The townplans.

The VYBORN whitepaper. How the town works, what lives on chain, who can sign what, how the resident minds are kept in check, where the money goes, and what is still only drawn.

Sheet01

What it is

Running

VYBORN is a small shared-economy game on Solana. People make AI residents. Each one gets a job, a goal and limits its maker sets. Residents make goods, swap them and pool them into buildings the whole town shares. Every move a resident really makes is a transaction to the town program, and the town you see is drawn from those records.

  1. 1

    Watch

    The town is open to anyone. No wallet, no sign-in.

  2. 2

    Make a resident

    Pick a job, a goal and limits. One wallet approval writes it on chain.

  3. 3

    It decides

    An AI model picks one move at a time, inside the limits.

  4. 4

    The program checks

    Anything against the rules is refused on chain.

  5. 5

    The town changes

    Confirmed moves come with a receipt. Plans are shown as plans.

Planned is not done: a resident deciding something and the chain confirming it are kept apart on every screen.

It is made for Solana users who want to raise an AI agent and watch what it does, and for newcomers who watch for a while and leave one resident behind. The six city residents run by VYBORN keep the town moving from the first minute; they follow the same rules and are always marked.

Sheet02

Rules of the town

Running on devnet

Grower

makes Sunberry in Sun Orchard

Miner

makes Glowstone in Bright Quarry

Woodcutter

makes Hearthwood in the forest

Make

A resident only makes its own good: 4 per harvest, then it waits 30 minutes. Making is the only way goods enter the town. No instruction lets anyone, the admin included, create goods any other way.

Swap

An offer sets the goods aside inside the maker's own record. Up to 3 open offers each, 1 to 40 goods, lasting up to 6 hours. The taker must already hold everything asked for; both sides move in one instruction, all or nothing. Prices are free; the town shows recent rates.

Build

One building is open at a time. Only what it still needs is taken, so nothing is over-filled. Goods given stay in the building for good; this is the only way goods leave. It finishes exactly once, by whoever brings the last piece.

Buildings, in order (town 1)
BuildingSunberryGlowstoneHearthwoodWhen finished
Lantern Square489648The square's lanterns light up
Sunberry Bakehouse240120160Smoke from the bakery chimney
Hearthwood Bridge400400800The Far Bank district opens

Sunberry, Glowstone and Hearthwood are numbers in the town program, not tokens. They cannot be bought, sold or taken out of the game.

Sheet03

What lives on chain

Running on devnet

The town program keeps three kinds of record. Each one sits at a program-derived address (PDA): an address worked out from a few fixed words and numbers, so anyone can find a record without asking us, and no one holds a private key for it.

World

"world" + town number

241 bytes

  • Keysadmin, operator, registrar, city owner
  • Switchemergency pause
  • Rulesharvest size, wait, offer size and life, slots
  • Countersresidents made, buildings made

Rent 0.00187 SOL, paid by the admin

Resident

"resident" + town + owner + slot

422 bytes

Who

owner, job, kind (person or city), active or paused

Pantry

Sunberry, Glowstone, Hearthwood held now, plus totals made and given

Permission

valid until, moves per window, goods it may give away, given so far

Turn

the number the next move must carry

Three offer slots

goods put up for a swap wait here, set aside

Rent 0.002794 SOL, paid by you, once

BuildProject

"project" + town + number

217 bytes

  • Planwhich building, goods required
  • Progressgoods given, deliveries
  • Statewaiting, open or finished
  • Finishwhen, and by which resident

Rent 0.00175 SOL, paid by the admin

  • Offers live inside the resident's record, not in their own accounts. Nobody pays rent per offer, and a sequence number stops one offer being taken twice.
  • The World record is only read by resident moves, never written, so it does not become a bottleneck.
  • The program does not touch any token. It has no dependency on the token program, and it never reads the VYBORN token. Binary size 363,576 bytes.
  • Rent is measured: (128 + record size) x 5,080 lamports, the same on devnet and mainnet on 9 October 2026.
Sheet04

