Open the app

Protocol

Prices and oracles

Tenor reads Pyth price accounts and the Jito stake pool on chain, and refuses prices that are stale or too uncertain.

Sources#

InputAccountOwner
SOL/USD7AviUf9nL62mcxNbQGKm4nKDQnPjswo6c5MX4D57HmyEPyth receiver
USDC/USD6HAuqASbHEh4w4REJEUUUCginTLfj1kwCh215ZLtMkrTPyth receiver
SOL per jitoSOLJito4APyf642JPZPx3hGc6WWJ8zPKtRbRs4P815AwbbSPL stake-pool program

The two price accounts are Pyth's push-oracle feed accounts for SOL/USD and USDC/USD, and the program accepts no others. Anyone can refresh them through Pyth's push oracle, which only ever replaces a price with a newer one, so nobody can pick an older update from inside the 60-second window.

Checks on every price#

  • Owned by the Pyth receiver rec2HHDDnjLfj4kE7VyEtFA1HPGQLK33259532cRyHp.
  • Fully verified through Wormhole; partially verified updates are rejected.
  • The feed ID matches SOL/USD or USDC/USD.
  • Published no more than 60 seconds before the chain clock and no more than 5 seconds after it.
  • Confidence no larger than 1% of the price, a positive price and a supported exponent.

The stake pool must be the pinned Jito pool, owned by the stake-pool program, with the expected mint, withdrawal authority and token supply, and updated in the current epoch. Its rate is total lamports ÷ pool token supply.

Conservative values#

ValueRule
SOL collateralprice − confidence
jitoSOL collateralSOL per jitoSOL × (SOL price − confidence) × 90%
Debt in USDUSDC price + confidence

The 10% jitoSOL haircut covers liquidity and depeg risk. The stake pool rate measures the stake behind each token, not what a market pays for it.

When prices are unavailable#

Only the steps that depend on collateral value need prices. If a feed is stale or too uncertain, they fail and can be retried once prices are fresh.

Needs fresh pricesWorks without prices
Borrow commitLend commit, reveal, clear
Take a loanRepay, add collateral
LiquidateRefunds, expiry, finalize, redeem

Repayment and refunds never wait on an oracle, and no instruction lets anyone substitute an off-chain number.