OpportunitiesEntities
Docs
    Ring Platform

    Decentralized Self-building Future

    Sign In
    Entities
    Opportunities
    Store
    Docs
    Platform Concepts
    RING EconomySonoratek LLCGlobal ImpactAI Meets Web3
    Get Started
    Quick StartCalculatorRoadmap
    Privacy|Contact
    v1.104.17|Sonoratek LLC

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Ring Oracle
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Profile Account Widgets
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Vertical Presets (SSOT)
    Ringization playbook
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Project configuration
    Public environment variables
    Order Lab secrets
    WalletConnect Project ID (Reown Cloud)
    Supported services
    NODUS wiki (project knowledge)
    Configuration playbook
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel Deployment
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Backend Services
    Firebase Integration
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)
    Ring Logo

    Loading documentation...

    Preparing Ring content

    Ring Logo

    Loading documentation...

    Preparing Ring content

    Ring Logo

    Loading documentation...

    Preparing Ring content

    WalletConductor

    WalletConductor is Ring Platform's orchestration facade for custodial native-token web3 and fiat credit money paths. Thin adapters (app/_actions/wallet.ts, /api/wallet/token/*, /api/wallet/desk/*, NFT market buy) call the conductor; it delegates PSPs to PaymentConductor and ledger math to creditBalanceService.

    Use Founder / Developer tabs in the docs sidebar to filter this page. Member-facing product UI: Wallet. HTTP/action inventory: Wallet API.

    Executive summary

    One layer for wallet money: card → credit points, desk → native token, gasless custodial sends, ad-hoc credit spend, and NFT market purchases. Fiat spend accounting uses credit.creditBalanceUnitToMainCurrency (usually 1) — never the desk oracle. External EVM POL/USDT via POST /api/wallet/transfer stays outside this conductor.

    WalletConductor — money paths

    What WalletConductor owns

    CapabilityMethodResult
    Card → credit pointsinitiateTopUpPaymentConductor wallet_topup → fiat ledger credit
    Card/PayPal → treasury nativeinitiateNativeOnrampPaymentConductor native_token_onramp (confidential+)
    Token DeskquoteDesk / executeDeskCredit points ↔ native at desk oracle (subscriber+)
    Custodial sendtransferNativeGasless native transfer + wallet_transactions row
    Native balancegetNativeBalanceCustodial balance for platform native chain
    Ad-hoc credit spendspendCreditsFiat ledger debit at creditBalanceUnitToMainCurrency
    Conductor boundary

    Not in WalletConductor: store/membership checkout debit (PaymentConductor credit_balance / SubscriptionConductor), and external EVM POST /api/wallet/transfer. Those remain separate SSOT paths by design.

    Two rates — do not mix

    RateSSOTUsed by
    Fiat credit accountingring-config.json → credit.creditBalanceUnitToMainCurrency (usually 1) via getMainCurrencyCreditAccountingRate()spendCredits, desk debit side, credit_balance checkout
    Token Desk oracleplatform_settings.web3.oracle.nativePerMainCurrency via native-token-oracle.tsquoteDesk / executeDesk points ↔ native only

    Why this matters for your clone

    WalletConductor is the operator-facing money spine behind the Wallet product. Members see top-up, desk, and send UI; your clone stays coherent because every path hits one facade — not scattered PSP and ledger calls.

    Credit top-up

    Any signed-in member buys credit points with a card. Points are fiat ledger units (1:1 with store mainCurrency when creditBalanceUnitToMainCurrency is 1).

    Token Desk

    Subscriber+ converts points ↔ native at the desk oracle. Changing nativePerMainCurrency never rewrites store or ad-hoc credit spend math.

    Native onramp

    Confidential+ card/PayPal → treasury native (feature-flagged). Does not add credit points.

    Implementation

    Facade: features/wallet/conductor/wallet-conductor.ts (server-only).

    Wire a surface

    1. 1

      Call the facade, not the ledger

      UI and routes should import WalletConductor (or the thin wrappers in app/_actions/wallet.ts). Do not debit creditBalanceService from feature UI for paths the conductor owns.

