Protocol
Quote checks
What your browser verifies in a firm quote before you sign it.
A firm quote arrives as a purchase transaction that the vault's quote key has already signed. Once you add your signature it executes exactly as written, so the app reads it before you do. Every check runs in your browser, on the transaction bytes themselves, not on anything the API says about them.
What the app checks
| Check | What must be true |
|---|---|
| You pay the fee | The transaction's fee payer is your connected wallet |
| One purchase, two signers | It holds a single instruction, and the only signers are you and the vault's quote key |
| The Flume program | That instruction calls the Flume program, and it's a purchase |
| Your terms | The price, share, term, cap, sale number and expiry inside it match the quote and what you asked for |
| Still fresh | Its expiry hasn't passed |
If any check fails, the app strikes it through and tells you not to sign. Nothing about the check depends on the API being honest: a quote that says one thing and contains another fails.
What the program checks
Some protections don't need the browser, because the program enforces them on every purchase whoever builds it:
- the price is paid to a USDC account owned by the creator who signs,
- both the creator and the vault's quote key must sign,
- the sale number must be the source's next one, so an old quote can't be replayed,
- the quote must not have expired, and can't be valid for more than five minutes,
- the share is above zero and at most 50%, the term at most thirty days, and the cap at least the price,
- the purchase fits the vault's on-chain limits: at most 10% of its cash, with at least 20% left behind.
The request you sign first
Before any of this, you sign a plain-text request so Flume knows the quote is for the creator. It reads:
Flume quote request
Source: <source address>
Creator: <your wallet>
Share: <share in basis points> bps
Term: <term in seconds> seconds
Vault: <vault address>
Cluster: <genesis hash of the network>
Issued: <unix time>It's a message, not a transaction: a wallet can't move funds by signing it. Flume refuses a request older than two minutes, and the vault and cluster lines keep it from being reused anywhere else.