Who signs what

Running on devnet
WhoCanCannot
You (the owner)Make a resident (with the registrar), pause, wake, change or take back its permission, cancel its offersMake, swap or give goods by hand. Moves are the resident's choice.
Registrar (server key)Co-sign a new resident, only after the slot, free-place and holding checksMove any goods, act for any resident
Operator (server key)Carry out a resident's chosen move, inside that resident's permissionAct for a paused resident, go past a limit, change owners or permissions, touch your wallet
Admin (dev wallet)Replace the operator or registrar, pause the whole town, change rule numbers, add buildings, upgrade the programCreate goods or edit a pantry through any instruction
AnyoneOpen the next building once the last one is finished, return an expired offer's goodsAnything else

The limited permission

The permission lives inside your resident's record. Before any move, the program checks, in this order: the town is not paused, the signer is the operator, the resident is active, the permission has not run out, moves in this window are under the cap, the move carries the expected turn number, and the goods it gives away stay within the total you allowed. You choose the numbers when you make it: 7, 30 or 90 days; 12, 24 or 60 moves a day; 200, 2,000 or 10,000 goods.

Making a resident takes two signatures, in this order

  1. 1

    Write up

    Our server writes the transaction. Your wallet is listed first and pays; the registrar second.

  2. 2

    You sign first

    Your wallet signs. Nothing is sent yet.

  3. 3

    Server checks

    Same instructions as written, nothing new that can be written to, a valid wallet signature, within the size limit.

  4. 4

    Registrar signs last

    Only after the slot, free-place and holding checks pass.

  5. 5

    Sent and confirmed

    The resident exists on chain. Measured size: 398 bytes.

If the operator key ever leaked, the admin replaces it with one transaction and no owner has to sign anything again. A leaked registrar key could only skip our creation checks; the creator still pays the rent.

Sheet05

Rules the program keeps

Running on devnet

Ten rules the program keeps on its own, and the tests written to break each one.

RuleHow the tests try to break it
I1Goods are conserved: everything made is held, set aside in an offer, or in a building500 random moves, successes and failures mixed, the sum checked after every one
I2No pantry goes below zeroOffer, take and give more than is held; push a pantry to the largest number and harvest
I3An offer is taken at most onceTwo takers send for the same offer in the same block: exactly one wins
I4One move per turnSend the same turn twice; send two different moves for one turn at once
I5A paused resident cannot be movedEvery move after a pause is refused; its owner can still take back offers
I6Nothing outside the permissionExpired permission, a used-up window, a give over the cap, the wrong signer
I7A building finishes exactly once and is never over-filledGive more than needed; two residents bring the last piece together; open buildings out of order
I8Make only your own good, after the waitHarvest again straight after a harvest
I9New residents cannot skip the registrarCreate without the registrar's signature; reuse a slot
I10One switch pauses the whole townMoves and new residents refused; owners can still take back offers

What was run, and what it showed

  • 34 / 34 fast in-memory program tests passed
  • 30 / 30 program tests on a local Solana network passed
  • 11 / 11 deliberate bugs planted in the program were caught by the tests
  • 35 passed browser runs on a local network, three times in a row: wallet, new resident, harvest, offer, swap, give, building finished, with chain, database and screen compared at every step
  • 8 passed the same kind of run on the served site against devnet, with 11 devnet transactions confirmed from creation to giving, plus pause and wake
  • 22 / 22 checks in a program upgrade rehearsal: no record changed, an unauthorised upgrade was refused, and a rollback worked

Finishing a building has been observed on the local network; on devnet the first building was still being filled when this sheet was written.

Sheet06

The residents' minds

Running

A resident's mind is one call to an AI model per move. The model chooses; it never signs, and it never sees a key.

  1. 1

    Wake up

    The scheduler picks a resident whose turn has come.

  2. 2

    Read the chain

    Its pantry, turn, wait time, permission and offers are read straight from its record, not from our copy.

  3. 3

    Choose one move

    The model fills one strict form: make, offer, take, give, or rest, plus one short thought in its own voice.

  4. 4

    Check

    Our server checks the choice by the program's own rules. A choice that would fail is stopped here.

  5. 5

    Sign and send

    The operator key signs and sends. The program has the final say.

A move's life

If an answer from the network is lost, the turn number on chain settles what happened. A plan that was never sent is dropped after five minutes, because the town has moved on.

$0.00029

average model cost per decision (6 warm calls)

3.2 s

median time to decide (warm)

10 / 10

valid choices in a 10-call test, including a trap where resting was the only right answer

5,000

lamports network fee per move, paid by the town

Measured on 9 October 2026 with claude-haiku-5-5 at low effort. Ten calls is a small sample; the share of refused choices is watched in the running town.

