Paper · v1.0

ENGOBE: Fired State for Programmable Non-Fungibles on Solana

ENGOBE core contributors

Abstract

ENGOBE is a metaprotocol for programmable non-fungible assets on Solana. Protocol actions, called firings, are written as memo data into ordinary Solana transactions that also pay a protocol fee to a public treasury. Indexers read these transactions in ledger order and apply a fixed, public set of validity rules to compute the state of every vessel: its owner, attributes, workshop memberships, attestations and full history. $ENGB is the protocol’s token. It is designed to pay for firings and to govern the parameters and standards of the protocol.

1 · Motivation

Static by default. Most NFT metadata is fixed at mint or edited by a single privileged key. Assets cannot evolve in response to use without a custom program or a trusted server.

Fragmented. Each application that adds state invents its own format, so that state is unreadable everywhere else.

Off-chain dependence. Rich behaviour usually lives in databases that can be changed, lost or switched off.

No shared stewardship. Standards are set by whoever ships first, with no process for the people who depend on them to improve them.

2 · Design overview

A firing is a Solana transaction with exactly two meaningful instructions:

1. System Program · transfer   signer → ENGOBE treasury   (protocol fee)
2. SPL Memo                    "engobe:{"v":1,"op":"…", …}"

The fee transfer makes every firing discoverable: an indexer lists the treasury’s transaction signatures, fetches each transaction, and reads the memo. Solana provides ordering, finality and censorship resistance. ENGOBE provides meaning. There is no custom on-chain program to upgrade or exploit, and every wallet that can sign a transaction can take part.

The identifier of anything created by a firing (a vessel or a proposal) is the signature of the transaction that created it. Identifiers are therefore unique, permanent and verifiable on any explorer.

3 · Operations

opNameEffect
mintFire a VesselCreate a vessel with name, optional image URL, description and attributes. Owner = signer.
setGlazeMerge attribute changes (null deletes), rename or re-image. Owner only.
linkEnter a WorkshopJoin the vessel to a workshop. Owner only.
giveHand overTransfer ownership to another address. Owner only.
bindFire an NFTAttach living state to an existing Metaplex NFT. Control follows the NFT holder.
modOpen a WorkshopRegister a workshop under a unique slug. Signer becomes owner and first assayer.
val—Workshop owner adds or removes assayers.
attAssayA assayer approves or rejects a vessel linked to their workshop.
propProposeOpen a governance proposal with a voting window of 1 hour to 31 days.
voteVoteVote yes, no or abstain. The latest vote per wallet counts.

4 · State and validity

State is a pure function of the ordered list of firings. An indexer applies the rules below and must reach the same state as every other honest indexer.

  1. Only successful transactions at confirmed commitment or stronger are considered.
  2. The memo must begin with engobe:, parse as JSON, carry "v":1 and match the schema of its op.
  3. The transaction must transfer at least the current fee for that op from the signer to the treasury.
  4. Ownership-gated ops (set, link, give) are valid only when signed by the current owner at that point in the ledger.
  5. Workshop slugs are first-come, first-served. att requires the signer to be a assayer of that workshop, and the vessel to be linked to it.
  6. Votes count only inside the proposal’s window.
  7. Invalid firings are kept in the record with a reason, but have no effect.

Because invalid firings have no effect, nobody can damage someone else’s vessel by writing bad data. The worst they can do is pay a fee for nothing.

5 · Workshops and Assayers

A workshop is an independent system inside ENGOBE with its own purpose: game items, membership passes, generative series, reputation badges, AI-native characters. Makers create vessels and link them in. Assayers, appointed by the workshop owner, attest whether each vessel meets the workshop’s standard. Applications can choose to trust only attested vessels. This turns quality control into an open, inspectable process rather than a private allow-list.

Over time, governance may define shared workshop standards, assayer requirements and incentive programs funded by the treasury.

6 · Binding existing NFTs

The bind op lets any Metaplex NFT gain ENGOBE state without migration. The binder becomes the controller of the bound vessel. When the NFT changes hands, the new holder issues a fresh bind and takes control, and the history stays intact. Indexers verify that the most recent binder still holds the NFT and flag the vessel if they do not.

7 · The $ENGB token

Paying for firings. At launch, fees are paid in SOL so that anyone can use the protocol on day one. Once $ENGB fee payment is enabled by governance, firings can be paid in $ENGB, which ties token demand directly to protocol usage.

Governance. $ENGB holders vote on fee levels, treasury spending, grants, workshop standards, assayer requirements and future versions of the rules.

Coordination. Treasury-funded incentives can reward makers, assayers and indexer operators who grow the network.

8 · Governance process

  1. Signal phase. One wallet, one vote, on-chain through the prop/vote ops. This builds the habit and the record before real weight is attached.
  2. Token phase. Once the $ENGB mint is set in the protocol config, votes are weighted by holdings at count time.
  3. Lifecycle. Proposal → open discussion → vote → execution by contributors → public review.
  4. Hardening. Over time, more decisions move to automatic execution as the tooling matures.

9 · Distribution

$ENGB has a fixed supply. Most of it is reserved for the people who use and build the protocol.

AllocationShareNotes
Public launch & liquidity65%Fair launch on Solana; no presale.
Community airdrop: round one10%Distributed first, through vesting contracts.
Community airdrop: later rounds20%Timing and eligibility announced separately.
Core team5%Reserved for contributors.

Airdrop eligibility will include early ENGOBE users on devnet and mainnet, workshop founders, assayers, and community contributors. Snapshots, claim windows and vesting schedules will be announced separately.

10 · Fees

opDevnet fee
mint0.001 SOL
set0.0005 SOL
link0.0005 SOL
give0.0005 SOL
bind0.001 SOL
mod0.001 SOL
val0.00025 SOL
att0.00025 SOL
prop0.001 SOL
vote0 SOL

Mainnet fees are set at launch and are adjustable by governance. Fees fund the treasury, which pays for grants, infrastructure and incentives.

11 · Security considerations

12 · Roadmap

Phase 1 — Foundation

Publish the v1 rules, launch the app and indexer on devnet, then mainnet. Documentation and examples.

Phase 2 — Builder tooling

Hosted indexer API, SDK packages, CLI releases, templates for games and generative art, first grants.

Phase 3 — Token utility

Fee payment in the protocol token, fee parameters exposed to governance, treasury reporting.

Phase 4 — Governance

Token-weighted voting, formal proposal process, treasury-funded grants and module standards.

Phase 5 — Ecosystem

Marketplace and wallet integrations, third-party modules, cross-app standards, progressive decentralisation of the treasury.

13 · Disclaimer

This document is for information only and is not financial, legal or tax advice. $ENGB is a utility and governance token for the ENGOBE protocol. Nothing here promises profit, price, adoption or success. Crypto networks carry technical, market, regulatory and liquidity risk, including total loss. Do your own research.