Onchain properties
Security & architecture
What the token form gives you, and where its limits are.
Self-custody
Your PerpTokens sit in your own wallet. The PerpTokens app doesn't hold them for you as a balance. Each product's token is a standard SPL token with no freeze authority, so nobody can freeze your balance.
The collateral backing a product is held by the product itself:
- Each product is controlled by its own program address (a PDA), and only that address can mint or burn the product's tokens or move its collateral.
- The collateral is deposited into the product's trading accounts on the underlying venue, which keeps it in the venue's own vault. That makes the venue's code and solvency matter to the product.
- The program has no instruction that lets an admin withdraw product collateral to an arbitrary address. Collateral only leaves a product through redemptions, limit-order refunds and payouts to their owners, and collected protocol fees.
The program is upgradeable. Whoever holds its upgrade authority can replace the program code, which could change any of the above.
Permissionless
You need only your own signature to mint and redeem, to place, cancel, and claim your limit orders, and to transfer the token. Nobody approves individual wallets.
Some actions are open to anyone at all. Anyone can call rebalance and sweep, claim a filled order on its owner's behalf, collect protocol fees to the configured destination, and publish NAV.
Transparency
Anyone can check the following onchain:
- each product's configuration: legs, markets, sides, weights, bands, caps, fees, status, and accrued protocol fees;
- each product's positions, collateral, and funding on the venue;
- token supply and every holder's balance.
NAV isn't stored anywhere. It's computed from that onchain state, so you can recompute it yourself. The product catalog, charts, history, and activity feeds in the app come from PerpTokens servers and aren't onchain.
Isolation
Products keep their collateral and trading state separate, and they're designed so that one product's results aren't netted against another's.
- Each product has its own program address, collateral account, token, and trading accounts on the venue.
- Within a product, cross legs share one account and its collateral, so they're margined together and can be liquidated together. SOLFETH is built this way.
- Isolated legs each have their own account and collateral. METALS uses isolated legs.
Products do share the underlying venue and its markets.
Composability
Products are standard SPL tokens with no transfer restrictions or extensions. Any wallet can hold them and send them, and any program that accepts SPL tokens can use them. There are no specific lending, vault, collateral, or aggregator integrations today.