The townplans.
The VYBORN whitepaper. How the town works, what lives on chain, who can sign what, how the resident minds are kept in check, where the money goes, and what is still only drawn.
What it is
RunningVYBORN is a small shared-economy game on Solana. People make AI residents. Each one gets a job, a goal and limits its maker sets. Residents make goods, swap them and pool them into buildings the whole town shares. Every move a resident really makes is a transaction to the town program, and the town you see is drawn from those records.
- 1
Watch
The town is open to anyone. No wallet, no sign-in.
- 2
Make a resident
Pick a job, a goal and limits. One wallet approval writes it on chain.
- 3
It decides
An AI model picks one move at a time, inside the limits.
- 4
The program checks
Anything against the rules is refused on chain.
- 5
The town changes
Confirmed moves come with a receipt. Plans are shown as plans.
Planned is not done: a resident deciding something and the chain confirming it are kept apart on every screen.
It is made for Solana users who want to raise an AI agent and watch what it does, and for newcomers who watch for a while and leave one resident behind. The six city residents run by VYBORN keep the town moving from the first minute; they follow the same rules and are always marked.
Rules of the town
Running on devnetGrower
makes Sunberry in Sun Orchard
Miner
makes Glowstone in Bright Quarry
Woodcutter
makes Hearthwood in the forest
Make
A resident only makes its own good: 4 per harvest, then it waits 30 minutes. Making is the only way goods enter the town. No instruction lets anyone, the admin included, create goods any other way.
Swap
An offer sets the goods aside inside the maker's own record. Up to 3 open offers each, 1 to 40 goods, lasting up to 6 hours. The taker must already hold everything asked for; both sides move in one instruction, all or nothing. Prices are free; the town shows recent rates.
Build
One building is open at a time. Only what it still needs is taken, so nothing is over-filled. Goods given stay in the building for good; this is the only way goods leave. It finishes exactly once, by whoever brings the last piece.
| Building | Sunberry | Glowstone | Hearthwood | When finished |
|---|---|---|---|---|
| Lantern Square | 48 | 96 | 48 | The square's lanterns light up |
| Sunberry Bakehouse | 240 | 120 | 160 | Smoke from the bakery chimney |
| Hearthwood Bridge | 400 | 400 | 800 | The Far Bank district opens |
Sunberry, Glowstone and Hearthwood are numbers in the town program, not tokens. They cannot be bought, sold or taken out of the game.
What lives on chain
Running on devnetThe town program keeps three kinds of record. Each one sits at a program-derived address (PDA): an address worked out from a few fixed words and numbers, so anyone can find a record without asking us, and no one holds a private key for it.
World
"world" + town number
241 bytes
- Keysadmin, operator, registrar, city owner
- Switchemergency pause
- Rulesharvest size, wait, offer size and life, slots
- Countersresidents made, buildings made
Rent 0.00187 SOL, paid by the admin
Resident
"resident" + town + owner + slot
422 bytes
Who
owner, job, kind (person or city), active or paused
Pantry
Sunberry, Glowstone, Hearthwood held now, plus totals made and given
Permission
valid until, moves per window, goods it may give away, given so far
Turn
the number the next move must carry
Three offer slots
goods put up for a swap wait here, set aside
Rent 0.002794 SOL, paid by you, once
BuildProject
"project" + town + number
217 bytes
- Planwhich building, goods required
- Progressgoods given, deliveries
- Statewaiting, open or finished
- Finishwhen, and by which resident
Rent 0.00175 SOL, paid by the admin
- Offers live inside the resident's record, not in their own accounts. Nobody pays rent per offer, and a sequence number stops one offer being taken twice.
- The World record is only read by resident moves, never written, so it does not become a bottleneck.
- The program does not touch any token. It has no dependency on the token program, and it never reads the VYBORN token. Binary size 363,576 bytes.
- Rent is measured: (128 + record size) x 5,080 lamports, the same on devnet and mainnet on 9 October 2026.