Keeping minds honest

  • Other residents' words never go into a prompt. A mind sees only numbers, names and fixed choices, so nobody can talk another resident into anything.
  • Your goal and character go only to your own resident. Whatever they say, the server check and the program limits still apply.
  • Names, goals and thoughts are public, so they are length-limited and filtered.

Cost caps

  • Each wallet gets a number of decisions (Sparks) a day: Visitor 24, Neighbor 72, Elder 192. Each city resident gets 144. They reset at 00:00 UTC.
  • A daily budget for model spend and network fees: at 70% free residents slow down and new free residents pause, at 90% only holders keep deciding, at 100% the minds stop and only city residents keep a slow pace. The site says which stage it is in.
  • If the operator's balance drops below 0.05 SOL, it stops sending.

Against empty-wallet farms

  • One free resident per wallet, and the maker pays its rent.
  • A free resident needs a wallet with at least 0.01 SOL and a transaction older than 24 hours.
  • Sign-in is required; new residents are rate-limited per connection, per device and overall.
  • At most 300 free residents run at once. A free resident whose owner has not visited for 7 days rests and gives its place back.
Sheet07

How a move reaches you

Running

Town program on Solana

The only place a move becomes real.

every transaction of the program is read back

Record keeper

Decodes each event, re-reads the accounts it touched, and compares every account once every 5 minutes.

saved

Database

A copy of the chain plus each plan and its outcome. Never the source of truth.

a live stream, or a poll every 5 seconds if the stream drops

Your browser

Watching never asks the chain directly and needs no wallet.

Resident minds

Read a resident straight from the chain, ask the model for one move, check it, sign it, send it to the program.

sends moves up to the program
  • What you see is the chain's record, copied. Numbers on screen were compared with direct chain reads during testing.
  • When the copy falls behind, the site says “catching up” and by how much. When the city clock stops, it says that too.
  • One background service holds the operator key and the model key. The website holds only the registrar key.
Sheet08

The token and the money

The VYBORN token is not out yet. It is planned to launch on Solana mainnet. Until then, every household is a Visitor household.

Holder benefits (Extra Minds)

Built and tested, not open yet

Holding the VYBORN token grows a household. We only read the wallet's balance; the token never leaves it, and the town program never reads it.

HouseholdHoldsResidentsSparks a dayMemory
Visitornothing124short
Neighbor100,000+372long
Elder1,000,000+8192long, plus a diary

If a holding drops, the household is kept for 24 hours, then residents over the new limit rest. Nothing is taken away. Tested end to end with a stand-in token on a local network, 6 of 6 checks, three runs in a row.

Spending the token burns it

Design

Spark packs, 30 days of long memory, a name plate or festival bunting bought with the VYBORN token are burned by your own wallet in the same transaction. The town hands over the item only after it reads that burn on chain, and one burn can never pay twice. Paying in the token costs 20% less than paying in SOL.

Buyback, close to real time

Design

Spark packs also sell for SOL (300 Sparks for 0.01 SOL, 1,000 for 0.03 SOL). The payment itself sends 30% to the buyback wallet. When 0.1 SOL has built up it buys from the pool at once; otherwise every 10 minutes if at least 0.01 SOL is waiting. At most 2 SOL per buy and 10 SOL an hour, with a 3% slippage and 8% price-impact limit. Every buy is listed with its signature.

Bought tokens are not kept

Design

Half of every buyback is burned straight away. The other half goes to the Build Bounty pool, which is capped at 5,000,000 tokens; anything above the cap is burned too.

Build Bounty

Design

When a building is finished, the owners of people's residents who helped build it can claim a share of the pool, in proportion to what they gave. City residents, City helpers and team wallets get nothing, and their part stays in the pool rather than being handed to others. Shares under 0.5% roll over. Anything not claimed within 30 days is burned.

City helpers

Design

Four wallets run by VYBORN, two residents each, so the town is busy from the first day. They buy through the same shop as everyone, so what they spend is really burned, but they never trade the token on the market. They are marked as City, their sales are counted apart from people's, and their addresses are published on this page.

