XRP Ledger Escrow Guide

How XRPL escrow works: the ledger holds the XRP until the release path becomes valid.

How XRPL escrow works begins with an EscrowCreate transaction that locks funds in a ledger object for a destination. The XRP cannot move through an ordinary payment while held; completion or cancellation must satisfy the escrow’s immutable timing and condition rules.

Create the escrow

EscrowCreate defines the funds, recipient and conditions.

The sender specifies the amount and destination, then supplies an allowed combination of FinishAfter, Condition and CancelAfter fields. Once validated successfully, the ledger creates an Escrow object that holds the funds.

Amount identifies the locked XRP or supported token.

Destination identifies the intended recipient.

FinishAfter can prevent early completion.

CancelAfter can establish an expiration time.

Hold the funds

Locked funds cannot be spent while the escrow remains unresolved.

The escrow exists as a ledger object. The sender remains responsible for its owner reserve while it is open, and settlement must follow the immutable fields established at creation.

Creation does not pay the recipient immediately.

Past time values cannot be used at creation.

Ledger close time determines time comparisons.

Conditional escrows support PREIMAGE-SHA-256 conditions.

Finish successfully

EscrowFinish delivers funds only when the requirements are satisfied.

A time-based escrow cannot finish before FinishAfter. A conditional escrow requires the matching fulfillment. If the transaction succeeds in a validated ledger, the Escrow object is destroyed and the funds reach the destination.

Anyone may submit EscrowFinish.

Required conditions must still be satisfied.

An expired escrow can no longer finish.

Conditional fulfillment increases transaction cost.

Cancel after expiration

Expiration permits cancellation; it does not automatically return funds.

After CancelAfter has passed, anyone may submit EscrowCancel. A successful cancellation destroys the Escrow object and returns the held funds to the sender.

The escrow remains on-ledger after merely expiring.

Cancellation fails before CancelAfter.

Expired escrow cannot be finished.

Completion or cancellation frees the owner reserve.

Transaction fields

How XRPL escrow works is determined at creation—not negotiated after funding.

EscrowCreate defines the destination, amount and permitted settlement path. Depending on the escrow type, it may include FinishAfter, CancelAfter and a PREIMAGE-SHA-256 Condition. These values become part of the ledger object, so a friendly promise or later message cannot silently replace them.

Destination identifies the eventual recipient.

FinishAfter blocks early completion.

CancelAfter creates an expiration boundary.

Condition requires the matching fulfillment.

State transitions

Held, ready and expired are different powers over the same locked funds.

Before its finish time, a timed escrow is held. After the time passes it may become ready to finish. If a valid CancelAfter time passes first without completion, the escrow becomes expired: it can no longer finish and can be cancelled so funds return to the sender. Expiration does not itself move money; an EscrowCancel transaction performs the return.

Maturity enables a valid finish path.

Expiration disables completion.

Cancellation returns eligible expired funds.

A ledger object remains until a transaction resolves it.

Verification

Do not trust an interface label when the ledger can provide the state.

Confirm the validated EscrowCreate transaction, owner, sequence, destination, amount and timing fields. Then verify the successful result of EscrowFinish or EscrowCancel. Validated transaction metadata—not a screenshot—shows whether the intended ledger change actually occurred.

Use validated ledger data.

Match owner and offer sequence.

Inspect finish and cancellation fields.

Confirm the final transaction result.

Application layer

Ledger-native escrow does not automatically judge freelance performance.

The XRPL can enforce supported time and cryptographic conditions. An application can add profiles, milestone scope, delivery evidence, review clocks and human approvals around payment. Understanding how XRPL escrow works means separating the native lock from the richer contract lifecycle that decides when an application should submit settlement.

Protocol rules control the ledger object.

Application rules coordinate off-chain work.

Subjective quality still needs human input.

The payment layer and work layer must agree.

Failure checklist

Model every terminal path before locking meaningful XRP.

Confirm who can submit EscrowFinish, who monitors eligibility, what happens when the fulfillment never appears and whether CancelAfter creates a recoverable expiration. Include reserve and transaction-cost implications, wallet signing responsibility and the evidence the application will display after settlement. A technically valid escrow can still be operationally dangerous when nobody owns the final action.

Assign monitoring responsibility.

Assign finish and cancellation responsibility.

Test success and expiration paths.

Never fund a lifecycle nobody can explain.

Frequently asked questions

How XRPL Escrow Works When the Ledger—not a Middleman—Controls Release

What is XRPL escrow?

XRPL escrow is a native ledger feature that locks funds for a destination until specified time or cryptographic conditions permit settlement.

Does XRPL escrow refund automatically at expiration?

No. After expiration, an EscrowCancel transaction must successfully cancel the escrow and return the funds.

Who can finish an XRPL escrow?

Anyone can submit EscrowFinish, but all applicable time and cryptographic conditions must be satisfied.

Can XRPL escrow judge freelance work?

No. Native escrow evaluates ledger time and cryptographic conditions, not subjective off-chain work quality.

Rules before risk

Structure the agreement before money or work changes hands.

Create a wallet-based contract with defined milestones, deadlines, review rules and XRP settlement instructions.