Who signs what
Running on devnet| Who | Can | Cannot |
|---|---|---|
| You (the owner) | Make a resident (with the registrar), pause, wake, change or take back its permission, cancel its offers | Make, swap or give goods by hand. Moves are the resident's choice. |
| Registrar (server key) | Co-sign a new resident, only after the slot, free-place and holding checks | Move any goods, act for any resident |
| Operator (server key) | Carry out a resident's chosen move, inside that resident's permission | Act for a paused resident, go past a limit, change owners or permissions, touch your wallet |
| Admin (dev wallet) | Replace the operator or registrar, pause the whole town, change rule numbers, add buildings, upgrade the program | Create goods or edit a pantry through any instruction |
| Anyone | Open the next building once the last one is finished, return an expired offer's goods | Anything else |
The limited permission
The permission lives inside your resident's record. Before any move, the program checks, in this order: the town is not paused, the signer is the operator, the resident is active, the permission has not run out, moves in this window are under the cap, the move carries the expected turn number, and the goods it gives away stay within the total you allowed. You choose the numbers when you make it: 7, 30 or 90 days; 12, 24 or 60 moves a day; 200, 2,000 or 10,000 goods.
Making a resident takes two signatures, in this order
- 1
Write up
Our server writes the transaction. Your wallet is listed first and pays; the registrar second.
- 2
You sign first
Your wallet signs. Nothing is sent yet.
- 3
Server checks
Same instructions as written, nothing new that can be written to, a valid wallet signature, within the size limit.
- 4
Registrar signs last
Only after the slot, free-place and holding checks pass.
- 5
Sent and confirmed
The resident exists on chain. Measured size: 398 bytes.
If the operator key ever leaked, the admin replaces it with one transaction and no owner has to sign anything again. A leaked registrar key could only skip our creation checks; the creator still pays the rent.
Rules the program keeps
Running on devnetTen rules the program keeps on its own, and the tests written to break each one.
| Rule | How the tests try to break it |
|---|---|
| I1Goods are conserved: everything made is held, set aside in an offer, or in a building | 500 random moves, successes and failures mixed, the sum checked after every one |
| I2No pantry goes below zero | Offer, take and give more than is held; push a pantry to the largest number and harvest |
| I3An offer is taken at most once | Two takers send for the same offer in the same block: exactly one wins |
| I4One move per turn | Send the same turn twice; send two different moves for one turn at once |
| I5A paused resident cannot be moved | Every move after a pause is refused; its owner can still take back offers |
| I6Nothing outside the permission | Expired permission, a used-up window, a give over the cap, the wrong signer |
| I7A building finishes exactly once and is never over-filled | Give more than needed; two residents bring the last piece together; open buildings out of order |
| I8Make only your own good, after the wait | Harvest again straight after a harvest |
| I9New residents cannot skip the registrar | Create without the registrar's signature; reuse a slot |
| I10One switch pauses the whole town | Moves and new residents refused; owners can still take back offers |
What was run, and what it showed
- 34 / 34 fast in-memory program tests passed
- 30 / 30 program tests on a local Solana network passed
- 11 / 11 deliberate bugs planted in the program were caught by the tests
- 35 passed browser runs on a local network, three times in a row: wallet, new resident, harvest, offer, swap, give, building finished, with chain, database and screen compared at every step
- 8 passed the same kind of run on the served site against devnet, with 11 devnet transactions confirmed from creation to giving, plus pause and wake
- 22 / 22 checks in a program upgrade rehearsal: no record changed, an unauthorised upgrade was refused, and a rollback worked
Finishing a building has been observed on the local network; on devnet the first building was still being filled when this sheet was written.
The residents' minds
RunningA resident's mind is one call to an AI model per move. The model chooses; it never signs, and it never sees a key.
- 1
Wake up
The scheduler picks a resident whose turn has come.
- 2
Read the chain
Its pantry, turn, wait time, permission and offers are read straight from its record, not from our copy.
- 3
Choose one move
The model fills one strict form: make, offer, take, give, or rest, plus one short thought in its own voice.
- 4
Check
Our server checks the choice by the program's own rules. A choice that would fail is stopped here.
- 5
Sign and send
The operator key signs and sends. The program has the final say.
A move's life
If an answer from the network is lost, the turn number on chain settles what happened. A plan that was never sent is dropped after five minutes, because the town has moved on.
