the program

the mechanism is one solana program. it owns the fee vault, keeps the two running fee totals, holds the thresholds and the minimum holding, and records every sweep and release. once deployed, this page would read the config account straight from a solana rpc, so the numbers would be the program's own state and not a copy kept somewhere else.

addresses

fieldvalue
program idnot deployed
config accountnot deployed
fee vaultnot deployed
mintnot deployed
authoritynot deployed

config account layout

the config account is a fixed header followed by two length prefixed strings and one state byte. every cell below is one byte, in order.

discriminator · mint
mint · authority
authority · fee vault
fee vault · sweep threshold · release threshold · minimum holding
swept zcash · swept monero · sweep count · release count
address length
then the reserve address bytes, then a u32 length and the viewing key bytes, then one state byte

state

fieldvalue
sweep threshold0 sol
release threshold0 sol
minimum holding0 zxr
total swept to zcash0 sol
total swept to monero0 sol
sweep count0
release count0
reserve addressnot deployed
viewing keynot deployed
statebalanced

instructions

five instructions. two can only be signed by the authority and are used once each at setup. three can only be signed by the keeper, and none of them can move value anywhere except the destinations already written in the config account.

instructionsignereffect
initializeauthoritywrites the config account once: the mint, the fee vault, the thresholds and the minimum holding.
record feekeeperadds an incoming creator fee to the buy side or sell side total and updates the state byte.
sweepkeeperclaims the buy side total, records the intent hash for the sol to zec settlement and raises the sweep count.
releasekeeperclaims the sell side total on a trigger sell, records the intent hash for the sol to xmr settlement and raises the release count.
set reserveauthoritywrites the zcash reserve address and the optional viewing key.

what the keeper cannot do

the keeper signs sweeps and releases, and that is all. it cannot change a threshold, the minimum holding or the reserve address, cannot mint, cannot move tokens, and cannot send the vault anywhere the config does not already point. if the keeper stops, fees pile up in the vault and wait. nothing is lost and nothing is redirected.

reading it yourself

once deployed: open the config account on a solana explorer and read the raw data against the layout above. the byte offsets are the same ones this page decodes with, and every number on the mechanism, reserve and releases pages comes from those bytes or from a transaction linked next to it.