Whitepaper · version 0.1 · September 2026
The design of vwap
How vwap prices, routes and settles trades in tokenized stocks, and how its launchpad creates, graduates and collects fees from coins.
1. Abstract
vwap is a thin, non-custodial layer over existing Solana infrastructure. For stock tokens it routes swaps through Jupiter and measures every quote against a 24-hour volume-weighted average price computed from on-chain trades. For new coins it runs a launchpad on Meteora's Dynamic Bonding Curve with a fixed fee schedule, graduating coins to Meteora DAMM v2 pools whose liquidity is locked for good. This paper describes the current system (Trade on mainnet, Launch on devnet) and marks what is planned.
2. System overview
- Browser. Static pages. A wallet connects through the Wallet Standard (Phantom, Solflare, Backpack and others) and signs transactions with
solana:signTransaction; nothing is signed without a wallet prompt. - vwap server. Serves the pages, caches market data, asks Jupiter for quotes, builds launch and curve transactions, and relays signed transactions to the network. It never takes custody of a user's tokens.
- Indexer. Reads each launched coin's pool state and trades from the chain.
- Keeper. One process that graduates full curves and collects and splits fees (section 11).
- External systems. Jupiter (routing and execution), Meteora DBC and DAMM v2 (launch curves and pools), Backed (stock tokens), GeckoTerminal (hourly bars), Pyth (market calendar), Solana RPC.
3. Market data and the VWAP yardstick
| Data | Source and refresh |
|---|---|
| Price, 24 h change, volume, liquidity | Jupiter token data, every 20 seconds. |
| Hourly bars (price and volume) | The deepest pool of each token on GeckoTerminal, refreshed every 10 minutes, one request at a time within the public rate limit. |
| Dividend multipliers | Each token's mint account on Solana, every 10 minutes. |
| US market calendar | The trading schedule published with Pyth's equity feeds, every 6 hours. |
The VWAP is anchored at the start of a 24-hour window of hourly bars and uses each bar's typical price:
The chart on every market draws the VWAP line beside the price, and the trade ticket reports the quoted price per share relative to the latest VWAP.
4. Stock-token amounts
xStocks are Token-2022 mints with 8 decimals and the scaled-UI-amount extension. Dividends raise a multiplier m instead of minting new tokens, so one UI token keeps tracking one share. Wallets show UI amounts; pools and transfers use raw amounts. vwap therefore converts at every boundary:
A newer multiplier applies once its effective timestamp has passed. Selling "max" uses the wallet's exact raw balance, so rounding never leaves dust behind.
5. Trade execution
- The ticket turns the typed amount into raw units (USDC has 6 decimals).
- The server asks Jupiter for an order. Without a wallet the answer is indicative; with the wallet's address Jupiter also returns a transaction for that wallet, with its slippage limit and network fees.
- The wallet signs. The server relays the signed transaction to Jupiter's execution endpoint and returns the result.
- A quote older than 20 seconds is refreshed before signing.
vwap adds no fee on this route. Input is validated (known mints only, whole raw amounts, valid addresses) and every endpoint is rate-limited per client.
6. Market sessions
The calendar string names a time zone, weekly hours and dated exceptions, for example America/New_York;0930-1600,…,C,C;1127/0930-1300,1225/C. vwap evaluates it in New York time, including daylight-saving changes, early closes and holidays, to show whether the session is open and when it next changes. On-chain trading does not stop when the session closes; vwap only warns that prices can drift from the last close.
7. Eligibility
Before the first live trade the user declares a country of residence and confirms three statements: they are eligible to hold the tokens, they understand a stock token is a third-party claim that can be paused, frozen or burned, and they are not subject to sanctions. The declaration stays in the browser; vwap collects no identity documents. Residents of the United States (including its territories), the United Kingdom, Canada, Australia and sanctioned countries can browse but cannot trade.
8. Launch engine
Each coin gets its own Meteora DBC configuration, created in the same launch:
| Token | SPL token, 6 decimals, 1,000,000,000 supply, mint authority removed at creation. 1% is left over for rounding and goes to the platform. |
|---|---|
| Curve | A cubic Bézier through market caps of $3,000, $3,400, $7,600 and $42,000, sampled at 12 points and turned into strictly rising square-root prices in raw units of the pair token. A stock pair prices it at the stock's live price, so it graduates at about $9,000 of the stock; a SOL pair prices it as if SOL were $103.17, so every SOL-pair coin graduates at exactly 85 SOL (market cap about 29 to 407 SOL) and its dollar value moves with SOL. The threshold is fixed in pair units when the coin is created. |
| Pair | SOL. Stock tokens are accepted by the engine when Meteora has issued their token badge on both DBC and DAMM v2; all 24 listed xStocks have one. A pair's USD price times its multiplier sets the curve. |
| Activation | By timestamp, so the fee schedule counts seconds. |
9. Fee schedule
The base fee follows DBC's exponential fee scheduler, one period per second:
At 1, 5 and 10 seconds the fee is 76.3%, 26.9% and 7.3%. The creator's first buy is placed in the transaction that creates the pool and is charged the ending rate, so the creator never pays the anti-sniper fee.
