Modeled redemption-route coverage for tracked stablecoins. This subsystem estimates how credibly a holder can exit to par or near-par outside secondary-market DEX liquidity, then exposes that estimate through a standalone snapshot API. Since redemption v4.3 the legacy effectiveExitScore blend is retired: same-notional exit is published by the Safety Score V9 Exit pillar alone, which composes the same route-scoring primitives from shared/lib/exit-route-scoring.ts.
Agent navigation — Grep the heading you need: Methodology Versioning · Coverage · Cron Schedule · Scoring Model · Route Modeling · Database Schema · API Endpoint · Frontend Consumers.
Methodology Versioning
- Current methodology version: <!-- GENERATED-START: methodology-version-redemption-backstop -->
v4.46<!-- GENERATED-END: methodology-version-redemption-backstop --> - Public methodology anchor:
/methodology/#redemption-backstop-methodology - Canonical source files:
shared/lib/redemption-backstops.ts,shared/lib/redemption-backstop-configs/*,shared/lib/redemption-backstop-scoring.ts,shared/lib/methodology-versions/registry.ts - Structured changelog:
shared/data/methodology-changelogs/redemption-backstop/
Latest v4.46 update: Morpho Vault V2 capacity checks the exact vault's liquidityAdapter() in the same run; a zero or unreadable adapter bounds capacity to independently measured fresh idle underlying. Generic non-USD ERC-4626 units are not published as USD without same-path FX valuation (erc4626-capacity-non-usd-unvalued), removing nominal TRY-as-USD telemetry from wiTRY while retaining its reserve evidence. Newly reviewed routes keep unmeasured liquidity unavailable rather than resolving a fixed-usd zero.
Earlier release history lives in shared/data/methodology-changelogs/redemption-backstop/; keep this document focused on the current contract.
The standalone history is published at /methodology/redemption-backstop-changelog/. The current methodology section distinguishes this route diagnostic from V9 Exit, which re-evaluates exact same-notional route evidence under the V9 policy.
Coverage
Configured coverage is defined statically behind the thin facade in shared/lib/redemption-backstops.ts, with route-family modules under shared/lib/redemption-backstop-configs/.
- Configured coins and family counts: derived from
REDEMPTION_BACKSTOP_CONFIGS; do not copy the changing roster or totals into this document - Route families:
offchain-issuer,stablecoin-redeem,collateral-redeem,queue-redeem,psm-swap, andbasket-redeem - No discovery layer: only coins present in
REDEMPTION_BACKSTOP_CONFIGSare modeled
The config registry is validated at module load time against TRACKED_META_BY_ID, so unknown IDs fail fast during build/test/runtime startup.
OUSD partner redemption (reviewed 2026-10-01). Tempo's OUSD guide documents current 1:1 USD minting and redemption through integration partners. The route retains verified-customer access and documented full-supply eventual capacity; open describes that documented partner route, not live operational telemetry or public-portal support. Bridge's stablecoin terms §3 commit only to processing an Order within two business days after Bridge determines it compliant, unless delayed by factors outside its reasonable control. That is not a settlement-completion bound: it does not say when the USD payout completes, and the compliance-determination start is itself unbounded. Noon's reviewed SLA differs because its terms define processing as transferring the redemption value. OUSD therefore carries no v9RouteReviewTerms settlement SLA and keeps the coarse days default horizon.
Bridge's OUSD launch statement says, "Bridge will not charge fees for minting or redeeming or impose liquidity restrictions that delay those transactions." Open Standard's live announcement says all integration paths support 1:1 mint and burn "at no cost." OUSD therefore uses fixedFee(0, ...), consistent with the Paxos/Gemini zero-issuer-fee precedent. Bridge User Terms §7.1 still requires checking fees through the partner account; bank, partner-service, and network charges may apply. The fixed value records the disclosed issuer redemption fee, not a zero all-in payout promise.
The live reserve dashboard and transparency endpoint are self-reported. No independent OUSD reserve report was linked at review; the live announcement promises future monthly attestations, while Bridge's FAQ describes quarterly reports. Standalone redemption remains NR until an admissible immediate-capacity floor exists. A first published independent report reconciling OUSD liabilities against approximately 100% highly liquid reserves would support review against the major-issuer 25% hot-buffer precedent (75% haircut), rather than promoting the dashboard's cash percentage directly. No pathUSD/USDC payout, same-day settlement, or live reserve payout buffer is inferred.
