Grimoire · v1.0

SPHRAGIS: Sealed State for Non-Fungible Assets on Solana

SPHRAGIS core contributors

Abstract

SPHRAGIS is a metaprotocol for programmable non-fungible assets on Solana. Protocol actions, called seals, are written as memo data into ordinary Solana transactions that also pay a protocol fee to a public treasury. Indexers read these transactions in ledger order and apply a fixed, public set of validity rules to compute the state of every relic: its owner, attributes, circle memberships, attestations and full history. $SPHRA is the protocol’s token. It is designed to pay for seals and to govern the parameters and standards of the protocol.

1 · Motivation

Static by default. Most NFT metadata is fixed at mint or edited by a single privileged key. Assets cannot evolve in response to use without a custom program or a trusted server.

Fragmented. Each application that adds state invents its own format, so that state is unreadable everywhere else.

Off-chain dependence. Rich behaviour usually lives in databases that can be changed, lost or switched off.

No shared stewardship. Standards are set by whoever ships first, with no process for the people who depend on them to improve them.

2 · Design overview

A seal is a Solana transaction with exactly two meaningful instructions:

1. System Program · transfer   signer → SPHRAGIS treasury   (protocol fee)
2. SPL Memo                    "sphragis:{"v":1,"op":"…", …}"

The fee transfer makes every seal discoverable: an indexer lists the treasury’s transaction signatures, fetches each transaction, and reads the memo. Solana provides ordering, finality and censorship resistance. SPHRAGIS provides meaning. There is no custom on-chain program to upgrade or exploit, and every wallet that can sign a transaction can take part.

The identifier of anything created by a seal (a relic or a proposal) is the signature of the transaction that created it. Identifiers are therefore unique, permanent and verifiable on any explorer.

3 · Operations

opNameEffect
mintCast a RelicCreate a relic with name, optional image URL, description and attributes. Owner = signer.
setInscribeMerge attribute changes (null deletes), rename or re-image. Owner only.
linkJoin a CircleJoin the relic to a circle. Owner only.
givePass onTransfer ownership to another address. Owner only.
bindSeal an NFTAttach living state to an existing Metaplex NFT. Control follows the NFT holder.
modOpen a CircleRegister a circle under a unique slug. Signer becomes owner and first warden.
val—Circle owner adds or removes wardens.
attWardA warden approves or rejects a relic linked to their circle.
propProposeOpen a governance proposal with a voting window of 1 hour to 31 days.
voteVoteVote yes, no or abstain. The latest vote per wallet counts.

4 · State and validity

State is a pure function of the ordered list of seals. An indexer applies the rules below and must reach the same state as every other honest indexer.

  1. Only successful transactions at confirmed commitment or stronger are considered.
  2. The memo must begin with sphragis:, parse as JSON, carry "v":1 and match the schema of its op.
  3. The transaction must transfer at least the current fee for that op from the signer to the treasury.
  4. Ownership-gated ops (set, link, give) are valid only when signed by the current owner at that point in the ledger.
  5. Circle slugs are first-come, first-served. att requires the signer to be a warden of that circle, and the relic to be linked to it.
  6. Votes count only inside the proposal’s window.
  7. Invalid seals are kept in the record with a reason, but have no effect.

Because invalid seals have no effect, nobody can damage someone else’s relic by writing bad data. The worst they can do is pay a fee for nothing.

5 · Circles and Wardens

A circle is an independent system inside SPHRAGIS with its own purpose: game items, membership passes, generative series, reputation badges, AI-native characters. Scribes create relics and link them in. Wardens, appointed by the circle owner, attest whether each relic meets the circle’s standard. Applications can choose to trust only attested relics. This turns quality control into an open, inspectable process rather than a private allow-list.

Over time, governance may define shared circle standards, warden requirements and incentive programs funded by the treasury.

6 · Binding existing NFTs

The bind op lets any Metaplex NFT gain SPHRAGIS state without migration. The binder becomes the controller of the bound relic. When the NFT changes hands, the new holder issues a fresh bind and takes control, and the history stays intact. Indexers verify that the most recent binder still holds the NFT and flag the relic if they do not.

7 · The $SPHRA token

Paying for seals. At launch, fees are paid in SOL so that anyone can use the protocol on day one. Once $SPHRA fee payment is enabled by governance, seals can be paid in $SPHRA, which ties token demand directly to protocol usage.

Governance. $SPHRA holders vote on fee levels, treasury spending, grants, circle standards, warden requirements and future versions of the rules.

Coordination. Treasury-funded incentives can reward scribes, wardens and indexer operators who grow the network.

8 · Governance process

  1. Signal phase. One wallet, one vote, on-chain through the prop/vote ops. This builds the habit and the record before real weight is attached.
  2. Token phase. Once the $SPHRA mint is set in the protocol config, votes are weighted by holdings at count time.
  3. Lifecycle. Proposal → open discussion → vote → execution by contributors → public review.
  4. Hardening. Over time, more decisions move to automatic execution as the tooling matures.

9 · Distribution

$SPHRA has a fixed supply. Most of it is reserved for the people who use and build the protocol.

AllocationShareNotes
Public launch & liquidity65%Fair launch on Solana; no presale.
Community airdrop: round one10%Distributed first, through vesting contracts.
Community airdrop: later rounds20%Timing and eligibility announced separately.
Core team5%Reserved for contributors.

Airdrop eligibility will include early SPHRAGIS users on devnet and mainnet, circle founders, wardens, and community contributors. Snapshots, claim windows and vesting schedules will be announced separately.

10 · Fees

opDevnet fee
mint0.001 SOL
set0.0005 SOL
link0.0005 SOL
give0.0005 SOL
bind0.001 SOL
mod0.001 SOL
val0.00025 SOL
att0.00025 SOL
prop0.001 SOL
vote0 SOL

Mainnet fees are set at launch and are adjustable by governance. Fees fund the treasury, which pays for grants, infrastructure and incentives.

11 · Security considerations

12 · Roadmap

Phase 1 — Foundation

Publish the v1 rules, launch the app and indexer on devnet, then mainnet. Documentation and examples.

Phase 2 — Builder tooling

Hosted indexer API, SDK packages, CLI releases, templates for games and generative art, first grants.

Phase 3 — Token utility

Fee payment in the protocol token, fee parameters exposed to governance, treasury reporting.

Phase 4 — Governance

Token-weighted voting, formal proposal process, treasury-funded grants and module standards.

Phase 5 — Ecosystem

Marketplace and wallet integrations, third-party modules, cross-app standards, progressive decentralisation of the treasury.

13 · Disclaimer

This document is for information only and is not financial, legal or tax advice. $SPHRA is a utility and governance token for the SPHRAGIS protocol. Nothing here promises profit, price, adoption or success. Crypto networks carry technical, market, regulatory and liquidity risk, including total loss. Do your own research.