| Stage | Split of the 2% fee |
|---|---|
| On the curve | Meteora protocol 20% (0.4% of volume); vwap, as the configuration's fee claimer, 80% (1.6%). The creator's share is set to 0%. |
| After graduation | Meteora protocol 20% (0.4%); the locked LP position 80% (1.6%), which the keeper splits: vwap 0.8%, $VWAP buyback 0.8%. |
10. The launcher
Wallets warn about transactions that carry a second signer, and creating a mint needs the mint's own key. vwap therefore has the user sign one plain SOL transfer and does the rest with its launcher wallet:
- Prepare. The server validates the form, computes the exact cost (rent for the config, pool, mint, metadata and token accounts, network and priority fees, Metaplex's fee, the first buy, a 0.001 SOL margin) and returns a transfer from the user to the launcher that carries a unique reference key. On a stock pair the first buy is not in SOL: the same transaction also moves that many shares of the stock (a Token-2022 transfer, in raw units: shares ÷ the dividend multiplier) into the launcher's account for that stock.
- Verify. After it lands, the payment must succeed, be paid by the wallet that prepared the launch, include the reference key, raise the launcher's balance by at least the cost (and its stock balance by the first buy, on a stock pair), and not have paid for another launch.
- Create. The launcher sends the configuration, then the pool with the first buy (the tokens go straight to the creator), then moves the pool's creator role to the user.
Each step's signature is saved before it is sent, so a retry or a restart never pays or sends twice. The mint and configuration keys are stored with owner-only permissions until the coin exists, then deleted. If a step fails permanently the payment is refunded, minus network fees and any rent already locked in accounts that were created. The SOL goes back first and the stock of a first buy in a separate transaction, so a stock paused by its issuer cannot hold the SOL back; the stock follows once it trades again. Token metadata is served by vwap at a URI that is written on-chain for good.
11. Graduation
When a curve holds its threshold the pool stops trading and anyone may migrate it. The migration creates a DAMM v2 pool under Meteora's customizable configuration with a 2% fee, collected in the pair token, and no dynamic fee. All of the liquidity goes to one position owned by vwap's fee wallet and is permanently locked: it can never be withdrawn, only its fees claimed. Any pair tokens above the threshold and any leftover coins go to the fee wallet.
12. The keeper
Every 30 seconds the keeper:
- migrates every full curve;
- claims vwap's share of curve fees once at least 0.01 of the pair token is waiting;
- claims the locked position's fees in each graduated pool and immediately sends half of each claim to the buyback wallet.
The launcher pays network fees; the fee wallet only signs. Every action is appended to a ledger with its signature and amounts. The split is performed by vwap's keeper, not enforced by an on-chain program: the ledger and the two wallets' histories are how it can be checked.
13. Security model
- User funds. Trades are signed in the user's wallet and settle on-chain; vwap holds nothing between quote and fill. The only funds vwap holds on a user's behalf are a launch payment in flight, which ends as a coin or a refund.
- Hot keys. The launcher and the fee wallet are hot keys on vwap's server; they only need working balances, and whatever they hold is at risk if the server is compromised.
- Trust. Users trust vwap to relay what Jupiter or Meteora built, to refund failed launches, and to carry out the post-graduation split. The locked liquidity, the fee rates and the coin's supply are enforced by Meteora's programs.
- Audits. vwap's code has not been audited. It relies on audited Jupiter, Meteora and Backed programs.
14. Planned: firm quotes
Not built yet. This section states design goals, not behaviour.
A second route will quote from vwap's own pools: an exact output valid for a few seconds, priced around an oracle reference with a spread made of a base, a size component and the oracle's confidence, quoted only while the US session is open, with inventory limits per market. It needs a live oracle feed (Pyth's price service now requires an API key) and pool capital, and it will be tested on devnet before it handles real funds.
15. Risks
- Smart-contract and integration risk in Jupiter, Meteora, Backed's token programs and vwap's own unaudited code.
- Issuer risk: stock tokens can be paused, frozen or burned by the issuer and are not shares.
- Market risk: off-hours drift, thin liquidity, and price moves within the slippage limit.
- Launch risk: launched coins are speculative and usually lose their value; the post-graduation split depends on vwap's keeper.
- Operational risk: hot keys, RPC outages and third-party APIs (Jupiter, GeckoTerminal) can interrupt service.
This whitepaper describes software, not an offer or advice. It will be revised as vwap changes.