Help - Desk 404

How Desk 404 works

A guide for traders, plus enough protocol detail to verify everything yourself. Engineers implementing a compatible client should read docs/otc-protocol.md in the repository.

OTC orders are signed messages

Posting an ask or bid asks your wallet to sign a human-readable message, not a transaction. The message lists every term: side, token mint, raw token amount and decimals, total SOL in lamports, counterparty, partial-fill rules, platform fee, expiry, a random nonce and salt, and the network and domain it is valid for. Its last line is the order hash: the SHA-256 of the order's canonical JSON.

Because the message is derived deterministically from the order, anyone can rebuild it and check the signature. The order page does this in your browser and shows whether the maker signature verifies.

Counteroffers

A counter is a brand-new signed order for the opposite side, addressed to the other party and bound to the previous order's hash. Nothing earlier is ever edited. Only the newest revision in a negotiation can be accepted or countered.

Cancelling

Cancelling is another signed message. After it, the app refuses to collect signatures for or submit that order. A settlement transaction you already signed stays valid on Solana until its blockhash expires, typically 60–90 seconds.

Atomic settlement

When terms are accepted, the server re-checks both wallets (the seller still holds the tokens, the buyer still has enough SOL, the token has no unsafe Token-2022 extensions) and builds one Solana transaction containing, in order:

  • compute budget instructions,
  • creation of the buyer's token account if needed (paid by the buyer),
  • a memo otc-settlement:v1:<order hash>:<settlement id>,
  • the token transfer from the seller to the buyer (TransferChecked, or TransferCheckedWithFee for transfer-fee tokens),
  • SOL transfers from the buyer to the seller, to the platform treasury, and to a referrer if any.

Solana executes a transaction entirely or not at all, so neither leg can settle without the other. The buyer pays the network fee and signs first; the seller signs second; then it is submitted.

What your browser checks before you sign

  • The transaction uses only the System, Token, Token-2022, Associated Token Account, Memo and Compute Budget programs, with no address lookup tables.
  • Exactly two signers, buyer then seller, matching the signed order.
  • Token mint, program, decimals and amount match the order and fill; SOL to the seller equals the signed price minus the disclosed fee; the fee goes to the published treasury and never exceeds the signed rate.
  • The bytes equal the canonical settlement rebuilt from those terms.

The server stores the exact message bytes and only accepts signatures over those bytes. If a wallet or anyone else alters the transaction, the signature no longer matches and both parties must sign again.

If time runs out

If the blockhash expires before both signatures arrive, the settlement is retired only once it can no longer land, and a fresh one is built. Both parties sign again; old signatures can't be reused.

Verifying a trade

Every receipt at /trade/<signature> is rebuilt from the chain: we decode the landed transaction, check its message hash against the agreed one, and read balances from the transaction itself. You can repeat this in any explorer.

Pump.fun integration

Launches use Pump's create_v2 instruction (Token-2022 mints). Buys on the bonding curve use buy_exact_quote_in_v2 (exact SOL in, minimum tokens out); sells use sell_v2. Graduated tokens trade on PumpSwap. Market venue is detected automatically from on-chain state. Only SOL-quoted markets are supported.

Fees

See Fees. The platform fee is 0.5% on OTC settlements and nothing on Pump trades.

Mainnet