OrbitDocs

Trust model

What each party has to trust, and what the contract guarantees.

Orbit is designed so that the trust each party needs is small and written down.

Authorization boundaries

Entrypointrequire_auth onWho is protected
create_vaultuserNobody can set billing terms on a subscriber's behalf
pull_fundsmerchantOnly the merchant named in the vault key can pull
batch_disbursesenderOnly the sender can spend their own allowance

Guarantees

Non-custodial

Orbit is only the spender. The contract never holds a token balance.

Atomic

A failed transfer reverts the whole invocation, including any earlier batch transfers and the cadence update.

No double pull

last_pull_timestamp is written in the same invocation as the transfer.

Overflow-safe

Release builds use overflow-checks = true, so arithmetic aborts instead of wrapping.

Known limitations

The contract is an MVP and has not been audited.

  • create_vault does not reject zero values. interval_seconds = 0 lets the merchant pull at any time, still capped by the allowance.
  • Re-running create_vault resets the cadence, so the merchant can pull again immediately. Clients should warn the subscriber before they re-subscribe.
  • Events are only published on success. A failed pull leaves no Orbit event, so track failures from the transaction result.
  • Errors are string panics, not typed error codes. See Contract errors.

On this page