Instruction set
xrs-node 0.1.1src/token.rsvariants 0–61
Sixty-two instructions, bincode-encoded, each prefixed by its u32 index.
Encoding
| Type | Encoding | Size |
|---|---|---|
| enum tag | u32 LE | 4 |
u8 | raw | 1 |
u32 | LE | 4 |
u64 | LE | 8 |
bool | 00 / 01 | 1 |
String | u64 LE length + UTF-8 | 8 + n |
Vec<u8> | u64 LE length + bytes | 8 + n |
Vec<String> | u64 LE count + each String | 8 + Σ(8 + nᵢ) |
Option<T> | 00, or 01 + T | 1 or 1 + T |
[u8; 32] | 32 raw bytes, no prefix | 32 |
inner_instruction | a whole instruction as Vec<u8> | 8 + n |
NativeTransfer { from: "Alice", to: "Bob", amount: 5 XRS } 36 bytes
0b000000 variant 11, u32 LE
0500000000000000 416c696365 "Alice": u64 length, UTF-8
0300000000000000 426f62 "Bob"
00f2052a01000000 5,000,000,000 lamports, u64 LE
Fields follow declaration order. No names, no padding.
Envelope
build → sign (Ed25519) → POST :56001/submit → mempool
→ block (4 s) → GET :50008/v2/tx/{sig} → final after 64 blocks
01 1 signature
<64 bytes> Ed25519 signature
01 00 01 1 required signer, 0 read-only signed, 1 read-only unsigned
02 2 account keys
<32 bytes> payer = signer
<32 zero bytes> program id, never read
<32 bytes> recent_blockhash
01 1 instruction
01 01 00 program index 1, 1 account, account index 0
<len> <data> compact-u16 length, then the instruction bytes
| Field | Rule |
|---|---|
| signer and fee payer | account_keys[0] |
program_id | all zero, never read |
accounts | ignored |
recent_blockhash | one of the last 150 block hashes; hex from getLatestBlockhash |
| versioned messages | refused |
| fee | 0.001 XRS per transaction, before any instruction runs |
| atomicity | none: instructions commit one by one; partial is a real status |
| Limit | Value |
|---|---|
| instructions per tx | 16 |
| account keys | 64 |
| instruction data | 8 KiB (SlashReport 65,535 B) |
| transaction | 128 KiB |
| block | 40,000 tx, 4 MiB |
| mempool | 50,000 tx, 64 MiB, 256 per account |
Submit body: POST /submit. Status: Explorer API.
Variants
| # | Variant | Fields (S = String) |
|---|---|---|
| Tokens 0–3 | ||
| 0 | TokenMint | token_id S, to S, amount u64 |
| 1 | TokenTransfer | token_id S, from S, to S, amount u64 |
| 2 | TokenBurn | token_id S, from S, amount u64 |
| 3 | TokenCreate | token_id S, name S, symbol S, decimals u8, max_supply u64, mint_authority S |
| Contracts 4–5 | ||
| 4 | ContractCall | contract_id S, method S, args Vec<u8> |
| 5 | ContractDeploy | contract_id S, contract_type_str S, params_json S |
| Alexandria 6–8 | ||
| 6 | TokenCreateRWA | token_id S, name S, symbol S, decimals u8, max_supply u64, mint_authority S, asset_type S, legal_doc_hash S, legal_doc_uri S, jurisdiction S, transfer_restricted bool, accredited_only bool, valuation u64 |
| 7 | RWAUpdateStatus | token_id S, new_status S, new_valuation Option<u64>, new_legal_doc_hash Option<S>, new_legal_doc_uri Option<S> |
| 8 | RWATransfer | token_id S, from S, to S, amount u64 |
| Staking 9–10 | ||
| 9 | Stake roster keys only on mainnet | pubkey S, amount u64 |
| 10 | Unstake | pubkey S, amount u64 |
| Native 11–14 | ||
| 11 | NativeTransfer | from S, to S, amount u64 |
| 12 | ValidatorAttestation | validator S, block_slot u64, block_hash_prefix Vec<u8> (32 bytes) |
| 13 | WrapXrs | amount u64 |
| 14 | UnwrapXrs | amount u64 |
| Agents 15–17 | ||
| 15 | RegisterAgent | agent_name S, agent_pubkey S, max_per_tx u64, max_daily u64, allowed_contracts Vec<S>, allowed_operations Vec<S>, expires_at_slot u64 |
| 16 | UpdateAgent | agent_pubkey S, new_max_per_tx Option<u64>, new_max_daily Option<u64>, new_allowed_contracts Option<Vec<S>>, new_allowed_operations Option<Vec<S>>, new_expires_at_slot Option<u64>, revoked bool |
| 17 | AgentExecute | owner_pubkey S, inner_instruction Vec<u8> |
| ARI 18–45 | ||
| 18 | CreateIdentity | identity_pubkey S, display_name S, identity_type S, parent_identity S, metadata_json S |
| 19 | UpdateIdentity | identity_pubkey S, new_display_name Option<S>, new_metadata Option<S>, deactivated bool |