    2. 2

      Keep fiat rate SSOT

      For spend paths, omit usdRate or pass getMainCurrencyCreditAccountingRate(). Never feed nativePerMainCurrency / desk oracle into fiat ledger debits.

    3. 3

      Respect the EVM boundary

      Custodial native send is transferNative. External SupportedCrypto (POL/USDT) stays on POST /api/wallet/transfer — do not fold that into WalletConductor without an explicit redesign.

    Module map

    LayerPath
    Facadefeatures/wallet/conductor/wallet-conductor.ts
    Provision

    Related documentation

    Generative Gallery

    Credit-first generative billing via spendCredits + generative_usage ledger.

    WalletConductor architecture

    Adapters, route map, sequences, env SSOT.

    Wallet feature

    Product architecture and member flows.

    Wallet API

    Actions, HTTP routes, rate SSOT tables.

    WalletConductor

    WalletConductor is Ring Platform's orchestration facade for custodial native-token web3 and fiat credit money paths. Thin adapters (app/_actions/wallet.ts, /api/wallet/token/*, /api/wallet/desk/*, NFT market buy) call the conductor; it delegates PSPs to PaymentConductor and ledger math to creditBalanceService.

    Use Founder / Developer tabs in the docs sidebar to filter this page. Member-facing product UI: Wallet. HTTP/action inventory: Wallet API.

    Executive summary

    One layer for wallet money: card → credit points, desk → native token, gasless custodial sends, ad-hoc credit spend, and NFT market purchases. Fiat spend accounting uses credit.creditBalanceUnitToMainCurrency (usually 1) — never the desk oracle. External EVM POL/USDT via POST /api/wallet/transfer stays outside this conductor.

    WalletConductor — money paths

    What WalletConductor owns

    CapabilityMethodResult
    Card → credit pointsinitiateTopUpPaymentConductor wallet_topup → fiat ledger credit
    Card/PayPal → treasury nativeinitiateNativeOnrampPaymentConductor native_token_onramp (confidential+)
    Token DeskquoteDesk / executeDeskCredit points ↔ native at desk oracle (subscriber+)
    Custodial sendtransferNativeGasless native transfer + wallet_transactions row
    Native balancegetNativeBalanceCustodial balance for platform native chain
    Ad-hoc credit spendspendCreditsFiat ledger debit at creditBalanceUnitToMainCurrency
    Conductor boundary

    Not in WalletConductor: store/membership checkout debit (PaymentConductor credit_balance / SubscriptionConductor), and external EVM POST /api/wallet/transfer. Those remain separate SSOT paths by design.

    Two rates — do not mix

    RateSSOTUsed by
    Fiat credit accountingring-config.json → credit.creditBalanceUnitToMainCurrency (usually 1) via getMainCurrencyCreditAccountingRate()spendCredits, desk debit side, credit_balance checkout
    Token Desk oracleplatform_settings.web3.oracle.nativePerMainCurrency via native-token-oracle.tsquoteDesk / executeDesk points ↔ native only

    Why this matters for your clone

    WalletConductor is the operator-facing money spine behind the Wallet product. Members see top-up, desk, and send UI; your clone stays coherent because every path hits one facade — not scattered PSP and ledger calls.

    Credit top-up

    Any signed-in member buys credit points with a card. Points are fiat ledger units (1:1 with store mainCurrency when creditBalanceUnitToMainCurrency is 1).

    Token Desk

    Subscriber+ converts points ↔ native at the desk oracle. Changing nativePerMainCurrency never rewrites store or ad-hoc credit spend math.

    Native onramp

    Confidential+ card/PayPal → treasury native (feature-flagged). Does not add credit points.

    Implementation

    Facade: features/wallet/conductor/wallet-conductor.ts (server-only).

    Wire a surface

    1. 1

      Call the facade, not the ledger

      UI and routes should import WalletConductor (or the thin wrappers in app/_actions/wallet.ts). Do not debit creditBalanceService from feature UI for paths the conductor owns.