Reviewed on-chain routes. Native Morpho vault withdrawals, sFRAX, sreUSD, Gnosis sDAI and sUSDf unwraps retain their concrete underlying-token outputs. USDso returns frxUSD, and USDFC redeems into FIL under its oracle/TCR/Trove constraints; its configured rate probe reads getRedemptionRateWithDecay() on the exact TroveManager. Spark USDC (Base MetaMorpho V1) and Spark USDT (Ethereum Vault V2) now have exact-vault reserve readers and reserve-sync capacity policies without static fallbacks. Missing telemetry publishes null capacity and missing-capacity, never a resolved zero for unmeasured liquidity. The V2 reader probes liquidityAdapter() on the exact vault in the same run: zero or unreadable adapter restricts capacity to independently measured fresh idle underlying, with machine-readable warning codes morpho-vault-v2-liquidity-adapter-zero / morpho-vault-v2-liquidity-adapter-unavailable. Missing idle means no capacity claim. Ordinary cash capacity excludes overlapping force-deallocation/in-kind positions; Vault V2 maxWithdraw/maxRedeem zero conventions are not capacity probes.
The generic ERC-4626 path emits no USD capacity for non-USD underlying without same-path FX valuation (erc4626-capacity-non-usd-unvalued), while retaining the reserve observation. This removes nominal TRY-as-USD telemetry for the pre-existing wiTRY adapter and prevents nominal EURCV-as-USD capacity on the new Steakhouse EURCV route. The pre-branch V2 consumers—Gauntlet USDC Prime, Steakhouse USDC and Steakhouse USDT—each had a nonzero exact-vault liquidityAdapter() at Ethereum block 26110272, so the selected-adapter guard does not change their capacity at that observed state; a future zero or unreadable adapter restricts them to fresh idle just like new routes.
Routes without an honest exact-output capacity model remain source-reviewed unconfigured in shared/data/coverage-dispositions/redemption-coverage-dispositions.ts, with defer / capacity-unpublished, rather than publishing invented zero capacity. This includes Legacy Spark V1, earnUSD, sUSDx, XGLD, Axis USDx and Forest Road USDfr. RISE Dollar and MANTRA USD's reviewed same-chain wM conversion also remains unconfigured: native-M custody and approved-swapper gate telemetry cannot certify the distinct wM output route. Legacy Spark's USDC/sUSDS holder choices are not an invented equal-weight basket or additive cash pocket.
strUSD and syrupUSDG retain their native queue/request-and-claim rails. Their configured ERC-4626 readers measure idle underlying, not additive encumbered cooldown-silo balances or guaranteed FIFO processing. syrupUSDG/earnUSD averages, sUSDx's serviced seven-day minimum and XGLD's cooldown are not guaranteed completion maxima. The deferred reviews preserve these known routes and their unknown funded throughput, settlement bounds and fees. XGLD's published 0.1% native redemption fee applies to XAUt output, not dollars or physical delivery. Axis USDx's approved RFQ settlement is atomic only after operator approval; indicative 2%-of-book/day and seven-day bands are not committed capacity, SLAs or binding fee bounds. Forest Road USDfr's KYC-gated direct USDC rail does not inherit the separate sUSDfr 21-day queue or its minimum.
Saturn sUSDat's NFT queue remains source-reviewed unconfigured pending exact-route capacity evidence. It returns USDat after operator processing, with a published 10 USDat request minimum and processing-time fee mode. Ethereum block 26108193 showed an unpaused vault, Elevated mode, 10 bps base and 50 bps elevated redemption fees; this does not establish resumed processing, a permanent all-in fee bound or funded queue capacity. The [undated V2 migration hold](https://raw.githubusercontent.com/saturn-organization/saturn-yield-dollar/main/docs/v2-deployment-operator procedure.md) leaves route availability unknown. STRCon recognized NAV and the observed USDat cash buffer are not executable queue throughput, and the apyUSD three-day precedent is not inherited.