| 20 | AttestReputation | subject_pubkey S, score u8, category S, evidence S |
| 21 | AgentMessage | to_identity S, message_type S, payload_json S, reply_to S, expires_at_slot u64 |
| 22 | SubDelegate disabled | sub_agent_pubkey S, sub_agent_name S, max_per_tx u64, max_daily u64, allowed_contracts Vec<S>, allowed_operations Vec<S>, expires_at_slot u64, max_depth u8 |
| 23 | ConditionalOrder | order_id S, condition_type S, condition_source S, condition_threshold u64, inner_instruction Vec<u8>, expires_at_slot u64, locked_amount u64 |
| 24 | CancelConditionalOrder | order_id S |
| 25 | RegisterOracle | oracle_id S, description S, feed_type S, update_interval_slots u64, stake_amount u64 |
| 26 | OracleSubmit | oracle_id S, value u64, metadata S |
| 27 | HardwareAttest | device_pubkey S, device_type S, manufacturer S, model S, firmware_version S, attestation_proof Vec<u8>, bound_identity S |
| 28 | RegisterCapability | provider_identity S, category S, tags Vec<S>, region S, description S, price_per_unit u64, max_concurrent u32, metadata_json S |
| 29 | UpdateCapability | provider_identity S, category S, new_tags Option<Vec<S>>, new_description Option<S>, new_price_per_unit Option<u64>, new_max_concurrent Option<u32>, new_metadata Option<S>, removed bool |
| 30 | QueryCapabilities no-op; read GET /capabilities/search | category S, tags Vec<S>, region S, min_reputation u8, max_price u64 |
| 31 | PostTask | task_id S, title S, description S, required_category S, required_tags Vec<S>, min_reputation u8, reward u64, expires_at_slot u64, max_claimants u32, verification S, verification_oracle S, verification_threshold u64 |
| 32 | ClaimTask | task_id S, claimant_identity S |
| 33 | ResolveTask | task_id S, resolution S, proof S |
| 34 | RegisterModel | identity_pubkey S, model_name S, model_hash S, model_version S, framework S, capabilities_json S, model_size_bytes u64, execution_environment S |
| 35 | UpdateModel | identity_pubkey S, model_hash S, new_version Option<S>, new_capabilities Option<S>, new_environment Option<S>, retired bool |
| 36 | OpenDispute | dispute_id S, dispute_type S, subject_id S, defendant S, reason S, evidence S, bond u64 |
| 37 | ResolveDispute | dispute_id S, action S, data S |
| 38 | SlashReport | agent_pubkey S, owner_pubkey S, violation_type S, evidence S, violation_slot u64 |
| 39 | CreateProposal | proposal_id S, title S, description S, proposal_type S, parameter_json S, voting_period_slots u64, quorum u64 |
| 40 | CastVote | proposal_id S, vote S |
| 41 | ExecuteProposal | proposal_id S |
| 42 | OpenChannel | channel_id S, counterparty S, deposit u64, channel_type S, expires_at_slot u64 |
| 43 | CloseChannel | channel_id S, final_balance_a u64, final_balance_b u64, message_count u64, counterparty_signature Vec<u8> |
| 44 | ForceCloseChannel | channel_id S, claimed_balance_self u64, claimed_balance_other u64, state_sequence u64, counterparty_signature Vec<u8> |
| 45 | AgentHeartbeat | identity_pubkey S, current_model_hash S, active_tasks u32, available_capacity u32, status_message S |
| ZK and PQ 46–53 | ||
| 46 | ZkProofSubmit | proof_id S, proof_system S, proof_data Vec<u8>, public_inputs Vec<u8>, verification_key_hash S, proof_type S, metadata_json S |
| 47 | ZkProofVerify read-only | proof_id S |
| 48 | ZkPrivateTransfer disabled | token_id S, from S, to S, amount_commitment Vec<u8>, range_proof Vec<u8>, balance_proof Vec<u8>, nullifier Vec<u8> |
| 49 | ZkIdentityProof disabled | identity_pubkey S, claim_type S, claim_value u64, proof_data Vec<u8>, public_inputs Vec<u8> |
| 50 | PqKeyRegister first registration only; rotate with 51 | ed25519_pubkey S, pq_public_key Vec<u8>, pq_algorithm S, security_level u8 |
| 51 | PqKeyRotate | ed25519_pubkey S, new_pq_public_key Vec<u8>, new_pq_algorithm S, rotation_proof Vec<u8> |
| 52 | PqSignedTransfer disabled | from S, to S, amount u64, pq_signature Vec<u8>, pq_algorithm S |
| 53 | PqAttest self-asserted marker | attestation_type S, reference_id S, pq_algorithm S, verified bool |
