OpportunitiesEntities
Docs
    Ring Platform

    Decentralized Self-building Future

    Sign In
    Entities
    Opportunities
    Store
    Docs
    Platform Concepts
    RING EconomySonoratek LLCGlobal ImpactAI Meets Web3
    Get Started
    Quick StartCalculatorRoadmap
    Privacy|Contact
    v1.104.17|Sonoratek LLC

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)
    Ring Logo

    Loading documentation...

    Preparing Ring content

    Ring Logo

    Loading documentation...

    Preparing Ring content

    Ring Logo

    Loading documentation...

    Preparing Ring content

    WalletConductor architecture

    WalletConductor is Ring Platform's server-only money facade for custodial native-token wallets and the fiat credit ledger. Thin adapters call the conductor; PaymentConductor owns PSP checkout for wallet_topup and native_token_onramp. Browser handoff after top-up is Conductor redirect + followCheckoutResult — see PaymentConductor architecture.

    Operator / product guide: WalletConductor · Wallet · PaymentConductor

    Use Founder / Developer tabs in the docs sidebar to filter this page. Feature overview (value + checklist): WalletConductor. HTTP/action inventory: Wallet API.

    Feature overview

    Capabilities, two-rate SSOT, operator checklist

    PaymentConductor architecture

    Ledger, webhooks, purpose handlers

    Wallet API

    Actions and HTTP surface

    Why this architecture matters

    • One money spine — top-up, Token Desk, custodial send, ad-hoc credit spend, and NFT market buy share one facade instead of scattered PSP/ledger calls.
    • Clear product split — card top-up buys credit points; desk converts points ↔ native; confidential+ onramp buys treasury native without adding points.
    • Safe operator knobs — desk oracle (nativePerMainCurrency) never rewrites store checkout or ad-hoc credit spend math (credit.creditBalanceUnitToMainCurrency).
    • Boundary by design — store/membership checkout and external EVM POST /api/wallet/transfer stay outside WalletConductor so clones do not mix rails accidentally.

    Request flow

    WalletConductor — adapter → facade → deps

    Core modules

    ModulePathResponsibility
    Facadefeatures/wallet/conductor/wallet-conductor.tsAll public orchestration methods
    Provisionfeatures/wallet/services/ensure-wallet.tsAtomic multi-chain wallet create (used by ensureNativeWallet)
    Credit ledgerfeatures/wallet/services/credit-balance-service.tsFiat points add/spend
    Fiat rate →

    Related documentation

    Related documentation

    Tunnel Protocol

    Depends-on: after transferNative / ensure, conductor fans out `wallet:list` via publishWalletListUpdate.

    WalletConductor

    Next-step: dual-audience product guide for operators.

    PaymentConductor architecture

    Same-workflow: PSP ledger and webhooks for wallet_topup / native_token_onramp.

    Wallet & Credit System

    See-also: member-facing wallet dashboard flows.

    WalletConductor architecture

    WalletConductor is Ring Platform's server-only money facade for custodial native-token wallets and the fiat credit ledger. Thin adapters call the conductor; PaymentConductor owns PSP checkout for wallet_topup and native_token_onramp. Browser handoff after top-up is Conductor redirect + followCheckoutResult — see PaymentConductor architecture.

    Operator / product guide: WalletConductor · Wallet · PaymentConductor

    Use Founder / Developer tabs in the docs sidebar to filter this page. Feature overview (value + checklist): WalletConductor. HTTP/action inventory: Wallet API.

    Feature overview

    Capabilities, two-rate SSOT, operator checklist

    PaymentConductor architecture

    Ledger, webhooks, purpose handlers

    Wallet API

    Actions and HTTP surface

    Why this architecture matters

    • One money spine — top-up, Token Desk, custodial send, ad-hoc credit spend, and NFT market buy share one facade instead of scattered PSP/ledger calls.
    • Clear product split — card top-up buys credit points; desk converts points ↔ native; confidential+ onramp buys treasury native without adding points.
    • Safe operator knobs — desk oracle (nativePerMainCurrency) never rewrites store checkout or ad-hoc credit spend math (credit.creditBalanceUnitToMainCurrency).
    • Boundary by design — store/membership checkout and external EVM POST /api/wallet/transfer stay outside WalletConductor so clones do not mix rails accidentally.

    Request flow

    WalletConductor — adapter → facade → deps

    Core modules

    ModulePathResponsibility
    Facadefeatures/wallet/conductor/wallet-conductor.tsAll public orchestration methods
    Provisionfeatures/wallet/services/ensure-wallet.tsAtomic multi-chain wallet create (used by ensureNativeWallet)
    Credit ledgerfeatures/wallet/services/credit-balance-service.tsFiat points add/spend
    Fiat rate →

    Related documentation

    Related documentation

    Tunnel Protocol

    Depends-on: after transferNative / ensure, conductor fans out `wallet:list` via publishWalletListUpdate.

    WalletConductor

    Next-step: dual-audience product guide for operators.

    PaymentConductor architecture

    Same-workflow: PSP ledger and webhooks for wallet_topup / native_token_onramp.

    Wallet & Credit System

    See-also: member-facing wallet dashboard flows.

    WalletConductor architecture

    WalletConductor is Ring Platform's server-only money facade for custodial native-token wallets and the fiat credit ledger. Thin adapters call the conductor; PaymentConductor owns PSP checkout for wallet_topup and native_token_onramp. Browser handoff after top-up is Conductor redirect + followCheckoutResult — see PaymentConductor architecture.

    Operator / product guide: WalletConductor · Wallet · PaymentConductor

    Use Founder / Developer tabs in the docs sidebar to filter this page. Feature overview (value + checklist): WalletConductor. HTTP/action inventory: Wallet API.

    Feature overview

    Capabilities, two-rate SSOT, operator checklist

    PaymentConductor architecture

    Ledger, webhooks, purpose handlers

    Wallet API

    Actions and HTTP surface

    Why this architecture matters

    • One money spine — top-up, Token Desk, custodial send, ad-hoc credit spend, and NFT market buy share one facade instead of scattered PSP/ledger calls.
    • Clear product split — card top-up buys credit points; desk converts points ↔ native; confidential+ onramp buys treasury native without adding points.
    • Safe operator knobs — desk oracle (nativePerMainCurrency) never rewrites store checkout or ad-hoc credit spend math (credit.creditBalanceUnitToMainCurrency).
    • Boundary by design — store/membership checkout and external EVM POST /api/wallet/transfer stay outside WalletConductor so clones do not mix rails accidentally.

    Request flow

    WalletConductor — adapter → facade → deps

    Core modules

    ModulePathResponsibility
    Facadefeatures/wallet/conductor/wallet-conductor.tsAll public orchestration methods
    Provisionfeatures/wallet/services/ensure-wallet.tsAtomic multi-chain wallet create (used by ensureNativeWallet)
    Credit ledgerfeatures/wallet/services/credit-balance-service.tsFiat points add/spend
    Fiat rate →

    Related documentation

    Related documentation

    Tunnel Protocol

    Depends-on: after transferNative / ensure, conductor fans out `wallet:list` via publishWalletListUpdate.

    WalletConductor

    Next-step: dual-audience product guide for operators.

    PaymentConductor architecture

    Same-workflow: PSP ledger and webhooks for wallet_topup / native_token_onramp.

    Wallet & Credit System

    See-also: member-facing wallet dashboard flows.

    lib/payments/credit-balance.ts
    getFiatCreditAccountingRate
    credit.creditBalanceUnitToMainCurrency SSOT
    Deskfeatures/wallet/chains/solana/desk-service.tsQuote + execute (subscriber+)
    Desk oraclefeatures/wallet/services/native-token-oracle.tsnativePerMainCurrency for desk only
    Custodial sendfeatures/wallet/chains/native-token-transfer-service.tsGasless native transfer
    PSP checkoutlib/payments/conductor/payment-conductor.tswallet_topup, native_token_onramp
    Onramp gatelib/payments/confidential-token-onramp.tsassertNativeTokenOnrampAllowed
    Actionsapp/_actions/wallet.tsSession-facing wrappers
    NFT buyfeatures/nft-market/services/solana-market-client.tsMarket purchase settlement