Ondo's address registry now records a GMIssuerManager securities-in-kind rail through Alpaca ITN. GLDon's reviewed source notes capture that rail without assuming GLDon-specific holder eligibility, executable throughput, settlement or fees and without upgrading its exit score. FRNT's Commission fee is explicitly zero, while unquantified LSP/payment-rail charges leave the complete modeled route's cost undisclosed-reviewed. The native sUSDf→USDf unwrap has restricted-address checks rather than inheriting the separate off-chain issuer's KYC gate.
npm run audit:coverage -- --domain=redemption-backstops --report <path> writes per-config audit rows with both the literal configured capacityBasis and the resolved runtime-style resolvedCapacityBasis. Reserve-sync rows use the tracked adapter's direct/proxy redemption-telemetry declaration when resolving that audit basis. The report also includes capacityFallbackSource for reserve-sync fallback ratios/USD buffers and dailyLimitUsd when a static model caps same-day capacity, so review queues can distinguish route-family defaults from explicit fallback or daily-limit constraints.
Cron Schedule
- Pattern:
11 */4 * * * - Function:
syncRedemptionBackstops(db, signal) - File:
worker/src/cron/sync-redemption-backstops.ts - Trigger order: runs after
sync-live-reservesin the 4-hourly reserve lane (worker/src/handlers/scheduled/hourly-live-reserves.ts)
The cron reads:
- The strict
stablecoinscache vialoadStablecoinsCache(...), including its generation timestamp, underlying price-observation timestamps and provenance, FX references, and same-generation prices used to derive current signed deviations - The latest DEX liquidity snapshot via
loadDexLiquiditySnapshot(db)so both the liquidity map and freshness can be reused - A preloaded map of the latest authoritative reserve snapshot metadata for routes that use live reserve telemetry for capacity or fee inputs
No external HTTP calls happen during the redemption-backstop pass itself; any live reserve telemetry is reused from D1.
Status semantics:
okwhen every active configured route resolves to a usable scored row and the reused DEX diagnostic input is fresh, when the only unresolved active rows are a tinymissing-capacitytail within the current active-config tolerance budget (max(1, ceil(activeConfigured * 1%))), when current market evidence intentionally marks a routeimpaired, or when a configured route is absent from the active runtime stablecoins cache but still materialized as a diagnosticmissing-cacherow. The DEX score remains backward-compatible context only; it never computes a combined exit score.degradedwhen at least one row is written but any active configured route fails, hits a non-missing-capacity/non-impaired/non-missing-cacheunresolved state, themissing-capacitytail exceeds that tolerance budget, the reused DEX liquidity snapshot is stale or missing, the runtime cache has no active configured route at all, a reserve-metadata or DEX-liquidity preload step failed, or the D1 write/retention step returned warningserrorwhen zero routes resolve to a usable scored row because of route failures, blocking unresolved states, all active configured routes missing capacity, or every configured route being absent from the active runtime stablecoins cache
Cron metadata includes synced, resolved, unresolved, unresolvedMissingCapacity (plus per-family/per-provider familyMissingCapacityBy / providerMissingCapacityBy breakdowns when any capacity is missing, so a single failing adapter family cannot hide inside the aggregate tolerance), unresolvedCritical, availabilityDegraded, marketImpliedDegraded, marketEvidenceUncertain, missingCapacityOkThreshold, coverageRatio, failed, configured, activeConfigured, cacheAbsentConfigured, dynamic, estimated, static, liquidityStale, severeActiveDepegThresholdBps, registry/run manifest fields (registryHash, familyCounts, strongProxyCount, heuristicCount, validatorVersion, configMethodologyVersion, v4ScoringParametersHash), and route-status producer fields (routeStatusProducer, routeStatusProducerFetches), plus capped matching ID lists or missingFromCache when relevant. Intentional confirmed impairment and current-evidence uncertainty do not by themselves degrade the cron run.
Scoring Model
Component Weights
Defined in shared/lib/redemption-backstop-scoring.ts:
| Component | Weight |
|---|---|
| Access | 0.20 |
| Settlement | 0.15 |
| Execution certainty | 0.15 |
| Capacity | 0.25 |
| Output asset quality | 0.15 |
| Cost | 0.10 |
If capacityScore is unavailable, computeRedemptionBackstopScore() returns null and the route is treated as unrated. When executable capacity is measured, zero capacity returns a zero headline with zero-executable-capacity; positive capacity below both the first 1% request-completion and $100,000 absolute-capacity breakpoints returns zero with immaterial-executable-capacity. Other components cannot manufacture a positive route score without a material executable exit.
