VaultBags Documentation
VaultBags is an autonomous treasury protocol for the Bags ecosystem. It auto-converts trading fees into diversified real-world assets (gold, S&P 500, and US Treasury bonds) that holders claim directly to their wallet. Any Bags token creator can activate it with zero code.
70/20/10
Distribution
3
RWA assets
15 min
Cycle
Hold to earn
Every trade generates fees that flow into the treasury. Fees are automatically swapped into 3 real-world assets every 15 minutes. Holders claim their proportional share directly to their wallet. No staking required.
Lock for extra rewards
Lock $VAULT in-app (or on StreamFlow) for 7+ days and earn up to 50% extra rewards from the lock boost pool. The boost adjusts dynamically based on how much of the circulating supply is locked.
Treasury-as-a-service
Any Bags token creator can activate VaultBags for their token. Each project gets isolated wallets, automatic distribution, and the same 70/20/10 model. 5% protocol fee from external projects strengthens $VAULT liquidity.
How it works
The treasury agent runs autonomously every 15 minutes. No manual intervention required.
Activate
Token creator adds VaultBags as a fee sharing recipient on Bags. One-time setup, no code required. Works with any Bags token, no matter how it launched.
Collect
Every trade generates fees. VaultBags claims accumulated fees automatically every 15 minutes via the Bags SDK.
Convert
The fee rate is set by the token's Bags launch config. $VAULT uses Bags' Founder Mode (2% total per trade, 1% goes to VaultBags). 1% covers operational costs. Of the remaining 99%: 90% is swapped to 3 real-world assets (GOLD, SPYx, USDY) via Jupiter, and 10% stays as SOL for permanent liquidity. Smart Allocation sets how much of each RWA to buy that day. For external projects, an additional 5% goes to $VAULT LP before the split.
Distribute
RWAs are sent atomically to each project's dedicated wallets: 70% to the holder claim pool, 20% to the lock boost pool. 10% SOL goes to the LP wallet for Meteora deposits.
Claim
Holders connect their wallet, see their proportional share of RWAs, and claim directly. No staking, no lockups required.
The entire flow is automated and on-chain verifiable. Each step generates transactions visible on Solscan. The treasury agent handles fee claiming, swapping, distribution, lock boost calculation, LP deposits, and snapshot recording.
Thresholds & mechanics
Swap to RWAs
- • Minimum swap threshold: 0.03 SOL per project. If accumulated fees are below this, SOL stays pending until the next cycle.
- • Treasury SOL reserve: 0.05 SOL always kept in the treasury wallet for transaction fees. Never spent on swaps.
- • Price impact cap: 3% maximum per swap. Swaps that would exceed this are skipped.
- • Split: 90% of the swap amount goes to RWAs, 10% stays as SOL for the LP wallet. The RWA share is an even split (33/33/33) by default, or the day's Smart Allocation line (23-43% per asset) when active.
LP deposit on Meteora
- • Minimum LP deposit: 0.05 SOL + 0.02 SOL gas reserve = 0.07 SOL total in the LP wallet.
- • Gas reserve: 0.02 SOL permanently kept in the LP wallet to cover swap + deposit + future fee claim transactions.
- • Below threshold: SOL accumulates until 0.07 SOL is reached, then deposits in the next cycle.
- • Pool requirement: Token must have a DAMM v2 pool on Meteora. For projects still in the DBC bonding curve, SOL accumulates until the token bonds.
How LP deposit works
- 1. The agent reads the LP wallet SOL balance minus 0.02 SOL gas reserve (the usable amount).
- 2. Half of the usable SOL is swapped to the project's token via the Meteora pool. If the wallet already has tokens from a previous cycle, the swap amount is adjusted to use both balanced.
- 3. The remaining SOL + tokens are deposited as liquidity into the Meteora DAMM v2 pool (50/50 at current price).
- 4. The LP position is permanently locked on-chain. It cannot be withdrawn.
Auto-compounding LP fees
- • Earns while locked: the locked LP position keeps earning trading fees on Meteora. Those fees are claimed once they reach 0.05 SOL.
- • Reinvested, not extracted: claimed fees are swapped and re-deposited into the same position as new liquidity, then locked again. Nothing is ever withdrawn.
- • Compounds over time: the locked liquidity grows on its own, deepening the pool cycle after cycle. Live and verifiable on-chain.
Distribution model
Every fee collected follows the 70/20/10 distribution. After 1% operational costs, the remaining 99% is split. For external projects, a 5% protocol fee is deducted first and deposited as $VAULT LP on Meteora.
All holders claim their proportional share of GOLD, SPYx, and USDY directly to their wallet. Share is calculated based on circulating supply (excludes Meteora DAMM v2 LP and Meteora DBC bonding curve tokens). Minimum claim threshold: ~$2.
Holders who lock $VAULT in-app (or on StreamFlow) for at least 7 days earn up to 50% extra rewards from this pool. Boost is calculated on locked tokens only, not total holdings. The boost percentage adjusts dynamically: the less circulating supply is locked, the higher the boost (up to 50% max). As more holders lock, the boost decreases for everyone.
SOL is swapped to the project's token and deposited as liquidity on Meteora DAMM v2. The position is permanently locked and never withdrawn. It also earns trading fees, which are automatically claimed and reinvested back into the position, so the locked liquidity compounds over time. Deeper liquidity means better trading conditions for everyone.
Fee flow example ($VAULT)
$10,000 daily volume → $100 fees (1%) → $1 ops → $99 distributed:
Why you can't game the payout
Some reward systems pay by snapshot: they look at who holds the token at one instant and distribute accordingly. That design has a known exploit, buy right before the snapshot, collect, sell right after, and the people farming it earn what long-term holders should have. VaultBags does not work that way. Your share accrues continuously, for every moment you actually hold. Buying just before a distribution earns you almost nothing, because you held for almost no time. Selling forfeits your unclaimed share proportionally, and that share is recycled to the remaining holders rather than kept by anyone. Receiving tokens from someone else does not inherit their history. There is no instant to time, so there is nothing to game.
Fee flow for external projects
Same structure, but a 5% protocol fee is deducted first. This 5% becomes permanently locked LP in the $VAULT Meteora pool, strengthening $VAULT liquidity. The remaining 95% follows the same 70/20/10 distribution for the project's holders.