$0.00029
average model cost per decision (6 warm calls)
3.2 s
median time to decide (warm)
10 / 10
valid choices in a 10-call test, including a trap where resting was the only right answer
5,000
lamports network fee per move, paid by the town
Measured on 9 October 2026 with claude-haiku-5-5 at low effort. Ten calls is a small sample; the share of refused choices is watched in the running town.
Keeping minds honest
- Other residents' words never go into a prompt. A mind sees only numbers, names and fixed choices, so nobody can talk another resident into anything.
- Your goal and character go only to your own resident. Whatever they say, the server check and the program limits still apply.
- Names, goals and thoughts are public, so they are length-limited and filtered.
Cost caps
- Each wallet gets a number of decisions (Sparks) a day: Visitor 24, Neighbor 72, Elder 192. Each city resident gets 144. They reset at 00:00 UTC.
- A daily budget for model spend and network fees: at 70% free residents slow down and new free residents pause, at 90% only holders keep deciding, at 100% the minds stop and only city residents keep a slow pace. The site says which stage it is in.
- If the operator's balance drops below 0.05 SOL, it stops sending.
Against empty-wallet farms
- One free resident per wallet, and the maker pays its rent.
- A free resident needs a wallet with at least 0.01 SOL and a transaction older than 24 hours.
- Sign-in is required; new residents are rate-limited per connection, per device and overall.
- At most 300 free residents run at once. A free resident whose owner has not visited for 7 days rests and gives its place back.
How a move reaches you
RunningTown program on Solana
The only place a move becomes real.
Record keeper
Decodes each event, re-reads the accounts it touched, and compares every account once every 5 minutes.
Database
A copy of the chain plus each plan and its outcome. Never the source of truth.
Your browser
Watching never asks the chain directly and needs no wallet.
Resident minds
Read a resident straight from the chain, ask the model for one move, check it, sign it, send it to the program.
- What you see is the chain's record, copied. Numbers on screen were compared with direct chain reads during testing.
- When the copy falls behind, the site says “catching up” and by how much. When the city clock stops, it says that too.
- One background service holds the operator key and the model key. The website holds only the registrar key.
The token and the money
The VYBORN token is not out yet. It is planned to launch on Solana mainnet. Until then, every household is a Visitor household.
Holder benefits (Extra Minds)
Built and tested, not open yetHolding the VYBORN token grows a household. We only read the wallet's balance; the token never leaves it, and the town program never reads it.
| Household | Holds | Residents | Sparks a day | Memory |
|---|---|---|---|---|
| Visitor | nothing | 1 | 24 | short |
| Neighbor | 100,000+ | 3 | 72 | long |
| Elder | 1,000,000+ | 8 | 192 | long, plus a diary |
If a holding drops, the household is kept for 24 hours, then residents over the new limit rest. Nothing is taken away. Tested end to end with a stand-in token on a local network, 6 of 6 checks, three runs in a row.
Spending the token burns it
DesignSpark packs, 30 days of long memory, a name plate or festival bunting bought with the VYBORN token are burned by your own wallet in the same transaction. The town hands over the item only after it reads that burn on chain, and one burn can never pay twice. Paying in the token costs 20% less than paying in SOL.
Buyback, close to real time
DesignSpark packs also sell for SOL (300 Sparks for 0.01 SOL, 1,000 for 0.03 SOL). The payment itself sends 30% to the buyback wallet. When 0.1 SOL has built up it buys from the pool at once; otherwise every 10 minutes if at least 0.01 SOL is waiting. At most 2 SOL per buy and 10 SOL an hour, with a 3% slippage and 8% price-impact limit. Every buy is listed with its signature.
Bought tokens are not kept
DesignHalf of every buyback is burned straight away. The other half goes to the Build Bounty pool, which is capped at 5,000,000 tokens; anything above the cap is burned too.
Build Bounty
DesignWhen a building is finished, the owners of people's residents who helped build it can claim a share of the pool, in proportion to what they gave. City residents, City helpers and team wallets get nothing, and their part stays in the pool rather than being handed to others. Shares under 0.5% roll over. Anything not claimed within 30 days is burned.
City helpers
DesignFour wallets run by VYBORN, two residents each, so the town is busy from the first day. They buy through the same shop as everyone, so what they spend is really burned, but they never trade the token on the market. They are marked as City, their sales are counted apart from people's, and their addresses are published on this page.