Route-Family Caps
Some route families are intentionally capped even when their component mix scores higher:
| Route family | Cap |
|---|---|
queue-redeem | 70 |
offchain-issuer | 65 |
An optional per-config totalScoreCap can apply an additional config-cap.
The exit-route observation envelope this producer emits is consumed by the Safety Score V9 Exit pillar, which is the only same-notional route grader. Redemption observations accept only issuer-redemption and protocol-redemption as potentially scoreable families; eventual-redemption is diagnostic-only. Reviewed documented-terms evidence uses a one-year review window. Reviewed opaque-fee observations can carry modeled capacity tagged with feeEvidence: "undisclosed-reviewed" while remaining producer-level non-score-eligible; a consumer must apply an explicit bounded-unknown fee policy rather than treating the route as cost-bounded. Route independence — and with it the pillar's bounded redundancy credit — is decided by the V9 Exit pillar from enumerated failure domains and physical resource keys.
The V9-only FPI path observes its Controller Pool, FRAX and FPI price feeds, and CPI tracker at one Ethereum block. Admission pins every dependency address and runtime hash, verifies current oracle rounds and controller/feed agreement, rejects paused or out-of-band state, and measures the live fee, quote, FRAX balance, and maximum redeemable FPI. Capacity is denominated as input FPI at the CPI peg; execution cost and the pinned FRAX output value remain separate so the all-in loss must satisfy the modeled-request ceiling. The configured CPI update bounds admit observations up to 62 days old at high model confidence, downgrade observations from 62 through 366 days to medium, and reject older state. The issuer collateral response and the nested route attempt publish through the same reserve-adapter result, so a failed issuer request cannot leave a new route attempt attached to stale composition. This evidence is consumed only by explicit V9 replay and does not alter standalone public redemption rows or scores.
Physical physicalCommodityDelivery retains its standalone diagnostic valuation: captured unscaled USD/oz times fine weight, net of published fees, tier 65 (55 when delivery terms are unbounded), and sameNotionalEligible: false. This methodology separately admits a reviewed physical-to-USD composed capability in Safety Exit; it does not change the standalone redemption score, manufacture a fiat promise from delivery, or backfill absent captured commodity prices.
The September 21 terms pass structures XAUt, PAXG, KAU, KAG, GGBR, PGOLD, XAUm, DGLD, XAGm, CGO and GLDT. CGO conservatively uses the contractual 1,000-token minimum rather than the FAQ's 10; both sources remain attached. XAUt's 430-token deposit is a conservative threshold, not a fixed bar weight. GLDT's CHF 300 vault-pickup charge is retained in source notes rather than converted into an invented USD delivery deduction. GLDY stays unstructured because no reviewed primary source publishes a physical minimum; contradictory secondary fees do not establish one.
Physical-to-USD Exit capability
physicalToUsd is a Safety-only reviewed config block. It names metal/fine ounces per token, token minimum and increment or enumerated fine-weight bar classes, vaults, sale/delivery scope, fineness, verified-customer eligibility, issuer percentage/fixed fees, delivery/insurance/assay/tax/conversion bounds, issuer settlement legs, optional best-effort issuer cash process, review/expiry and quoted evidence. Terms expire at the earlier explicit expiry or 90 days; the captured raw metal reference retains its 24-hour bound. Missing lot/weight, unstated issuer timing and explicitly unbounded inputs publish null beside a named rejection, never inferred capacity. A Good Delivery gold class may conservatively require 430 tokens plus fee per deposit and count 350 fine ounces; excess deposit is refunded without charging a price/retention loss (LBMA §2.1.7, Paxos §11.4).
