A coin that can only be born where it happens.
People check in at a venue with a code the host's device signs, pool SOL while the doors are open, and when the doors close the coin is created on pump.fun and bought with the whole pool in one instruction. The people who were there are its first holders, at one price.
A1Overview
A spot is one event at one place: a bar night, a booth, a rave on a ferry. On the map it is a gate with a code like G04. Each spot fixes its coin up front: name, ticker, picture, place, how many people can check in, and when the doors open and close.
A host answers for the spot. The host registers a bond and one to four device keys: a screen at the venue or the host's phone. The screen runs the beacon, which shows a check-in code that changes every 15 seconds.
Only a wallet that checked in with a live code can put SOL into the spot's pool. After the doors close, anyone can send the launch. If the pool reached the spot's minimum, the coin is born and every pass holder can claim a share of it, pro rata to what they pooled. If not, every commit goes back in full.
A2Checking in



The code is a link: /c#irl1.<spot>.<bucket>.<key>.<signature>. The site builds one transaction from it: the native Ed25519 signature check of the host's code, then check_in, which reads that check from the instructions sysvar and writes your Pass.
Two ways in
- Room code. Anyone who sees the screen can use it while it is live. Each 15 second window checks in at most
ceil(capacity / 60)wallets this way, and the room code can fill at most the spot's room-code share of the passes. - Tap. You show your wallet code, the host's beacon scans it and signs a code for your wallet only. Taps can fill the whole capacity. Use it when the room code's share is full or when a host wants every pass bound to a person.
Seeker phones
A wallet holding a Seeker Genesis Token (one per Seeker phone) can link it to its pass. That raises the wallet's pool cap from 1 to 2 SOL at this spot. One Seeker boosts one pass per spot, even if the token moves to another wallet.
A3Lifecycle
| Board shows | On chain | What can happen |
|---|---|---|
| Doors | Open, before starts_at | Nothing yet. The spot is on the map. |
| Boarding | Open, between starts_at and ends_at | Check in, pool, take SOL back (until 10 min before the end), link a Seeker. |
| Departing | Open, after ends_at, inside the launch window | Anyone sends birth: born if the pool reached its minimum, otherwise failed. |
| Missed | Open, after the launch window | Anyone sends expire: failed, refunds open. |
| Born | Launched | Claim half of your coins and your SOL back; the other half stays staked and earns fee shares until you unstake. |
| Cancelled | Failed | Every commit refunds in full (anyone can push a refund). The host can run it again. |
A4Trust model
"I was here" on chain means one thing: the host's registered device signed a code for this spot in this 15 second window. The host is a trusted party (a bar, a booth, an organiser). The program guarantees the limits around it, not the host's honesty.
- What the program enforces. The code's time window (the current or previous 15 s), one pass per wallet per spot, one Seeker per spot, the per-window and per-spot room-code caps, the capacity, and that only pass holders can pool and become the first holders.
- GPS is only a soft signal on this website. Your location only moves the map. Nothing on chain reads a location; the spot's latitude and longitude are a pin.
- A room code can be relayed live to someone who is not there (a video call, a photo sent in seconds). Rotation stops screenshots, not live streams. The damage is bounded: a code lives 15 to 30 seconds, checks in at most
ceil(capacity / 60)wallets per window, and can fill only the room-code share of the spot. The rest needs a tap, which binds one wallet in front of the host. - A host can sign for people who were not there. Its bond answers for that, but only through the admin's
slash_host, a trusted arbiter power (see B4). There is no on-chain proof of absence. - One person can hold several wallets. The per-wallet cap and the per-window room-code cap limit it; a Seeker token is one per phone.
A5The beacon
The beacon page turns any browser into the host's device. It keeps an Ed25519 key in the browser's storage, created as non-extractable where the browser supports WebCrypto Ed25519 (the page can sign with it but cannot read it). Browsers without it fall back to a key kept in the browser's storage.
- Connect the host wallet and create the screen's key.
- Register as a host with a bond of 1 SOL for each spot you will have open at the same time (or add the screen to an existing host: up to four keys, revoke a lost one at once).
- Open a spot from a fixed menu: capacity, room-code share, when the doors open, how long they stay open.
- Show the code full screen. Every 15 seconds the screen signs
"irlpad:v1" || spot || bucket || 32 zero bytes; in tap mode it signs the same with the attendee's wallet instead of the zero bytes.
The bucket is floor(chain time / 15). The beacon follows the chain's clock, not the device's, and signs a second behind so a fast device clock never produces a code from the future.
A6Worked example
Mainnet defaults; this network's values are in A8.
