Skip to main content
This page describes a design. The program deployed on devnet runs the direct path only: one wager, one draw. The figures below are design targets, and the final parameters will be set from measurements.

Why

On the direct path every wager pays for its own oracle draw. With ORAO’s mainnet fee and Solana’s reduced rent fully active, a wager’s fixed overhead is 934 440 lamports (oracle fee, locked request rent and crank fee), about 0.11 USD at 120 USD per SOL. Keeping that overhead within 150 bps of the stake sets the direct path’s reference minimum at 7.5 USDC. Most of that cost is per draw, not per wager. Shared by a round of wagers, one draw costs well under a cent per wager. That is what makes round-ups, cashbacks and other payouts of a few cents possible.

How a round works

  • One draw per round. Small wagers join a round. One ORAO request serves it, and each wager settles on its own outcome, derived from the draw and the wager’s identifier, so outcomes stay independent.
  • Rounds exist only when there are wagers. The first wager opens a round. No wager, no round, no draw, no cost.
  • Admitted on entry. A wager joining a round passes every check open_wager runs (paytable, caps, breakers) and its liability is reserved at once.
  • Paid, then closed. A round is paid once its stakes and any sponsorship cover its draw. It closes at the next tick boundary, every 37 slots (about 13 seconds); no transaction is needed to close it. Wagers joining before the boundary still enter.
  • Seed after the close. From the close slot + 2, anyone requests the round’s draw, with a seed built on the first slot hash after the close, exactly as on the direct path:
  • Grouped settlement. Several wagers settle in one transaction, for a settlement share far below the direct path’s 200 000 lamports.

Who pays the draw

  • Wagers, in proportion to their stake. Each wager is charged its share of the draw pro rata to its stake, never more than 150 bps of the stake at the round’s prices. Each wager prepays the most it could be charged and gets the rest back at settlement.
  • The pool never pays for a draw.
  • Sponsors. Anyone (the app, a merchant) may add SOL to a round’s draw so it is paid sooner. A merchant-funded win-back can sponsor its own rounds so they close at once. Sponsorship cannot be withdrawn; unused sponsorship returns.

A way out, never forced

  • A user or their app may cancel a wager until its round is paid. The stake returns to the account it came from; nothing more comes back than went in.
  • From about 600 seconds after a round’s first wager, anyone may refund the round if its draw is still unpaid. Nobody is paid to do it, so no bot races to empty slow rounds.
  • On the beacon path the protocol and app fees are held until settlement, so a cancellation or refund returns exactly what the wager put in, and the pool never returns fees it did not receive.
  • A closed round that is not requested, or not fulfilled, within T_SETTLE forfeits as a whole, like a direct wager: the seed exists by then, so a refund would hand an option to whoever withheld the draw.

Capacity follows payment

One draw decides a whole round, so a round’s aggregate liability is capped at a governed multiple k of one wager’s cap, starting at k = 1. And a round may only reserve capacity in proportion to how much of its draw is paid:
Nobody can fill a round, and freeze the pool’s capacity, without paying for draws. Only one round accepts wagers at a time, so at most one unpaid round exists. Throughput comes from rounds closing every tick, not from their size.

Minimum stake

The target is 0.10 USD, so a ten-cent round-up can win back a purchase. Reaching it requires grouped settlement to cost about 5 000 lamports per wager; if it lands nearer 20 000, the beacon’s minimum would be about 0.50 USD. The beacon’s minimum stake is a governed parameter, set from that measurement. Below the minimum, apps can accumulate small amounts into one ticket.

Liquidity providers

A round’s wagers join the epoch accounting when the round closes, not when they join: before the close no seed exists, so nothing can be known and nothing needs keeping out of the price. The strike never waits for a round that has not closed, so a liquidity provider’s claim timing is unchanged.

Two paths, the app’s choice