Reviewed configs cover PAXG, XAUT, KAU, KAG, XAUm, XAGm, GGBR, PGOLD, DGLD, CGO and GLDT; a configured candidate is not an admitted route. XAUT models delivery within Switzerland, without inferring Zurich from the country; Kinesis global door delivery and DGLD Swiss-to-European shipping conservatively retain cross-border logistics. Matrixdock's stated T+3 applies only after stablecoin-order execution, Kinesis contact time and GGBR processing time are not bullion-release promises, and XAGm's approximate silver-bar range does not establish a guaranteed fine-weight floor. PGOLD keeps unpublished fees rather than reviving a legacy quote; CGO uses the contractual kilogram minimum, lower contractual purity and both published transfer/redemption charges. GLDT retains its specific one-gram NFT class and the published CHF300 pickup charge as unavailable in USD (unbounded), not as an unpublished fee eligible for a policy estimate.
For each existing $100K/$1M/$10M/$25M grid request, the pure evaluator sizes affordable integer lots without borrowing, values delivered fine metal at the captured reference and computes N = G − issuer fees − bounded logistics/tax/conversion − modelled sale spread, c = 10,000 × (G − N) / G. Physical admission requires c ≤ 500 bps; cost scoring uses the same 200-bps denominator as every other route, not the physical admission ceiling. Gross input capacity and net proceeds are both traced. All deductions enter execution cost once: USD output retention remains one, output quality and offchain route ceiling remain 65, and weights and delay/backlog/minimum multipliers are unchanged. Physical routes admit any verified (KYC'd) customer with a neutral eligibility multiplier, without changing other route families. There is no metal-price-movement charge. Best-effort cash branches use their independently reviewed lots, costs and final-USD timing with the existing low model-confidence factor and the same policy sale spread for their bar class/location; an issuer's attempt to sell never implies a zero spread.
Optional throughput on the physical route or its independently reviewed cash branch specifies delivered-fine-metal-equivalent tokens per calendar periodSec, with a source URL and evidence quote. Each grid point is bounded by affordable integer lots and documented throughput over that branch's complete maximum settlement window. Without documented throughput, policy credits at most one minimum redeemable lot per window, using the conservative delivered fine-weight floor and captured spot; it does not infer inventory or buyer demand from supply, mint-rate limits, processing times or minimum denominations. The current reviewed sources establish no physical throughput, so configs retain that conservative fallback rather than invented limits. Admitted capacity is modelled-terms-lower-bound, never exact-lower-bound, and keeps the existing medium/low model-confidence discounts.
One authority, semantic.exit.physicalToUsd in the methodology policy JSON, owns these conservative modelled sale spreads:
| Metal / bar class | London or Zurich (bps) | Other vault (bps) |
|---|---|---|
| Gold Good Delivery | 100 | 200 |
| Gold kilobar | 200 | 300 |
| Gold small bar / coin | 400 | 500 |
| Silver Good Delivery | 100 | 200 |
| Silver kilobar | 300 | 400 |
| Silver small bar / coin | 800 | 900 |
These are policy estimates, not executable dealer bids. BullionVault's primary tariff quotes 0.10% for the first 1–4 400oz gold bars and 0.10% markdown for 32–80 1000oz silver bars; its daily-price sale charges 0.5%. A 1% primary-vault Good Delivery spread deliberately exceeds both. GoldSilver's dealer buyback guide states larger gold bars (including kilo) bid about 1% or less below spot, recognized 1oz gold bars/sovereign coins 1–2%, generic gold 2–4%, and silver coins 5–8%; policy uses 2% gold kilo, 4% small gold and the upper 8% small-silver figure, with an additional 1% outside primary vaults. The 3% silver-kilo value is a conservative model choice between professional large-bar and retail small-silver evidence, not a dealer quote. Small-silver sale routes exceeding the physical ceiling receive no credit.
Explicit published charges win. Unpublished issuer redemption fees use 100 bps and USD100 fixed, conversion 50 bps; fee assumptions publish fee-policy-assumed and low confidence. USD100 covers ordinary transfer/processing friction above BullionVault's cited ACH USD10/SWIFT typically≤USD30; 50 bps conversion exceeds its 30-bps currency switch. In-vault spread covers unpublished transport/insurance/assay, without charging them twice. Same-jurisdiction delivered routes conservatively estimate transport USD3000/500/100 and assay USD1000/100/50 per Good Delivery/kilobar/small lot plus 100-bps insurance. BullionVault's tariff cites Zurich release USD1200/bar plus USD1000–2000 armoured transport, London USD600/bar plus USD250–750; the Good Delivery allowance exceeds those primary-market examples, and the smaller-lot/assay/insurance values are deliberately conservative policy estimates rather than logistics quotes. Cross-border logistics without published bounds remain unavailable; explicit unbounded never becomes an estimate.
