programs/powerchain-token is the Anchor controller for the canonical PWRC Token-2022 mint. Version 1.2.1 supports:
- validation of the nine-decimal PWRC mint and required extensions;
- one-time fixed-supply issuance and permanent mint-authority removal;
- holder-authorized checked transfers and burns;
- protocol pause and two-step authority transfer;
- idempotent payment transfers backed by receipt PDAs;
- base-unit arithmetic with checked
u128fee calculations; - structured events for transfers, payments, burns, issuance, and pause changes.
The canonical Token-2022 program is:
TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb
A payment receipt is derived from:
["pwrc-payment", state PDA, 32-byte payment ID]
The payment ID must be generated by the payment service and persisted before submission. Reusing it causes the receipt account initialization to fail, preventing accidental duplicate execution through this instruction.
The agent-facing Pay integration is documented in skills/pay/SKILL.md. It can discover paid API providers and complete user-approved HTTP 402 payments through a local Pay client. It is deliberately outside the Anchor and Move programs.
The on-chain programs do not trust an HTTP response, QR code, payment URL, provider callback, or agent tool result as proof of settlement. Application services must independently validate the final chain transaction, expected asset, recipient, amount, reference, finality, and replay status before updating an order. No scan, deep link, or 402 response may trigger an automatic transfer without explicit wallet or local-user authorization.
PWRC transfers use transfer_checked with nine decimals. The program records the fee implied by its configured basis points and maximum cap, while Token-2022 applies and withholds the actual transfer fee. Settlement systems must inspect the confirmed transaction and Token-2022 account state before marking a payment complete.
The Move package in contract/ remains a wrapped-PWRC bridge scaffold with capability controls, pause state, replay protection, and supply accounting. It is not a production bridge without independent review and finalized custody rules.
pnpm program:build
pnpm program:test
pnpm anchor:test
pnpm sui:testRequired local tools are Anchor CLI, Rust/Cargo, Solana CLI, and Sui CLI. Deployment keypairs must not be committed.
- Build and test on localnet and devnet before mainnet deployment.
- Confirm deployed program IDs match
Anchor.tomland checked-in configuration. - Confirm mint decimals, supply, extension authorities, and fee parameters on-chain.
- Test duplicate payment IDs, insufficient funds, paused state, and maximum-fee boundaries.
- Keep upgrade and fee authorities in hardware-backed or managed custody.
- Obtain an independent security audit before production deployment.
- Root
Cargo.tomlcentralizes exact Anchor and Token-2022 dependency versions. - The program crate inherits workspace version, edition, license, repository, homepage, and minimum Rust version.
- Release builds enable overflow checks, fat LTO, one code-generation unit, symbol stripping, and abort-on-panic behavior.
Anchor.tomlpins Anchor CLI 0.32.1 and uses pnpm for TypeScript integration tests.contract/Move.tomlremains separate because the Sui wrapper is an independent package and deployment domain.
The application now exposes a sample paid HTTP route through @solana/pay-kit at /api/v1/pay-kit/report. The gate supports the configured MPP/x402 protocol preference and stablecoin settlement assets. This integration remains off-chain application middleware: the Anchor program does not parse HTTP credentials, trust payment headers, or authorize PWRC delivery from a Pay Kit receipt alone. Any flow that converts a paid API action into an on-chain PWRC transfer must still submit and validate the corresponding program instruction and idempotent payment receipt PDA.