Skip to content

Key history (HF15) ​

A DLT node starts from a snapshot and keeps no past blocks, so on its own it cannot tell which key an account held at some moment in the past. An account could sign something, change its keys and claim the signature was never theirs. From HF15 consensus keeps a permanent record of every key an account stopped standing behind, so the past can be proven from the current state alone.

What is recorded ​

When an account's keys change, the node writes one row per member of the old authority of every role that actually changed:

FieldMeaning
accountWhose key it was
rolemaster, active, regular or memo
keyThe key; the null key when the member was an account
auth_accountThe member account (account_auths); empty for a key
weightWeight of this member; 0 for memo
weight_thresholdThreshold of the role; 0 for memo
valid_until_blockLast block in which the key still held (inclusive); the change is in the next block
valid_until_timeTime of that block

If the old authority of a role was empty (no keys and no accounts), the node still writes one marker row for that role: key is the null key, auth_account is empty, weight is 0. It keeps the rotation cooldown working for an empty→populated change; such rows also show up in get_key_history_by_key for the null key.

The row says: account A held key B in role R with weight D out of threshold E until block F at time G. "Since when" is the block after the valid_until_block of the previous row of the same role (or unknown, for keys that were already in place when HF15 activated — there is no earlier history to take it from). The current keys are in the account itself.

Rows are written by every path that changes keys: account_update, account recovery, direct sale and auction close. A role whose authority did not change writes nothing — re-sending the same authority is not a change. Rows are never removed. This is separate from the master authority history used by recovery, which is kept for 30 days only.

Rate limit ​

From HF15 an actual change of active, regular or memo_key through account_update is allowed at most once an hour per role, like master already was. Each role is limited separately: changing regular does not block changing active in the same hour. Recovery and account sales are not limited.

Read API ​