Tax is not imposed on every holder sale. Modelled in-vault sales have zero tax for gold and silver; delivered/released metal uses only the unpublished-tax jurisdiction fallback: Hong Kong 0; Singapore 0 for qualified IPM (gold fineness≥0.995, silver≥0.999); Switzerland gold0/silver810 bps; London/EU investment gold0/silver2000 bps; other gold0 only at fineness≥0.995, otherwise2000 bps, and other silver2000 bps. These are release/import-cost allowances, not a claim that a selling holder owes buyer VAT. Sources: IRAS IPM guide §§2–5, HMRC investment-gold exemption and 20% standard VAT, Swiss FTA rates and VAT Ordinance Art.44, EU Directive 2006/112/EC Arts.344–356, and Hong Kong government's no-sales-tax/VAT statement.
Curated settlement legs cover issuer release/delivery only. An explicit maximum wins; a stated typical time without maximum uses clamp(3 × typical, 10, 30) business days at low confidence with settlement-maximum-policy-assumed. The policy vocabulary maps “several business days” (including “up to several”) to 7 typical, hence 21 maximum. No stated issuer time earns no credit. The evaluator automatically appends the modelled dealer-sale leg: LBMA spot-market convention describes forward delivery as later than two business days, so spot T+2 supplies a policy typical2 and conservative maximum10 business days. Sequential maxima include intervening weekends in calendar delay; the existing settlement multipliers are the only time charge. Public primary/alternative traces retain endpoint, holder scope, branch, lots/tokens, gross/net USD, cost, maximum time, freshness budgets, assumptions and rejection reason.
Severe active downside depegs add a current-exercisability gate on top of the static route score. The incident gate is an open live depeg_events row whose explicit direction is below peg; peak_deviation_bps, peak_price, started_at, and incident age remain historical context and never establish present severity. degraded / market-implied requires the same stablecoins generation used by the redemption run to be no more than 1800 seconds old, its underlying priceObservedAt ?? priceUpdatedAt to be finite, non-future, and no more than 1800 seconds old, non-cached and authoritative price trust, an authoritative peg reference, and a finite current signed deviation at or below -2500 bps. A fresh authoritative deviation above that boundary releases this overlay without closing the incident. If currency cannot be established, the route publishes unknown / market-implied, remains resolutionState: impaired, applies market-implied-depeg-evidence-uncertain, and withholds its score; a missing feed therefore cannot turn a permanently collapsed asset into an open static route.
Confirmed downside impairment and current-evidence uncertainty both propagate through modeled outputs. Dependency weights come from variantOf and pegReferenceId parents when either is set; otherwise, for every route family except offchain-issuer, they are derived from reserve composition (reserves[].pct) and declared dependencies (dependencies[].weight). Only dependencies with confirmed current severe evidence contribute to outputImpairedShare, and the dependency with the largest absolute current severe deviation supplies the attribution. Any confirmed severe dependency takes precedence over uncertain dependencies; when none is currently severe but at least one relevant open incident is uncertain, the route is unknown and unrated. The direct strong-live exception remains limited to current permissionless atomic/immediate live-direct capacity and never bypasses output impairment or uncertainty. The redemption producer only reads depeg_events; lifecycle ownership, recovery, and incident closure remain with the depeg producer.
Declared tracked-stablecoin outputs also carry an additive downstream-resolution disclosure. When an output row in the same snapshot is not resolved, the otherwise independent upstream row publishes outputDependencyResolution: { stablecoinId, resolutionState }; the field is omitted when every observed output row is resolved. This marker does not suppress a valid same-run measurement, change routeStatus, downgrade confidence, alter any score, or gate Safety Score V9 Exit eligibility. It is stored in the existing redemption details_json envelope, so it adds no typed D1 column and requires no migration or redemption methodology-version bump.