    2. 2

      Keep fiat rate SSOT

      For spend paths, omit usdRate or pass getMainCurrencyCreditAccountingRate(). Never feed nativePerMainCurrency / desk oracle into fiat ledger debits.

    3. 3

      Respect the EVM boundary

      Custodial native send is transferNative. External SupportedCrypto (POL/USDT) stays on POST /api/wallet/transfer — do not fold that into WalletConductor without an explicit redesign.

    Module map

    LayerPath
    Facadefeatures/wallet/conductor/wallet-conductor.ts
    Provision

    Related documentation

    Generative Gallery

    Credit-first generative billing via spendCredits + generative_usage ledger.

    WalletConductor architecture

    Adapters, route map, sequences, env SSOT.

    Wallet feature

    Product architecture and member flows.

    Wallet API

    Actions, HTTP routes, rate SSOT tables.

    WalletConductor

    WalletConductor is Ring Platform's orchestration facade for custodial native-token web3 and fiat credit money paths. Thin adapters (app/_actions/wallet.ts, /api/wallet/token/*, /api/wallet/desk/*, NFT market buy) call the conductor; it delegates PSPs to PaymentConductor and ledger math to creditBalanceService.

    Use Founder / Developer tabs in the docs sidebar to filter this page. Member-facing product UI: Wallet. HTTP/action inventory: Wallet API.

    Executive summary

    One layer for wallet money: card → credit points, desk → native token, gasless custodial sends, ad-hoc credit spend, and NFT market purchases. Fiat spend accounting uses credit.creditBalanceUnitToMainCurrency (usually 1) — never the desk oracle. External EVM POL/USDT via POST /api/wallet/transfer stays outside this conductor.

    WalletConductor — money paths

    What WalletConductor owns

    CapabilityMethodResult
    Card → credit pointsinitiateTopUpPaymentConductor wallet_topup → fiat ledger credit
    Card/PayPal → treasury nativeinitiateNativeOnrampPaymentConductor native_token_onramp (confidential+)
    Token DeskquoteDesk / executeDeskCredit points ↔ native at desk oracle (subscriber+)
    Custodial sendtransferNativeGasless native transfer + wallet_transactions row
    Native balancegetNativeBalanceCustodial balance for platform native chain
    Ad-hoc credit spendspendCreditsFiat ledger debit at creditBalanceUnitToMainCurrency
    Conductor boundary

    Not in WalletConductor: store/membership checkout debit (PaymentConductor credit_balance / SubscriptionConductor), and external EVM POST /api/wallet/transfer. Those remain separate SSOT paths by design.

    Two rates — do not mix

    RateSSOTUsed by
    Fiat credit accountingring-config.json → credit.creditBalanceUnitToMainCurrency (usually 1) via getMainCurrencyCreditAccountingRate()spendCredits, desk debit side, credit_balance checkout
    Token Desk oracleplatform_settings.web3.oracle.nativePerMainCurrency via native-token-oracle.tsquoteDesk / executeDesk points ↔ native only

    Why this matters for your clone

    WalletConductor is the operator-facing money spine behind the Wallet product. Members see top-up, desk, and send UI; your clone stays coherent because every path hits one facade — not scattered PSP and ledger calls.

    Credit top-up

    Any signed-in member buys credit points with a card. Points are fiat ledger units (1:1 with store mainCurrency when creditBalanceUnitToMainCurrency is 1).

    Token Desk

    Subscriber+ converts points ↔ native at the desk oracle. Changing nativePerMainCurrency never rewrites store or ad-hoc credit spend math.

    Native onramp

    Confidential+ card/PayPal → treasury native (feature-flagged). Does not add credit points.

    Implementation

    Facade: features/wallet/conductor/wallet-conductor.ts (server-only).

    Wire a surface

    1. 1

      Call the facade, not the ledger

      UI and routes should import WalletConductor (or the thin wrappers in app/_actions/wallet.ts). Do not debit creditBalanceService from feature UI for paths the conductor owns.