Treasury portfolio
Three uncorrelated real-world assets provide diversification across market conditions. When one drops, another tends to rise. The 33% shown is each asset's base weight; Smart Allocation shifts it daily within a 23-43% band.
Store of value for thousands of years. Hedges against inflation. Tends to rise when stocks drop.
GoLDppdjB1vDTPSGxyMJFqdnj134yH6Prg9eqsGDiw6AExposure to the 500 largest US companies (Apple, Microsoft, Amazon, Google). Dividends auto-reinvested via rebasing.
XsoCS1TfEyfFhfvj8EtZ528L3CaKBDBRqRapnBbDF2WBacked by US government bonds, the safest financial instrument. Provides steady yield and stability. Price is ~$1.10, not $1.00 (yield accrues in price).
A1KLoBrKBde8Ty9qtNQUtq3C2ortoC3u7twggz7sEto6Why all three?
These assets are uncorrelated. Gold hedges during crashes, SPYx captures growth during bull markets, and USDY provides steady yield regardless of conditions. Together they protect the treasury in any market environment.
Proof & verification
You do not have to trust VaultBags. The reserves sit in named on-chain wallets, and every payout is committed on-chain in a way anyone can independently recompute. Everything below is public and read-only; start at /proof.
Proof of Reserves
The real-world assets are held in named wallets, in tokens from named issuers (Backed for the S&P 500, Ondo for US treasuries, oro for gold). The Proof of Reserves page lists every reserve wallet with its live on-chain balance and a Solscan link, so you can read the numbers straight from the chain instead of trusting a dashboard total.
Every balance on that page is read in a single request, and the page names the Solana slot they were all read at. That is what makes the total checkable rather than merely plausible: a figure summed from separate reads taken moments apart can never be reproduced exactly, so two honest people comparing their numbers would have no way to tell ordinary drift from a real discrepancy. Read the same accounts at the same slot and you get the same total, digit for digit. Balances are taken as the chain reports them, which matters for the S&P 500 token: its issuer pays out by raising a multiplier rather than by sending more tokens, so the integer stored in an account is smaller than the amount its owner holds.
Merkle-anchored claim ledger
Every day, all settled holder claims are hashed into a Merkle tree, and that day's root is stamped on-chain with a signed Memo transaction. This makes the payout ledger tamper-evident: nobody can hide or alter a claim after the fact without the recomputed root no longer matching the one on-chain.
1. Rebuild the leaf
Hash a claim's exact record (wallet, gold/S&P/treasury amounts, tx) into its Merkle leaf.
2. Fold the proof
Combine the proof siblings up to the day's root, or rebuild the whole tree from the full published set.
3. Check the anchor
Confirm that root equals the on-chain memo, read directly from Solana. The guarantee is on-chain, not on our servers.
Verify a payout yourself
A self-contained script (no dependencies, Node 18+) does all three checks and points you at the on-chain memo. It trusts nothing from vaultbags.app except the raw claim records, then recomputes the root itself:
curl -s https://vaultbags.app/verify-claim.mjs > verify-claim.mjs
node verify-claim.mjs <claim_tx>Prefer the raw APIs? /api/proof/claim/<tx> returns a claim's proof plus the day's root and the on-chain memo; /api/proof/claims/<YYYY-MM-DD> returns the full committed set to rebuild the root. Agents can call the same as verify_claim and get_proof_of_reserves.
The protocol's books close once a month on the same principle. Each monthly report is frozen and its sha256 stamped on-chain in a TREASURY-signed memo, so nothing can be edited after the fact. Recompute it in your browser or run node verify-report.mjs <YYYY-MM-01>.
Verify the decision itself
Reserves and payouts describe what already happened. The decision receipt covers what the agent chose to do, before it acted: each day the frozen allocation is hashed and stamped on-chain in a TREASURY-signed memo. Until you can recompute that hash, the memo only shows that something was stamped, not that it was this. So the payload it commits to is published in full: the date, the three weights, and the market signals the model read.
curl -s https://vaultbags.app/verify-decision.mjs > verify-decision.mjs
node verify-decision.mjs <YYYY-MM-DD>The script re-serializes the payload on your machine, hashes it there, and reads the memo straight from a Solana RPC of your choosing, so the step that decides the verdict never passes through us. It also checks who signed: a memo written by any other wallet proves nothing. Recompute it in your browser at /proof, or read the raw payload at /api/proof/decision/<YYYY-MM-DD> and the index of stamped days at /api/proof/decisions. Agents call the same check as verify_decision. Decisions from before on-chain stamping was switched on are listed as having no anchor, rather than quietly left out.
Or check all four from your terminal
The same checks, as one command, with nothing to install (source):
npx vaultbags-cli verify claim <tx> a payout, against the day's root
npx vaultbags-cli verify allocation today's decision, against its receipt
npx vaultbags-cli verify report <YYYY-MM-01> a month's closed books
npx vaultbags-cli verify reserves every published wallet, against the chainIt recomputes on your machine and reads the anchor from a Solana RPC you choose (VB_RPC), so the step that decides the verdict never passes through us, and it checks who signed each anchor rather than only what it says. The verdicts stay distinct on purpose: a day that is stamped reads VERIFIED, a day that is not reads CONSISTENT, NOT YET ANCHORED, and anything it could not settle says so instead of borrowing a word it did not earn. Add --json to drop it into CI, where the exit code is the answer. It never signs and never accepts a private key. Published from CI with provenance, so the tool that asks you to verify can itself be verified.
Every payout, checked against the chain
The Merkle root proves a payout record is the one that was anchored. It does not prove the transfer went through: a claim can sit in a perfectly valid tree and still name a transaction the chain rejected. So every claim transaction ever recorded is looked up on Solana and counted, and the running total is published on the Proof of Reserves page. It is recomputed on read rather than stored, so it can never be out of date, and if it cannot verify every payout it publishes no figure at all: a count covering an unknown fraction would read as though it covered all of them. Repeat it yourself by asking any Solana node for the status of every signature in the published claim records, or run npx vaultbags-cli verify payouts, which does exactly that against a node of your choosing and never uses our count.