    Facade API

    MethodAuth / gatesDelegates to
    initiateTopUpSession; amount 25–2000PaymentConductor wallet_topup; returns redirect
    initiateNativeOnrampSession + confidential+ + onramp flagPaymentConductor native_token_onramp
    quoteDesk / executeDeskassertTokenDeskSubscriberAccessdesk-service + oracle
    getNativeBalanceCaller userIdnative-token-transfer-service
    transferNativeCaller userIdtransfer service + wallet_transactions + publishWalletListUpdate(userId, 'updated')
    spendCreditsCaller userIdcreditBalanceService + fiat rate (+ credit:balance tunnel via service)
    ensureNativeWalletCaller supplies id (OAuth-safe)ensure-wallet (+ wallet:list when wallets change)
    ensureFundedSessionensure + optional credit floor
    purchaseNftListingIdempotency keySolanaMarketClient

    Also exported: getWalletConductorNativeChain() → getNativeChain().

    Two rates — do not mix

    RateSSOTUsed by
    Fiat credit accountingcredit.creditBalanceUnitToMainCurrency via getFiatCreditAccountingRate()spendCredits, desk debit side, PaymentConductor credit_balance
    Token Desk oracleplatform_settings.web3.oracle.nativePerMainCurrencyquoteDesk / executeDesk only
    Conductor boundary

    Not owned by WalletConductor: store/membership checkout (store_order, membership_upgrade, credit_balance / native_token rails), SubscriptionConductor membership lifecycle, and external EVM POST /api/wallet/transfer (Polygon POL / SupportedCrypto). Prefer /api/wallet/token/transfer for platform native custodial sends.

    Thin adapters (verified)

    Server Actions (app/_actions/wallet.ts)

    ActionConductor method
    ensureUserWalletsensureNativeWallet
    getNativeTokenBalanceActiongetNativeBalance
    spendCreditsspendCredits
    transferNativeTokenstransferNative
    executeDeskQuoteexecuteDesk
    initiateCreditTopupPaymentinitiateTopUp
    initiateNativeTokenOnrampPaymentinitiateNativeOnramp
    createPinAccessTokenActionensureNativeWallet

    Desk quote has no action wrapper — HTTP only (POST /api/wallet/desk/quote). NFT buy: app/_actions/nft-market.ts → purchaseNftListing. OAuth: auth.ts → ensureNativeWallet.

    HTTP routes that call WalletConductor

    MethodPathConductor method
    POST/api/wallet/desk/quotequoteDesk
    POST/api/wallet/desk/executeexecuteDesk
    POST/api/wallet/ensureensureNativeWallet
    GET/api/wallet/token/balancegetNativeBalance
    POST/api/wallet/token/transfertransferNative
    POST/api/wallet/credit/spendspendCredits (fiat rate SSOT)

    Explicitly outside the facade

    Path / surfaceWhy
    POST /api/wallet/transferEVM SupportedCrypto path — not Solana custodial SSOT
    POST /api/wallet/credit/topupChain-proof credit add via creditBalanceService (not card top-up)
    GET /api/wallet/credit/spend410 deprecated — use getSpendSummary / GET /api/wallet/credit/history
    Store / membership PaymentConductor purposesCheckout rails, not wallet facade

    Sequence — card → credit points

    initiateTopUp → wallet_topup

    See PaymentConductor architecture for CheckoutRedirect and WayForPay for HPP POST.

    Sequence — ad-hoc credit spend

    spendCredits fiat SSOT

    Environment & config (verified)

    KeyRole
    WALLET_ENCRYPTION_KEYCustodial key encryption
    SOLANA_RPC_URL / SOLANA_TREASURY_PRIVATE_KEYCustodial Solana + gas sponsorship
    CONFIDENTIAL_TOKEN_ONRAMP / NEXT_PUBLIC_CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnrampNative card onramp gate (isNativeTokenOnrampEnabled)
    credit.creditBalanceUnitToMainCurrencyFiat ledger accounting multiplier
    ORACLE_QUOTE_SECRET / RING_ORACLE_DEFAULT_RATEDesk quote HMAC + fallback

    Server SSOT for onramp: lib/ring-config-chain.ts → isNativeTokenOnrampEnabled(). Runtime role gate: assertNativeTokenOnrampAllowed (confidential/admin/superadmin + flag).

