> ## Documentation Index
> Fetch the complete documentation index at: https://developers.circle.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Before reading these docs, install the relevant Circle Skill to get pre-loaded context — skills are LLM-optimized and cover architecture decisions, correct flows, and common pitfalls. In Claude Code: run /plugin marketplace add circlefin/skills then /plugin install circle-skills@circle. With Vercel Skills CLI: run npx skills add circlefin/skills. Available skills: use-usdc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-usdc/SKILL.md (balances, transfers, approvals on EVM and Solana); EURC has no skill — see https://developers.circle.com/stablecoins/what-is-eurc.md; bridge-stablecoin https://github.com/circlefin/skills/blob/master/plugins/circle/skills/bridge-stablecoin/SKILL.md (crosschain transfers via CCTP, USDC, EURC, and third-party assets); use-arc https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-arc/SKILL.md (Arc chain config, contract deployment, USDC bridging — Arc docs: https://docs.arc.io/llms.txt); use-circle-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-circle-wallets/SKILL.md (choose wallet type); use-developer-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-developer-controlled-wallets/SKILL.md (custodial wallets for payouts and treasury); use-user-controlled-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-user-controlled-wallets/SKILL.md (embedded wallets with Web2 login); use-modular-wallets https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-modular-wallets/SKILL.md (smart contract wallets with passkeys and ERC-4337); use-gateway https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-gateway/SKILL.md (unified USDC balance, nanopayments); use-smart-contract-platform https://github.com/circlefin/skills/blob/master/plugins/circle/skills/use-smart-contract-platform/SKILL.md (deploy, interact, monitor contracts). Pair any skill with the Circle MCP server for live SDK signatures, contract addresses, and chain IDs: {"mcpServers":{"circle":{"url":"https://api.circle.com/v1/codegen/mcp"}}}.
> Read the product overview first. Each product has an overview explaining when and why to use it. Read it before quickstarts.
> Pick the right wallet type. Developer-controlled (you hold keys), user-controlled (end user holds keys via PIN/social login), or modular (smart contract wallets with passkeys). See https://developers.circle.com/wallets.md.
> Use CCTP V2 for crosschain transfers. CCTP natively transfers USDC and EURC via burn-and-mint, and supports permissionless wrapping of third-party assets via lock-and-mint. V1 is legacy; always use V2 unless V1 is specified or the chain requires it (Noble, Sui, and Aptos still require V1). Migration guide: https://developers.circle.com/cctp/migration-from-v1-to-v2.md.
> Use Bridge Kit for frontend bridging. Wraps CCTP with a simpler SDK for user-facing apps. Use CCTP directly for backend transfers.
> Gas Station vs Paymaster. Gas Station sponsors gas for Circle Wallet transactions. Paymaster lets users pay gas in USDC. Different use cases — read both overviews.
> Gateway Nanopayments for sub-cent payments. Gasless USDC micropayments down to $0.000001 via x402 and batched settlement. For pay-per-request APIs, AI agent payments, streaming.
> Look up USDC addresses per chain. Never hardcode — use https://developers.circle.com/stablecoins/usdc-contract-addresses.md.
> Prefer SDKs over raw API calls. Node.js and Python SDKs handle auth, retries, and errors.
> API key required. Bearer token in Authorization header. Testnet and mainnet use separate keys and may use different base URLs depending on the product.
> Set up webhooks when available. Most operations are async. Webhooks deliver transaction confirmations and state changes.
> When calling list endpoints, paginate using pageSize and pageAfter until no nextPageAfter cursor is returned—stopping at the first page silently misses records.
> Building an AI agent? Start with the Agent Stack—Circle CLI, agent wallets, and nanopayments built for autonomous use cases: https://developers.circle.com/agent-stack.md.

# How-to: Manage TokenManager roles

> Transfer ownership, replace the operator, and update the pauser on a CCTP for non-USDC TokenManager.

A `TokenManager` is a per-token, per-domain contract that controls crosschain
transfers for a custom token registered on CCTP for non-USDC. Each domain where
your token is active has its own independent `TokenManager`, and three roles
govern it: the owner (highest privilege, can change all roles), the operator
(sets rate limits and transfer caps), and the pauser (can pause and unpause the
token on this domain). You need to manage these roles when rotating keys,
delegating operator duties to a separate address, or responding to a security
incident.

