Stellar
Architecture
Contracts and trust boundaries in the Spectra Stellar stack.
Stellar Core v2 is a Soroban port of the Spectra yield-tokenization system. Bridge and oracle contracts are separate workspaces connected through interfaces and configuration rather than one monolithic deployment.
Core contracts
| Component | Responsibility |
|---|---|
| Registry | Protocol addresses, fees, deployable PT/YT hashes, and the registered PT set. |
| Factory | Deploys and initializes a PT, which deploys its paired YT, then registers the PT. |
| Principal Token | Holds IBT backing; manages issuance, redemption, rates, yield, fees, maturity, and YT policy. |
| Yield Token | Transferable claim on pre-maturity variable yield. PT controls mint, burn, pause, and upgrade actions. |
| Router | Executes typed command batches and pre-authorizes nested calls to external components. |
| Limit Order Engine | Registers maker-authorized orders and atomically settles PT/YT/IBT exchanges. |
| Vault wrappers | Adapt yield sources to the FungibleVault interface expected by PT. |
Deployment relationship
- Deploy the Registry and set the PT and YT WASM hashes and protocol configuration.
- Deploy the Factory and grant it permission to register PTs.
- Deploy the Router and configure its Registry and peripheral addresses.
- Deploy optional components such as the Limit Order Engine, bridge, broker, and wrappers.
- Deploy each PT market through the Factory; the PT deploys its YT during the same call tree.
PT market deployment is permissionless. Treat Registry membership as discovery data, not proof that an IBT or market is approved.
External boundaries
- Blend: backing exchange rate, liquidity, and bad-debt behavior.
- Broker: swap output and route behavior used by Router batches.
- Bridge: cross-chain authentication, liveness, gas, and wrapped-token backing.
- Oracle consumers: selection of the correct PT-bound deterministic oracle.
- Soroban runtime: authorization trees, resource limits, token trustlines, and storage TTL.
Bind every integration to explicit Core, bridge, oracle, and deployment versions. Similar interfaces in different repositories are not evidence that those versions are compatible.