Rules
Rules bound what a tank will pay for. Inodra checks them before it signs as sponsor. A transaction that breaks a rule gets 403 with a code that names the rule. The tank pays nothing for a rejected transaction.
Edit rules on the tank card in the dashboard. Changes apply to the next submit.
All rules
| Rule | Type | Default | Ceiling |
|---|---|---|---|
maxBudgetMist | MIST string | 0.05 SUI | 10 SUI |
dailyCapMist | MIST string or null | none | 1000 SUI |
maxSponsorshipsPerSenderPerDay | integer or null | none | 1,000,000 |
allowedSenders | address list or null | any | 100 entries |
allowedTargets | target pattern list or null | any | 100 entries |
allowedRecipients | address list or null | any | 100 entries |
allowedCoinTypes | coin type list or null | any | 100 entries |
maxTransferMistPerCoinType | coin type to MIST map or null | none | 100 entries |
allowPublish | boolean | false | |
lowBalanceAlertMist | MIST string or null | none |
null means the rule is off. An empty list is a rule that allows nothing: every transaction it applies to is rejected. The dashboard sends null when you clear a list. MIST strings are decimal integers. 1 SUI = 1,000,000,000 MIST.
Budget and price
maxBudgetMist caps the gas budget of one transaction. A transaction with a higher budget gets 403 BUDGET_EXCEEDS_TANK_MAX. GET /v1/gas/config returns this value as maxGasBudgetMist, so clients can set the budget from it.
The gas price must be at or above the reference gas price, and at most 5 times it. Outside that band the codes are 422 GAS_PRICE_BELOW_REFERENCE and 403 GAS_PRICE_TOO_HIGH.
Daily caps
dailyCapMist caps the total gas budget the tank admits per UTC day. The meter counts budgets at admission and releases the unused part at settlement. When the cap is reached the code is 429 DAILY_CAP_EXCEEDED. GET /v1/gas/pool returns dailySpentMist and dailyResetsAt.
maxSponsorshipsPerSenderPerDay caps how many sponsorships one sender address gets per UTC day. Use it to stop one wallet from draining the tank. The code is 429 SENDER_CAP_EXCEEDED.
Allowed senders
allowedSenders is a list of addresses. When set, the transaction sender must be in it. The code is 403 SENDER_NOT_ALLOWED. Addresses are normalized to 0x plus 64 hex characters.
Allowed targets
allowedTargets is a list of patterns for Move calls. When set, every MoveCall in the transaction must match one pattern. The code is 403 TARGET_NOT_ALLOWED.
| Pattern | Matches |
|---|---|
0xPKG | Any function in any module of the package |
0xPKG::game | Any function in module game |
0xPKG::game::play | Only play in module game |
0xPKG::*::play | Not allowed. A function needs a module. |
Patterns pin a package id, not a package name. When you upgrade a package, its id changes. Add the new id to the list before you point clients at it. Module and function names are case-sensitive.
Transactions with no Move call, such as a plain transfer, pass this rule.
Allowed recipients
allowedRecipients is a list of addresses. When set, every TransferObjects command in the transaction must send to an address in the list. The code is 403 RECIPIENT_NOT_ALLOWED.
The recipient must be a plain address input. A recipient computed by an earlier command gets 403 RECIPIENT_NOT_STATIC.
This rule reads the transaction structure. It cannot see transfers made inside a Move call. A function that calls transfer::public_transfer is not policed by this rule. Pair allowedRecipients with allowedTargets so only functions you trust can run.
Coin types and transfer limits
allowedCoinTypes lists the coin types the sender may spend. maxTransferMistPerCoinType caps how much of each coin type the sender may spend in one transaction. The codes are 403 COIN_TYPE_NOT_ALLOWED and 403 TRANSFER_LIMIT_EXCEEDED.
Coin types are full struct tags, for example 0x2::sui::SUI or 0xPKG::usdc::USDC. The package part is normalized.
These two rules need the transaction's balance changes, so Inodra simulates the transaction before it signs.
- Simulation adds one round trip to the node, about 100 to 500 milliseconds.
- If the simulation fails, the submit fails with
422 SIMULATION_FAILEDand the tank pays nothing. - If the node cannot simulate, the submit fails with
503 SIMULATION_UNAVAILABLE. Inodra does not guess. - Amounts computed inside Move calls are checked on a best-effort basis. The check reads the simulated balance changes for the sender. A function that spends a different amount at execution time than in simulation can pass the check.
Leave both rules off when you do not need them. Without them no simulation runs.
Publish
allowPublish allows Publish and Upgrade commands. It is false by default because these are the most expensive commands. The code is 403 PUBLISH_NOT_ALLOWED.
Low balance alert
lowBalanceAlertMist sets the spendable balance below which the organization owner gets an email. At most one email per 24 hours per tank. This rule never rejects a transaction.
Reading the rules
GET /v1/gas/pool?tank=<name> returns the current rules as rules. Use it to build the transaction within bounds, for example to pick a target the tank allows.