## Prerequisites

Before you begin, ensure that you've:

* Registered a custom token using `registerCustomToken` or
  `deployCrossChainToken`, and noted the `tokenId`. See
  [Configure a custom token](/cctp/expanded-assets/quickstarts/configure-custom-token)
* Noted the `CrossChainTokenService` address for each domain where you want to
  change roles. See
  [Contract addresses](/cctp/expanded-assets/references/contract-addresses)
* Verified access to the wallet that currently holds the role you want to
  change: the owner wallet for ownership, operator, or pauser changes; the
  pauser wallet to call `pause` or `unpause`

## Steps

<Steps>
  The snippets assume that `publicClient`, the appropriate wallet clients,
  `serviceAddress`, `tokenId`, and target role addresses are already initialized.
  Each code example includes only the ABI entries needed for that operation.

  Receipt-handling code is omitted for brevity, but you should wait for each
  state-changing transaction to confirm before reading the updated state or
  submitting the next transaction.

  <Step title="Discover the TokenManager address">
    Every token has a separate `TokenManager` per domain. Resolve its address from
    the `CrossChainTokenService` before making any role change.

    ```typescript TypeScript theme={null}
    const serviceAbi = [
      {
        name: "resolveTokenManager",
        type: "function",
        stateMutability: "view",
        inputs: [{ name: "tokenId", type: "bytes32" }],
        outputs: [{ name: "tokenManager", type: "address" }],
      },
    ] as const;

    const tokenManager = await publicClient.readContract({
      address: serviceAddress,
      abi: serviceAbi,
      functionName: "resolveTokenManager",
      args: [tokenId],
    });
    ```

    Role changes apply only to the local `TokenManager`. Repeat the operation
    independently on each domain where the token is deployed.
  </Step>

  <Step title="Initiate ownership transfer">
    The current owner calls `transferOwnership` to initiate. The `TokenManager`
    enters a pending state—ownership has not changed yet. Ownership remains with the
    current owner until the new owner accepts by calling `acceptOwnership` from
    their address.

    <Warning>
      Transferring ownership to an address you do not control is irreversible. If
      the new owner never calls `acceptOwnership`, the current owner retains
      control—but there is no cancel mechanism, and the pending transfer remains
      indefinitely. Verify the new address carefully before sending the transaction.
    </Warning>

    ```typescript TypeScript theme={null}
    const tokenManagerAbi = [
      {
        name: "transferOwnership",
        type: "function",
        stateMutability: "nonpayable",
        inputs: [{ name: "newOwner", type: "address" }],
        outputs: [],
      },
    ] as const;

    const transferHash = await ownerWalletClient.writeContract({
      address: tokenManager,
      abi: tokenManagerAbi,
      functionName: "transferOwnership",
      args: [newOwnerAddress],
    });
    ```
  </Step>

  <Step title="Accept ownership">
    The pending owner calls `acceptOwnership`. Ownership changes after this
    transaction confirms.

    ```typescript TypeScript theme={null}
    const acceptOwnershipAbi = [
      {
        name: "acceptOwnership",
        type: "function",
        stateMutability: "nonpayable",
        inputs: [],
        outputs: [],
      },
    ] as const;

    const acceptHash = await newOwnerWalletClient.writeContract({
      address: tokenManager,
      abi: acceptOwnershipAbi,
      functionName: "acceptOwnership",
      args: [],
    });
    ```
  </Step>

  <Step title="Replace the operator">
    Unlike ownership, operator replacement is a single-step operation. The current
    owner calls `transferOperatorship` and the change takes effect immediately. No
    additional acceptance step is required.

