Access Control
Ownable and Roles.
Access Control is a free Web3 & DApp Development Fundamentals lesson on CoddyKit. This is lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Web3 & DApp Development Fundamentals learning path, and your progress syncs across the web and the CoddyKit app. The Web3 & DApp Development Fundamentals course includes 4 lessons in total.
Why Access Control
Many contract functions should only be callable by certain accounts — minting tokens, pausing the system, withdrawing funds. Access control enforces who can do what.
OpenZeppelin offers two main patterns: Ownable and AccessControl.
The Ownable Pattern
Ownable gives a contract a single privileged owner. Import and inherit it:
import "@openzeppelin/contracts/access/Ownable.sol";
contract Vault is Ownable {
constructor() Ownable(msg.sender) {}
}The deployer becomes the initial owner.
import "@openzeppelin/contracts/access/Ownable.sol";
contract Vault is Ownable {
constructor() Ownable(msg.sender) {}
}The onlyOwner Modifier
Restrict a function to the owner with the onlyOwner modifier:
function withdraw() public onlyOwner {
payable(owner()).transfer(address(this).balance);
}If anyone else calls it, the transaction reverts automatically.
function withdraw() public onlyOwner {
payable(owner()).transfer(address(this).balance);
}Transferring Ownership
Ownable lets you hand control to another address:
// Give ownership to a new account
vault.transferOwnership(newOwner);
// Or give it up forever
vault.renounceOwnership();Renouncing makes onlyOwner functions permanently uncallable — use with care.
// Give ownership to a new account
vault.transferOwnership(newOwner);
// Or give it up forever
vault.renounceOwnership();Limits of a Single Owner
One owner is simple but limiting:
- No way to grant different permissions to different people.
- A single key is a single point of failure.
For richer setups, use role-based access control.
The AccessControl Pattern
AccessControl supports many named roles. Inherit it and define your roles:
import "@openzeppelin/contracts/access/AccessControl.sol";
contract Token is AccessControl {
bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
}Roles are identified by a hashed name.
import "@openzeppelin/contracts/access/AccessControl.sol";
contract Token is AccessControl {
bytes32 public constant MINTER_ROLE = keccak256("MINTER_ROLE");
}Granting Roles
The deployer typically gets the admin role and then grants others:
constructor() {
_grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
_grantRole(MINTER_ROLE, msg.sender);
}The DEFAULT_ADMIN_ROLE can grant and revoke all other roles.
constructor() {
_grantRole(DEFAULT_ADMIN_ROLE, msg.sender);
_grantRole(MINTER_ROLE, msg.sender);
}The onlyRole Modifier
Restrict functions to holders of a role:
function mint(address to, uint256 amount)
public onlyRole(MINTER_ROLE) {
_mint(to, amount);
}Only accounts granted MINTER_ROLE can mint; everyone else reverts.
function mint(address to, uint256 amount)
public onlyRole(MINTER_ROLE) {
_mint(to, amount);
}Managing Roles at Runtime
Admins can grant and revoke roles after deployment:
token.grantRole(MINTER_ROLE, alice);
token.revokeRole(MINTER_ROLE, alice);
// Check membership
bool canMint = await token.hasRole(MINTER_ROLE, alice);An account can even renounce its own role.
token.grantRole(MINTER_ROLE, alice);
token.revokeRole(MINTER_ROLE, alice);
// Check membership
bool canMint = await token.hasRole(MINTER_ROLE, alice);Choosing a Pattern
Which to use?
- Ownable — simple admin tasks, one trusted operator.
- AccessControl — multiple roles, separation of duties, DAOs.
For production, consider giving the owner/admin role to a multisig rather than a single key.
Each Role Has an Admin
In AccessControl, every role has an admin role that controls who can grant or revoke it. By default that is DEFAULT_ADMIN_ROLE, but you can change it:
// Make MANAGER_ROLE the admin of MINTER_ROLE
_setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);This lets you build hierarchies of permissions.
// Make MANAGER_ROLE the admin of MINTER_ROLE
_setRoleAdmin(MINTER_ROLE, MANAGER_ROLE);Quick Check
Test your understanding of access control.
Recap
You learned OpenZeppelin's access control patterns.
- Ownable gives one
owner; restrict withonlyOwnerand transfer or renounce ownership. - AccessControl supports many roles identified by hashed names.
- Grant the admin role at deploy; protect functions with
onlyRole. - Admins grant/revoke roles at runtime; accounts can renounce roles.
- Use Ownable for simple cases, AccessControl (ideally behind a multisig) for complex ones.
Frequently Asked Questions
Is the “Access Control” lesson free?
Yes — the full text of “Access Control” is free to read here on the web. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Web3 & DApp Development Fundamentals course, upgrade to CoddyKit PRO. The Web3 & DApp Development Fundamentals course includes 4 lessons in total.
What will I learn in “Access Control”?
Ownable and Roles. You practise Web3 & DApp Development Fundamentals with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Web3 & DApp Development Fundamentals?
No prior experience is required. Web3 & DApp Development Fundamentals on CoddyKit is structured for beginners through advanced learners, so you can start here or from the beginning and move at your own pace. This is lesson 2 of 4.
How long does the “Access Control” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Web3 & DApp Development Fundamentals lesson?
Yes. Every Web3 & DApp Development Fundamentals lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Why OpenZeppelin
- Access Control
- Token Extensions
- Upgradeable Contracts