# Prerequisites and Permissions
Source: https://docs.chain.link/ccip/evm/concepts/cross-chain-token/rate-limits/prerequisites-and-permissions
Last Updated: 2025-06-09

> For the complete documentation index, see [llms.txt](/llms.txt).

> **NOTE: CCIP 2.0**
>
> This page describes permissions on `TokenPool` v2.0 contracts. Differences for **v1.x pools** are noted inline.

Managing CCIP rate limits is a privileged, operator-level action. Before you inspect or modify any rate limit configuration, you must meet the prerequisites on this page.

## Required permissions

To **update** rate limits, the submitting wallet must be either:

- the pool **owner**, or
- the address returned by `getDynamicConfig()` as `rateLimitAdmin`

The update function is `setRateLimitConfig`. Without one of these roles, you can read onchain data but cannot make changes.

In most cases, the `rateLimitAdmin` role is assigned to a multisig wallet rather than to an individual externally owned account.

## How rate limit admin access is granted

Admin access is not self-assigned. Only the pool owner can set the `rateLimitAdmin`.

### v2.0 pools

The `rateLimitAdmin` is set through `setDynamicConfig`:

```solidity
function setDynamicConfig(
  address router,
  address rateLimitAdmin,
  address feeAdmin
) external;
```

Verify the current configuration:

```solidity
function getDynamicConfig()
  external
  view
  returns (address router, address rateLimitAdmin, address feeAdmin);
```

The update function is `setRateLimitConfig`.

### v1.x pools

v1.x pools use standalone admin functions:

```solidity
function getRateLimitAdmin() external view returns (address);
function setRateLimitAdmin(address rateLimitAdmin) external; // owner only
```

The update functions are `setChainRateLimiterConfig` (single lane) or `setChainRateLimiterConfigs` (batch).

## Scope of admin authority

### rateLimitAdmin can:

- update inbound and outbound rate limits for configured remote chains
- on v2.0: update default and fast-finality buckets via `setRateLimitConfig`

### rateLimitAdmin cannot:

- add or remove remote chains (`applyChainUpdates`): owner only
- change admin addresses: owner only (`setDynamicConfig` on v2.0; `setRateLimitAdmin` on v1.x)

### Owner can:

- everything `rateLimitAdmin` can do
- add or remove remote chains via `applyChainUpdates`

> **NOTE: v1.x pools**
>
> Removing a chain deletes that lane's inbound/outbound rate limit state. There is no fast-finality state to clean up.

> **NOTE: v2.0 pools only**
>
> The owner can also call `setAllowedFinalityConfig` to control which finality modes the pool accepts, and
> `setDynamicConfig` to update the router, rate limit admin, and fee admin together.

Each token pool has its own owner and `rateLimitAdmin`. Their authority covers the inbound and outbound limits of every remote chain configured on that pool (and both bucket types on v2.0).

## Operational expectations

Before you change anything, make sure that:

- you understand the token's decimal precision and smallest unit **on each chain** you configure
- you have reviewed the current inbound and outbound configurations (and fast-finality buckets on v2.0)
- you are prepared to validate values carefully before submitting transactions
- **v2.0 pools:** Config changes immediately refill buckets to full capacity.
- **v1.x pools:** Config changes do **not** immediately refill to full capacity. The bucket continues refilling at the normal rate.

Rate limit changes are applied onchain and take effect immediately.

## Responsibility boundary

By managing rate limits, you take responsibility for the availability of cross-chain transfers for the affected token and lane.

Incorrect configuration can:

- unintentionally block transfers
- allow more volume than intended
- create operational or user-facing disruption

For this reason, rate limit management should follow a deliberate review process and use a multisig workflow where possible.

## What's next

If you meet these prerequisites, the next step is to [inspect the current inbound and outbound rate limit configuration](/ccip/evm/concepts/cross-chain-token/rate-limits/inspect-current-rate-limits) before making any changes.

> **CAUTION: Disclaimer**
>
> Chainlink CCIP is an interoperability messaging protocol. Chainlink does not hold or transfer any assets. The
> performance and behaviour of applications using Chainlink CCIP may depend on coding, engineering, configuration, and
> other technical implementation choices made by developers, token issuers, Cross-Chain Verifiers, and other
> participants. Users remain responsible for evaluating, configuring, testing, deploying, operating, and maintaining
> their own applications and integrations, including assessing any applicable operational, security, technical, and
> legal or regulatory risks. Please review the [Chainlink Terms of Service](https://chain.link/terms) which provides
> important information and disclosures. By using Chainlink CCIP, you expressly acknowledge and agree to accept these
> terms. Cross-Chain Verifiers (CCVs) may be operated by third parties. The security, availability, governance, and
> operational profile of a CCV varies depending on the verifier selected. Users are solely responsible for evaluating
> any CCVs used in connection with their applications or integrations and determining whether they are appropriate for
> their intended use case. This code represents an example of using a Chainlink product or service. It is provided "AS
> IS" and "AS AVAILABLE" without warranties of any kind, has not been audited, and may omit checks or error handling.
> Each party intending to use this reference implementation must perform its own audits, security and code review, and
> testing before any production deployment and ensure the operation and performance of such code matches expectations.
> Neither Chainlink Labs, the Chainlink Foundation, nor Chainlink node operators are responsible for outcomes due to
> errors in this example or how it is deployed or operated. Use of the Chainlink Network is subject to the Chainlink
> Foundation Terms of Service, which provides important information and disclosures. By using this code, you acknowledge
> and agree to these terms.