Concepts

The Subscriptions program

The Solana program behind Fianto subscriptions, what it checks on every charge, how plans are created, and the payer's shared USDC approval.

3 min read

Fianto subscriptions run on the Solana Subscriptions program, at De1egAFMkMWZSN5rYXRj9CAdheBamobVNubTsi9avR44. The program, not Fianto, holds each subscription's terms and checks every charge against them. Fianto's charging key can take a renewal only within what the program allows.

Plans

Each recurring price gets a plan on Solana. A plan holds:

  • the amount per period, the mint (USDC) and the period, 30 or 365 days;
  • the destinations: your receiving wallet and, when the fee is above zero, Fianto's treasury;
  • the pullers: the keys allowed to take a charge, which are Fianto's charging keys;
  • no end date.

The amount, the mint, the period and the destinations can never change once the plan exists. Only the list of pullers can be edited.

Fianto creates a plan lazily: the first subscription session your server creates for a price starts it. Fianto's plan-owner key signs the plan's transaction and pays its rent. Until the plan is on chain, the hosted checkout page shows the plan as preparing, with no pay button. Fianto retries a failed creation after 30 seconds, 2 minutes, 10 minutes and 1 hour, then marks the plan failed, and the checkout page refuses the session with subscription_plan_failed. The next subscription session for the price starts a fresh plan. Fianto creates at most 50 new plans per merchant in any 24 hours.

A plan belongs to one price, one receiving wallet, one fee and one treasury. When your wallet or the fee changes, the next subscription session for the price gets a new plan. New subscribers pay into the new plan; existing subscribers keep the old one, with the old wallet and the old fee.

Subscribing

What the subscribe transaction contains
The instructions in the subscribe transaction, who signs it and who paysone transaction, in this order1Set compute budget2Create USDC authorityonly when the wallet has none3Subscribebound to the plan's terms4Pull price → merchant's walletcarries the session reference5Pull service fee → Fianto's treasuryonly when the fee is above zerodashed: only sometimes included · the first period is charged herewho signspayer's walletFianto's charging keyco-signswho payspayernetwork fee + both rentsFianto's charging keynothingrent is read from Solanaat subscribe time

Scroll sideways to see the whole diagram →

Show as text
  1. Set the compute budget.
  2. Create the payer's USDC authority, only when the wallet has none.
  3. Subscribe, bound to the plan's terms.
  4. Pull the price to the merchant's wallet; this pull carries the session reference.
  5. Pull the service fee to Fianto's treasury, only when the fee is above zero.
  6. The first period is charged inside this transaction.
  7. The payer's wallet signs and is the fee payer: the payer pays the network fee and both rents (the subscription's and, when it is created, the USDC authority's).
  8. Fianto's charging key co-signs and pays nothing.
  9. The rent is read from Solana at subscribe time.

The payer signs one subscribe transaction. It creates the payer's USDC authority when the wallet has none, subscribes the wallet to the plan, which binds the plan's terms to the subscription, and pulls the first period: the price to your wallet and, when it is above zero, the service fee to the treasury.

Who pays for the subscribe transaction

The payer is the fee payer. The payer pays the network fee and the rent for the subscription's account and, when this transaction creates it, for the USDC authority. The rent is read from Solana at subscribe time. Fianto's charging key co-signs and pays nothing.

After that, Fianto's charging key signs each renewal and pays its network fee. See Subscription lifecycle for when renewals happen.

What the program checks

The program refuses:

  • a signer that is not on the plan's puller list;
  • a transfer to anywhere but the plan's destinations;
  • more than the plan amount in one period;
  • any charge after the subscription is cancelled or has expired;
  • a charge on a plan that is sunset or expired;
  • terms that differ from the ones bound when the payer subscribed;
  • a USDC authority that is stale.

So even Fianto cannot take more than the subscription's own terms allow, or send it anywhere else.

The shared USDC approval

To let the program take renewals, the payer's wallet approves it to move USDC. That approval is shared: there is one per wallet and mint, used by every Subscriptions-program subscription that wallet holds, in every shop, Fianto's or not. It is approved for the largest possible amount (u64::MAX), so a wallet may show it with no amount limit. What limits Fianto is each subscription's own terms on Solana, checked by the program as above.

Do not tell payers to touch the shared approval

Never tell a payer to close or revoke the shared approval to stop one subscription. It affects every subscription on that wallet, not just one, and it is not how a subscription is cancelled. To stop one subscription, the payer cancels that subscription, or asks the shop.

A payer whose approval stopped letting Fianto take a payment can renew it from the payer portal. That re-enables every subscription that uses the approval. See Failed renewals.

See also

Was this page helpful? Tell us

On this page