Docs

Handling Permissioned Tokens in the Morpho App

Some loan assets and collaterals supported by the Morpho protocol are permissioned tokens. These tokens require contract-level whitelisting to function properly in Morpho app flows.

When a permissioned token is used through the Morpho app, the token issuer must whitelist the contracts that hold or transfer the token during the relevant flow, including the Morpho Bundles the app routes through.

Issuer whitelisting requirements

The issuer must whitelist the relevant Morpho core protocol contract, every vault contract (and Vault V2 adapter) that receives or sends the token, and each Bundle contract required by the token's intended use:

  • Variable Rate Market (Morpho Blue): the Morpho Blue core protocol contract and BlueBundlesV1 for supply, borrow, repay, withdraw, and position migration flows on app.morpho.org. This includes both collateral supply and direct loan-asset supply.
  • Fixed Rate Market (Morpho Midnight): the Morpho Midnight core protocol contract and MidnightBundlesV1 for flows on markets.morpho.org.
  • Morpho Vaults V1 and V2: each vault address that accepts the token, plus VaultBundlesV1 for vault deposits, withdrawals, and V1-to-V2 migrations. During a deposit, VaultBundlesV1 sends the token to the vault; during a withdrawal, the vault sends the token to VaultBundlesV1. Both addresses must therefore be whitelisted.
  • Vault V2 adapters: the MorphoMarketV1AdapterV2 set up on each Vault V2 that holds the token. During allocation the vault transfers the token to the adapter, and during deallocation the adapter transfers it back, so the adapter must be whitelisted alongside the vault. Each adapter is deployed for a single vault (its parentVault is immutable), so there is no chain-wide adapter address to whitelist: confirm the adapter address of each vault with its curator.
  • Vault exit flows: VaultExitBundlesV1 for in-kind redemption (V1 and V2) and Vault V2 force-withdraw flows.

Whitelist each contract only when the token is intended to support the corresponding flow. For example, a token intended only as collateral in a Variable Rate Market needs the Morpho Blue core protocol contract and BlueBundlesV1 whitelisted.

All contract deployment addresses are available on the addresses page.

When listing a permissioned token, curators must confirm with the asset issuer that the required protocol, vault, adapter, and Bundle contracts are whitelisted for the intended flows.

Permit2 and approval UX

Permit2 is not required for permissioned tokens to work with Morpho. It is an optional improvement that can make the frontend flow smoother by letting users sign an off-chain approval instead of sending a separate ERC-20 approve transaction.

If Permit2 is available on the target chain and the issuer wants to support this signature-based approval flow, the issuer should also whitelist the Permit2 contract at token level. Permit2 contract implementations are maintained in the Uniswap Permit2 repository.

The Morpho SDK handles this as a best-effort path: when signature support is enabled, it can return Permit / Permit2 signature requests where supported, and otherwise falls back to the standard approval flow. Permissioned-token support therefore depends on the relevant Morpho core protocol, vault, and Bundle contracts being whitelisted. Permit2 whitelisting remains an optional UX enhancement.