    Security notes

    • Custodial keys never leave the server; UI uses Server Actions / authenticated routes
    • Desk requires subscriber+; native onramp requires confidential+ and feature flag
    • Fiat spend must use getFiatCreditAccountingRate() — never feed desk nativePerMainCurrency into credit ledger debits
    • Prefer /api/wallet/token/* — retired /api/wallet/ring/* aliases are removed

    Wallet API

    Deep-dive: Server Actions and HTTP inventory.

    lib/payments/credit-balance.ts
    getFiatCreditAccountingRate
    credit.creditBalanceUnitToMainCurrency SSOT
    Deskfeatures/wallet/chains/solana/desk-service.tsQuote + execute (subscriber+)
    Desk oraclefeatures/wallet/services/native-token-oracle.tsnativePerMainCurrency for desk only
    Custodial sendfeatures/wallet/chains/native-token-transfer-service.tsGasless native transfer
    PSP checkoutlib/payments/conductor/payment-conductor.tswallet_topup, native_token_onramp
    Onramp gatelib/payments/confidential-token-onramp.tsassertNativeTokenOnrampAllowed
    Actionsapp/_actions/wallet.tsSession-facing wrappers
    NFT buyfeatures/nft-market/services/solana-market-client.tsMarket purchase settlement

    Facade API

    MethodAuth / gatesDelegates to
    initiateTopUpSession; amount 25–2000PaymentConductor wallet_topup; returns redirect
    initiateNativeOnrampSession + confidential+ + onramp flagPaymentConductor native_token_onramp
    quoteDesk / executeDeskassertTokenDeskSubscriberAccessdesk-service + oracle
    getNativeBalanceCaller userIdnative-token-transfer-service
    transferNativeCaller userIdtransfer service + wallet_transactions + publishWalletListUpdate(userId, 'updated')
    spendCreditsCaller userIdcreditBalanceService + fiat rate (+ credit:balance tunnel via service)
    ensureNativeWalletCaller supplies id (OAuth-safe)ensure-wallet (+ wallet:list when wallets change)
    ensureFundedSessionensure + optional credit floor
    purchaseNftListingIdempotency keySolanaMarketClient

    Also exported: getWalletConductorNativeChain() → getNativeChain().

    Two rates — do not mix

    RateSSOTUsed by
    Fiat credit accountingcredit.creditBalanceUnitToMainCurrency via getFiatCreditAccountingRate()spendCredits, desk debit side, PaymentConductor credit_balance
    Token Desk oracleplatform_settings.web3.oracle.nativePerMainCurrencyquoteDesk / executeDesk only
    Conductor boundary

    Not owned by WalletConductor: store/membership checkout (store_order, membership_upgrade, credit_balance / native_token rails), SubscriptionConductor membership lifecycle, and external EVM POST /api/wallet/transfer (Polygon POL / SupportedCrypto). Prefer /api/wallet/token/transfer for platform native custodial sends.

    Thin adapters (verified)

    Server Actions (app/_actions/wallet.ts)

    ActionConductor method
    ensureUserWalletsensureNativeWallet
    getNativeTokenBalanceActiongetNativeBalance
    spendCreditsspendCredits
    transferNativeTokenstransferNative
    executeDeskQuoteexecuteDesk
    initiateCreditTopupPaymentinitiateTopUp
    initiateNativeTokenOnrampPaymentinitiateNativeOnramp
    createPinAccessTokenActionensureNativeWallet

    Desk quote has no action wrapper — HTTP only (POST /api/wallet/desk/quote). NFT buy: app/_actions/nft-market.ts → purchaseNftListing. OAuth: auth.ts → ensureNativeWallet.