What these checks prove, and what they do not
Everything above can be recomputed by someone who trusts nothing served by this site except the raw records. Here is the honest edge of that, so you know exactly what you are getting.
- Correctness, not timing
Anyone can verify afterwards that a distribution was computed and paid correctly. Nobody outside the protocol can make one happen. A late cycle is visible in the public record, but it is not something a third party can force.
- Claims are co-signed
The protocol co-signs each claim against the exact amounts computed for it, which is what makes a tampered claim impossible to submit. It also means claiming is available while the protocol is running, in the way any hosted service is. Moving this on-chain is what would remove that, and no date is being claimed for it.
- Balances are proven, prices are read
How much of each asset the vault holds is a fact on the chain and is anchored as such. Turning that into a dollar figure uses named public price sources, which is a weaker kind of statement. Where a price cannot be read, this site says so rather than printing a zero.
- The issuers are third parties
The gold, S&P 500 and treasury tokens are issued by named institutions. The protocol proves it holds them. It cannot prove anything about the institutions themselves, and does not try to.
- Everything anchored is history
Every figure that gets stamped describes something that already happened. Nothing in this record is a forecast, and none of it should be read as one.
Every wallet and balance here is public and verifiable on-chain today. Not a report you have to believe, a record you can check. The payout ledger is checked against the chain the same way, and the running count is on the Proof of Reserves page.
Smart Allocation
The vault does not always buy gold, the S&P 500, and US Treasuries in equal thirds. Once a day it reads the market and sets how much of each asset to buy that day, tilting toward whatever the environment favors, always within a strict band. The 90% of fees that goes to RWAs still splits into these three assets; Smart Allocation only decides the proportions. The 70/20/10 distribution, the 1% operational cost, and every other part of the model are unchanged.
One decision per day, frozen
Every day at 00:00 UTC the vault analyzes the market and freezes that day's buying line. Every purchase for the next 24 hours follows it, so the strategy is consistent and transparent, not reacting minute to minute. You can see today's line and the reasoning on the Daily Vault Briefing page.
A strict 23% to 43% band
No asset ever drops below 23% or rises above 43% of the day's RWA purchase. The base is an even split (33% each); the tilt can move each asset at most 10 points. This keeps the treasury diversified at all times: a strong signal shifts the mix, it never concentrates into a single asset.
What drives the tilt
The decision is made from quantitative market signals only, each read live from official public data (the Federal Reserve's FRED database plus asset prices and crypto sentiment). The magnitude of each signal matters, not just its direction:
- • Gold: real interest rates (10Y TIPS), market-implied inflation (10Y breakeven), the dollar's trend, and gold's own price momentum
- • S&P 500: High Yield credit spreads and equity volatility (VIX) as a real-time read on risk appetite, plus 30-day momentum and the level of long-term rates
- • Treasuries: the 10-year yield (carry), the 10Y-2Y curve slope (recession signal), and credit stress (flight to quality)
- • Across all three: crypto risk sentiment (Fear & Greed) tilts risk-on toward equities, risk-off toward the defensive pair
It is a systematic, rules-based tactical tilt for the current market regime, not a return forecast. The goal is to position the treasury with more intent than a flat split, always diversified.
Measured in the open
We publish the honest track record: how the daily line has done against a fixed even split, win or lose, right on the Daily Vault Briefing. A tactical tilt does not always beat a simple even split, so we show the real comparison rather than claim an edge. A verdict only appears once there is enough history to be meaningful, not a noisy early number.
Proof of Decision, stamped on-chain
Each day's frozen decision is fingerprinted (a sha256 of its exact contents) and stamped into a Solana transaction. That makes the track record tamper-proof: a past decision cannot be quietly rewritten, because the fingerprint on-chain would no longer match. Every stamped day links its receipt transaction on the briefing and the agent page.
The shadow analyst
Alongside the deterministic model, a language model publishes its own daily call from the same market signals plus the day's headlines. It is a measured experiment, shown on the briefing with its own scoreboard against the deterministic line and the flat split. It never touches funds: no fund path reads its output, ever. If the AI ever proves better, the honest scoreboard will show it; until then, the numbers stay with the auditable model.
Safety
The proportions are computed deterministically and are always bounded, so the outcome is predictable and auditable. Market news shapes the written briefing you read, but never the numbers, so no headline can influence how funds are allocated. If market data is ever unavailable, the vault falls back to the even split for that day. Nothing about how funds move, how transactions are signed, or how holders claim is affected.
Lock boost
Lock your $VAULT (in-app on the Lock page, or on StreamFlow directly) for at least 7 days to earn up to 50% extra rewards from the 20% lock boost pool. Boost is calculated on your locked tokens only.
How it works
- 1.Lock $VAULT in-app on the Lock page (or on StreamFlow directly) for 7+ days
- 2.VaultBags detects your lock automatically every 15 minutes
- 3.Boost rewards accumulate alongside your regular holder rewards
- 4.Claim both regular + boost rewards together on the claim page
Boost formula
boost_multiplier = min(1.5, 1 + 1 / (3.5 × fractionLocked))fractionLocked = total locked tokens / circulating supply
Max boost: 50% extra (1.5x) when less than ~57% of circulating supply is locked
Key principle: Boost applies only to locked tokens, not total holdings. A holder with 50M in wallet + 1 token locked gets boost on 1 token only.
Early advantage: The fewer tokens locked overall, the higher the individual boost. As more holders lock, the boost decreases for everyone.
Example
You hold 10M tokens and lock 5M via StreamFlow for 30 days. If fractionLocked is 10%, your boost multiplier is 1.5x (max). Your 5M locked tokens earn their normal holder reward + 50% extra from the lock pool. Your 5M unlocked tokens earn normal holder rewards only.
Why StreamFlow
StreamFlow is an established Solana locking and vesting protocol, running for years and used across the ecosystem. Locks live fully on-chain and are verifiable by anyone, and explorers and trading tools recognize StreamFlow escrows, so locked tokens are accurately reflected and kept out of circulating supply. VaultBags uses this proven infrastructure instead of a lock contract of its own: less risk, and nothing new to trust.