| Deals 54–60 | ||
| 54 | CreateDeal | deal_id S, counterparty S, amount u64, terms S |
| 55 | AcceptDeal | deal_id S, instance u64, expected_party_a S, expected_amount u64, expected_terms_hash [u8; 32] |
| 56 | ConfirmDeal | deal_id S, instance u64 |
| 57 | CancelDeal | deal_id S, instance u64 |
| 58 | DisputeDeal | deal_id S, instance u64, reason S, bond u64 |
| 59 | SettleDeal | deal_id S, instance u64 |
| 60 | ReclaimDeal after 648,000 slots | deal_id S, instance u64 |
| ZK registry 61 | ||
| 61 | ZkVkRegister | vk_id S, vk_base64 S, claim_type S, description S |
Contract types
| Type | Deploy strings | Deployable |
|---|---|---|
TimeLock | timelock, time_lock | yes |
Escrow | escrow | yes |
Swap | swap | yes |
Vesting | vesting | yes |
MultiSig | multisig, multi_sig | yes |
RealWorldAsset | rwa, real_world_asset, realworldasset | yes |
Launchpad | launchpad, launch_pad | yes |
AgentRegistry | agent_registry, agent, agents | yes |
IdentityRegistry | identity, identity_registry | yes |
ConditionalOrderBook | conditional, conditional_orders, orders | no |
LimitOrder | limit, limit_order, limit_orders | yes |
DcaOrder | dca, dca_order, dollar_cost_averaging | yes |
OracleRegistry | oracle, oracle_registry, oracles | yes |
DeviceRegistry | device, device_registry, hardware | no |
CapabilityRegistry | capability, capabilities, cap_registry | yes |
TaskBoard | task, tasks, task_board, bounty | no |
ModelRegistry | model, model_registry, models | yes |
DisputeRegistry | dispute, disputes, arbitration | no |
Governance | governance, gov, dao | yes |
StateChannelRegistry | channel, channels, state_channel | no |
ZkVerifierRegistry | zk, zk_verifier, zero_knowledge | no |
PqKeyRegistry | pq, pq_keys, post_quantum, quantum | no |
DealRegistry | deal, deals, escrow_deal | no |
ContractCall args: a JSON object, {} at minimum; the two swap methods take 16 raw bytes.
Agent execution
| Inner instruction | Budgeted as |
|---|---|
NativeTransfer | amount |
TokenTransfer | amount |
ContractCall | spend derived from the method and JSON args |
WrapXrs, UnwrapXrs | amount |
Stake, Unstake | amount (accepted, no effect) |
TokenMint, TokenBurn | amount |
| anything else | refused |
| Rule | Value |
|---|---|
max_per_tx | per call |
max_daily | 21,600-slot window |
allowed_operations | exact strings; empty = all |
allowed_contracts | exact contract_id, ContractCall only |
expires_at_slot | 0 = never |
| spend recorded | after success |
| agents per owner | 50 |
Delegated calls to launchpad and RWA contracts and to the agent registry are refused.
Vectors
| Instruction | Bytes | Hex |
|---|---|---|
NativeTransfer | 36 | 0b0000000500000000000000416c6963650300000000000000426f6200f2052a01000000 |
Stake | 27 | 0900000007000000000000005465737456616c0010a5d4e8000000 |
TokenMint | 36 | 00000000050000000000000078555344430300000000000000426f6200ca9a3b00000000 |
WrapXrs | 12 | 0d00000000e40b5402000000 |
ContractCall swap | 60 | 040000000500000000000000706f6f6c310b00000000000000737761705f615f746f5f62100000000000000080969800000000000100000000000000 |
AgentExecute(NativeTransfer) | 61 | 110000000500000000000000416c69636524000000000000000b0000000500000000000000416c6963650300000000000000426f6200f2052a01000000 |
CreateDeal | 58 | 3600000006000000000000006465616c2d310300000000000000426f6200943577000000000d0000000000000073686970203120776964676574 |
AcceptDeal | 79 | 3700000006000000000000006465616c2d3101000000000000000500000000000000416c6963650094357700000000734c5fd1cd9fd0bb047abb8c90edf73dd1cc4584be43973dd64c92a8402fa65d |
RegisterAgent | 112 | 0f0000000900000000000000546573744167656e7409000000000000007075626b6579313233e803000000000000d00700000000000001000000000000000600000000000000706f6f6c5f6101000000000000000c00000000000000436f6e747261637443616c6c0000000000000000 |
import { Instructions, TestVectors } from 'xeris-sdk';
// row 1
Instructions.nativeTransfer('Alice', 'Bob', 5_000_000_000).toString('hex');
TestVectors.verify().ok; // true