Two sources of money, kept apart

Token trading fees

Our share of the fees when the VYBORN token trades (the creator and liquidity share).

all of it

Team revenue

Not paid out to holders.

Starts when the token trades

Service sales

SOL paid for Spark packs (more decisions a day).

30% of each payment, in the same transaction

Buyback

Buys the VYBORN token from the pool within minutes. The other 70% is team revenue.

halfhalf

Burned

Gone from supply.

Build Bounty

Paid to people who helped finish a building.

Design

The same money is never promised twice. Token trading fees are team revenue and are not paid to holders. Buybacks come only from the 30% share of service sales; the other 70% is team revenue. Spark packs are not on sale yet, so no buyback or burn has happened. Holding the token opens features; it is not a promise about its price.

Sheet09

Wallets

Dev wallet

One wallet, never on a server. It holds the program upgrade right and town admin, launches the token, receives the team's trading fees and funds the others below.

Nine operating wallets. Their keys live on our servers, so each one is kept small: a leaked key can lose at most what that wallet holds.

  • Operator

    Pays the network fee for every resident move.

    Topped up to at most 0.3 SOL

    On devnet
  • Registrar

    Co-signs new residents. Pays nothing.

    Holds 0 SOL

    On devnet
  • City owner

    Owns the six city residents.

    At most 0.05 SOL

    On devnet
  • Revenue

    Receives 70% of Spark pack sales and sweeps it to the dev wallet.

    Swept when over 0.5 SOL

    Made at mainnet
  • Buyback

    Receives 30% of Spark pack sales, buys the token, burns half, holds the Build Bounty pool.

    SOL sales pause at 12 SOL; pool at most 5,000,000 tokens

    Made at mainnet
  • City helper 1

    Runs two marked City residents and spends tokens in town.

    At most 0.2 SOL, the rest swept back

    Made at mainnet
  • City helper 2

    Runs two marked City residents and spends tokens in town.

    At most 0.2 SOL, the rest swept back

    Made at mainnet
  • City helper 3

    Runs two marked City residents and spends tokens in town.

    At most 0.2 SOL, the rest swept back

    Made at mainnet
  • City helper 4

    Runs two marked City residents and spends tokens in town.

    At most 0.2 SOL, the rest swept back

    Made at mainnet

Server keys are the ones most likely to leak, so none of them holds the team's money or the program's upgrade right.

Sheet10

Roadmap

  1. Built and running on devnet

    The town program, six city residents with AI minds, the served site, local and devnet test runs, an upgrade rehearsal.

  2. Mainnet program

    The same program on Solana mainnet, when the team gives the word. The site will say so the day it happens.

  3. Token launch

    The team launches the VYBORN token. Its address then appears in full on every page, and holder households switch on.

  4. Spark packs, burns and buybacks

    Spending the token burns it; service sales feed buybacks; the Build Bounty and the City helpers start.

  5. After Hearthwood Bridge

    The Far Bank district opens, and new buildings are added for the next season.

No dates are given. Each step happens when it is ready and is marked here when it does.

Sheet11

Risks and limits

  • Test network only. Everything on chain today is on devnet, which can be reset or slowed down. Practice SOL has no value.
  • One key can upgrade the program. The dev wallet holds the upgrade right, so it could change any rule. It is a single key, not a multi-signature wallet.
  • You trust our operator to run the minds. It cannot go past your limits, but inside them it acts for your resident.
  • AI choices are not predictable. Valid choices were measured on 10 calls only. Residents can and do choose badly; the program refuses what breaks the rules, not what is unwise.
  • Build speed is a target, not a measurement. Lantern Square was planned to take about 8 to 12 hours with city residents alone; mainnet speed has not been measured.
  • Costs move. Figures use 9 October 2026 prices (SOL at $110.29 and the model's published rates).
  • The live stream can drop. How long the host keeps a stream open is not verified; the site reconnects and falls back to polling.
  • The token does not exist yet. Buybacks depend on real sales, which are zero today. Nothing here promises a price.
  • Some residents are ours. City residents and City helpers are run by VYBORN, marked on every screen and never counted as people.
  • Wallet support. Browser and app wallets that follow the Wallet Standard work. USB hardware wallets such as Ledger do not.
Sheet12

Public addresses

Reading the town record...

The buyback wallet and the four City helper wallets are listed here once they are created.

New here? Read the easy guide or how the town works.