    HTTP routes that call WalletConductor

    MethodPathConductor method
    POST/api/wallet/desk/quotequoteDesk
    POST/api/wallet/desk/executeexecuteDesk
    POST/api/wallet/ensureensureNativeWallet
    GET/api/wallet/token/balancegetNativeBalance
    POST/api/wallet/token/transfertransferNative
    POST/api/wallet/credit/spendspendCredits (fiat rate SSOT)

    Explicitly outside the facade

    Path / surfaceWhy
    POST /api/wallet/transferEVM SupportedCrypto path — not Solana custodial SSOT
    POST /api/wallet/credit/topupChain-proof credit add via creditBalanceService (not card top-up)
    GET /api/wallet/credit/spend410 deprecated — use getSpendSummary / GET /api/wallet/credit/history
    Store / membership PaymentConductor purposesCheckout rails, not wallet facade

    Sequence — card → credit points

    initiateTopUp → wallet_topup

    See PaymentConductor architecture for CheckoutRedirect and WayForPay for HPP POST.

    Sequence — ad-hoc credit spend

    spendCredits fiat SSOT

    Environment & config (verified)

    KeyRole
    WALLET_ENCRYPTION_KEYCustodial key encryption
    SOLANA_RPC_URL / SOLANA_TREASURY_PRIVATE_KEYCustodial Solana + gas sponsorship
    CONFIDENTIAL_TOKEN_ONRAMP / NEXT_PUBLIC_CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnrampNative card onramp gate (isNativeTokenOnrampEnabled)
    credit.creditBalanceUnitToMainCurrencyFiat ledger accounting multiplier
    ORACLE_QUOTE_SECRET / RING_ORACLE_DEFAULT_RATEDesk quote HMAC + fallback

    Server SSOT for onramp: lib/ring-config-chain.ts → isNativeTokenOnrampEnabled(). Runtime role gate: assertNativeTokenOnrampAllowed (confidential/admin/superadmin + flag).

    Security notes

    • Custodial keys never leave the server; UI uses Server Actions / authenticated routes
    • Desk requires subscriber+; native onramp requires confidential+ and feature flag
    • Fiat spend must use getFiatCreditAccountingRate() — never feed desk nativePerMainCurrency into credit ledger debits
    • Prefer /api/wallet/token/* — retired /api/wallet/ring/* aliases are removed

    Wallet API

    Deep-dive: Server Actions and HTTP inventory.

    lib/payments/credit-balance.ts
    getFiatCreditAccountingRate
    credit.creditBalanceUnitToMainCurrency SSOT
    Deskfeatures/wallet/chains/solana/desk-service.tsQuote + execute (subscriber+)
    Desk oraclefeatures/wallet/services/native-token-oracle.tsnativePerMainCurrency for desk only
    Custodial sendfeatures/wallet/chains/native-token-transfer-service.tsGasless native transfer
    PSP checkoutlib/payments/conductor/payment-conductor.tswallet_topup, native_token_onramp
    Onramp gatelib/payments/confidential-token-onramp.tsassertNativeTokenOnrampAllowed
    Actionsapp/_actions/wallet.tsSession-facing wrappers
    NFT buyfeatures/nft-market/services/solana-market-client.tsMarket purchase settlement

    Facade API

    MethodAuth / gatesDelegates to
    initiateTopUpSession; amount 25–2000PaymentConductor wallet_topup; returns redirect
    initiateNativeOnrampSession + confidential+ + onramp flagPaymentConductor native_token_onramp
    quoteDesk / executeDeskassertTokenDeskSubscriberAccessdesk-service + oracle
    getNativeBalanceCaller userIdnative-token-transfer-service
    transferNativeCaller userIdtransfer service + wallet_transactions + publishWalletListUpdate(userId, 'updated')
    spendCreditsCaller userIdcreditBalanceService + fiat rate (+ credit:balance tunnel via service)
    ensureNativeWalletCaller supplies id (OAuth-safe)ensure-wallet (+ wallet:list when wallets change)
    ensureFundedSessionensure + optional credit floor
    purchaseNftListingIdempotency keySolanaMarketClient

    Also exported: getWalletConductorNativeChain() → getNativeChain().