    2. 2

      Keep fiat rate SSOT

      For spend paths, omit usdRate or pass getMainCurrencyCreditAccountingRate(). Never feed nativePerMainCurrency / desk oracle into fiat ledger debits.

    3. 3

      Respect the EVM boundary

      Custodial native send is transferNative. External SupportedCrypto (POL/USDT) stays on POST /api/wallet/transfer — do not fold that into WalletConductor without an explicit redesign.

    Module map

    LayerPath
    Facadefeatures/wallet/conductor/wallet-conductor.ts
    Provision

    Related documentation

    Generative Gallery

    Credit-first generative billing via spendCredits + generative_usage ledger.

    WalletConductor architecture

    Adapters, route map, sequences, env SSOT.

    Wallet feature

    Product architecture and member flows.

    Wallet API

    Actions, HTTP routes, rate SSOT tables.

    Wallet provision
    ensureNativeWallet
    Atomic multi-chain wallets (OAuth-safe, no session)
    Min credit gateensureFundedSession-gated provision + credit floor
    NFT market buypurchaseNftListingIdempotent RING buy via Solana market client

    NFT market buy

    Eligible buyers pay RING from the custodial wallet through purchaseNftListing (idempotent sale row).

    Operator checklist

    1. 1

      Confirm credit unit SSOT

      Keep credit.creditBalanceUnitToMainCurrency: 1 in ring-config.json unless you intentionally scale points vs fiat. Desk oracle changes never affect store checkout or POST /api/wallet/credit/spend.

    2. 2

      Separate desk oracle from fiat

      Superadmins set nativePerMainCurrency for desk conversion only. Do not expect that rate on ad-hoc credit spend.

    3. 3

      Gate native onramp carefully

      Native card onramp is confidential+ and feature-flagged (CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnramp). Leave it off until treasury ops and compliance are ready.

    Prefer Server Actions from UI. Keep HTTP wallet routes for MCP and non-React clients. Prefer /api/wallet/token/* — retired /api/wallet/ring/* aliases are removed.

    features/wallet/services/ensure-wallet.ts
    Credit ledgerfeatures/wallet/services/credit-balance-service.ts
    Fiat ratelib/ring-config-core.ts → getCreditUnitToMainCurrencyRate / lib/payments/credit-balance.ts → getMainCurrencyCreditAccountingRate
    Deskfeatures/wallet/chains/solana/desk-service.ts
    Desk oraclefeatures/wallet/services/native-token-oracle.ts
    Custodial sendfeatures/wallet/chains/native-token-transfer-service.ts
    PSP checkoutlib/payments/conductor/payment-conductor.ts
    Store credit raillib/payments/processors/credit-balance.processor.ts (PaymentConductor — not WC)
    Actionsapp/_actions/wallet.ts
    NFT buyfeatures/nft-market/services/solana-market-client.ts

    Method contracts

    MethodAuth / gatesNotes
    ensureNativeWalletCaller supplies idOAuth-safe; returns { ok, native, wallets }
    ensureFundedSessionProvisions + optional credit minimum
    initiateTopUpSessionAmount 25–2000; purpose wallet_topup
    initiateNativeOnrampSession + confidential metadataOptional processor paypal/stripe/wayforpay
    quoteDesk / executeDeskassertTokenDeskSubscriberAccessSolana desk SSOT
    transferNativeCaller supplies userIdWrites wallet_transactions; touches contacts
    spendCreditsCaller supplies userIdDefaults usdRate to getMainCurrencyCreditAccountingRate()
    purchaseNftListingIdempotency keyStatus: pending → submitted → confirmed / failed
    getNativeBalanceCaller supplies userIdThin wrap of transfer service

    Sequence — card credit top-up

    initiateTopUp → wallet_topup

    Card tab omits processor (env SSOT). PayPal tab sets processor=paypal. Client: lib/payments/checkout-redirect.ts.

