamentals