the mechanism is a single solana program. it owns the fee vault, keeps the two running fee totals, holds the thresholds and the minimum holding, and records every sweep and every release. the site reads the program config account directly from a solana rpc, so the numbers here are the program's own state and not a copy of it kept somewhere else.
| field | value |
|---|---|
| program id | |
| config account | |
| fee vault | |
| mint | |
| authority |
the config account is a fixed header followed by two length prefixed strings and one state byte. every cell below is one byte, in order, and the values shown under each field are the values the account currently holds.
| field | value |
|---|---|
| sweep threshold | |
| release threshold | |
| minimum holding | |
| total swept to zcash | |
| total swept to monero | |
| sweep count | |
| release count | |
| reserve address | |
| viewing key | |
| state |
five instructions exist. two can only be signed by the authority and are used once each at setup. three can only be signed by the keeper, and none of them can move value anywhere other than the destinations already written in the config account.
| instruction | signer | effect |
|---|---|---|
| initialize | authority | writes the config account once, setting the mint, the fee vault, the thresholds and the minimum holding. |
| record fee | keeper | adds an arriving creator fee to the buy side or the sell side total, and updates the state byte. |
| sweep | keeper | claims the buy side total, records the intent hash for the sol to zec settlement and increments the sweep count. |
| release | keeper | claims the sell side total on a triggering sell, records the intent hash for the sol to xmr settlement and increments the release count. |
| set reserve | authority | writes the zcash reserve address and the optional viewing key. |
the keeper signs sweeps and releases, and that is the extent of it. it cannot change a threshold, cannot change the minimum holding, cannot change the reserve address, cannot mint, cannot move tokens and cannot send the fee vault anywhere the config account does not already point. if the keeper stops, fees accumulate in the vault and wait. nothing is lost and nothing is redirected.
open the config account on a solana explorer and read the raw account data against the layout above. the byte offsets are the same ones this page decodes with. every number on the mechanism, reserve and releases pages comes from those bytes or from a transaction linked next to it.