如何通过NEAR Shell/REPL/API-JS为多签合约账户添加密钥?
Hey there! Let's break this down—first covering how to add keys to a multisig contract account using common NEAR tools, then solving your immediate problem of being stuck with one full-access key and a 2-confirmation requirement.
General: Adding Keys to a Multisig Contract Account
Adding keys to a multisig account depends on whether you hold a full-access key for the account (which lets you skip multisig approval) or only function-call keys (which require multisig confirmations). Below are steps for the three tools you mentioned:
Using NEAR CLI (Shell)
If you have a full-access key for the multisig account, you can directly call the add_key method:
near call <multisig-account-id> add_key '{"public_key": "<NEW_PUBLIC_KEY>", "permission": "<PERMISSION_OBJECT>"}' --accountId <multisig-account-id>
- Replace
<multisig-account-id>with your multisig account (e.g.,msig.testnet) <NEW_PUBLIC_KEY>is the public key of the key you want to add (format:ed25519:abc123...)<PERMISSION_OBJECT>defines the key's access:- For a key that can manage multisig requests (add/confirm/delete), use:
{"FunctionCall": {"allowance": "100000000000000", "receiver_id": "<multisig-account-id>", "method_names": ["add_request", "confirm_request", "delete_request"]}} - For full access (not recommended for multisig participants), use
{"FullAccess": {}}
- For a key that can manage multisig requests (add/confirm/delete), use:
Using NEAR REPL
- Launch the REPL with
near repl - Connect to your multisig account using your full-access key:
const account = await near.account("<multisig-account-id>"); - Call the
add_keymethod to add your new key:await account.functionCall( "<multisig-account-id>", "add_key", { public_key: "<NEW_PUBLIC_KEY>", permission: { FunctionCall: { allowance: "100000000000000", receiver_id: "<multisig-account-id>", method_names: ["add_request", "confirm_request", "delete_request"] } } }, "300000000000000", // Gas limit "0" // No deposit needed );
Using near-api-js
In a Node.js script, set up your connection and call add_key:
const { connect, keyStores } = require("near-api-js"); const path = require("path"); const config = { networkId: "testnet", keyStore: new keyStores.UnencryptedFileSystemKeyStore(path.join(process.env.HOME, ".near-credentials")), nodeUrl: "https://rpc.testnet.near.org", }; async function addMultisigKey() { const near = await connect(config); const account = await near.account("<multisig-account-id>"); await account.functionCall( "<multisig-account-id>", "add_key", { public_key: "<NEW_PUBLIC_KEY>", permission: { FunctionCall: { allowance: "100000000000000", receiver_id: "<multisig-account-id>", method_names: ["add_request", "confirm_request", "delete_request"] } } }, "300000000000000", "0" ); console.log("New key added to multisig account!"); } addMultisigKey();
Your Specific Scenario: Stuck with 1 Full-Access Key & 2 Required Confirmations
Good news—since you hold the full-access key for the msig account, you can bypass the multisig confirmation requirement entirely. Full-access keys have unrestricted control over the account, so you can fix this in two ways:
Option 1: Add a Second Key Immediately
Use your full-access key to call add_key directly via NEAR CLI:
near call msig add_key '{"public_key": "<YOUR_SECOND_PUBLIC_KEY>", "permission": {"FunctionCall": {"allowance": "100000000000000", "receiver_id": "msig", "method_names": ["add_request", "confirm_request", "delete_request"]}}}' --accountId msig
Once this key is added, you’ll have a second valid key to confirm multisig requests.
Option 2: Reduce Required Confirmations to 1
If you just want to unlock the contract right away, you can update the num_confirmations setting directly:
near call msig update_num_confirmations '{"num_confirmations": 1}' --accountId msig
This lets you perform all operations with your existing full-access key, and you can add more keys or adjust the confirmation count later when you’re set up properly.
内容的提问来源于stack exchange,提问作者mattdlockyer

