An exact or limited approval bounds how many units of a token the spender may pull. An effectively unlimited approval avoids repeating that limit-setting step, but leaves broader permission over the token balance at that account.
Compare exposure with a concrete example
Hypothetical example: you hold 500 units and intend to swap 100. A cap of 100 limits that allowance to 100 units. An unlimited permission can remain relevant to the remaining 400 and to later deposits, subject to the spender’s code and token behavior.
The cap is not a promise that the transaction is safe. A malicious spender can still misuse the amount you authorize. Verify the spender before deciding how much access to grant.
Understand what the cap does not cover
A permission for one ERC-20 token is not automatically permission for every asset. Separate approvals, permits or account delegations may create other exposure. Read the actual request type.
MetaMask explains custom spending caps and unlimited approvals. OpenZeppelin’s implementation also illustrates that a maximum allowance may not decrease as ordinary finite allowance does.
Choose based on intended use
A narrow cap can require another transaction when you trade again, with additional signing effort and network cost. A reusable cap reduces that friction but demands ongoing trust in the authorized contract.
For an exact-output trade, the needed cap can be the maximum input, not the optimistic estimate. Inspect the actual request before reducing it. After the activity ends, review whether unused permission should remain.
Sources & verification (3)
Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.
- What is a token approval?
Spender permissions, custom cap, future-balance exposure and malicious approvals.
https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-token-approval/ - ERC20 | OpenZeppelin Docs
ERC-20 implementation behavior, zero-first approval compatibility and pausable token extension.
https://docs.openzeppelin.com/contracts/5.x/api/token/erc20 - ERC-20: Token Standard
Allowance, spender, transferFrom, metadata and approval event semantics.
https://eips.ethereum.org/EIPS/eip-20