Docs menu

YONDER docs, for developers

Contract

YonderCollection is a buyer-paid ERC-721 on Robinhood Chain 4663. Its EIP-712 domain is Yonder Collection, version 1, bound to the chain and deployed collection address. It inherits Ownable and Pausable. No relayer or hook mints pieces for buyers.

Status

Deployment

Constructor fields, in order: address owner, address signer, address token, address pool, uint256 minBuy. The first claimer can publish the fixed constructor payload through the canonical CREATE2 proxy. The owner, signer, token, selling pool and positive minimum are fixed by that payload. Only the owner can rotate the nonzero signer with setSigner. It emits SignerChanged(oldSigner,newSigner). Pending authorizations from the old signer then fail. Roll out the matching API SIGNER_KEY with the on-chain change.

Mint authorization

MintAuthorization(address buyer,bytes32 buyRef,uint256 amountIn,uint256 deadline,address stealth,bytes ephemeralPubKey,bytes1 viewTag)
mintForBuy(address buyer, bytes32 buyRef, uint256 amountIn, uint256 deadline, bytes signature, address stealth, bytes ephemeralPubKey, bytes1 viewTag)

The API checks a confirmed token Transfer from the selling pool to the final buyer and signs this typed message. The contract checks signer, deadline, minimum, transaction sender equal to buyer, unused buy reference and a lifetime one-claim rule for that buyer through claimedBuyer, regardless of current NFT balance. A repeated buyer reverts with BuyerAlreadyClaimed(). The contract does not inspect past token transfers itself. The buyer pays the network fee. A signer mistake can authorize an ineligible buy, so the API proof remains a trust boundary.

The client prepares stealth, ephemeralPubKey and viewTag locally before POST /api/mint-auth. The request contains txHash, optional logIndex and the three public delivery fields. The response echoes all three. The client checks an exact match before minting. The EIP-712 struct hashes dynamic ephemeralPubKey as keccak256(ephemeralPubKey). The API accepts a nonzero stealth address distinct from the buyer, a valid 33-byte compressed secp256k1 public key, and one byte of view tag. The client never sends wallet signatures, private ephemeral keys, spending keys or viewing keys to the API.

Functions and events

Public and operator ABI entries: mintForBuy, authorizationHash, ownerOf, stealthOf, tokenURI, usedBuy, claimedBuyer, setSigner, pause, unpause. Inherited ERC-721 owner, approval, transfer and ERC-165 functions remain available. The contract emits SignerChanged(oldSigner,newSigner), Landed, ERC-5564 Announcement, Transfer as applicable. renounceOwnership reverts to preserve signer rotation.

Yonder privacy mechanism

A buyer signs locally to derive separate spending and viewing keys. The client creates a one-time stealth destination, and mintForBuy announces it through the canonical ERC-5564 Announcer. The buyer-paid mint transaction publicly links buyer and destination. Scan derives the destination and confirms ownerOf. A stealth account needs native gas to transfer.

Artwork and metadata

imageForTraits(uint8[4], bool, bytes32) draws the YONDER bust, lit visor and glyph from public trait picks. tokenURI embeds that on-chain SVG and marks STEALTH. Landed(tokenId,buyer,buyRef,seed) records the original buyer and buy reference; seed equals seedOf(tokenId). The buyer and stealth destination are linked by the buyer-paid mint transaction.

Ethers browser bundle provenance

The local pristine ethers 6.16.0 UMD bundle has SHA-256 9a85a5aa81305f85e6546452fd2093a8a68932bed3cec4f6491e4d031a90bc95. The shipped bundle has SHA-256 65772f76fae0bc74e7b923bc27aa928f48d7a9a72cc374f6393cf9378129d789. Byte comparison found one local license header and five address literal splits. The splits join the same address at runtime. The six exact edits are in contracts/vendor-patches/ethers.umd.min.patch.json. From the workspace root, run node .foreman/seven-cooks/privacy-tools/round5-vendor-proof.cjs to apply the edits to the pristine copy and compare every shipped byte.

The reported SigningKey.addPoints defect is not present in the local evidence: its implementation is byte identical in pristine and shipped ethers 6.16.0. Both compute the compressed point G + 2G as 3G. No addPoints correction can be attributed to this shipped bundle without another verified baseline.

Launch inputs

Collection, token, pool, minimum, owner and signer addresses must be set to real launch values. The buyer must have native gas for the first CREATE2 publication and mint. No production collection address is claimed on this page.