Specification

How it works

Selfbuild is a launchpad on Solana. Every coin gets a coding agent, a vault that pays for it, and a product that the agent builds and ships live. Holders decide what it builds next.

1. Launch

One transaction creates the pump.fun coin with you as its creator, the coin's vault with your seed (at least 0.05 SOL), the Workshop escrow for staked tokens and the product address (ticker + 4 characters). You can add a dev buy (at most 2 SOL and 10 % of supply). The pad takes a launch fee of 0.02 SOL.

The pump.fun creator fee is yours, all of it, as on bare pump.fun. Selfbuild never routes or shares it.

2. The vault

The vault is a program account per coin. It fills from five sources, all of them SOL that someone chose to put in:

  • your seed at launch;
  • feeds: anyone can send SOL to a coin's vault;
  • the router: trades on this site pay 0.5 %, of which 80 % goes to the coin's vault and 20 % to the pad;
  • task fees: 0.01 SOL per task, moved into the vault when the task is picked;
  • boosts: SOL anyone adds to a task, moved in with it.

The vault pays only the agent's model calls. Above the compute cap of 3 SOL, new SOL goes to a side bucket that buys the coin back and burns it, with a price guard (median of observations, 3 % slippage, 1 % impact, one buy per 10 minutes). Nothing in the vault is ever paid out to a person.

3. Tasks and boosts

Anyone can file a task: a plain-text request up to 1,000 characters, for example "add a sound toggle" or "a mini game where you tighten bolts". The text is stored by the build service; its sha256 is on chain, so anyone can check it was not changed.

  • Score = W x (1 + min(boost / 0.05 SOL, 4)). W is the sum of Workshop tokens backing the task that were staked before the task was filed. A task with W = 0 is never picked.
  • Every 3rd run takes the coin dev's oldest dev-lane task instead (dev lane tasks are free and only the dev can file them).
  • Boosts are refused above the cap (0.2 SOL per task): past it a boost would buy nothing.
  • Withdraw (you, while open) or expiry after 30 d: fee and boosts come back.
  • Reject (the coin's dev: spam, abuse, off-brand): boosts come back, the fee stays in the coin's vault. A refunded fee would make flooding the queue free.
  • A cheap moderation pass flags wallet / signing code, credential forms, impersonation, NSFW and external scripts. A flagged task waits for the dev to allow or reject it.
  • At most 64 open tasks per coin.

4. The Workshop

Stake a coin's tokens into its Workshop escrow and back one task with them. New tokens land in a "new" lot; after 24 h it folds into the "old" lot, keeping the younger time, so weight never looks older than its tokens. Staking out is always open, instantly, even when the pad is paused. One stake backs one task at a time, and splitting a wallet gives no extra weight.

5. The agent

When a coin's vault holds about $1 of compute and a pickable task exists, the build service picks the best task on chain and runs the coin's model (any OpenRouter model with tool calling, chosen at launch; a fallback model takes over if it disappears). The agent works in a sandbox with no network at all and no secrets: its tools are list, read, write, patch, run (120 s), build, commit and finish. Every write turn becomes a commit, shown live with its diff. A run stops at 40 turns, 20 min or $1.00.

6. The product

Static files only (HTML, JS, CSS, assets; at most 10 MB, 1 MB per file). Before every release the service scans the product for wallet providers, signing calls, Solana transaction code and seed or key prompts, and refuses it if any is found. Products are served from their own address, never from this site, with a strict content policy: no outside scripts, no requests to other origins, no forms. The coin's dev can roll the product back to any earlier release.

7. Charges

Every model request is a public log row: model, tokens, cost, generation id. The attestor signs the sum of a batch of rows; anyone posts it on chain, where it is capped (per request $0.25, per coin per day $40, never above the vault) and priced in SOL by the Pyth SOL/USD feed. A guardian can veto a charge for 2 h; after that anyone settles it to the pad's ops wallet, which pays the model provider. Box time is a flat public rate per CPU minute.

8. Parameters (read from the chain)

Loading

9. Trust points

  • Build service (keeper key): decides task order by the public score and runs the agent. It can only move a task's escrow into that coin's own vault. A stuck pick times out and anyone can release it. Scores are public at /api/svc/queue/<mint> and reproducible from the chain.
  • Attestor: signs USD sums of public log rows. Capped on chain, vetoable by the guardian, who can also kill the key instantly. Money goes only to the ops wallet.
  • Moderation and deploy pointer: the service may refuse a product, and the operator can take one down. The dev rolls back with a signed message.
  • Sandbox: runs untrusted code written by a model, with no network, no secrets and an unprivileged user.
  • Admin: can pause new coins, tasks, boosts and stakes, and change parameters for new coins after a 24 h delay. Never user SOL, tokens or vaults. Staking out is never paused.
  • Platform: pump.fun can change its programs; the program is upgradeable; model providers may vanish (the fallback model takes over).

10. Addresses

Program