Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Jetty

Live Demo:https://jetty-sol.vercel.app/Documentation Hub:https://jetty-sol.vercel.app/docs

An open-source, no-code compliance layer for Token-2022 Transfer Hooks on Solana.

Jetty is designed to demonstrate how developers and issuers can enforce modular, on-chain compliance policies without writing a single line of custom Rust. By attaching the Jetty Program to your Token-2022 Transfer Hook, you gain a zero-code compliance dashboard to manage your token's rules.

Disclaimer:Jetty is currently an unaudited MVP. It is designed as a proof-of-concept and should not be used in production with high-value assets until a formal security audit has been completed.


The Vision

Token-2022 introduced Transfer Hooks, but the barrier to entry for issuers to actually write, audit, and deploy custom Rust hooks is extremely high. Jetty was built to abstract this complexity.

The MVP ships with a comprehensive suite of core compliance modules — Global Pause, Allowlist, Denylist, Volume Limits, Anti-Dust, Receiver Cap, Velocity Limiter, and Vesting / Lockup — all built on a single, modular execution pattern. The vision for Jetty is to be the place issuers come to manage their transfer hook needs, instead of writing and maintaining that logic themselves. Easy controls, vetted modules, and one dashboard — so compliance rules can be configured and trusted with confidence, without the overhead of running custom infrastructure.


Core Modules

Every SPL Token-2022 transfer is atomically intercepted by Jetty and evaluated against the issuer's active policy on-chain.

ModuleUse CaseMechanism
Global PauseExploit mitigation, migrationInstantly freeze all token transfers across the entire network.
AllowlistPermissioned trading, OFAC complianceRestricts transfers strictly to pre-approved wallets.
DenylistExploit mitigationBlock explicitly flagged wallets from transferring tokens.
Volume LimitsAnti-whale, bot protectionSet a maximum ceiling for any single transaction.
Anti-DustSpam protectionSet a minimum transfer size to prevent dust attacks.
Receiver CapFair-launch distribution, anti-whaleLimit maximum holder balances based on total supply percentage.
Velocity LimiterMEV protection, dump mitigationEnforce cooldown periods between successive transfers.
Vesting / LockupTeam tokens, scheduled unlocksLock tokens until a predefined timestamp for scheduled releases.

All modules share a single execution pattern: each policy is a flag on the mint's HookConfig, checked inline inside one execute instruction with an early-exit design — a rejected transfer (e.g., a triggered Global Pause) aborts immediately rather than evaluating the remaining rules, and disabled modules cost next to nothing since they're skipped by their gating check.


Technical Architecture

The Jetty MVP is built on a modern stack designed for high throughput and rapid iteration:

  1. Smart Contract Layer (Anchor/Rust): Fully implements the SPL Transfer Hook interface. Uses a fixed, precomputed ExtraAccountMetaList so transfers are intercepted transparently without requiring callers to manually resolve extra accounts.
  2. Event Indexing (Helius Webhooks): On-chain state changes are piped in real-time via Helius Webhooks to the backend.
  3. Edge Database (Turso / LibSQL): Low-latency database storing the compliance audit trail and off-chain metadata.
  4. Admin Dashboard (Next.js): A zero-code interface for policy authorities to manage their token's rules, with dedicated configuration views per module, client-side validation to prevent contradictory configurations (e.g., a minimum transfer amount set above the maximum), and warning banners for unusual-but-valid combinations (e.g., Allowlist and Denylist both active).
  5. RPC Security: A rate-limited backend proxy (/api/rpc) keeps private RPC provider keys (Helius/QuickNode) out of the client bundle entirely.

Security

  • The Handshake Rule: Rotating the Policy Authority requires a dual-signature authorization — both the current and new authority must sign — to prevent accidental ownership loss.
  • Strict Transfer Verification: The execute hook verifies it is being invoked via a legitimate Token-2022 transfer context, rejecting direct or malicious invocations.
  • Memory Safety: The on-chain program is built with zero unsafe blocks and zero unwrap() panics in the execute hot path.

Test Suite

The program is covered by a modular TypeScript/Mocha test suite, with each module tested in its own isolated file against a fresh mint and PDA state, asserting against specific custom Anchor error codes rather than generic failures.


Roadmap

Phase 1: Proof of Concept & MVP — Complete

  • SVM-optimized Transfer Hook architecture
  • Global Pause, Volume Limits, Anti-Dust, Receiver Cap
  • Allowlist, Denylist, Vesting / Lockup, Velocity Limiter
  • Handshake Rule for authority rotation
  • Helius Webhook + Turso DB integration for audit trails
  • Devnet deployment & Next.js admin dashboard with secured RPC proxy

Phase 2: Extensibility & Production Readiness — Upcoming

  • Directional Transfer Lock (send-only / receive-only accounts)
  • DeFi Protocol Whitelist (exempt known AMM/DEX vaults from allowlist/denylist checks)
  • Rolling 24-Hour Volume Limit (time-windowed velocity control)
  • Custom Transfer Hook support — expand the module library with additional vetted policies as new needs emerge
  • Hook Registry — a growing library of vetted compliance modules issuers can enable for their token with confidence
  • Smart Contract Security Audit
  • Off-Chain Oracles — allow Jetty to read from trusted KYC providers to auto-provision AllowlistEntry PDAs
  • @jetty/sdk npm package
  • Mainnet Beta Launch

Development Setup

# Clone the repository
git clone https://github.com/Yashb404/jetty
cd jetty
# Build the Anchor program
yarn install
anchor build
# Run the test suite
anchor test --skip-local-validator
# Start the admin dashboardcd app
yarn install
yarn run dev

License

MIT

About

Universal on-chain compliance layer for SPL Token-2022 Transfer Hooks on Solana.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages