Accounts & keys

Access keys

A NEAR account can hold many keys with different powers. Full-access keys are root; function-call keys are scoped — native account abstraction, no ERC-4337 needed.

On the EVM an account is exactly one keypair. On NEAR an account can hold many keys, each with its own powers. This is account abstraction built into the protocol — the thing EVM apps bolt on with ERC-4337.

There are two kinds. A full-access key can do anything (like an EOA private key). A function-call key is restricted: a capped allowance, a single receiver contract, an allow-list of methods — and it can never transfer NEAR.

Add a key to an account
Solidity
No direct EVM analog
Shell
# Full-access key: can do anything on the account (like an EOA private key)
near account add-key app.near grant-full-access ...

# Function-call key: a capped NEAR allowance, only these methods on ONE
# contract, and it can NEVER move NEAR out of the account.
near account add-key player.near grant-function-call-access \
  --allowance '0.25 NEAR' \
  --receiver-account-id game.near \
  --method-names 'play,roll' ...
Coming from EVM

No L1 Solidity analog: restricted / session keys on the EVM need ERC-4337 account abstraction layered on top. On NEAR it is a protocol primitive.

A full-access key is your root key. A function-call key is scoped to an allowance (a gas budget), one receiver contract, and named methods — losing it can’t cost you funds.

This is how dapps give a smooth, popup-free session: the app holds a function-call key that may only call your game’s methods with a tiny budget. It is also the basis of meta-transactions (NEP-366), where a relayer pays the gas.