> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fade.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Architecture

> The accounts, their seeds, and what each instruction writes.

Fade is one Anchor program. Three rules shape it:

1. **Two sides that never share a write.** Wagers and liquidity-provider flows each have their own state account and token accounts. Only two instructions touch both: the strike, and the request that opens an epoch. A rush of deposits or withdrawals never competes with wagers for the same accounts.
2. **Constant cost per instruction.** No instruction iterates over requests, wagers or apps. The strike costs the same with one request or ten thousand.
3. **Every unit of work is prepaid to whoever does it.** Requesting randomness, settling, expiring, striking and claiming are all paid, so none depends on goodwill or on the party that created the work coming back.

## Accounts

| Account | Seeds | Side | Lifetime |
| - | - | - | - |
| `Config` | `["config"]` | Governance | Never closed |
| `Pool` | `["pool"]` | Wagers | Never closed |
| Pool USDC (`vault_usdc`) | `["usdc-vault"]` | Wagers | Never closed |
| Payout escrow | `["payout-escrow"]` | Wagers | Never closed |
| `Integrator` (app record) | `["integrator", authority]` | Wagers | Created by the first wager, never closed |
| `Wager` | `["wager", integrator, nonce]` | Wagers | Closed at settlement or expiry (or by `claim_payout`); rent to its payer |
| `vrf_payer` | `["vrf-payer", wager]` | Wagers | System-owned; drained to the wager's payer at close |
| `Queue` | `["queue"]` | Liquidity | Never closed; its lamports above rent are the strike fund |
| Deposit queue USDC | `["deposit-queue"]` | Liquidity | Never closed |
| Payable USDC | `["payable"]` | Liquidity | Never closed |
| Share mint | `["shares"]` | Liquidity | Never closed |
| Share escrow | `["share-escrow"]` | Liquidity | Never closed |
| Share claims | `["share-claims"]` | Liquidity | Never closed |
| `EpochRecord` | `["epoch", epoch_id]` | Liquidity | Closed by the claim that releases it last; rent to the strike fund |
| `DepositRequest` | `["deposit", epoch_id, owner]` | Liquidity | Closed at the claim; rent to the owner |
| `WithdrawRequest` | `["withdraw", epoch_id, owner]` | Liquidity | Closed at the final claim; rent to the owner |

Every token account is owned by the data-less `["vault-authority"]` PDA. Integers in seeds are little-endian `u64`. A program app signs as `["fade-integrator"]` under its **own** program id.

### `Pool`

`total_assets`, `total_shares`, `total_reserved_liability`, `open_pool_credits`; the epoch counters that gate the strike (wagers opened before and after the live close, and a generation number); a copy of the live close time; a ring of hourly share-price maxima for the drawdown breaker; `volume_total`; and the results of wagers opened after the live close, which the strike leaves out of its price. Identity: the pool USDC account holds at least `total_assets`.

### `Queue`

The two live epochs (`current`, waiting for its price, and `next`, filling), each with its deposits, queued withdrawal shares and request counts; the running indices that let a withdrawal served over several epochs be claimed once; the next epoch id. Its lamports above its rent-exempt minimum are the strike fund.

### `Wager`

`status` (`Open`, `Requested`, `PayoutPending`), `integrator`, `nonce`, `payer`, `beneficiary`, `stake`, `pool_credit`, `payout_max`, `reserved_liability`, the `cap` that applied, `paytable_edge_bps`, `integrator_fee_bps`, `pool_edge_bps`, `open_slot`, `open_ts`, `expiry_slot`, the bound `randomness` account, `entropy_slot`, `entropy_hash`, `seed`, `bucket`, `payout`, the crank fee still held, and the paytable itself (up to 32 buckets).

### `Integrator`

The authority (the app's signing address), the `fee_account`, open liability, open wager count, `next_nonce`, `volume_total`, a `paused` flag and its creation time.

### `Config`

The council, the guardian, the protocol treasury, the USDC mint, the pause flags, the risk parameters, and at most one pending parameter change.

## What each instruction writes

| Instruction | Wager side | Liquidity side |
| - | - | - |
| `open_wager` | `Pool`, pool USDC, `Integrator`, `Wager`, `vrf_payer`, treasury and app fee accounts | none |
| `request_randomness` | `Wager`, `vrf_payer`, the ORAO request | none |
| `settle_wager`, `expire_wager` | `Pool`, pool USDC, `Integrator`, `Wager`, `vrf_payer`, beneficiary or payout escrow | none |
| `claim_payout` | Payout escrow, `Wager` | none |
| `request_deposit` | `Pool` only if it opens an epoch | `Queue`, deposit queue USDC, `DepositRequest` |
| `request_withdraw` | `Pool` only if it opens an epoch | `Queue`, share escrow, `WithdrawRequest` |
| `strike_epoch` | `Pool`, pool USDC | `Queue`, deposit queue, payable USDC, share mint, share escrow, share claims, `EpochRecord` |
| `claim_deposit` | none | Share claims, `EpochRecord`, `DepositRequest` |
| `claim_withdraw` | none | Payable USDC, one or two `EpochRecord`s, `WithdrawRequest` |

Claims never read `Pool`: the price is in the epoch record.

## Money flows

```mermaid theme={null}
flowchart LR
    S[Stake source] -- protocol fee --> T[Protocol treasury]
    S -- app fee --> F[App fee account]
    S -- pool credit --> V[Pool USDC]
    V -- payout --> B[Beneficiary]
    V -. beneficiary cannot receive .-> E[Payout escrow]
    E -- claim_payout --> B
    D[LP USDC] -- request_deposit --> Q[Deposit queue]
    Q -- strike --> V
    V -- strike --> P[Payable USDC]
    P -- claim_withdraw --> L[LP USDC]
```

## Throughput

Every open writes `Pool`. At about 65 000 compute units per open and Solana's per-account write limit per block, `Pool` allows on the order of 180 opens per block. The liquidity side never contends with it except at the strike.

## Composition

`open_wager`, `settle_wager` and the other wager instructions can sit in any transaction. `request_deposit` and `request_withdraw` inspect the transaction's top-level instructions and refuse any outside an allowlist (compute budget, system, token, associated token and Fade's own liquidity instructions). The check sees only top-level instructions, so it is defence in depth; epoch pricing carries the real load.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.