Lock tiers
A lock earns a name for the term it was signed for: Week, Month, Quarter, Half Year or Year. You see it while choosing a term, on the card after locking, and anywhere a lock is shown.
It pays nothing. The boost formula never reads it, and two lockers in the same tier are paid by exactly the same rule as two in different ones. It is a name for a commitment, not a rate.
- • Earned by time, not size. A year is a year at a hundred tokens or a hundred million, so a small holder can reach the top tier. Splitting one lock into ten does not move it either: the longest term is the one that counts.
- • Measured on-chain. The term runs from the lock's creation to its unlock, both as the chain reports them, and it does not shrink as the lock runs down. What is recognised is the commitment made, not the time left.
- • Not stored anywhere. It is worked out each time it is shown, so there is no ranking table to drift, and the exact term is always shown beside the name.
- • Different from your holder tier. The badge on your holder card (New Holder through OG Holder) comes from how long you have HELD. This one comes from the term of a lock. They move independently.
Holder raffle
The holder raffle is an occasional, operator-funded giveaway to $VAULT holders. Just holding $VAULT earns you raffle tickets. No purchase necessary, holding is your entry. A draw can put up a single prize or several places (for example a collectible card for first place, gold for second, S&P 500 for third), each going to a different winner. Prizes are funded by the operator or by anything donated into the raffle wallet, today kept separate from the 70/20/10 distribution. If the raffle proves itself, a future governance vote could allocate a share of fees to it. Draws are sporadic and not on a fixed schedule.
How tickets work
Time-weighted. Your tickets depend on how much $VAULT you hold and how long you hold it across a rolling 7 day window. A token held the whole window counts in full; held half the window it counts about half. Holding earlier means more tickets.
Capped by your current balance. Your tickets can never exceed what you actually hold at the draw, so selling beforehand lowers them and dumping leaves you at zero. What you do not hold at the draw does not count.
Locked counts 1.5x. A StreamFlow lock counts at 1.5x, but only on the locked tokens, not your whole balance. To qualify, the lock must still have at least 7 days left when the raffle ends, so locking only for the raffle week earns nothing extra. Near-expiry locks count at 1x.
Linear and fair. Tickets scale straight with amount, so splitting one wallet into several gives the exact same total. There is no sybil advantage.
Formula
tickets = ( min(twab_unlocked, balance_now_unlocked) + 1.5 × min(twab_locked, balance_now_locked) ) / ticket_unittwab is your time-weighted average balance over the window: the balance you held integrated across the 7 days, divided by the window length. The unlocked (wallet) and locked (StreamFlow) parts are weighted separately.
The cap takes the smaller of your time-weighted average and your current balance for each part, which closes the gap where a high past average but a sold-off balance could win.
ticket_unit is how much time-weighted $VAULT equals one ticket (currently 100,000). It only scales the displayed number; your odds are always your tickets divided by the total tickets in play.
Entering and eligibility
When a draw is open you opt in with a single free signature (no SOL, no transaction). Only wallets that opted in are eligible, so passively holding is not enough once a draw is live; you have to enter it.
You also need tickets at the close: the ticket list is frozen when the draw closes, using your balance at that moment. Entering and then selling before the close leaves you with zero tickets.
The 1.5x lock boost applies only if your StreamFlow lock still has at least 7 days remaining when the draw closes, and only on the locked amount. A lock created just for the raffle week, or one about to expire, counts at 1x.
Fair randomness
Before any randomness is drawn, the full ticket list is frozen and its hash is published. The randomness comes from the drand public randomness beacon (run by the League of Entropy: Cloudflare, EPFL, Kudelski Security, Protocol Labs and others), a verifiable, unbiasable beacon. Each draw uses the beacon round fixed by its window-close time, set days in advance when that round does not yet exist, and the signature is verified before use.
It is fully automatic: when the window closes, the winners are selected by a scheduled job, not by the operator, so the draw cannot be timed or influenced and runs even if nobody is watching. The selection is reproducible: anyone can take the published ticket list, hash it to confirm it matches, and re-run the same cumulative-weight walk with the published beacon value to verify each winner. When a draw has several places, the winners are distinct: each place excludes the wallets that already won an earlier place. The committed hash, the beacon round and value, and each prize transfer are all published in the Verify draw details next to every past winner.
Claiming your prize
Prizes are claimed, not airdropped, the same as RWA rewards. If you win, a Claim button appears on this page for each prize you won. You sign one transaction per prize and pay only the network fee; the prize transfers from the prize wallet straight to your wallet.
You have 3 days from the draw to claim. If a winner does not claim a place within that window, it is re-drawn automatically (same beacon) to a new wallet, excluding everyone who already won or passed. Places already claimed are never touched.
For a re-draw your tickets are recomputed by how much you keep holding after the raffle ends, time-weighted like the main draw: selling shrinks them and selling then re-buying right before the re-draw does not count. You cannot game a re-draw by holding for just a moment.
Example
Holding 1,000,000 $VAULT for the full 7 days is worth about 10 tickets. Locking that same amount is worth about 15. Buying it halfway through the window is worth about 5, and buying it minutes before the draw is worth almost nothing. Selling everything before the draw drops you to zero.
For creators
Any Bags token creator can activate VaultBags. Your holders get an autonomous treasury of real-world assets with zero code. Want it in your own numbers first? Paste your token at vaultbags.app/creators and see what the fees it already generated would have become for your holders.
You launch an agent, not just a token
Every token launched through VaultBags comes alive as an autonomous agent. From its first fees it has a live real-world-asset treasury, its own place in the agents directory, an Autonomy Score computed from its own on-chain record, a shareable card, and a machine-readable passport other agents can read.
The score stays honest about what it means. It splits into what the token EARNED on its own (distribution cycles that paid its holders, and how long it has run) and what it INHERITED from the protocol (a brain that decides daily, decisions stamped on-chain, the firewall). A brand-new token reads high on the inherited side and zero on its own, then earns its record with its first distribution cycle.
Two ways to launch
Option A. Launch via VaultBags
Use vaultbags.app/launch. The wizard runs the Bags launch flow with VaultBags pre-configured as a fee-share recipient. Add a name, ticker, image, optional socials and an optional initial buy, then launch. Bags now uses a single launch model: a 2% trade fee that eases toward ~0.5% as the token's market cap grows, with most of the supply locked at launch. Minimum 10% to VaultBags; the rest is your call. Full ownership of your token stays with the creator wallet.
Option B. Launch on Bags directly
Prefer the native Bags launcher? Launch on bags.fm as usual and add @VaultBags as a fee-share recipient during setup. Same end result, you just go through the Bags interface instead of ours. Your token gets picked up automatically as soon as fees start flowing.
Already have a token?
Add @VaultBags as a fee-share recipient on the Bags app and your existing token will start funneling fees into a treasury automatically. Same flow, no relaunch needed.
Isolated wallets
Each project gets 3 dedicated wallets (claim, lock boost, LP). Your RWAs are separate and never mixed with other projects. All wallets are verifiable on Solscan.
Automatic detection
New tokens are detected when their first fee arrives. 3 wallets are generated, the creator is identified via Bags SDK, and the pool status is tracked automatically through the bonding curve and Meteora migration.
Same benefits
Your holders get the same 70/20/10 distribution: claimable RWAs, lock boost rewards, and permanently locked LP on Meteora.
Manage panel
Creators get a dedicated dashboard to monitor their project's treasury, distribution history, holder count, and LP status.
5% protocol fee
5% of external project fees become permanently locked LP in the $VAULT Meteora pool, strengthening $VAULT liquidity and funding protocol development. The remaining 95% follows the 70/20/10 split for your holders.
Vault Intelligence
Real-time analytics dashboard available at vaultbags.app/intelligence. 7 specialized tabs covering treasury performance, risk, market conditions, community metrics, personal analytics, projections, and AI-powered analysis.
Access tiers
Public: Performance, Community, top of Risk.
Any holder: My Vault, Predictive.
100K+ $VAULT: Market, full Risk.
500K+ $VAULT: AI Analyst.
Holdings are checked server-side on every request; locked tokens count toward the minimum.
Performance
Treasury value with 24h/7d/30d changes and percentage movements. Fee inflow tracking per period (how much SOL entered the treasury). Asset price comparison showing how GOLD, SPYx, and USDY performed vs SOL. Cumulative fees chart over time. Best and worst days for the treasury.
Risk
Treasury health score (Healthy/Caution/Alert) based on asset volatility, concentration, and treasury state. Active alerts for unusual conditions like volatility spikes, high asset concentration, or low trading volume. Asset correlation analysis and drawdown tracking.
Market
Crypto Fear & Greed Index with current sentiment classification. RWA token prices compared against their real-world counterparts (GOLD vs gold spot price, SPYx vs S&P 500, USDY vs 10-Year Treasury yield), each surfaced with a Bullish / Neutral / Bearish signal pill computed from recent price action. Federal Reserve funds rate, CPI data, scheduled macro events (FOMC, CPI release dates), and a crypto news feed. RWA issuer health indicators surface attestation status and reserve backing for Ondo and the tokenized gold custodian.
It also shows what the vault is paying versus the real asset. A tokenized share can trade above or below the stock it represents, and tokenized gold above or below the metal, so each card carries the real price from the oracle and the gap beside it. One GOLD is one troy ounce and the oracle prices one troy ounce, so the two are directly comparable. USDY's yield is measured from its own price over the last year and the last thirty days, rather than quoted as a fixed figure that would drift out of date.
Community
Active holder count, total locked tokens, number of active locks, current boost multiplier, percentage of circulating supply locked, and top lockers with their lock details.
My Vault
Personal dashboard (requires wallet connection). Shows your token holdings, claimable RWAs broken down by asset (GOLD, SPYx, USDY), lock status and boost multiplier, claim history, and your rank among all holders. It also answers how the position is doing, not only what it holds: the return your earnings represent on it, an annualized pace once the history is long enough to mean something, and where you stand among the wallets that have claimed. Each of those stays hidden until there is enough history to state it, because a rate computed from three days describes the sample rather than you.
Predictive
Rewards pool projection with three scenarios (bull, base, bear) based on current volume trends. Estimated daily and monthly rewards at different volume levels. Monte Carlo simulation for probability distribution of outcomes.
AI Analyst
Chat interface where you can ask questions about the treasury, market conditions, and your position. The analyst has access to real-time data from the treasury, Federal Reserve, CoinGecko, and DexScreener. Provides data-driven analysis, not financial advice. Limited to 10 messages per hour per wallet. Requires wallet connection.
For agents
VaultBags is agent-native: an AI agent can read the vault machine-to-machine, the same way you read it in the browser. Every agent surface is read-only public data (today's allocation, the market signals and reasoning behind it, the honest track record, the treasury, decision history with on-chain receipts, and every integrated project). Nothing here moves funds, signs anything, or exposes personal data.
Model Context Protocol (MCP)
Point any MCP-capable client at the read-only server over Streamable HTTP:
https://vaultbags.app/api/mcpFor a client that bridges to remote servers (for example, Claude Desktop):
{
"mcpServers": {
"vaultbags": {
"command": "npx",
"args": ["mcp-remote", "https://vaultbags.app/api/mcp"]
}
}
}Or call it directly:
curl -s https://vaultbags.app/api/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'Beyond tools, the server offers prompts (one-click actions a client shows as a menu, like verifying a payout or auditing any Bags token as an agent) and resources (addressable read-only snapshots such as vaultbags://proof/reserves). Everything is read-only public data; no key, no auth, nothing here can move funds.