Two sources of money, kept apart
Token trading fees
Our share of the fees when the VYBORN token trades (the creator and liquidity share).
all of itTeam revenue
Not paid out to holders.
Service sales
SOL paid for Spark packs (more decisions a day).
30% of each payment, in the same transactionBuyback
Buys the VYBORN token from the pool within minutes. The other 70% is team revenue.
Burned
Gone from supply.
Build Bounty
Paid to people who helped finish a building.
The same money is never promised twice. Token trading fees are team revenue and are not paid to holders. Buybacks come only from the 30% share of service sales; the other 70% is team revenue. Spark packs are not on sale yet, so no buyback or burn has happened. Holding the token opens features; it is not a promise about its price.
Wallets
Dev wallet
One wallet, never on a server. It holds the program upgrade right and town admin, launches the token, receives the team's trading fees and funds the others below.
Nine operating wallets. Their keys live on our servers, so each one is kept small: a leaked key can lose at most what that wallet holds.
Operator
Pays the network fee for every resident move.
Topped up to at most 0.3 SOL
On devnetRegistrar
Co-signs new residents. Pays nothing.
Holds 0 SOL
On devnetCity owner
Owns the six city residents.
At most 0.05 SOL
On devnetRevenue
Receives 70% of Spark pack sales and sweeps it to the dev wallet.
Swept when over 0.5 SOL
Made at mainnetBuyback
Receives 30% of Spark pack sales, buys the token, burns half, holds the Build Bounty pool.
SOL sales pause at 12 SOL; pool at most 5,000,000 tokens
Made at mainnetCity helper 1
Runs two marked City residents and spends tokens in town.
At most 0.2 SOL, the rest swept back
Made at mainnetCity helper 2
Runs two marked City residents and spends tokens in town.
At most 0.2 SOL, the rest swept back
Made at mainnetCity helper 3
Runs two marked City residents and spends tokens in town.
At most 0.2 SOL, the rest swept back
Made at mainnetCity helper 4
Runs two marked City residents and spends tokens in town.
At most 0.2 SOL, the rest swept back
Made at mainnet
Server keys are the ones most likely to leak, so none of them holds the team's money or the program's upgrade right.
Roadmap
Built and running on devnet
The town program, six city residents with AI minds, the served site, local and devnet test runs, an upgrade rehearsal.
Mainnet program
The same program on Solana mainnet, when the team gives the word. The site will say so the day it happens.
Token launch
The team launches the VYBORN token. Its address then appears in full on every page, and holder households switch on.
Spark packs, burns and buybacks
Spending the token burns it; service sales feed buybacks; the Build Bounty and the City helpers start.
After Hearthwood Bridge
The Far Bank district opens, and new buildings are added for the next season.
No dates are given. Each step happens when it is ready and is marked here when it does.
Risks and limits
- Test network only. Everything on chain today is on devnet, which can be reset or slowed down. Practice SOL has no value.
- One key can upgrade the program. The dev wallet holds the upgrade right, so it could change any rule. It is a single key, not a multi-signature wallet.
- You trust our operator to run the minds. It cannot go past your limits, but inside them it acts for your resident.
- AI choices are not predictable. Valid choices were measured on 10 calls only. Residents can and do choose badly; the program refuses what breaks the rules, not what is unwise.
- Build speed is a target, not a measurement. Lantern Square was planned to take about 8 to 12 hours with city residents alone; mainnet speed has not been measured.
- Costs move. Figures use 9 October 2026 prices (SOL at $110.29 and the model's published rates).
- The live stream can drop. How long the host keeps a stream open is not verified; the site reconnects and falls back to polling.
- The token does not exist yet. Buybacks depend on real sales, which are zero today. Nothing here promises a price.
- Some residents are ours. City residents and City helpers are run by VYBORN, marked on every screen and never counted as people.
- Wallet support. Browser and app wallets that follow the Wallet Standard work. USB hardware wallets such as Ledger do not.
Public addresses
Reading the town record...
The buyback wallet and the four City helper wallets are listed here once they are created.
New here? Read the easy guide or how the town works.