Docs

Protocol

Quote checks

What your browser verifies in a firm quote before you sign it.

A firm quote arrives as a purchase transaction that the vault's quote key has already signed. Once you add your signature it executes exactly as written, so the app reads it before you do. Every check runs in your browser, on the transaction bytes themselves, not on anything the API says about them.

What the app checks

CheckWhat must be true
You pay the feeThe transaction's fee payer is your connected wallet
One purchase, two signersIt holds a single instruction, and the only signers are you and the vault's quote key
The Flume programThat instruction calls the Flume program, and it's a purchase
Your termsThe price, share, term, cap, sale number and expiry inside it match the quote and what you asked for
Still freshIts expiry hasn't passed

If any check fails, the app strikes it through and tells you not to sign. Nothing about the check depends on the API being honest: a quote that says one thing and contains another fails.

What the program checks

Some protections don't need the browser, because the program enforces them on every purchase whoever builds it:

  • the price is paid to a USDC account owned by the creator who signs,
  • both the creator and the vault's quote key must sign,
  • the sale number must be the source's next one, so an old quote can't be replayed,
  • the quote must not have expired, and can't be valid for more than five minutes,
  • the share is above zero and at most 50%, the term at most thirty days, and the cap at least the price,
  • the purchase fits the vault's on-chain limits: at most 10% of its cash, with at least 20% left behind.

The request you sign first

Before any of this, you sign a plain-text request so Flume knows the quote is for the creator. It reads:

Text
Flume quote request
Source: <source address>
Creator: <your wallet>
Share: <share in basis points> bps
Term: <term in seconds> seconds
Vault: <vault address>
Cluster: <genesis hash of the network>
Issued: <unix time>

It's a message, not a transaction: a wallet can't move funds by signing it. Flume refuses a request older than two minutes, and the vault and cluster lines keep it from being reused anywhere else.