# The Subscriptions program (/concepts/subscriptions-program)

Fianto subscriptions run on the Solana Subscriptions program, at
`De1egAFMkMWZSN5rYXRj9CAdheBamobVNubTsi9avR44`. The program, not Fianto, holds each subscription's
terms and checks every charge against them. Fianto's charging key can take a renewal only within
what the program allows.

## Plans [#plans]

Each recurring price gets a **plan** on Solana. A plan holds:

* the **amount** per period, the **mint** (USDC) and the **period**, 30 or 365 days;
* the **destinations**: your receiving wallet and, when the fee is above zero, Fianto's treasury;
* the **pullers**: the keys allowed to take a charge, which are Fianto's charging keys;
* no end date.

The amount, the mint, the period and the destinations can never change once the plan exists. Only
the list of pullers can be edited.

Fianto creates a plan lazily: the first subscription session your server creates for a price starts
it. Fianto's plan-owner key signs the plan's transaction and pays its rent. Until the plan is on
chain, the hosted checkout page shows the plan as preparing, with no pay button. Fianto retries a
failed creation after 30 seconds, 2 minutes, 10 minutes and 1 hour, then marks the plan failed, and
the checkout page refuses the session with `subscription_plan_failed`. The next subscription session
for the price starts a fresh plan. Fianto creates at most 50 new plans per
merchant in any 24 hours.

A plan belongs to one price, one receiving wallet, one fee and one treasury. When your wallet or the
fee changes, the next subscription session for the price gets a new plan. New subscribers pay into
the new plan; existing subscribers keep the old one, with the old wallet and the old fee.

## Subscribing [#subscribing]

**What the subscribe transaction contains**

1. Set the compute budget.
2. Create the payer's USDC authority, only when the wallet has none.
3. Subscribe, bound to the plan's terms.
4. Pull the price to the merchant's wallet; this pull carries the session reference.
5. Pull the service fee to Fianto's treasury, only when the fee is above zero.
6. The first period is charged inside this transaction.
7. The payer's wallet signs and is the fee payer: the payer pays the network fee and both rents (the subscription's and, when it is created, the USDC authority's).
8. Fianto's charging key co-signs and pays nothing.
9. The rent is read from Solana at subscribe time.

The payer signs one subscribe transaction. It creates the payer's USDC authority when the wallet has
none, subscribes the wallet to the plan, which binds the plan's terms to the subscription, and pulls
the first period: the price to your wallet and, when it is above zero, the service fee to the
treasury.

> **Who pays for the subscribe transaction:**
>
> The payer is the fee payer. The payer pays the network fee and the rent for the subscription's
> account and, when this transaction creates it, for the USDC authority. The rent is read from Solana
> at subscribe time. Fianto's charging key co-signs and pays nothing.

After that, Fianto's charging key signs each renewal and pays its network fee. See
[Subscription lifecycle](/concepts/subscription-lifecycle) for when renewals happen.

## What the program checks [#what-the-program-checks]

The program refuses:

* a signer that is not on the plan's puller list;
* a transfer to anywhere but the plan's destinations;
* more than the plan amount in one period;
* any charge after the subscription is cancelled or has expired;
* a charge on a plan that is sunset or expired;
* terms that differ from the ones bound when the payer subscribed;
* a USDC authority that is stale.

So even Fianto cannot take more than the subscription's own terms allow, or send it anywhere else.

## The shared USDC approval [#the-shared-usdc-approval]

To let the program take renewals, the payer's wallet approves it to move USDC. That approval is
**shared**: there is one per wallet and mint, used by every Subscriptions-program subscription that
wallet holds, in every shop, Fianto's or not. It is approved for the largest possible amount
(`u64::MAX`), so a wallet may show it with no amount limit. What limits Fianto is each subscription's own
terms on Solana, checked by the program as above.

> **Do not tell payers to touch the shared approval:**
>
> Never tell a payer to close or revoke the shared approval to stop one subscription. It affects
> every subscription on that wallet, not just one, and it is not how a subscription is cancelled. To
> stop one subscription, the payer cancels that subscription, or asks the shop.

A payer whose approval stopped letting Fianto take a payment can renew it from the payer portal.
That re-enables every subscription that uses the approval. See
[Failed renewals](/payers/failed-renewals).

## See also [#see-also]

- [Subscription lifecycle](/concepts/subscription-lifecycle): Renewals, past due, cancels and end reasons.

- [Subscriptions for developers](/developers/subscriptions): Create subscription sessions and follow them.

- [Cancel a subscription](/payers/cancel-a-subscription): How a payer cancels, and why not through the approval.

- [Fees](/concepts/fees): The service fee a plan carries.