Protocol
Architecture
One native Solana program: its accounts, who can sign what, how a move is checked, and what the administrator can and can't do.
Yoke is a native Rust program. Instructions are Borsh-encoded, state is fixed-size, custody uses the canonical SPL Token program, and all arithmetic is checked integer math. On-chain state is the only authority; the indexer is a read-only cache for finding accounts.
Deployment
Yoke’s program and pool addresses are listed here once it is live.
Accounts
| Account | Seeds | Size | Holds |
|---|---|---|---|
| Pool | "pool", USDC mint | 256 | Share and debt totals, debt index, rate curve, pause flag |
| Pool vault | "vault", pool | 165 | The pool's USDC |
| Adapter registry | "adapters", pool | 434 | The Save and Orca accounts, set once |
| Credit account | "credit", pool, owner | 192 | Debt units, nonce, move state |
| Custody | "custody", credit, asset 0–3 | 165 each | USDC, SOL, Save receipts, Orca LP tokens |
| Lender | "lender", pool, owner | 96 | Shares |
| Council | "council", pool | 288 | Governance account, YOKE mint, five seats |
| Council vault | "council-vault", council | 165 | Bonded YOKE |
| Bond | "bond", council, owner | 96 | An owner's bonded YOKE and their seat, if any |
The pool signs for its vault; each credit account signs for its four custody accounts. Before using any account the program checks its address, owner, mint and token state, and that it has no delegate and no alternate close authority. Token-2022 is not supported.
Debt and rounding
Amounts are USDC base units, six decimals. Debt is stored as units against an index with a scale of 10¹²; a debt is ceil(units × index ÷ 10¹²). New debt rounds up, repayments never charge more than offered, and the pool's total receivable uses the same ceiling on total units, so it never counts rounding it can't collect.
How a move is checked
begin records the next nonce, the mode, its own index and the index of end, and, for a liquidation, the account's collateral and debt before anything happens. It then reads the instructions sysvar and requires:
- a Yoke
endat the recorded index with the same nonce and exactly the same account list, - every instruction in between to be a Yoke adapter step with the same nonce and accounts,
- at most nine steps, no nested
begin, and nothing from any other program in between, - every Yoke instruction to be top-level, so no other program can call into a move.
Each adapter step checks again that it sits inside the active move, and end must execute at its recorded index.
Only two Yoke instructions may be called by another program: set_seat and update_adapters, because SPL Governance executes passed proposals that way. Both need the governance account's signature, and neither can sit inside a move.
Pausing
The pool's administrator, the guardian council, can pause and unpause it; three of its five members sign. A pause stops new lender deposits, opening accounts, borrowing, and adapter steps that deposit into Save or Orca. Repaying, liquidating, lender withdrawals, closing and unwinding all keep working.
What the administrator can do
- Initialize the pool. Only the Yoke program's upgrade authority can, once, choosing the rate curve, which is fixed afterwards.
- Register the adapters. Once. After that, only governance can replace the registration, and only with the same custody mints.
- Hand the key to the guardian council. Once. From then on the council is the administrator.
- Pause and unpause. With three seated council members signing.
The administrator has no instruction that moves funds out of the pool, out of a credit account, or out of a lender account.
The upgrade authority belongs to YOKE governance, and the administrator key to its guardian council. See Vote with it.
The indexer
The backend reads every Yoke account from finalized blocks into PostgreSQL and serves them over a read-only API. It holds no keys and submits nothing. It checks the chain's genesis hash, account owners, layouts and addresses, and marks its snapshot stale when it falls behind. See Indexer API.