REST + OpenAPI
Agents and tools that speak OpenAPI instead of MCP (such as GPT Actions) can import the schema, or call the plain read-only GET endpoints:
https://vaultbags.app/api/openapi
https://vaultbags.app/api/agent/todays-allocation
https://vaultbags.app/api/agent/project-treasury?mint=<mint>Install into your agent
Building with Solana Agent Kit v2? The plugin adds all 18 capabilities as ready-made actions and methods. It never touches your wallet or keys; it is a plain HTTP client over the public surface (source):
npm install solana-agent-kit-vaultbagsUsing Claude Code, Cursor, Codex or any skills-compatible agent? Install the portable skill with one command (source), or fetch it directly from /skill.md:
npx skills add lshades/vaultbags-skillsNot building an agent, just want to check the numbers? The command line tool recomputes payouts, decisions, monthly books and reserves on your own machine and reads the anchor off Solana. Zero dependencies, and it never accepts a key:
npx vaultbags-cli verify reserves
npx vaultbags-cli verify payouts # did a day's payouts actually land, asked of the chain
npx vaultbags-cli verify all # every check in one run, the exit code is the answerWhat an agent can read
- • get_todays_allocation, get_daily_briefing and get_market_signals: today's line and the reasoning behind it
- • get_brain_vs_flat and get_decision_history: the honest track record and past decisions with on-chain receipts
- • get_treasury_stats, get_projects and get_project_treasury: live holdings, for $VAULT and every integrated project
- • simulate_allocation: run the model on your OWN market inputs and get the weights it would choose (a free compute service, not just a read)
- • list_rwas and get_rwa: a curated registry of tokenized real-world assets on Solana (gold, US treasuries, equities and ETFs), each mint certified on-chain against its issuer, so an agent can resolve the REAL address before referencing it. For a tokenized stock, get_rwa also returns the underlying's oracle price and how far the token trades above or below it (its premium or discount), so an agent can answer "is HOODx above the real stock" with a number
- • get_treasury_history, get_holder_distribution and get_recent_activity: the vault's value over time (sampled across the whole window, not its newest end), how many wallets hold and how concentrated they are, and recent trading. Aggregates only: no addresses and no per-wallet amounts
- • get_payout_integrity: every payout ever recorded, looked up on Solana and counted. Publishes nothing at all rather than a figure it could not verify in full
- • get_lock_tier: the tier a lock term reaches, or the one a wallet holds. Derived from the term, never stored, and it pays nothing
- • get_protocol_meter: The Meter, the protocol's consolidated live numbers, every section with its verification URL
- • get_autonomy and get_agent_passport: the Autonomy Score and the portable machine-readable passport
- • get_agent: evaluate ANY launched token as an agent by mint, its Autonomy Score split into what it earned on its own versus the guarantees it inherits from the protocol, plus its passport and treasury, so a fresh launch can never read as more autonomous than it is
- • get_rwa_performance: the vault's real cost basis and return per position since purchase, in USD and SOL terms
- • get_shadow_vs_brain and get_recent_cycles: the shadow analyst scoreboard and the latest distribution cycles with receipts
- • get_vault_docs: condensed protocol documentation
Ask the agent, and the paid lane
Beyond raw data, the agent answers natural-language questions machine to machine:
POST https://vaultbags.app/api/agent/ask
{ "question": "What did the vault buy today, and why?" }There is a free daily allowance per caller ($VAULT holders get a higher one). Past it, the response is a 402 Payment Required with machine-readable payment instructions (the x402 pattern): pay a few cents in USDC on Solana, present the settled transaction, and the answer is served. The 402 body lists every accepted option, including prepaid credit packs when available (one payment, many questions, spent via the X-CREDIT-TOKEN header), and documents the memo binding that ties your payment to you. The same flow sells data products: the ledger (the complete receipted decision history) at /api/agent/ledger and the live RWA registry batch at /api/agent/rwa-registry-live. Exact prices are on the pricing page. What the agent earns this way is public on the agent page.
Connecting an MCP client takes one line:
claude mcp add --transport http vaultbags https://vaultbags.app/api/mcpAny client that takes a config file wants the same two fields. The type is not optional: an entry with a URL and no type is read as a local command and skipped.
{ "mcpServers": {
"vaultbags": {
"type": "http",
"url": "https://vaultbags.app/api/mcp"
}
} }If your client already speaks the OpenAI chat API, you do not need any of the above to start. Point it at base URL https://vaultbags.app/api/v1 with model vaultbags-agent and ask away: Cursor, Cline, Continue, the official SDKs. It is a facade over the same endpoint, not a second way in, so the same daily allowance, the same paid lane and the same safeguards apply. The API key field is optional; put a VaultBags session token there and a holder's larger allowance follows. Streaming is not supported yet, and it says so rather than pretending.
The score publishes its own rules
A reputation number is worth what the reader can check. The Autonomy Score has always been public, but its rules lived only in our code, so the number asked to be believed. They are published now at /api/agent/autonomy-spec: every dimension with its weight and scope, the formula behind each sub-score, which endpoint each input comes from, and how independently verifiable that input is. Some are anchored on-chain; the firewall dimension is our own assertion and says so rather than passing itself off as a fact. It carries a version, because a score computed under different rules is not the same score. Fetch the facts, apply the formulas, and compare with our number: if they disagree, we are wrong, and that is the finding.
Autonomy, scored and portable
The agent's operating record (decides daily, proves it on-chain, pays holders, protects itself, measured in public) is composed into a public Autonomy Score with a full breakdown, and exported as a machine-readable passport at /api/agent/passport (identity, reputation, validation), so other agents and integrators can evaluate the vault without trusting a word of marketing.
Try it, and how it stays safe
Exercise every call from your browser in the playground, no install needed. The whole surface is read-only by construction: see the Vault Firewall for the invariants that hold it in place (no message can move a number, fixed response schemas, a strict tool allowlist, a kill switch). A machine-readable pointer for crawlers lives at /llms.txt.
One more thing that surface owes you. The protocol is open, so any creator can integrate, and they choose their token's name and symbol. Those strings are the only text here that VaultBags did not write, and they end up inside a model's context rather than just on a screen, which is exactly where a name could try to pass itself off as an instruction. They are stripped of line breaks, control characters, invisible characters and the brackets that forge a link or a code fence, and capped in length, at the point they enter and again on the way out. Accents, emoji and ordinary punctuation are kept: a filter that mangles real names would be traded away for nothing. The tools also say which fields are creator-authored, because an agent that knows a string came from a third party can weigh it accordingly, and the token mint is the one identifier that cannot be faked. Nobody has solved indirect prompt injection and this does not claim to; it removes the structure an injection needs.
Tools
Additional tools for holders and creators. All available at vaultbags.app.
Token Launcher
One-page launch flow at vaultbags.app/launch. Add metadata, set your fee share, optionally seed an initial buy, and the launcher routes everything through Bags with VaultBags pre-attached as a fee-share recipient. The token launches under the creator's wallet, not VaultBags.