    Two rates — do not mix

    RateSSOTUsed by
    Fiat credit accountingcredit.creditBalanceUnitToMainCurrency via getFiatCreditAccountingRate()spendCredits, desk debit side, PaymentConductor credit_balance
    Token Desk oracleplatform_settings.web3.oracle.nativePerMainCurrencyquoteDesk / executeDesk only
    Conductor boundary

    Not owned by WalletConductor: store/membership checkout (store_order, membership_upgrade, credit_balance / native_token rails), SubscriptionConductor membership lifecycle, and external EVM POST /api/wallet/transfer (Polygon POL / SupportedCrypto). Prefer /api/wallet/token/transfer for platform native custodial sends.

    Thin adapters (verified)

    Server Actions (app/_actions/wallet.ts)

    ActionConductor method
    ensureUserWalletsensureNativeWallet
    getNativeTokenBalanceActiongetNativeBalance
    spendCreditsspendCredits
    transferNativeTokenstransferNative
    executeDeskQuoteexecuteDesk
    initiateCreditTopupPaymentinitiateTopUp
    initiateNativeTokenOnrampPaymentinitiateNativeOnramp
    createPinAccessTokenActionensureNativeWallet

    Desk quote has no action wrapper — HTTP only (POST /api/wallet/desk/quote). NFT buy: app/_actions/nft-market.ts → purchaseNftListing. OAuth: auth.ts → ensureNativeWallet.

    HTTP routes that call WalletConductor

    MethodPathConductor method
    POST/api/wallet/desk/quotequoteDesk
    POST/api/wallet/desk/executeexecuteDesk
    POST/api/wallet/ensureensureNativeWallet
    GET/api/wallet/token/balancegetNativeBalance
    POST/api/wallet/token/transfertransferNative
    POST/api/wallet/credit/spendspendCredits (fiat rate SSOT)

    Explicitly outside the facade

    Path / surfaceWhy
    POST /api/wallet/transferEVM SupportedCrypto path — not Solana custodial SSOT
    POST /api/wallet/credit/topupChain-proof credit add via creditBalanceService (not card top-up)
    GET /api/wallet/credit/spend410 deprecated — use getSpendSummary / GET /api/wallet/credit/history
    Store / membership PaymentConductor purposesCheckout rails, not wallet facade

    Sequence — card → credit points

    initiateTopUp → wallet_topup

    See PaymentConductor architecture for CheckoutRedirect and WayForPay for HPP POST.

    Sequence — ad-hoc credit spend

    spendCredits fiat SSOT

    Environment & config (verified)

    KeyRole
    WALLET_ENCRYPTION_KEYCustodial key encryption
    SOLANA_RPC_URL / SOLANA_TREASURY_PRIVATE_KEYCustodial Solana + gas sponsorship
    CONFIDENTIAL_TOKEN_ONRAMP / NEXT_PUBLIC_CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnrampNative card onramp gate (isNativeTokenOnrampEnabled)
    credit.creditBalanceUnitToMainCurrencyFiat ledger accounting multiplier
    ORACLE_QUOTE_SECRET / RING_ORACLE_DEFAULT_RATEDesk quote HMAC + fallback

    Server SSOT for onramp: lib/ring-config-chain.ts → isNativeTokenOnrampEnabled(). Runtime role gate: assertNativeTokenOnrampAllowed (confidential/admin/superadmin + flag).

    Security notes

    • Custodial keys never leave the server; UI uses Server Actions / authenticated routes
    • Desk requires subscriber+; native onramp requires confidential+ and feature flag
    • Fiat spend must use getFiatCreditAccountingRate() — never feed desk nativePerMainCurrency into credit ledger debits
    • Prefer /api/wallet/token/* — retired /api/wallet/ring/* aliases are removed

    Wallet API

    Deep-dive: Server Actions and HTTP inventory.

    1. Docs
    2. /Architecture
    3. /WalletConductor architecture

    Updated Jul 20, 20265 min listen

    1. Docs
    2. /Architecture
    3. /WalletConductor architecture

    Updated Jul 20, 20265 min listen

    1. Docs
    2. /Architecture
    3. /WalletConductor architecture

    Updated Jul 20, 20265 min listen