Concepts
The Subscriptions program
The Solana program behind Fianto subscriptions, what it checks on every charge, how plans are created, and the payer's shared USDC approval.
Fianto subscriptions run on the Solana Subscriptions program, at
De1egAFMkMWZSN5rYXRj9CAdheBamobVNubTsi9avR44. The program, not Fianto, holds each subscription's
terms and checks every charge against them. Fianto's charging key can take a renewal only within
what the program allows.
Plans
Each recurring price gets a plan on Solana. A plan holds:
- the amount per period, the mint (USDC) and the period, 30 or 365 days;
- the destinations: your receiving wallet and, when the fee is above zero, Fianto's treasury;
- the pullers: the keys allowed to take a charge, which are Fianto's charging keys;
- no end date.
The amount, the mint, the period and the destinations can never change once the plan exists. Only the list of pullers can be edited.
Fianto creates a plan lazily: the first subscription session your server creates for a price starts
it. Fianto's plan-owner key signs the plan's transaction and pays its rent. Until the plan is on
chain, the hosted checkout page shows the plan as preparing, with no pay button. Fianto retries a
failed creation after 30 seconds, 2 minutes, 10 minutes and 1 hour, then marks the plan failed, and
the checkout page refuses the session with subscription_plan_failed. The next subscription session
for the price starts a fresh plan. Fianto creates at most 50 new plans per
merchant in any 24 hours.
A plan belongs to one price, one receiving wallet, one fee and one treasury. When your wallet or the fee changes, the next subscription session for the price gets a new plan. New subscribers pay into the new plan; existing subscribers keep the old one, with the old wallet and the old fee.
Subscribing
Scroll sideways to see the whole diagram →
Show as text
- Set the compute budget.
- Create the payer's USDC authority, only when the wallet has none.
- Subscribe, bound to the plan's terms.
- Pull the price to the merchant's wallet; this pull carries the session reference.
- Pull the service fee to Fianto's treasury, only when the fee is above zero.
- The first period is charged inside this transaction.
- The payer's wallet signs and is the fee payer: the payer pays the network fee and both rents (the subscription's and, when it is created, the USDC authority's).
- Fianto's charging key co-signs and pays nothing.
- The rent is read from Solana at subscribe time.
The payer signs one subscribe transaction. It creates the payer's USDC authority when the wallet has none, subscribes the wallet to the plan, which binds the plan's terms to the subscription, and pulls the first period: the price to your wallet and, when it is above zero, the service fee to the treasury.
Who pays for the subscribe transaction
The payer is the fee payer. The payer pays the network fee and the rent for the subscription's account and, when this transaction creates it, for the USDC authority. The rent is read from Solana at subscribe time. Fianto's charging key co-signs and pays nothing.
After that, Fianto's charging key signs each renewal and pays its network fee. See Subscription lifecycle for when renewals happen.
What the program checks
The program refuses:
- a signer that is not on the plan's puller list;
- a transfer to anywhere but the plan's destinations;
- more than the plan amount in one period;
- any charge after the subscription is cancelled or has expired;
- a charge on a plan that is sunset or expired;
- terms that differ from the ones bound when the payer subscribed;
- a USDC authority that is stale.
So even Fianto cannot take more than the subscription's own terms allow, or send it anywhere else.
The shared USDC approval
To let the program take renewals, the payer's wallet approves it to move USDC. That approval is
shared: there is one per wallet and mint, used by every Subscriptions-program subscription that
wallet holds, in every shop, Fianto's or not. It is approved for the largest possible amount
(u64::MAX), so a wallet may show it with no amount limit. What limits Fianto is each subscription's own
terms on Solana, checked by the program as above.
Do not tell payers to touch the shared approval
Never tell a payer to close or revoke the shared approval to stop one subscription. It affects every subscription on that wallet, not just one, and it is not how a subscription is cancelled. To stop one subscription, the payer cancels that subscription, or asks the shop.
A payer whose approval stopped letting Fianto take a payment can renew it from the payer portal. That re-enables every subscription that uses the approval. See Failed renewals.
See also
Was this page helpful? Tell us