    Sequence — ad-hoc credit spend

    spendCredits fiat SSOT

    Environment & config (verified)

    KeyRole
    WALLET_ENCRYPTION_KEYCustodial key encryption
    SOLANA_RPC_URL / SOLANA_TREASURY_PRIVATE_KEYCustodial Solana + gas sponsorship
    CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnrampNative card onramp gate
    credit.creditBalanceUnitToMainCurrencyFiat ledger accounting multiplier
    ORACLE_QUOTE_SECRET / RING_ORACLE_DEFAULT_RATEDesk quote HMAC + fallback

    PaymentConductor

    PSP rails used by top-up and onramp.

    Wallet provision
    ensureNativeWallet
    Atomic multi-chain wallets (OAuth-safe, no session)
    Min credit gateensureFundedSession-gated provision + credit floor
    NFT market buypurchaseNftListingIdempotent RING buy via Solana market client

    NFT market buy

    Eligible buyers pay RING from the custodial wallet through purchaseNftListing (idempotent sale row).

    Operator checklist

    1. 1

      Confirm credit unit SSOT

      Keep credit.creditBalanceUnitToMainCurrency: 1 in ring-config.json unless you intentionally scale points vs fiat. Desk oracle changes never affect store checkout or POST /api/wallet/credit/spend.

    2. 2

      Separate desk oracle from fiat

      Superadmins set nativePerMainCurrency for desk conversion only. Do not expect that rate on ad-hoc credit spend.

    3. 3

      Gate native onramp carefully

      Native card onramp is confidential+ and feature-flagged (CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnramp). Leave it off until treasury ops and compliance are ready.

    Prefer Server Actions from UI. Keep HTTP wallet routes for MCP and non-React clients. Prefer /api/wallet/token/* — retired /api/wallet/ring/* aliases are removed.

    features/wallet/services/ensure-wallet.ts
    Credit ledgerfeatures/wallet/services/credit-balance-service.ts
    Fiat ratelib/ring-config-core.ts → getCreditUnitToMainCurrencyRate / lib/payments/credit-balance.ts → getMainCurrencyCreditAccountingRate
    Deskfeatures/wallet/chains/solana/desk-service.ts
    Desk oraclefeatures/wallet/services/native-token-oracle.ts
    Custodial sendfeatures/wallet/chains/native-token-transfer-service.ts
    PSP checkoutlib/payments/conductor/payment-conductor.ts
    Store credit raillib/payments/processors/credit-balance.processor.ts (PaymentConductor — not WC)
    Actionsapp/_actions/wallet.ts
    NFT buyfeatures/nft-market/services/solana-market-client.ts

    Method contracts

    MethodAuth / gatesNotes
    ensureNativeWalletCaller supplies idOAuth-safe; returns { ok, native, wallets }
    ensureFundedSessionProvisions + optional credit minimum
    initiateTopUpSessionAmount 25–2000; purpose wallet_topup
    initiateNativeOnrampSession + confidential metadataOptional processor paypal/stripe/wayforpay
    quoteDesk / executeDeskassertTokenDeskSubscriberAccessSolana desk SSOT
    transferNativeCaller supplies userIdWrites wallet_transactions; touches contacts
    spendCreditsCaller supplies userIdDefaults usdRate to getMainCurrencyCreditAccountingRate()
    purchaseNftListingIdempotency keyStatus: pending → submitted → confirmed / failed
    getNativeBalanceCaller supplies userIdThin wrap of transfer service

    Sequence — card credit top-up

    initiateTopUp → wallet_topup

    Card tab omits processor (env SSOT). PayPal tab sets processor=paypal. Client: lib/payments/checkout-redirect.ts.

    Sequence — ad-hoc credit spend

    spendCredits fiat SSOT

    Environment & config (verified)

    KeyRole
    WALLET_ENCRYPTION_KEYCustodial key encryption
    SOLANA_RPC_URL / SOLANA_TREASURY_PRIVATE_KEYCustodial Solana + gas sponsorship
    CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnrampNative card onramp gate
    credit.creditBalanceUnitToMainCurrencyFiat ledger accounting multiplier
    ORACLE_QUOTE_SECRET / RING_ORACLE_DEFAULT_RATEDesk quote HMAC + fallback

    PaymentConductor

    PSP rails used by top-up and onramp.

