Protocol
Prices and oracles
Tenor reads Pyth price accounts and the Jito stake pool on chain, and refuses prices that are stale or too uncertain.
Sources#
| Input | Account | Owner |
|---|---|---|
| SOL/USD | 7AviUf9nL62mcxNbQGKm4nKDQnPjswo6c5MX4D57HmyE | Pyth receiver |
| USDC/USD | 6HAuqASbHEh4w4REJEUUUCginTLfj1kwCh215ZLtMkrT | Pyth receiver |
| SOL per jitoSOL | Jito4APyf642JPZPx3hGc6WWJ8zPKtRbRs4P815Awbb | SPL stake-pool program |
The two price accounts are Pyth's push-oracle feed accounts for SOL/USD and USDC/USD, and the program accepts no others. Anyone can refresh them through Pyth's push oracle, which only ever replaces a price with a newer one, so nobody can pick an older update from inside the 60-second window.
Checks on every price#
- Owned by the Pyth receiver
rec2HHDDnjLfj4kE7VyEtFA1HPGQLK33259532cRyHp. - Fully verified through Wormhole; partially verified updates are rejected.
- The feed ID matches SOL/USD or USDC/USD.
- Published no more than 60 seconds before the chain clock and no more than 5 seconds after it.
- Confidence no larger than 1% of the price, a positive price and a supported exponent.
The stake pool must be the pinned Jito pool, owned by the stake-pool program, with the expected mint, withdrawal authority and token supply, and updated in the current epoch. Its rate is total lamports ÷ pool token supply.
Conservative values#
| Value | Rule |
|---|---|
| SOL collateral | price − confidence |
| jitoSOL collateral | SOL per jitoSOL × (SOL price − confidence) × 90% |
| Debt in USD | USDC price + confidence |
The 10% jitoSOL haircut covers liquidity and depeg risk. The stake pool rate measures the stake behind each token, not what a market pays for it.
When prices are unavailable#
Only the steps that depend on collateral value need prices. If a feed is stale or too uncertain, they fail and can be retried once prices are fresh.
| Needs fresh prices | Works without prices |
|---|---|
| Borrow commit | Lend commit, reveal, clear |
| Take a loan | Repay, add collateral |
| Liquidate | Refunds, expiry, finalize, redeem |
Repayment and refunds never wait on an oracle, and no instruction lets anyone substitute an off-chain number.