sheardocs

Developers

Program reference

Accounts, PDA seeds, instructions, events and error codes of the Shear Anchor program.

Shear is one Anchor 0.31.1 program. It holds TSLAx in Token-2022 accounts, issues vault shares and calls as legacy SPL tokens, runs the weekly USDC auction and settles each round against a Pyth close mark. This page lists its on-chain interface. The TypeScript SDK builds the same instructions, and the indexer API serves the decoded accounts and events.

Program ID#

The program ID is GG8Db3XMAfAaa4RT38e5uaeFSDjztEyaATpR6B3AxMcn. The IDL ships with the SDK as idl/shear.json; its address field carries the same ID.

Pinned addresses#

The program compares these addresses against compiled constants, in account constraints or in the handler, and rejects any other mint, oracle owner or feed. The SDK exports them under the names below.

SDK constantAddressRole
TSLA_X_MINTXsDoVfqeBukxuZHWhdvWHBhgEHjGNst4MLodqsJHzoBTSLAx mint. Token-2022, 8 decimals. Collateral, deposits and call payouts.
USDC_MINTEPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1vUSDC mint. Legacy SPL Token, 6 decimals. Bid escrow and premium.
PYTH_RECEIVERrec2HHDDnjLfj4kE7VyEtFA1HPGQLK33259532cRyHpPyth receiver program. Price update accounts must be owned by it.
TSLA_FEED16dad506d7db8da01c87581c87ca897a012a153557d4d578c3b9c9e1bc0632f1Pyth feed ID of the regular-session TSLA price, 32 bytes in hex.
TOKEN_2022_PROGRAM_IDTokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEbToken program of every TSLAx account, passed as asset_program.
TOKEN_PROGRAM_IDTokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DAToken program of shares, calls and USDC, passed as token_program.

The program also pins the issuer keys on the TSLAx mint. Every instruction that reads the mint checks them, together with its extension set. See corporate actions and trust.

Program constantAddressChecked as
MINT_AUTHORITY7pt9tkctJPK7PPNQJ77GKg8ZffSF6QxoMiCFYHxrtaCjMint authority of TSLAx.
PAUSE_AUTHORITYJDq14BWvqCRFNu1krb12bcRpbGtJZ1FLEakMw6FdxJNsFreeze authority and Pausable extension authority.
ISSUER5aMNNLQJwAEeoemTEMkv5NVjqKwvvefRYCQ5Z67HFvEqConfidential-transfer authority, permanent delegate, transfer-hook authority, metadata-pointer authority and token-metadata update authority.
MULTIPLIER_AUTHORITYS7vYFFWH6BjJyEsdrPQpqpYTqLTrPRK6KW3VwsJuRaSAuthority of the ScaledUiAmount multiplier.

The mint must carry exactly the Token-2022 extensions 4, 6, 12, 14, 18, 19, 25 and 26 (ConfidentialTransferMint, DefaultAccountState, PermanentDelegate, TransferHook, MetadataPointer, TokenMetadata, ScaledUiAmount, Pausable), with confidential auto-approve off, no auditor, no transfer-hook program and the token not paused.

Units#

All amounts are unsigned integers in base units. The program uses no floating point. TSLAx amounts are raw Token-2022 amounts, before the mint’s ScaledUiAmount multiplier.

QuantityScaleOne unitFields
TSLAx8 decimals100_000_000 = 1 TSLAxamount, deposit, offered, snapshot_nav, payouts
Vault shares8 decimals100_000_000 = 1 shareshares, min_shares, pending_withdraw, withdraw
Calls8 decimals100_000_000 = 1 call on 1 TSLAxquantity, sold, allocation, claimed_options
USDC6 decimals1_000_000 = 1 USDCescrow, charge, premium_total, premium_credit
Premium price6 decimals per whole call1_000_000 = 1 USDC per calllimit_premium_micro, clearing, reserve_premium_micro
USD mark6 decimals per whole TSLAx1_000_000 = 1 USDstrike, settlement
Multiplier9 decimals1_000_000_000 = 1.0entry_multiplier, close_multiplier
Premium accumulator18 decimals10^18 = 1 micro-USDC per share atompremium_index, premium_fraction
Basis points1/10,000500 = 5%otm_bps, max_confidence_bps
TimeUnix seconds1790971200 = 2026-10-02 20:00 UTCopen, close, expiry, auction_end, observed_at

One call atom covers one raw TSLAx atom. A USD mark is the value of one whole raw TSLAx token: the Pyth TSLA price at 6 decimals times the mint multiplier. See oracle.

Constants#

ConstantValueMeaning
MAX_BIDS16Bids per round.
DISPUTE_SECONDS900Window after observe_expiry for challenge_expiry; settle_round waits for it to pass.
Observation window3600observe_expiry and challenge_expiry run from expiry to expiry + 3600.
Timeout604800timeout_settle opens 7 days after expiry.
Strike mark age60start_round needs a Pyth update published within the last 60 seconds.
Corporate-action window900Mint reads fail within 900 seconds of a scheduled multiplier activation.
PREMIUM_SCALE1_000_000_000_000_000_000Scale of the premium accumulator.
MULTIPLIER_SCALE1_000_000_000Scale of the multiplier.
UNSTAKE_SECONDS604800Wait from request_unstake to the earliest withdraw_stake.
STAKE_DECIMALS6Decimals the bidder stake mint must have.

Accounts#

Eight account types. Each starts with Anchor’s 8-byte discriminator. Field names below are the Rust names; decoded TypeScript objects use camelCase, so share_mint becomes shareMint.

Vault#

One per underlying mint, created by initialize. The vault PDA is the authority of the share mint, custody and premium accounts.

FieldTypeMeaning
adminPubkeySigner of initialize, or the account that later accepted the role. Registers sessions, authorizes bidders and sets the bidder stake.
underlyingPubkeyTSLAx mint.
share_mintPubkeyShare mint. Legacy SPL Token, 8 decimals.
custodyPubkeyToken-2022 TSLAx account holding assets between rounds.
premiumPubkeyUSDC account holding auction premium until claimed.
bumpu8PDA bump.
configVaultConfigParameters set at initialize.
premium_indexu128Cumulative premium, micro-USDC per share atom scaled by 10^18.
round_indexu64Index of the latest round. 0 before the first round.
activeboolTrue from start_round until close_round.
pending_adminPubkeyNamed by set_admin; becomes admin when it signs accept_admin. Default key when none.

VaultConfig is fixed at initialize. See parameters.

FieldTypeBoundsMeaning
otm_bpsu16100 to 5000Strike offset above the entry mark.
max_confidence_bpsu161 to 500Largest accepted Pyth confidence, as a share of price.
auction_secondsu32300 to 7200Auction length.
reserve_premium_microu64above 0Lowest bid, micro-USDC per whole call.

Session#

One regular market session, committed by the vault admin with register_session. Sessions are immutable. See calendar.

FieldTypeMeaning
vaultPubkeyVault the session belongs to.
openi64Session open, Unix seconds.
closei64Session close, Unix seconds. Also a PDA seed.
calendar_hash[u8; 32]Non-zero commitment to the calendar the session came from.
weekly_expiryboolWhether a round may expire at this close.

Bidder#

One per wallet per vault, created by authorize_bidder or stake_bidder. A wallet can bid when allowed is true, or when it holds a stake with unlock_at 0. Approval is checked first, so an approved wallet’s bids never count against its stake. See bidder stake.

FieldTypeMeaning
vaultPubkeyVault.
ownerPubkeyBidder wallet.
allowedboolApproved by the vault admin.
stakeu64Stake mint atoms held in the escrow at ["stake", bidder]. 0 without a stake.
unlock_ati640 while the stake is active. After request_unstake, the earliest withdraw_stake, Unix seconds.
open_bidsu16Bids placed through the stake and not yet claimed.

StakeConfig#

One per vault, created by the first set_bidder_stake. The mint is fixed by that call.

FieldTypeMeaning
vaultPubkeyVault.
mintPubkeyStake mint: legacy SPL Token, 6 decimals, no mint or freeze authority.
amountu64Atoms each new stake locks. 0 stops new stakes; earlier stakes keep what they locked.
bumpu8PDA bump.

Position#

One per owner per vault. Its shares sit in a vault-owned token account at ["position-shares", position] and move only through program instructions. See premium.

FieldTypeMeaning
vaultPubkeyVault.
ownerPubkeyOwner wallet.
sharesu64Share atoms held. Must equal the position share account balance.
pending_withdrawu64Share atoms locked by an open withdrawal ticket.
premium_indexu128Vault premium_index at the last checkpoint.
premium_creditu64Credited premium not yet claimed, micro-USDC.
premium_fractionu128Remainder below one micro-USDC, scaled by 10^18.

Round#

One per weekly round, created by start_round. The round PDA is the authority of the round’s collateral, deposits, reserve, bid escrow and call mint.

FieldTypeMeaning
vaultPubkeyVault.
indexu64Round number, from 1.
bumpu8PDA bump.
phasePhaseCurrent phase.
expiryi64Close of the expiry session, Unix seconds. The settlement mark is the second before.
auction_endi64End of bidding: start time plus auction_seconds.
strikeu64Strike, micro-USD per whole TSLAx.
entry_multiplieru64TSLAx multiplier at start_round, 9 decimals.
offeredu64TSLAx atoms moved into collateral. Equal to the call atoms offered.
soldu64Call atoms allocated by the auction.
clearingu64Clearing premium, micro-USDC per whole call. 0 when nothing sold.
premium_totalu64Premium charged to all bids, micro-USDC.
option_mintPubkeyCall mint of this round.
bid_countu8Bids placed, at most 16.
claimed_bidsu8Bids settled through claim_bid.
bids[BidRecord; 16]Bid book. Entries past bid_count are zeroed.
pending_ticketsu32Tickets opened and not yet processed.
settlementu64Settlement mark: Pyth close times close_multiplier, micro-USD per whole TSLAx.
close_multiplieru64TSLAx multiplier at the close second, 9 decimals.
observed_ati64Time observe_expiry ran. The dispute window starts here.
oracle_publishi64Publish time of the observed Pyth update.
oracle_pricei64Raw Pyth price of the observed update.
oracle_exponenti32Pyth exponent of the observed update.
reserve_totalu64TSLAx atoms moved to the reserve at settlement.
claimed_optionsu64Call atoms burned through claim_option.
snapshot_navu64Custody TSLAx after settlement. Tickets use it.
snapshot_supplyu64Share supply at settlement. Tickets use it.
fallbackboolTrue when timeout_settle settled the round.

BidRecord is one entry of Round.bids:

FieldTypeMeaning
ownerPubkeyBidder wallet.
quantityu64Call atoms bid for.
limitu64Limit premium, micro-USDC per whole call.
allocationu64Call atoms filled. Set by finalize_auction.
chargeu64Premium owed, micro-USDC. Set by finalize_auction.

Ticket#

One per owner per round. Holds at most one queued deposit and one queued withdrawal. See deposits.

FieldTypeMeaning
roundPubkeyRound.
ownerPubkeyOwner wallet.
positionPubkeyOwner’s position.
initializedboolSet on first use. Counts toward pending_tickets.
processedboolSet by process_ticket.
depositu64TSLAx atoms queued.
min_sharesu64Fewest share atoms the owner accepts for the deposit.
withdrawu64Share atoms queued for withdrawal.

Bid#

One per bidder per round. Receipt for the escrow; the bid terms live in Round.bids.

FieldTypeMeaning
roundPubkeyRound.
ownerPubkeyBidder wallet.
indexu8Slot in Round.bids.
escrowu64USDC escrowed, micro-USDC.
claimedboolSet by claim_bid.
stakedboolPlaced through a stake rather than an approval. Its claim lowers Bidder.open_bids.

Phase#

Borsh enum on Round.phase. The decoded TypeScript value is an object with one key, such as { Active: {} }. See settlement.

VariantIndexMeaningLeaves by
Auction0Bids accepted until auction_end.finalize_auction to Active.
Active1Calls outstanding until expiry.observe_expiry to Observed. settle_round to Settled when nothing sold. timeout_settle to Settled.
Observed2Close mark recorded; dispute window open.challenge_expiry to Disputed. settle_round to Settled.
Settled3Reserve set aside and NAV snapshot taken. Tickets process; calls are claimable.close_round to Closed.
Closed4Round finished and vault inactive. Calls stay claimable.Final.
Disputed5Conflicting authenticated close marks.timeout_settle to Settled.

PDAs#

Seeds are a UTF-8 string followed by 32-byte public keys or little-endian integers: index as u64, close as i64. Seeds below are exactly those in the account contexts.

AccountSeedsHolds
Vault"vault", underlying_mintVault state.
Share mint"shares", vaultLegacy SPL mint, 8 decimals, mint authority vault.
Custody"custody", vaultToken-2022 TSLAx account, authority vault.
Premium"premium", vaultUSDC account, authority vault.
Session"session", vault, close (i64 LE)Session state.
Bidder"bidder", vault, ownerApproval and stake of one wallet.
Stake escrow"stake", bidderStake mint token account, authority bidder.
Stake config"stake-config", vaultStake mint and amount.
Position"position", vault, ownerPosition state.
Position shares"position-shares", positionShare token account, authority vault.
Round"round", vault, index (u64 LE)Round state.
Collateral"collateral", roundToken-2022 TSLAx account under the calls, authority round.
Deposits"deposits", roundToken-2022 TSLAx account for queued deposits, authority round.
Reserve"reserve", roundToken-2022 TSLAx account paying calls after settlement, authority round.
Bid escrow"bids", roundUSDC account, authority round.
Call mint"options", roundLegacy SPL mint, 8 decimals, mint authority round.
Ticket"ticket", round, ownerQueue entry.
Bid"bid", round, ownerBid receipt.
Deriving PDAs
import { PublicKey } from '@solana/web3.js';

const PROGRAM = new PublicKey('GG8Db3XMAfAaa4RT38e5uaeFSDjztEyaATpR6B3AxMcn');
const TSLAX = new PublicKey('XsDoVfqeBukxuZHWhdvWHBhgEHjGNst4MLodqsJHzoB');
const pda = (...seeds: Buffer[]) => PublicKey.findProgramAddressSync(seeds, PROGRAM)[0];
const u64 = (n: bigint) => { const b = Buffer.alloc(8); b.writeBigUInt64LE(n); return b; };

const vault = pda(Buffer.from('vault'), TSLAX.toBuffer());
const round = pda(Buffer.from('round'), vault.toBuffer(), u64(1n));
const ticket = pda(Buffer.from('ticket'), round.toBuffer(), owner.toBuffer());

For the pinned TSLAx mint the vault-level addresses are:

AccountAddress
Vault9Q5nHgxW9864oE6q8JLjp6GioUkkQF1f3EsUcSgVYru9
Share mintE61GhHfpx832wdG5BneKCzsujGP8au7FfKcaUyvv3NR7
CustodyJAVt8HP5aphQPnxisZhXedRHeRCREdcQL2mzUZKDDELe
Premium7N1ieKGMaJXfhuZnJd5wSWx343iahVLZRT9EXDafd98j

Instructions#

Names here are the Rust snake_case names. The Anchor TypeScript client and ShearClient.instruction use camelCase for instruction, argument and account names: fund_ready is fundReady, min_shares is minShares, position_shares is positionShares. Each table lists the checks in the handler. Account constraints (PDA seeds, has_one, token mints and authorities) apply as well; account lists are under instruction accounts.

Instructions marked mint check read the TSLAx mint. They fail with UnsupportedMint or UnsupportedExtension if its authorities or extensions differ from the pinned set, with IssuerPaused while the issuer has paused the token, and with CorporateActionWindow within 900 seconds of a scheduled multiplier activation. observe_expiry reads the multiplier at expiry - 1 and also fails if an activation falls between that second and the observation. See corporate actions.

Owner-signed#

Signed by the position owner, who pays rent for any account the instruction creates. claim_option is signed by whoever holds the calls and needs no position.

InstructionArgumentsRequiresEffect
create_position—No position for this owner yet.Creates the Position and its share token account, starting at the current premium_index.
fund_readyamount: u64, min_shares: u64Vault inactive. amount above 0. Share supply is 0 or custody above 0. Minted shares above 0 and at least min_shares. Mint check.Moves amount TSLAx from source to custody and mints shares at the custody ratio.
redeem_readyshares: u64, min_assets: u64Vault inactive. shares above 0 and at most the position’s shares. No pending withdrawal. Assets at least min_assets. Mint check.Burns shares and sends their pro-rata custody TSLAx to destination.
queue_depositamount: u64, min_shares: u64amount above 0. Vault active and round is its current round, in Auction, Active or Observed. No deposit on this ticket yet. Mint check.Moves amount TSLAx into the round’s deposits account and records it on the owner’s ticket.
request_withdrawalshares: u64shares above 0. Same round condition as queue_deposit. No withdrawal on the ticket or position yet. shares at most the position’s shares.Locks shares on the position and records them on the owner’s ticket.
transfer_sharesshares: u64shares above 0. Recipient position differs from the sender. shares at most sender shares minus pending_withdraw. Any phase.Moves shares to another position of the vault, checkpointing premium on both.
claim_premium—Credited premium above 0 after the checkpoint. Any phase.Checkpoints the position and sends its whole premium_credit in USDC to destination.
claim_optionquantity: u64Round Settled or Closed. quantity above 0. claimed_options + quantity at most sold. Mint check.Burns quantity calls and pays payout(claimed + quantity) - payout(claimed) TSLAx from the reserve; after a fallback settlement, quantity atoms.
  • A second deposit on the same ticket fails with DuplicateRequest; a second withdrawal with InvalidAmount.
  • min_shares on a queued deposit is checked against the settlement snapshot in process_ticket. A deposit that would mint fewer shares is refunded to the owner.
  • A queued withdrawal keeps earning the round’s premium. Its shares stay locked against transfer_shares until the ticket is processed.
  • Between owners, shares move only through transfer_shares, and the recipient must already have a position. Calls are ordinary SPL tokens and move freely.

Bidder#

Signed by the bidder wallet, which pays rent for what it creates. A wallet bids after the vault admin approves it with authorize_bidder, or after it locks the bidder stake with stake_bidder. See bidding and bidder stake.

InstructionArgumentsRequiresEffect
place_bidquantity: u64, limit_premium_micro: u64Round in Auction and before auction_end. Bidder allowed, or holding a stake with unlock_at 0. quantity above 0 and at most offered. Limit at least reserve_premium_micro. Fewer than 16 bids. No earlier bid from this wallet in the round.Creates the Bid and escrows ceil(quantity × limit_premium_micro / 10^8) USDC from source. A bid through the stake sets staked and raises open_bids.
claim_bid—Round past Auction. Bid not claimed. Signer is the bid owner.Refunds escrow minus charge to refund in USDC and mints the allocated calls to options. Lowers open_bids for a staked bid.
stake_bidder—StakeConfig amount above 0. Wallet holds no stake in this vault.Creates the Bidder if needed and the stake escrow, and moves amount of the stake mint from source into it.
request_unstake—Stake above 0 and unlock_at 0.Sets unlock_at to now plus UNSTAKE_SECONDS. The stake no longer qualifies the wallet to bid.
withdraw_stake—Stake above 0 and unlock_at set. Now at or after unlock_at. open_bids is 0.Sends the whole escrow to destination, closes the escrow to the signer and clears the stake.

Permissionless#

Any wallet can send these; the keeper sends them on schedule. Only start_round names a signer, keeper, which pays rent for the new round accounts. The others need only a fee payer.

InstructionArgumentsRequiresEffect
start_roundindex: u64Vault inactive. index equals round_index + 1. Share supply above 0. Now inside the strike session. Expiry session is a weekly expiry closing 1 to 8 days from now. Fully verified Pyth TSLA update published inside the strike session within the last 60 seconds, confidence within limit. Auction ends no later than the strike session close. Custody above 0. Mint check.Creates the round and its five token accounts, sets the strike, moves all custody TSLAx to collateral and opens the auction.
finalize_auction—Round in Auction. Now at or after auction_end.Clears the auction, moves the charged premium to the vault premium account, raises premium_index and sets the round Active.
observe_expiry—Round Active with sold above 0. Now within one hour after expiry. Fully verified Pyth update published at exactly expiry - 1, previous publish time earlier, confidence within limit. Mint check.Records the settlement mark and sets the round Observed.
challenge_expiry—Round Observed. Within 900 seconds of observed_at and one hour of expiry. A valid update for the same second with a different price or exponent.Sets the round Disputed.
settle_round—Round Active with sold 0, or Observed for at least 900 seconds. Collateral at least offered. Mint check.Moves the call liability to the reserve, returns the rest to custody, records the NAV snapshot and sets the round Settled.
timeout_settle—Round Active or Disputed. Now at least expiry plus 7 days. Collateral at least offered. Mint check.Reserves one TSLAx atom per sold call atom, returns the rest, sets fallback and sets the round Settled.
process_ticket—Round Settled. Ticket initialized and not processed. Mint check.Pays the withdrawal at the snapshot ratio, then admits the deposit at the snapshot ratio or refunds it below min_shares.
close_round—Round Settled. pending_tickets is 0. Round is the vault’s current round.Sets the round Closed and the vault inactive.
reclaim_option_dust—Round Closed. Every bid claimed. claimed_options equals sold. Call supply 0. Reserve balance 0.Verifies that the round’s call liability is extinguished. Moves no tokens.

Admin#

initialize is signed by the program’s upgrade authority, which becomes the vault admin. accept_admin is signed by the account set_admin named. The rest are signed by the vault admin, which pays rent for what they create. See trust, calendar and governance.

InstructionArgumentsRequiresEffect
initializeconfig: VaultConfigSigner is the upgrade authority recorded in the program’s ProgramData. USDC mint has 6 decimals. otm_bps 100 to 5000, max_confidence_bps 1 to 500, auction_seconds 300 to 7200, reserve_premium_micro above 0. Mint check.Creates the vault, share mint, custody and premium accounts.
register_sessionopen: i64, close: i64, calendar_hash: [u8; 32], weekly_expiry: boolSigner is the vault admin. close more than one hour away. open before close. Length 12,600 to 23,400 seconds. close falls on a Monday to Friday UTC date. Hash not all zero. No session with this close yet.Creates an immutable Session.
authorize_bidderallowed: boolSigner is the vault admin.Creates or updates the Bidder entry for owner and sets allowed. Leaves any stake as it is.
set_adminnew_admin: PubkeySigner is the vault admin.Sets pending_admin. The default key cancels a pending handover.
accept_admin—Signer is pending_admin, which is not the default key.Makes the signer the vault admin and clears pending_admin.
set_bidder_stakeamount: u64Signer is the vault admin. On the first call, mint is a legacy SPL mint with 6 decimals, supply above 0, no mint authority and no freeze authority; afterwards it must be the recorded mint.Creates StakeConfig if needed and sets amount for new stakes.

Instructions that create an account with init fail when it already exists: a second create_position, a second place_bid from one wallet in a round, a second register_session for the same close, or a second stake_bidder while the escrow is open.

Formulas#

Integer formulas in the handlers. Division rounds as listed; checked arithmetic fails with Arithmetic on overflow.

ValueFormulaRounding
Pyth markprice scaled from its exponent to 6 decimalsDown. Exponent -12 to 0; result 1 to 10^15.
Effective pricemark × multiplier / 10^9Down.
Strikeeffective_price × (10000 + otm_bps) / 10000Up.
Bid escrowquantity × limit_premium_micro / 10^8Up.
Bid chargeallocation × clearing / 10^8Up.
Premium index steppremium_total × 10^18 / share_supplyDown.
Premium checkpoint(shares × (index - position_index) + fraction) / 10^18Down, added to premium_credit; the remainder stays in premium_fraction.
Call payoutq × (settlement - strike) / settlement, or 0 if settlement ≤ strikeDown.
fund_ready sharesamount if supply is 0, else amount × supply / custodyDown.
redeem_ready assetsshares × custody / supplyDown.
Ticket withdrawalwithdraw × snapshot_nav / snapshot_supplyDown.
Ticket deposit sharesdeposit × snapshot_supply / snapshot_nav, or 0 if NAV is 0Down.

Auction clearing sorts bids by limit, highest first, with ties broken by ascending owner public-key bytes, and fills them in order up to offered. If total demand exceeds offered, the clearing premium is the limit of the last bid that received a fill; otherwise it is reserve_premium_micro. Every filled bid pays the clearing premium. With nothing sold, clearing is 0.

Calls are claimed against cumulative liability: a claim of q pays payout(claimed + q) - payout(claimed). Any split of claims pays out exactly the reserve, and claim order moves an individual payout by at most one atom.

Instruction accounts#

Accounts in IDL order. Pass every one; the SDK builds with accountsStrict and resolves none. Token accounts named source, destination, refund and options belong to the signer, except the destination of process_ticket, which belongs to the ticket owner.

InstructionSignerAccounts
initializeadminadmin, self_program, program_data, underlying_mint, usdc_mint, vault, share_mint, custody, premium, asset_program, token_program, system_program
register_sessionadminadmin, vault, session, system_program
authorize_bidderadminadmin, vault, owner, bidder, system_program
set_adminadminadmin, vault
accept_adminnew_adminnew_admin, vault
set_bidder_stakeadminadmin, vault, stake_config, mint, system_program
stake_bidderownerowner, vault, stake_config, mint, bidder, escrow, source, token_program, system_program
request_unstakeownerowner, vault, bidder
withdraw_stakeownerowner, vault, bidder, escrow, destination, token_program
create_positionownerowner, vault, share_mint, position, position_shares, token_program, system_program
fund_readyownerowner, vault, underlying_mint, share_mint, custody, position, position_shares, source, asset_program, token_program
redeem_readyownerowner, vault, underlying_mint, share_mint, custody, position, position_shares, destination, asset_program, token_program
queue_depositownerowner, vault, round, position, ticket, underlying_mint, deposits, source, asset_program, system_program
request_withdrawalownerowner, vault, round, position, ticket, underlying_mint, deposits, source, asset_program, system_program
transfer_sharesownerowner, vault, share_mint, sender, recipient, sender_shares, recipient_shares, token_program
claim_premiumownerowner, vault, position, premium, destination, token_program
claim_optionownerowner, vault, round, underlying_mint, option_mint, options, reserve, destination, asset_program, token_program
place_bidownerowner, vault, round, bidder, bid, bids, source, token_program, system_program
claim_bidownerowner, round, bid, bidder, bids, refund, option_mint, options, token_program
start_roundkeeperkeeper, vault, underlying_mint, usdc_mint, share_mint, custody, strike_session, expiry_session, price_update, round, collateral, deposits, reserve, bids, option_mint, asset_program, token_program, system_program
finalize_auction—vault, round, share_mint, bids, premium, token_program
observe_expiry—vault, round, underlying_mint, price_update
challenge_expiry—vault, round, underlying_mint, price_update
settle_round—vault, round, underlying_mint, share_mint, custody, collateral, reserve, asset_program
timeout_settle—vault, round, underlying_mint, share_mint, custody, collateral, reserve, asset_program
process_ticket—vault, round, ticket, position, underlying_mint, share_mint, custody, deposits, position_shares, destination, asset_program, token_program
close_round—vault, round
reclaim_option_dust—vault, round, underlying_mint, option_mint, reserve, custody, asset_program
  • request_withdrawal shares its account context with queue_deposit, so it takes deposits and a TSLAx source although it moves no tokens.
  • program_data is the program’s ProgramData account under the upgradeable BPF loader.
  • price_update is a Pyth PriceUpdateV2 account owned by the receiver, with full verification. See oracle.
  • strike_session and expiry_session are Session PDAs of the vault, derived from their close.
  • In transfer_shares, sender is the signer’s position and recipient the position of the receiving owner.

Events#

Anchor events, written as Program data: log lines. Decode them with the IDL or with decodeEvent from the SDK. Units follow the account fields.