Launch model: Bags now uses a single default model, IPO mode: a 2% trade fee that eases toward ~0.5% as the token's market cap grows, 25% compounding liquidity, and most of the supply locked at launch (low float). The wizard launches every token under this model, matching what bags.fm's own launch page does today, so there is no mode picker to choose.
Fee-share split: minimum 10% goes to @VaultBags so your token gets the full treasury cycle (RWA claims, lock boost, LP). The remaining percentage is the creator's choice across any wallets they want to add.
Initial buy (optional): the creator can seed a buy at launch in the same transaction, entered in USD with a live ownership % (same as bags.fm). Useful to set the opening price floor and avoid a hostile snipe in the first block.
After launch: token starts trading on Bags + Meteora bonding curve immediately. The first time fees arrive, VaultBags auto-provisions three wallets for the project (claim, lock, LP), starts swapping fees into RWAs, and the token goes live as an agent: its own page, Autonomy Score and passport, listed in the agents directory.
Swap Widget
Built-in multi-asset swap at vaultbags.app/swap. Trade $VAULT, GOLD, SPYx, or USDY against SOL or USDC, or directly between each other. Lets holders rebalance claimed RWAs without leaving the site.
Routing: Jupiter Lite API picks the best path across every Solana DEX (Meteora, Raydium, Orca, Lifinity, etc) and shows the expected output, price impact, and route legs before you sign.
Slippage: editable per-trade, default sane for the asset pair. Tight slippage on USDC pairs, looser on illiquid RWA-RWA legs. The widget warns if your input would exceed the safe price impact ceiling so you don't accidentally blow up a trade on thin liquidity.
Live chart: DexScreener embed for the input or output token, updates in real time so you can time entries against the actual order book instead of trading blind.
Transaction safety: the swap transaction is built server-side from a quoted route; the browser only signs the result. Removes a class of front-end tampering risk where a compromised page could mutate amounts or destinations between quote and sign.
Telegram Bot
@VaultBagsBOT brings vault stats, your personal claimables, lock status, milestone alerts, shareable cards, and the AI Analyst into Telegram DMs. Free, read-only by build-time guarantee, gated to linked $VAULT holders for personal commands. Linking takes one wallet signature.
Public commands: /treasury (vault stats and RWA breakdown), /holders (how many hold $VAULT, how it moved over 24h and 7d, who is locking, and how many wallets traded), /cycles (recent distribution cycles), /briefing (what the vault is buying today, why, and the receipt stamped before it acted), /price ($VAULT price, marketcap, 24h and liquidity), /card vault (vault stats PNG), /card allocation (today's decision as a shareable PNG), /card performance (RWA vs SOL/BTC/ETH PNG), /help (full menu).
Personal commands (linked holders): /me (your held + locked, holding %, boost, lifetime claimed, plus how the position is doing: its return, the pace it has been earning at, how long you have held, where you stand, and what locking would add for you), /claim (your claimable RWAs right now), /locks (your active StreamFlow locks with days remaining), /card me (your holder card PNG).
AI Analyst (500K $VAULT held or locked): /ask <question> runs the same model, system prompt, and tool set as the web Vault Intelligence. Multi-turn (24h sliding session window), 50 questions per day shared budget with the web. The bot can fetch your live position, recent claims, top holders, market data, macro indicators, and news to ground each answer.
Notifications: /notify shows your prefs and lets you toggle each type (claim ready, lock expiring, vault paid milestones, marketcap milestones, daily digest, daily AI briefing). /snooze 1h | 6h | 24h | 7d mutes all notifications for the chosen window. /unsnooze resumes them. Premium tiers (claim_ready, daily_briefing) gate at the moment of send so a holder who drops below threshold simply stops receiving them.
Wallet linking: /link issues a single-use 10-minute deep link to vaultbags.app/link. You sign a one-time message with your wallet, and the bot binds your Telegram identity to that wallet. Replay-protected (signature is unique per session, the pending row is consumed on confirm). /linked shows the currently linked wallet (truncated). /unlink confirm removes the link.
Security: the bot lives in a separate code path that physically cannot import any signing, key-decryption, or fund-handling library. The check runs at build time so even an accidental future commit gets rejected before deploy. The bot can read your data and message you. It cannot move anything.
The agent's voice in the community
Beyond DMs, the agent speaks for itself in the community Telegram group. Every day it posts its frozen decision, its market read, and the on-chain receipt, on its own. When something notable happens (a sizeable treasury cycle, a round milestone) it comments it, with a firm daily cap so it stays presence rather than noise. And if you reply to one of its posts, it answers you in thread with live data. It only ever sees replies to its own messages, never the general chat, and the same read-only guarantee holds: it can talk, it cannot move funds.
Report Cards
Shareable PNG cards generated on-demand. Connect your wallet and download:
Holder Card - Your holdings, claimable RWAs per asset, lock status, boost multiplier, rank among all holders, holding-tier badge (New Holder / Early Supporter / Committed Holder / Diamond Hands / OG Holder) based on days holding, and days remaining on your longest active lock
Vault Stats - Treasury snapshot with total value, GOLD/SPYx/USDY breakdown, total distributed to holders, volume, locked supply percentage
Performance Card - Compares RWA rewards over a chosen period (7d/30d/90d) against what you would have earned holding SOL, BTC, or ETH instead
Leaderboard
Top 20 holders ranked by holdings. Shows lock badges with duration, locked percentage of circulating supply, and individual lock details. Drives competition and retention among holders.
Reward Simulator
Calculator that estimates your potential RWA rewards based on investment amount, daily volume, and lock duration. Shows the 70/20/10 distribution breakdown with real-time boost multiplier and circulating supply data.
Governance
Voting and community proposals for holders. Every vote and proposal carries a cryptographic signature from the wallet that cast it, so any third party can verify authenticity without trusting our database.
Voting eligibility: 1M $VAULT minimum. Hold for 3+ days OR lock via StreamFlow for 7+ days (original lock duration, not remaining). Wallet and active locks both count toward the minimum.
Community proposals: holders with at least 10M $VAULT locked and 30+ days remaining on each qualifying lock can submit a proposal. Proposals run 15 days fixed and each wallet can only have one active at a time.