    Wallet provision
    ensureNativeWallet
    Atomic multi-chain wallets (OAuth-safe, no session)
    Min credit gateensureFundedSession-gated provision + credit floor
    NFT market buypurchaseNftListingIdempotent RING buy via Solana market client

    NFT market buy

    Eligible buyers pay RING from the custodial wallet through purchaseNftListing (idempotent sale row).

    Operator checklist

    1. 1

      Confirm credit unit SSOT

      Keep credit.creditBalanceUnitToMainCurrency: 1 in ring-config.json unless you intentionally scale points vs fiat. Desk oracle changes never affect store checkout or POST /api/wallet/credit/spend.

    2. 2

      Separate desk oracle from fiat

      Superadmins set nativePerMainCurrency for desk conversion only. Do not expect that rate on ad-hoc credit spend.

    3. 3

      Gate native onramp carefully

      Native card onramp is confidential+ and feature-flagged (CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnramp). Leave it off until treasury ops and compliance are ready.

    Prefer Server Actions from UI. Keep HTTP wallet routes for MCP and non-React clients. Prefer /api/wallet/token/* — retired /api/wallet/ring/* aliases are removed.

    features/wallet/services/ensure-wallet.ts
    Credit ledgerfeatures/wallet/services/credit-balance-service.ts
    Fiat ratelib/ring-config-core.ts → getCreditUnitToMainCurrencyRate / lib/payments/credit-balance.ts → getMainCurrencyCreditAccountingRate
    Deskfeatures/wallet/chains/solana/desk-service.ts
    Desk oraclefeatures/wallet/services/native-token-oracle.ts
    Custodial sendfeatures/wallet/chains/native-token-transfer-service.ts
    PSP checkoutlib/payments/conductor/payment-conductor.ts
    Store credit raillib/payments/processors/credit-balance.processor.ts (PaymentConductor — not WC)
    Actionsapp/_actions/wallet.ts
    NFT buyfeatures/nft-market/services/solana-market-client.ts

    Method contracts

    MethodAuth / gatesNotes
    ensureNativeWalletCaller supplies idOAuth-safe; returns { ok, native, wallets }
    ensureFundedSessionProvisions + optional credit minimum
    initiateTopUpSessionAmount 25–2000; purpose wallet_topup
    initiateNativeOnrampSession + confidential metadataOptional processor paypal/stripe/wayforpay
    quoteDesk / executeDeskassertTokenDeskSubscriberAccessSolana desk SSOT
    transferNativeCaller supplies userIdWrites wallet_transactions; touches contacts
    spendCreditsCaller supplies userIdDefaults usdRate to getMainCurrencyCreditAccountingRate()
    purchaseNftListingIdempotency keyStatus: pending → submitted → confirmed / failed
    getNativeBalanceCaller supplies userIdThin wrap of transfer service

    Sequence — card credit top-up

    initiateTopUp → wallet_topup

    Card tab omits processor (env SSOT). PayPal tab sets processor=paypal. Client: lib/payments/checkout-redirect.ts.

    Sequence — ad-hoc credit spend

    spendCredits fiat SSOT

    Environment & config (verified)

    KeyRole
    WALLET_ENCRYPTION_KEYCustodial key encryption
    SOLANA_RPC_URL / SOLANA_TREASURY_PRIVATE_KEYCustodial Solana + gas sponsorship
    CONFIDENTIAL_TOKEN_ONRAMP / desk nativeTokenOnrampNative card onramp gate
    credit.creditBalanceUnitToMainCurrencyFiat ledger accounting multiplier
    ORACLE_QUOTE_SECRET / RING_ORACLE_DEFAULT_RATEDesk quote HMAC + fallback

    PaymentConductor

    PSP rails used by top-up and onramp.

    1. Docs
    2. /Features
    3. /WalletConductor

    Updated Jul 14, 20265 min listen

    1. Docs
    2. /Features
    3. /WalletConductor

    Updated Jul 14, 20265 min listen

    1. Docs
    2. /Features
    3. /WalletConductor

    Updated Jul 14, 20265 min listen