- Open. The Salt Lamp registers as a host with a 1 SOL bond (one bond per spot it has open at the same time) and opens "Salt Lamp Friday",
$SALT, 300 passes, room-code share 225, doors 20:00 to 02:00. The bond is now locked until 7 days after the launch window. - Check in. 120 people check in over the night. Each one sends
[Ed25519SigVerify(host key, signature, 81-byte message), check_in(bucket, key_idx, tap)]. At most 5 room-code check-ins land per 15 seconds (300 / 60). - Pool. 80 of them commit between 0.01 and 1 SOL (2 SOL with a Seeker). The pool reaches 30 SOL. Anyone can take SOL back until 01:50.
- Birth. At 02:00 anyone sends
birth, alone in its transaction. Budget = 30 - 0.03 rent reserve = 29.97 SOL; deployed = min(29.97, 70) = 29.97 SOL; launch fee 2.5% = 0.749 SOL booked for the pad on the spot's fee account (the treasury is not an account ofbirth, so no treasury can block a launch); the rest buys$SALTin one pump.fun purchase. Whatever the rents did not use comes back as SOL. - Claim. A wallet that pooled 0.6 SOL is owed 0.6 / 30 = 2% of the coins bought and 2% of the SOL that came back. Everyone paid the same price.
claim_tokenssends the free half of those coins and the SOL; the other half stays staked in the spot's vault. - Fees. The coin's pump.fun creator fees flow to the spot: 40% to the attendees by what they pooled, 25% to the host, 20% to the creator, 15% to the pad. An attendee earns while its half is staked.
unstakepays what it earned, sends the staked half, and ends earning for that pass for good.
Above the cap: a pool of 90 SOL deploys 70 SOL; the other 19.97 SOL comes back pro rata with the coins. Below the minimum: a pool of 1.5 SOL (minimum 2) fails and every commit is refunded.
A7Where the SOL goes
A8Parameters
Copied into every spot when it opens, so a change only affects spots opened later. "This network" is read from the program's config now.
| Parameter | This network | Mainnet default | Hard bounds |
|---|---|---|---|
| Doors open for | ... | 1 h - 12 h | 30 min - 12 h |
| Take-backs close before the end | ... | 10 min | 0 - 1 h |
| Launch window after the end | ... | 24 h | 1 h - 7 d |
| Bond stays locked after that | ... | 7 d | 1 d - 30 d |
| Host bond | ... | 1 SOL | 0.1 - 100 SOL |
| Max capacity | ... | 2000 | 1 - 10000 |
| Commit per wallet | ... | 0.01 - 1 SOL | min 0.01 - 1, max up to 10 |
| Cap with a Seeker | ... | 2 SOL | max - 20 SOL |
| Minimum pool to launch | ... | 2 SOL | 0.5 - 70 SOL |
| Birth cap (deployed at most) | ... | 70 SOL | min raise - 80 SOL |
| Rent reserve | ... | 0.03 SOL | up to 0.05 SOL |
| Launch fee | ... | 2.5% | up to 5% |
| Creator fee split | ... | 40 / 25 / 20 / 15 | attendees at least 25%, pad at most 25% |
Per spot: capacity 1 to max capacity, room-code share 0 to capacity, start from now (5 minutes of clock slack) to 30 days ahead, name 1-32 plain characters, ticker 1-10 of A-Z and 0-9, place 1-48 plain characters, picture on IPFS (ipfs:// or https://ipfs.io/ipfs/).
B1Program reference
Program id irLMgHrfRDbDjoHUc38HnwsfCFVM7zk117eHXUatCqk. Anchor 0.31. Unaudited and upgradeable.
Accounts
| Account | Seeds | Holds |
|---|---|---|
| Config | "config" | admin, pending admin, treasury, paused, parameters, next spot id |
| Host | "host", authority | device keys (4 slots: Ed25519 or P-256), bond (lamports above rent), bond lock, open spots, verified badge, slashed total |
| Spot | "spot", id u64 LE | host, creator, coin metadata, place and pin, capacity, doors, parameters, state, counters, the 15 s bucket ring, birth results, fee books |
| vault | "vault", spot | the pool; after birth the coin's buyer and holder of unclaimed coins |
| fees | "fees", spot | the coin's pump.fun creator; creator fees until paid |
| Pass | "pass", spot, wallet | window, room code or tap, key slot, time, cap, Seeker, committed, claims, coins sent out, fee debt, unstaked |
| SgtUse | "sgt", spot, sgt mint | one Seeker counts once per spot |
Instructions
| Instruction | Who | What |
|---|---|---|
| register_host | host wallet | 1-4 distinct device keys, bond at least host_bond (blocked by pause) |
| add_key / revoke_key | host | fill the first free slot / clear a slot at once |
| top_up_bond / withdraw_bond | host | withdraw only after the lock ends |
| open_spot | creator + host (both sign) | fixes the coin and the doors; needs bond ≥ host_bond × (open spots + 1); locks the bond until end + launch window + bond hold (this site opens spots with the host as creator) |
| check_in(bucket, key_idx, tap) | attendee | right after an Ed25519 / secp256r1 signature-check instruction over the 81-byte message |
| link_sgt | checked-in wallet | Seeker Genesis Token check, raises the cap |
| commit / withdraw | checked-in wallet | during the doors; the running total stays 0 or within the wallet's range |
| birth | anyone, alone in its transaction | after the end, inside the launch window: failed below the minimum, else fee (booked) + create + one buy; frees one of the host's open spots |
