Overview
Patchbay is a constant-product AMM on Solana where every pool is a patch: an ordered chain of up to four hook modules that run before and after swaps and liquidity changes.
- Inuser pays
- Dynamic feebefore_swap
- Curvex · y = k
- Limit orderafter_swap
- Outuser is paid
The idea#
- A pool is two mints, a static fee and a patch: an ordered list of up to four module accounts.
- A module is a program plus a module account. The last byte of the module account’s address is its permission flags: eight bits, the eight jacks on its faceplate.
- On every swap and liquidity change the AMM calls the modules whose bits are set, in patch order. They can raise the fee, refuse a withdrawal, record a price or fill orders.
- The patch is part of the pool’s address, so it never changes. The same pair can have many pools, one per patch and fee.
Built-in modules#
Four modules ship in the patchbay-modules program. Anyone can create one with their own parameters and plug it into a new pool. Your own program can sit in the same slots.
| Module | Jacks | What it does |
|---|---|---|
| Dynamic fee | 0x43 | Raises the fee after large price moves. The extra fee decays with a half-life. |
| TWAP oracle | 0x01 | Records a time-weighted price before each swap. Any program can read it. |
| Limit order | 0x82 | Fills resting orders after a swap moves the price across them. |
| Lockup | 0x10 | Refuses liquidity removal until the pool’s unlock time. |
| Your module | any valid byte | Any program that implements the hook interface. See Write a module. |
The same in every pool#
- Constant product,
x · y = k, on raw token atoms. Swaps are exact input. All math is checkedu128and rounds in the pool’s favour. - The static fee is set at creation, from 0 to 10%. A Dynamic fee module can override it, up to 50%. A share of the LP fee, at most 25%, can go to the protocol treasury.
min_amount_outalways holds. Whatever the modules do, the user receives at least that much or the transaction reverts.- Modules cannot move vault funds, receive your signature or call back into the pool. See Security.
Clusters#
Program IDs are the same on every cluster. Devnet is the public test deployment, with test mints and seeded pools; mainnet-beta follows with the same IDs. The full list is on Addresses.
Not in v1#
- Exact-output swaps.
- Multi-hop routing inside the program. The app routes between pools; on mainnet it compares with Jupiter and falls back to it.
- Concentrated liquidity.
- On-chain token governance. The module registry is curated by an admin key, which can later be handed to a multisig or a DAO.
Read next#
- How it worksThe pool key, hook points and the order modules run in.
- Built-in modulesDynamic fee, TWAP oracle, Limit order and Lockup.
- Write a moduleBuild your own module program and mine its address.
- IntegrateSDK, quotes and routing for wallets and aggregators.
- SecurityWhat a module can and cannot do inside a swap.
- FAQShort answers to common questions.