Abstract
ENGOBE is a metaprotocol for programmable non-fungible assets on Solana. Protocol actions, called firings, are written as memo data into ordinary Solana transactions that also pay a protocol fee to a public treasury. Indexers read these transactions in ledger order and apply a fixed, public set of validity rules to compute the state of every vessel: its owner, attributes, workshop memberships, attestations and full history. $ENGB is the protocol’s token. It is designed to pay for firings and to govern the parameters and standards of the protocol.
1 · Motivation
Static by default. Most NFT metadata is fixed at mint or edited by a single privileged key. Assets cannot evolve in response to use without a custom program or a trusted server.
Fragmented. Each application that adds state invents its own format, so that state is unreadable everywhere else.
Off-chain dependence. Rich behaviour usually lives in databases that can be changed, lost or switched off.
No shared stewardship. Standards are set by whoever ships first, with no process for the people who depend on them to improve them.
2 · Design overview
A firing is a Solana transaction with exactly two meaningful instructions:
1. System Program · transfer signer → ENGOBE treasury (protocol fee)
2. SPL Memo "engobe:{"v":1,"op":"…", …}"
The fee transfer makes every firing discoverable: an indexer lists the treasury’s transaction signatures, fetches each transaction, and reads the memo. Solana provides ordering, finality and censorship resistance. ENGOBE provides meaning. There is no custom on-chain program to upgrade or exploit, and every wallet that can sign a transaction can take part.
The identifier of anything created by a firing (a vessel or a proposal) is the signature of the transaction that created it. Identifiers are therefore unique, permanent and verifiable on any explorer.
3 · Operations
| op | Name | Effect |
|---|---|---|
mint | Fire a Vessel | Create a vessel with name, optional image URL, description and attributes. Owner = signer. |
set | Glaze | Merge attribute changes (null deletes), rename or re-image. Owner only. |
link | Enter a Workshop | Join the vessel to a workshop. Owner only. |
give | Hand over | Transfer ownership to another address. Owner only. |
bind | Fire an NFT | Attach living state to an existing Metaplex NFT. Control follows the NFT holder. |
mod | Open a Workshop | Register a workshop under a unique slug. Signer becomes owner and first assayer. |
val | — | Workshop owner adds or removes assayers. |
att | Assay | A assayer approves or rejects a vessel linked to their workshop. |
prop | Propose | Open a governance proposal with a voting window of 1 hour to 31 days. |
vote | Vote | Vote yes, no or abstain. The latest vote per wallet counts. |
4 · State and validity
State is a pure function of the ordered list of firings. An indexer applies the rules below and must reach the same state as every other honest indexer.
- Only successful transactions at confirmed commitment or stronger are considered.
- The memo must begin with
engobe:, parse as JSON, carry"v":1and match the schema of itsop. - The transaction must transfer at least the current fee for that op from the signer to the treasury.
- Ownership-gated ops (
set,link,give) are valid only when signed by the current owner at that point in the ledger. - Workshop slugs are first-come, first-served.
attrequires the signer to be a assayer of that workshop, and the vessel to be linked to it. - Votes count only inside the proposal’s window.
- Invalid firings are kept in the record with a reason, but have no effect.
Because invalid firings have no effect, nobody can damage someone else’s vessel by writing bad data. The worst they can do is pay a fee for nothing.
5 · Workshops and Assayers
A workshop is an independent system inside ENGOBE with its own purpose: game items, membership passes, generative series, reputation badges, AI-native characters. Makers create vessels and link them in. Assayers, appointed by the workshop owner, attest whether each vessel meets the workshop’s standard. Applications can choose to trust only attested vessels. This turns quality control into an open, inspectable process rather than a private allow-list.
Over time, governance may define shared workshop standards, assayer requirements and incentive programs funded by the treasury.
6 · Binding existing NFTs
The bind op lets any Metaplex NFT gain ENGOBE state without migration. The binder becomes the controller of the bound vessel. When the NFT changes hands, the new holder issues a fresh bind and takes control, and the history stays intact. Indexers verify that the most recent binder still holds the NFT and flag the vessel if they do not.
7 · The $ENGB token
Paying for firings. At launch, fees are paid in SOL so that anyone can use the protocol on day one. Once $ENGB fee payment is enabled by governance, firings can be paid in $ENGB, which ties token demand directly to protocol usage.
Governance. $ENGB holders vote on fee levels, treasury spending, grants, workshop standards, assayer requirements and future versions of the rules.
Coordination. Treasury-funded incentives can reward makers, assayers and indexer operators who grow the network.
8 · Governance process
- Signal phase. One wallet, one vote, on-chain through the
prop/voteops. This builds the habit and the record before real weight is attached. - Token phase. Once the $ENGB mint is set in the protocol config, votes are weighted by holdings at count time.
- Lifecycle. Proposal → open discussion → vote → execution by contributors → public review.
- Hardening. Over time, more decisions move to automatic execution as the tooling matures.
9 · Distribution
$ENGB has a fixed supply. Most of it is reserved for the people who use and build the protocol.
| Allocation | Share | Notes |
|---|---|---|
| Public launch & liquidity | 65% | Fair launch on Solana; no presale. |
| Community airdrop: round one | 10% | Distributed first, through vesting contracts. |
| Community airdrop: later rounds | 20% | Timing and eligibility announced separately. |
| Core team | 5% | Reserved for contributors. |
Airdrop eligibility will include early ENGOBE users on devnet and mainnet, workshop founders, assayers, and community contributors. Snapshots, claim windows and vesting schedules will be announced separately.
10 · Fees
| op | Devnet fee |
|---|---|
mint | 0.001 SOL |
set | 0.0005 SOL |
link | 0.0005 SOL |
give | 0.0005 SOL |
bind | 0.001 SOL |
mod | 0.001 SOL |
val | 0.00025 SOL |
att | 0.00025 SOL |
prop | 0.001 SOL |
vote | 0 SOL |
Mainnet fees are set at launch and are adjustable by governance. Fees fund the treasury, which pays for grants, infrastructure and incentives.
11 · Security considerations
- No program risk. ENGOBE deploys no custom on-chain code. It inherits Solana’s security and the audited System and Memo programs.
- Deterministic indexing. The rules are versioned. Indexers that disagree can compare their inputs transaction by transaction.
- Spam. Every firing costs a fee, and invalid ones change nothing.
- Size. Memos are capped at 560 bytes. Large media lives on Arweave or IPFS and is referenced by URL.
- Keys. Treasury keys should be held in multisig. Governance can rotate the treasury through a rules update.
12 · Roadmap
Phase 1 — Foundation
Publish the v1 rules, launch the app and indexer on devnet, then mainnet. Documentation and examples.
Phase 2 — Builder tooling
Hosted indexer API, SDK packages, CLI releases, templates for games and generative art, first grants.
Phase 3 — Token utility
Fee payment in the protocol token, fee parameters exposed to governance, treasury reporting.
Phase 4 — Governance
Token-weighted voting, formal proposal process, treasury-funded grants and module standards.
Phase 5 — Ecosystem
Marketplace and wallet integrations, third-party modules, cross-app standards, progressive decentralisation of the treasury.
13 · Disclaimer
This document is for information only and is not financial, legal or tax advice. $ENGB is a utility and governance token for the ENGOBE protocol. Nothing here promises profit, price, adoption or success. Crypto networks carry technical, market, regulatory and liquidity risk, including total loss. Do your own research.