| expire | anyone | past the launch window: failed; frees one of the host's open spots |
| refund | anyone (pays the pass wallet) | failed spot: the whole commit back |
| claim_tokens | anyone (payer funds the token account) | the free half of the pass's coins and its SOL back, pro rata; the other half stays staked |
| unstake | the pass wallet | pays the unpaid fee share, sends the staked half, leaves the fee leg for good |
| collect_fees / unwrap_fees / sync_fees | anyone | collect pump.fun creator fees, book them |
| claim_fees | anyone (pays the pass wallet) | a pass that has not unstaked: its accrued share of the attendees' fees |
| claim_host_fees / claim_creator_fees / collect_treasury | anyone | pay the booked legs to their owners |
| init_config / update_config / set_treasury / propose_admin + accept_admin / set_paused / set_verified / slash_host | admin | see B4 |
The presence message
"irlpad:v1" (9) || spot (32) || bucket u64 LE (8) || wallet (32) = 81 bytes. The signature-check instruction must carry exactly one signature, read nothing from other instructions, and contain the host's key from the given slot and exactly this message.
B2Errors
Rendered from the program's interface file (irl.json), plus the shared checks.
| Code | Name | Message |
|---|---|---|
| ... |
B3Verify on chain
- Open the spot's gate page and the program in an explorer. The Spot account shows
passes,total,starts_at,ends_atand its parameters. - Every check-in transaction starts with a signature-check instruction whose public key equals one of the host's four device keys (Host account).
- The vault holds exactly the pool plus its rent floor while the spot is open. /stats recounts that every pool equals the sum of its passes.
- After birth, the pump.fun curve's creator is the spot's fees account, and the vault's token account holds exactly the coins not yet claimed.
B4Admin powers
| Can | Cannot |
|---|---|
| Pause new hosts and new spots | Stop check-ins, commits, births, refunds or claims of existing spots |
| Change parameters for spots opened later | Change a live spot's parameters |
| Change the treasury (never to a program or the default key); hand over the admin in two steps (propose, then the new admin accepts); set the verified-venue badge | Touch any pool, coin, SOL back, refund or creator fee |
| Slash a host's bond to the treasury (trusted arbiter), only while it is locked | Slash an idle host's bond |
slash_host is a trusted arbiter power. There is no on-chain proof that a host signed for people who were not there. The arbiter decides off chain and the reason's hash goes into the event. It can take up to the whole bond while the bond is locked, and nothing else.
B5Risks
- The host is trusted: it can sign for absent people. The bond and the arbiter are the answer, not a proof.
- A live room code can be relayed; bounded by its 15-30 s life, the per-window cap and the room-code share.
- Sybil wallets inside the room are limited by caps, not stopped.
- Earning needs the staked half in the spot: an attendee who wants the fee share cannot trade that half until it unstakes, and unstaking is final.
- A host needs one bond per spot it has open at the same time; the bond answers for all of them together.
- A device clock more than ~15 s off the chain makes codes fail; the beacon uses the chain's clock.
- pump.fun keeps its own admin powers over its curves. The program is unaudited and upgradeable.
B6FAQ
Does the site track my location?
No. "Near me" asks the browser once to move the map. Nothing about your location is sent or stored, and check-in never needs it.
Can I check in from home?
Only with a code the host's device signed in the last 15 to 30 seconds. Someone could relay a live room code to you; the room code's share and per-window cap limit how many passes that can produce, and a host can switch to taps.
What if the pool misses its minimum?
The spot fails and every commit goes back in full. Anyone can push a refund to you, or you take it yourself. The host can run it again with the same name, ticker, picture and place.
Can I get my SOL back before the end?
Yes, until the last minutes of the doors (the take-back lock). What stays in must be zero or at least the minimum commit.
Why does birth have to run alone?
So nobody can buy the new coin in the same transaction as its creation. The first holders are the pass holders, at one price.
Why is half of my coin staked?
So the fee share goes to people who still hold. The program never reads your wallet balance (a lent bag could fool that); it keeps half of each allocation in the spot's vault and pays the attendees' 40% of creator fees to the passes that are still staked. Unstake whenever you like: you get your earnings and the staked half at once, and that pass stops earning.
What does the verified badge mean?
The admin marked the host as a known venue. It changes nothing about funds.
Can the host's phone key be a passkey?
The program also accepts P-256 keys (checked by the secp256r1 precompile), the kind phones keep in secure hardware. This beacon page uses Ed25519.