Skip to content

Rules ​

Rules bound what a tank will pay for. Inodra checks them before it signs as sponsor. A transaction that breaks a rule gets 403 with a code that names the rule. The tank pays nothing for a rejected transaction.

Edit rules on the tank card in the dashboard. Changes apply to the next submit.

All rules ​

RuleTypeDefaultCeiling
maxBudgetMistMIST string0.05 SUI10 SUI
dailyCapMistMIST string or nullnone1000 SUI
maxSponsorshipsPerSenderPerDayinteger or nullnone1,000,000
allowedSendersaddress list or nullany100 entries
allowedTargetstarget pattern list or nullany100 entries
allowedRecipientsaddress list or nullany100 entries
allowedCoinTypescoin type list or nullany100 entries
maxTransferMistPerCoinTypecoin type to MIST map or nullnone100 entries
allowPublishbooleanfalse
lowBalanceAlertMistMIST string or nullnone

null means the rule is off. An empty list is a rule that allows nothing: every transaction it applies to is rejected. The dashboard sends null when you clear a list. MIST strings are decimal integers. 1 SUI = 1,000,000,000 MIST.

Budget and price ​

maxBudgetMist caps the gas budget of one transaction. A transaction with a higher budget gets 403 BUDGET_EXCEEDS_TANK_MAX. GET /v1/gas/config returns this value as maxGasBudgetMist, so clients can set the budget from it.

The gas price must be at or above the reference gas price, and at most 5 times it. Outside that band the codes are 422 GAS_PRICE_BELOW_REFERENCE and 403 GAS_PRICE_TOO_HIGH.

Daily caps ​

dailyCapMist caps the total gas budget the tank admits per UTC day. The meter counts budgets at admission and releases the unused part at settlement. When the cap is reached the code is 429 DAILY_CAP_EXCEEDED. GET /v1/gas/pool returns dailySpentMist and dailyResetsAt.

maxSponsorshipsPerSenderPerDay caps how many sponsorships one sender address gets per UTC day. Use it to stop one wallet from draining the tank. The code is 429 SENDER_CAP_EXCEEDED.

Allowed senders ​

allowedSenders is a list of addresses. When set, the transaction sender must be in it. The code is 403 SENDER_NOT_ALLOWED. Addresses are normalized to 0x plus 64 hex characters.

Allowed targets ​

allowedTargets is a list of patterns for Move calls. When set, every MoveCall in the transaction must match one pattern. The code is 403 TARGET_NOT_ALLOWED.

PatternMatches
0xPKGAny function in any module of the package
0xPKG::gameAny function in module game
0xPKG::game::playOnly play in module game
0xPKG::*::playNot allowed. A function needs a module.

Patterns pin a package id, not a package name. When you upgrade a package, its id changes. Add the new id to the list before you point clients at it. Module and function names are case-sensitive.

Transactions with no Move call, such as a plain transfer, pass this rule.

Allowed recipients ​

allowedRecipients is a list of addresses. When set, every TransferObjects command in the transaction must send to an address in the list. The code is 403 RECIPIENT_NOT_ALLOWED.

The recipient must be a plain address input. A recipient computed by an earlier command gets 403 RECIPIENT_NOT_STATIC.

This rule reads the transaction structure. It cannot see transfers made inside a Move call. A function that calls transfer::public_transfer is not policed by this rule. Pair allowedRecipients with allowedTargets so only functions you trust can run.

Coin types and transfer limits ​

allowedCoinTypes lists the coin types the sender may spend. maxTransferMistPerCoinType caps how much of each coin type the sender may spend in one transaction. The codes are 403 COIN_TYPE_NOT_ALLOWED and 403 TRANSFER_LIMIT_EXCEEDED.

Coin types are full struct tags, for example 0x2::sui::SUI or 0xPKG::usdc::USDC. The package part is normalized.

These two rules need the transaction's balance changes, so Inodra simulates the transaction before it signs.

  • Simulation adds one round trip to the node, about 100 to 500 milliseconds.
  • If the simulation fails, the submit fails with 422 SIMULATION_FAILED and the tank pays nothing.
  • If the node cannot simulate, the submit fails with 503 SIMULATION_UNAVAILABLE. Inodra does not guess.
  • Amounts computed inside Move calls are checked on a best-effort basis. The check reads the simulated balance changes for the sender. A function that spends a different amount at execution time than in simulation can pass the check.

Leave both rules off when you do not need them. Without them no simulation runs.

Publish ​

allowPublish allows Publish and Upgrade commands. It is false by default because these are the most expensive commands. The code is 403 PUBLISH_NOT_ALLOWED.

Low balance alert ​

lowBalanceAlertMist sets the spendable balance below which the organization owner gets an email. At most one email per 24 hours per tank. This rule never rejects a transaction.

Reading the rules ​

GET /v1/gas/pool?tank=<name> returns the current rules as rules. Use it to build the transaction within bounds, for example to pick a target the tank allows.

The full-stack Sui data layer.