{
  "object": "jepeta_content_article",
  "schemaVersion": "1.0.0",
  "id": "article.disconnect-vs-revoke-token-access",
  "contentType": "security_intelligence",
  "title": "Disconnecting a Wallet Is Not Revoking Token Access: The Exact Difference",
  "slug": "disconnect-vs-revoke-token-access",
  "category": "security",
  "intent": "Show why disconnecting a dapp does not cancel an ERC-20 spending allowance and how to verify both controls separately.",
  "directAnswer": "Disconnecting a wallet removes an application's current wallet connection permissions. Revoking a token allowance changes an onchain spending authorization for a specific token and spender. The actions are not interchangeable: a spender may retain allowance after you disconnect, and a revocation does not automatically sign you out of the website.",
  "sections": [
    {
      "heading": "Two permissions, two different places",
      "paragraphs": [
        "A wallet connection is usually an application/session permission: the site may request your account address and ask the wallet to present transactions for signing. Removing that connection changes what the site can request through the wallet interface. A token approval is a separate ERC-20 state recorded on a blockchain. The approved spender may be a router, vault or another contract. Disconnecting the visible session does not undo a previous blockchain transaction. [MetaMask explicitly separates these actions](https://support.metamask.io/more-web3/learn/how-to-revoke-smart-contract-allowances-token-approvals/)."
      ]
    },
    {
      "heading": "Compare the actual effects",
      "paragraphs": [
        "| Action | Where the change happens | What it normally stops | What it does **not** prove |\n| --- | --- | --- | --- |\n| Disconnect a dapp | Wallet connection/session settings | The site's current wallet session | Previously granted token allowances are gone |\n| Revoke allowance | Onchain token contract state | The spender's permission to transfer that token under the allowance | The website is trustworthy or a position has been closed |\n| Move funds to a different wallet | Onchain wallet balances | Leaving those tokens in the old address | Old permissions on the old address have been erased |\n\nA wallet interface may give these controls similar names. Check which action actually produces a blockchain transaction and what address it modifies."
      ]
    },
    {
      "heading": "Example: a swap approval that outlives a visit",
      "paragraphs": [
        "Imagine you approve a router to move a token, complete a swap and then disconnect the dapp. The site's connection may be gone, yet a nonzero token allowance can remain. A properly functioning spender still has the authorization recorded onchain. Ethereum.org explains that onchain allowances can persist long after an application session ends. This example illustrates a permission boundary; it is not a claim that a particular exchange or router is abusing that permission."
      ]
    },
    {
      "heading": "How to verify a disconnect",
      "paragraphs": [
        "Open your wallet's connected-sites or permissions screen and remove the site's connection if you no longer use it. Confirm that the site cannot silently reconnect using the same wallet session. The details vary across MetaMask Extension, mobile wallets and hardware-wallet integrations. Avoid accepting a new permission request only to verify that the old one disappeared. Disconnecting is useful privacy and account-session hygiene, but it is not the onchain step."
      ]
    },
    {
      "heading": "How to verify an onchain revocation",
      "paragraphs": [
        "Use an official allowance viewer or a carefully verified revocation tool on the correct network. Inspect the **spender**, **token contract** and **allowance**, not just a logo. If you revoke it, examine the transaction before signing, pay the required network fee, wait for confirmation, then refresh the allowance view. [Ethereum.org's revocation guide](https://ethereum.org/guides/how-to-revoke-token-access) describes this chain-specific workflow and explains why network selection matters. Revocation does not require exposing a seed phrase."
      ]
    },
    {
      "heading": "Mistakes worth avoiding",
      "paragraphs": [
        "Do not equate 'not connected' with 'no active approvals'. Do not assume one approval tool covers every chain. Do not trust a dapp's name if its spender address does not match independently verified documentation. Do not assume revocation retroactively reverses transfers made before confirmation. Finally, do not confuse wallet permissions with token-level safety: even a perfectly revoked allowance says nothing about future liquidity, contract ownership or application security."
      ]
    },
    {
      "heading": "Next step",
      "paragraphs": [
        "A useful habit is to perform two separate checks after experimenting with a DeFi app: remove any unwanted wallet connection and inspect standing token allowances on the correct network. Our [permission hygiene checklist](https://jepeta.dev/articles/token-approval-hygiene-guide/) organizes these steps; the [Jepeta scanner](https://jepeta.dev/#scanner) is a different tool for investigating token-level evidence. Neither is a safety guarantee."
      ]
    }
  ],
  "sources": [
    {
      "id": "metamask_allowance",
      "label": "MetaMask: revoke smart-contract allowances versus disconnect",
      "url": "https://support.metamask.io/more-web3/learn/how-to-revoke-smart-contract-allowances-token-approvals/",
      "sourceType": "primary",
      "publishedAt": null,
      "verifiedAt": "2026-10-09T05:35:44.898Z"
    },
    {
      "id": "metamask_disconnect",
      "label": "MetaMask: disconnect a wallet from a dapp",
      "url": "https://support.metamask.io/more-web3/dapps/disconnect-wallet-from-a-dapp/",
      "sourceType": "primary",
      "publishedAt": null,
      "verifiedAt": "2026-10-09T05:35:44.898Z"
    },
    {
      "id": "ethereum_revoke",
      "label": "Ethereum.org: revoke token access and confirm onchain",
      "url": "https://ethereum.org/guides/how-to-revoke-token-access",
      "sourceType": "primary",
      "publishedAt": null,
      "verifiedAt": "2026-10-09T05:35:44.898Z"
    }
  ],
  "sourceDates": [
    {
      "sourceId": "metamask_allowance",
      "publishedAt": null,
      "verifiedAt": "2026-10-09T05:35:44.898Z"
    },
    {
      "sourceId": "metamask_disconnect",
      "publishedAt": null,
      "verifiedAt": "2026-10-09T05:35:44.898Z"
    },
    {
      "sourceId": "ethereum_revoke",
      "publishedAt": null,
      "verifiedAt": "2026-10-09T05:35:44.898Z"
    }
  ],
  "originalEvidence": [
    {
      "type": "structured_comparison",
      "description": "Primary-source editorial comparison of documented security or import/tax procedures, including a task-oriented checklist and limits. No live wallet test, tax filing, or exchange API account verification is claimed.",
      "url": "https://support.metamask.io/more-web3/learn/how-to-revoke-smart-contract-allowances-token-approvals/",
      "observedAt": "2026-10-09T05:35:44.898Z"
    }
  ],
  "datePublished": "2026-10-09T05:35:44.898Z",
  "dateModified": "2026-10-09T05:35:44.898Z",
  "reviewedAt": "2026-10-09T05:35:44.898Z",
  "affiliate": {
    "enabled": false,
    "partnerId": null,
    "linkId": null,
    "disclosureRequired": false,
    "rel": null
  },
  "disclosure": null,
  "internalLinks": [
    "/articles/token-approval-hygiene-guide/",
    "/articles/token-approval-risk-before-swap/",
    "/articles/trezor-clear-signing-vs-phishing-2026/",
    "/#scanner"
  ],
  "telegramCohort": {
    "surface": "article",
    "cohortId": "article"
  },
  "format": "markdown",
  "seoTitle": "Disconnect vs Revoke Token Approval: What Actually Changes",
  "metaDescription": "Disconnecting a wallet removes an application's current wallet connection permissions. Revoking a token allowance changes an onchain spending authorization",
  "quality": {
    "decision": "publish",
    "citabilityScore": 100,
    "reviewedAt": "2026-10-09T05:35:44.898Z",
    "policyVersion": "1.0.0"
  },
  "canonicalUrl": "https://jepeta.dev/articles/disconnect-vs-revoke-token-access/",
  "jsonUrl": "https://jepeta.dev/articles/disconnect-vs-revoke-token-access/index.json"
}