EventEmitted byFields
VaultInitializedinitializevault: Pubkey, admin: Pubkey
SessionRegisteredregister_sessionvault: Pubkey, open: i64, close: i64, calendar_hash: [u8; 32]
SharesFundedfund_readyvault: Pubkey, owner: Pubkey, assets: u64, shares: u64
ReadyRedeemedredeem_readyvault: Pubkey, owner: Pubkey, shares: u64, assets: u64
RoundStartedstart_roundvault: Pubkey, round: Pubkey, index: u64, strike: u64, expiry: i64, offered: u64
DepositQueuedqueue_depositround: Pubkey, owner: Pubkey, amount: u64
WithdrawalQueuedrequest_withdrawalround: Pubkey, owner: Pubkey, shares: u64
BidPlacedplace_bidround: Pubkey, owner: Pubkey, quantity: u64, limit: u64
AuctionFinalizedfinalize_auctionround: Pubkey, sold: u64, clearing: u64, premium: u64
BidClaimedclaim_bidround: Pubkey, owner: Pubkey, options: u64, refund: u64
ExpiryObservedobserve_expiryround: Pubkey, settlement: u64, publish_time: i64, dispute_until: i64
ExpiryDisputedchallenge_expiryround: Pubkey
RoundSettledsettle_roundround: Pubkey, reserved: u64, nav: u64, supply: u64
OracleFailureSettledtimeout_settleround: Pubkey, reserved: u64, nav: u64, supply: u64
TicketProcessedprocess_ticketround: Pubkey, owner: Pubkey, withdrawal: u64, deposit: u64, minted_shares: u64, deposit_refunded: bool
RoundClosedclose_roundround: Pubkey, index: u64
PremiumClaimedclaim_premiumvault: Pubkey, owner: Pubkey, amount: u64
OptionClaimedclaim_optionround: Pubkey, owner: Pubkey, quantity: u64, payout: u64
AdminProposedset_adminvault: Pubkey, admin: Pubkey, pending: Pubkey
AdminAcceptedaccept_adminvault: Pubkey, admin: Pubkey
BidderStakeSetset_bidder_stakevault: Pubkey, mint: Pubkey, amount: u64
BidderStakedstake_biddervault: Pubkey, owner: Pubkey, amount: u64
UnstakeRequestedrequest_unstakevault: Pubkey, owner: Pubkey, amount: u64, unlock_at: i64
StakeWithdrawnwithdraw_stakevault: Pubkey, owner: Pubkey, amount: u64

create_position, authorize_bidder, transfer_shares and reclaim_option_dust emit no event. In TicketProcessed, minted_shares is 0 when deposit_refunded is true, and deposit_refunded is also true for a ticket that queued no deposit.

Errors#

Custom errors start at 6000 in declaration order and appear in logs as custom program error: 0x1770 and up. Constraints without a custom error, such as PDA seeds, has_one and token mint or authority checks, fail with Anchor’s built-in codes below 6000.

CodeHexNameMessage
60000x1770ArithmeticChecked integer arithmetic failed
60010x1771InvalidConfigInvalid vault parameters
60020x1772UnsupportedMintOnly the verified Token-2022 TSLAx mint is supported
60030x1773UnsupportedExtensionMint extension or issuer authority differs from supported policy
60040x1774IssuerPausedIssuer paused the underlying token
60050x1775InvalidMultiplierInvalid fixed-point corporate-action multiplier
60060x1776CorporateActionWindowCorporate-action activation or historical multiplier ambiguity
60070x1777InvalidOracleOwnerPyth update has an unexpected program owner
60080x1778InvalidOracleInvalid Pyth account, feed, or price
60090x1779UnverifiedOraclePyth update must have full guardian verification
60100x177aOracleConfidencePyth confidence interval exceeds vault limit
60110x177bWrongOracleTimestampPyth timestamp differs from immutable session mark
60120x177cObservationWindowClose observation must occur within one hour after regular session
60130x177dNoConflictNo conflicting authenticated close mark supplied
60140x177eWrongPhaseInstruction unavailable in current round phase
60150x177fInvalidSessionInvalid or uncommitted regular-session calendar window
60160x1780MarketClosedOperation requires an open regular market session
60170x1781EmptyVaultVault has no assets or shares
60180x1782InvalidAmountAmount must be positive and within owned balance
60190x1783DuplicateRequestDuplicate round request
60200x1784UnauthorizedSigner or account is not authorized
60210x1785WithdrawalLockedRequested shares are locked for round withdrawal
60220x1786SlippageMinimum share output was not met
60230x1787ShareMismatchPosition share ledger differs from custody account
60240x1788InvalidBidBid is outside whitelist or auction bounds
60250x1789AuctionFullAuction supports at most sixteen bidders
60260x178aCustodyShortfallIssuer removed underlying collateral
60270x178bPendingTicketsRound tickets must be processed before next round
60280x178cNothingToClaimPosition has no whole premium units to claim
60290x178dOutstandingOptionsOption liabilities must be extinguished before dust reclaim
60300x178eStakeUnavailableVault takes no new bidder stakes
60310x178fInvalidStakeMintStake mint must be a fixed-supply six-decimal SPL token without a freeze authority
60320x1790AlreadyStakedWallet already holds a stake in this vault
60330x1791NotStakedWallet has no stake in the required state
60340x1792StakeLockedStake is locked until the wait ends and every staked bid is claimed