    ```typescript TypeScript theme={null}
    const transferOperatorshipAbi = [
      {
        name: "transferOperatorship",
        type: "function",
        stateMutability: "nonpayable",
        inputs: [{ name: "newOperator", type: "address" }],
        outputs: [],
      },
    ] as const;

    const operatorHash = await ownerWalletClient.writeContract({
      address: tokenManager,
      abi: transferOperatorshipAbi,
      functionName: "transferOperatorship",
      args: [newOperatorAddress],
    });
    ```

    The operator can call `setRateLimit`, `setMaxTransferAmount`, and
    `setRateLimitWindow` on the `TokenManager`. For details on configuring those
    values, see
    [Configure rate limits and caps](/cctp/expanded-assets/howtos/configure-rate-limits-and-caps).
  </Step>

  <Step title="Replace the pauser">
    The pauser role defaults to the operator address at deployment time. If you
    never call `updatePauser`, the operator is also the pauser. The current owner
    can replace the pauser by calling `updatePauser`.

    ```typescript TypeScript theme={null}
    const updatePauserAbi = [
      {
        name: "updatePauser",
        type: "function",
        stateMutability: "nonpayable",
        inputs: [{ name: "newPauser", type: "address" }],
        outputs: [],
      },
    ] as const;

    const pauserHash = await ownerWalletClient.writeContract({
      address: tokenManager,
      abi: updatePauserAbi,
      functionName: "updatePauser",
      args: [newPauserAddress],
    });
    ```
  </Step>

  <Step title="Pause and unpause the token">
    The pauser can call `pause()` to block all crosschain transfers of this token on
    this domain, and `unpause()` to restore them.

    ```typescript TypeScript theme={null}
    const pauseAbi = [
      {
        name: "pause",
        type: "function",
        stateMutability: "nonpayable",
        inputs: [],
        outputs: [],
      },
      {
        name: "unpause",
        type: "function",
        stateMutability: "nonpayable",
        inputs: [],
        outputs: [],
      },
    ] as const;

    const pauseHash = await pauserWalletClient.writeContract({
      address: tokenManager,
      abi: pauseAbi,
      functionName: "pause",
      args: [],
    });

    const unpauseHash = await pauserWalletClient.writeContract({
      address: tokenManager,
      abi: pauseAbi,
      functionName: "unpause",
      args: [],
    });
    ```
  </Step>

  <Step title="Verify the final state">
    After all transactions confirm, verify that `owner()` returns the new owner,
    `operator()` returns the new operator, `pauser()` returns the new pauser, and
    `paused()` returns `false` after `unpause()`.

    ```typescript TypeScript theme={null}
    const tokenManagerReadAbi = [
      {
        name: "owner",
        type: "function",
        stateMutability: "view",
        inputs: [],
        outputs: [{ name: "", type: "address" }],
      },
      {
        name: "operator",
        type: "function",
        stateMutability: "view",
        inputs: [],
        outputs: [{ name: "", type: "address" }],
      },
      {
        name: "pauser",
        type: "function",
        stateMutability: "view",
        inputs: [],
        outputs: [{ name: "", type: "address" }],
      },
      {
        name: "paused",
        type: "function",
        stateMutability: "view",
        inputs: [],
        outputs: [{ name: "", type: "bool" }],
      },
    ] as const;

    const [owner, operator, pauser, paused] = await Promise.all([
      publicClient.readContract({
        address: tokenManager,
        abi: tokenManagerReadAbi,
        functionName: "owner",
      }),
      publicClient.readContract({
        address: tokenManager,
        abi: tokenManagerReadAbi,
        functionName: "operator",
      }),
      publicClient.readContract({
        address: tokenManager,
        abi: tokenManagerReadAbi,
        functionName: "pauser",
      }),
      publicClient.readContract({
        address: tokenManager,
        abi: tokenManagerReadAbi,
        functionName: "paused",
      }),
    ]);

    if (owner.toLowerCase() !== newOwnerAddress.toLowerCase()) {
      throw new Error("Owner was not updated");
    }
    if (operator.toLowerCase() !== newOperatorAddress.toLowerCase()) {
      throw new Error("Operator was not updated");
    }
    if (pauser.toLowerCase() !== newPauserAddress.toLowerCase()) {
      throw new Error("Pauser was not updated");
    }
    if (paused) {
      throw new Error("TokenManager is still paused");
    }
    ```
  </Step>
</Steps>