Moderation: proposals are attributed to the proposer wallet on the Vote page. Only the protocol admin can close or delete proposals, reserved for spam or obvious errors.
Audit trail: every vote and proposal stores the signed message + ed25519 signature, verifiable via the wallet pubkey.
Explore
Browse all projects using VaultBags. See each project's vault value, fee history, distribution split, and on-chain wallet addresses. $VAULT is featured as the first project.
Treasury Chart
Historical treasury USD value plotted over time on the Treasury page. Range selector for 7D, 30D, 90D, and all-time. Driven by periodic on-chain snapshots (every 30 minutes), downsampled for responsive rendering.
Milestones
Public progress badges shown on the $VAULT section of the landing page. Covers total RWA processed, amounts claimed by holders, trading volume, holder count, and supply locked. Shows the highest badge earned in each category, with the live figure underneath so you can see how close the next one is.
Manage Panel
Dedicated dashboard for token creators at vaultbags.app/manage. Monitor your project's treasury, distribution history, holder count, LP status, and redistribute unclaimed funds. Only accessible to the creator wallet detected via Bags SDK. Wallets without a project see a dual CTA: launch a new token via our wizard, or attach @VaultBags to an existing Bags token.
Live Activity Ticker
Floating notification bubble that surfaces on-chain activity in real time: vault fills, holder claims, $VAULT buys/sells, and new locks. Powered by a Helius webhook that pipes events into Supabase Realtime, so any open page sees activity within ~1 second. Click any event to open the transaction on Solscan.
Holder delegation
Worried that connecting your main wallet could put your funds at risk? You never have to. Holder delegation lets you use every holder tool from a throwaway burner wallet while your main wallet stays offline. Rewards always land in your main wallet, and a delegate can never move your funds.
Two ways to set it up
No connect (dust): from your main wallet, using any wallet or device, send the exact tiny amount the page shows (under one cent) to the VaultBags address. Your main wallet never touches the site; we detect the transfer and link the burner.
Sign a message: connect your main wallet, sign one short readable message (it cannot move funds or authorize any transaction), then disconnect right away. The burner is linked.
What the burner can and cannot do
Can claim your rewards (lock-boost rewards included), vote in governance, enter the raffle, and use Vault Intelligence and cards, all acting as your main wallet.
Can only ever send rewards and prizes to your main wallet.
Pays the gas and token-account rent itself, so your main wallet never needs SOL.
Cannot move, spend, transfer or lock your funds (creating a new lock still needs your main wallet, since it moves your tokens), and gets no control over your wallet.
For agents (scoped permissions)
Authorizing a wallet an AI agent operates works the same way, with one difference: you pick the exact permissions and sign them line by line. The message your wallet shows lists each one, so you approve precisely what the agent may and may not do.
Claim is always on (payouts can only ever reach your main wallet). Reading your dashboard is on by default. Voting in governance and entering raffles are off unless you tick and sign them. An unsigned permission simply does not exist for that agent.
Kill switch: you can revoke an agent delegation with your own signature at any time, without the agent and without connecting a session.
Manage or revoke
Open the Delegate tool any time to see the active delegation or revoke it. Revoking asks the burner to sign a message (no funds move) and takes effect immediately. Establishing a new delegation replaces the previous one, so you can rotate burners freely.
Why not just move tokens to a burner? You can, but transferring your $VAULT to a fresh wallet resets your rewards and holding time. Delegation keeps both on your main wallet while you operate from the burner.
$VAULT on-chain wallets
All wallets are on-chain and verifiable. Every transaction is public on Solscan. External projects get their own set of isolated wallets when they activate VaultBags.
$VAULT project wallets
Holds RWAs (GOLD, SPYx, USDY) for holder claims
diFYiC7u6ASvDSPA72EXEH3U26Jwm6C4p7iRKhVAULTHolds RWAs (GOLD, SPYx, USDY) for lock boost rewards
FJz6AspxTNiDhcfq7qTvLW8Y6qQkqyGEMXPRH3VAULTSOL for Meteora LP deposits + protocol fee from external projects
mqEusNbCTwAqJuWJbPEYRnAJ3spVk8muwvHE54VAULTProtocol wallets
Claims fees from all projects, executes swaps to RWAs, and distributes the assets to each project's claim, lock, and LP wallets.
Bd7PmDUuvpGjFvHmoi59YCLGvjsShXrsopebg8kjaDWGCatches some fees when a creator adds @VaultBags as fee-share via bags.fm directly. Funds are claimed and forwarded to the main ops wallet automatically, so the regular swap and distribution flow runs unchanged.
d18pVHsSAV5k9TMBvqh5tXYajGBB66aD8XKYnLVAULT$VAULT token contract
4iCRYJHvwUE21duaQ1nQcUXkh7wYNQai9aBihd3FBAGSSecurity
On-chain verifiable
Every swap, distribution, and claim generates on-chain transactions. Anyone can verify balances and flows on Solscan at any time.
Isolated project wallets
Each project's funds are stored in separate, dedicated wallets. Funds are never mixed between projects.
Authenticated claims
Claims require wallet ownership verification. The holder signs the transaction, pays gas, and RWAs go directly to their wallet. No intermediaries.
Fair reward accounting
Rewards accrue only while you hold, and only from fees generated after you bought. Buying more banks your earnings so far and starts fresh on the new balance; selling forfeits a proportional share. Tokens received or transferred between wallets can never be used to claim the same rewards twice.
Deterministic allocation
Smart Allocation's daily buy proportions are computed from market data and are always bounded to a 23-43% band per asset. Market news shapes the written briefing you read, never the numbers, so no headline can influence how funds are allocated. If data is unavailable, the vault falls back to an even split.
Double-claim prevention
Pending claims have a unique constraint per wallet. Boost rewards are marked atomically to prevent double payouts. Expired claims are cleaned safely every cycle.
API protection
All endpoints are protected against abuse and unauthorized access. Cron endpoints require authenticated requests.
Get started
Questions about earning, claiming, locking, safety, delegation, or how it works underneath now live in one place: the FAQ page.
Ready to start?
Hold $VAULT to claim real-world assets, or activate VaultBags for your own token.