Protocol

Architecture

One native Solana program: its accounts, who can sign what, how a move is checked, and what the administrator can and can't do.

Yoke is a native Rust program. Instructions are Borsh-encoded, state is fixed-size, custody uses the canonical SPL Token program, and all arithmetic is checked integer math. On-chain state is the only authority; the indexer is a read-only cache for finding accounts.

Deployment

Yoke’s program and pool addresses are listed here once it is live.

Accounts

AccountSeedsSizeHolds
Pool"pool", USDC mint256Share and debt totals, debt index, rate curve, pause flag
Pool vault"vault", pool165The pool's USDC
Adapter registry"adapters", pool434The Save and Orca accounts, set once
Credit account"credit", pool, owner192Debt units, nonce, move state
Custody"custody", credit, asset 0–3165 eachUSDC, SOL, Save receipts, Orca LP tokens
Lender"lender", pool, owner96Shares
Council"council", pool288Governance account, YOKE mint, five seats
Council vault"council-vault", council165Bonded YOKE
Bond"bond", council, owner96An owner's bonded YOKE and their seat, if any

The pool signs for its vault; each credit account signs for its four custody accounts. Before using any account the program checks its address, owner, mint and token state, and that it has no delegate and no alternate close authority. Token-2022 is not supported.

Debt and rounding

Amounts are USDC base units, six decimals. Debt is stored as units against an index with a scale of 10¹²; a debt is ceil(units × index ÷ 10¹²). New debt rounds up, repayments never charge more than offered, and the pool's total receivable uses the same ceiling on total units, so it never counts rounding it can't collect.

How a move is checked

begin records the next nonce, the mode, its own index and the index of end, and, for a liquidation, the account's collateral and debt before anything happens. It then reads the instructions sysvar and requires:

  • a Yoke end at the recorded index with the same nonce and exactly the same account list,
  • every instruction in between to be a Yoke adapter step with the same nonce and accounts,
  • at most nine steps, no nested begin, and nothing from any other program in between,
  • every Yoke instruction to be top-level, so no other program can call into a move.

Each adapter step checks again that it sits inside the active move, and end must execute at its recorded index.

Only two Yoke instructions may be called by another program: set_seat and update_adapters, because SPL Governance executes passed proposals that way. Both need the governance account's signature, and neither can sit inside a move.

Pausing

The pool's administrator, the guardian council, can pause and unpause it; three of its five members sign. A pause stops new lender deposits, opening accounts, borrowing, and adapter steps that deposit into Save or Orca. Repaying, liquidating, lender withdrawals, closing and unwinding all keep working.

What the administrator can do

  • Initialize the pool. Only the Yoke program's upgrade authority can, once, choosing the rate curve, which is fixed afterwards.
  • Register the adapters. Once. After that, only governance can replace the registration, and only with the same custody mints.
  • Hand the key to the guardian council. Once. From then on the council is the administrator.
  • Pause and unpause. With three seated council members signing.

The administrator has no instruction that moves funds out of the pool, out of a credit account, or out of a lender account.

The upgrade authority belongs to YOKE governance, and the administrator key to its guardian council. See Vote with it.

The indexer

The backend reads every Yoke account from finalized blocks into PostgreSQL and serves them over a read-only API. It holds no keys and submits nothing. It checks the chain's genesis hash, account owners, layouts and addresses, and marks its snapshot stale when it falls behind. See Indexer API.

Next

Yoke

One credit account across Save and Orca, on Solana.

Follow on X
© 2026 YokeYoke is software on Solana; every transaction is signed by your own wallet. Borrowing, lending and liquidating can lose money. Read the risks first.