Exact-request execution certificates (local V10)
Safety Score methodology 10.0 admits new unsupported-rail execution only through an optional executionCertificate on the existing route observation, paired with executionModelId. Legacy documented issuer routes remain separate and retain their current charge, including issuer non-disclosure. The reviewed structural registry starts empty; no coin capacity or review identity is authored by this code wave.
shared/types/exit-route.ts owns the strict certificate/review/point/gate shapes. semantic.exit.executionModels in the methodology policy owns admitted model IDs, required gates, exact-request requirements, source/price maximum ages, future skew, permitted capacity bases and certification ceilings. shared/lib/safety-score-v9/exit-execution.ts is the common compiler/evaluator admission authority. New live models currently use a 300-second source/price budget; they do not inherit the more lenient stale-retention treatment of legacy routes. Missing model/review is method-unsupported; a supported read/proof failure is producer-failed; explicit issuer non-disclosure remains issuer-undisclosed. Review identity, deployment, implementation, holder scenario, source generation, canonical-supply-sized request, raw input conversion, every output identity/value, gate clocks and settlement maximum must match. An observed executable zero is distinct from diagnostic/unavailable state.
The implemented permissioned adapter is worker/src/lib/exit-execution/securitize-offramp.ts. It pins the off-ramp proxy/implementation, asset/provider/output identities, dependency bytecode and EIP-1967 implementation bindings, then reads pause, transfer-not-burn, internal two-step semantics and provider inventory. Each passing prefix receives its own NAV/fee/minimum-output quote and actual holder redeem(amount,minOutput) eth_call, with real token balance/approval prerequisites and no state overrides. It also obtains gas estimate/gas price and requires a current native-USD reference. A view quote alone, provider inventory alone, absent approved holder context, failed execution or unknown gas value is diagnostic. Internal two-step transfers are one transaction; external queues/issuer processing are not silently recast as atomic.
The certificate records executable input notional separately from retained output USD. Output legs keep their real denomination (for example, VBILL's RLUSD, FUSD's USDT, scrvUSD's pool USDaf versus separate vault crvUSD). Integer raw-unit arithmetic is preserved until the existing numeric valuation/curve boundary. Execution fees and gas affect execution cost; the output-valuation mechanism applies output-price retention once. Unknown valuation of one basket leg invalidates the basket. Shared provider/token inventory, PSM/vault resources and settlement accounts are common-mode resources, not additive independent liquidity.
buildRedemptionBackstopEntry appends new producer observations without replacing its documented issuer route. buildSafetyScoreV9RouteReviews uses certificate-specific holder/access/settlement/resource/output semantics rather than inheriting one issuer entry's terms for every rail. The compiler admits the exact canonical-supply stress request and the evaluator independently rechecks current policy, review, clock and request before accepting the point; missing exact points cannot fall back to smaller legacy curves. Public projection excludes customer identities, prerequisites, evidence IDs and producer configuration.
Other approved model IDs are explicitly research-only/diagnostic in policy until their exact callable identity and model prerequisites exist. Queues require funded claims and a proven completion maximum, not accepted requests, epoch length or T+ estimates; bridge withdrawals require the complete initiation/proof/finalization/destination-liquidity path; physical-to-USD retains its existing separate documented/modelled method and must not become an observed certificate. Mento, vault, basket, conditional, rate-bearing and uncovered DEX families are not activated by this registry's existence.
The authoring inventory and live diagnostic are internal working notes and BuildExit-live.mts. The diagnostic invokes the production runtime against current APIs/RPC, records the observation clock, response hashes, exact requests and honest failures, and writes BuildExit-live-observations.json. It is injectable only into a separately labeled copy of a capture; it never backdates evidence, rewrites canonical supply or claims a production score. Later live facts must fail admission at an older capture clock, and an attribution-only diagnostic must preserve all unrelated observations and recompute normal input fingerprints. No cron schedule, methodology version or deployment changes are part of this capability.
Route Modeling
Config Registry
Each configured coin declares:
routeFamilyaccessModelsettlementModelexecutionModeloutputAssetTypecapacityModelcostModel- optional
costModel.feeDescription - optional
holderEligibility - optional
routeStatus(open,unknown, or reviewedsuspended) - required
routeSuspensionwhen suspended: exactrouteId, namedchannel,suspendedAt, reason,reviewer,reviewedAt, and primary-source URL/quote pairs - optional
routeExitCorrelation - optional
totalScoreCap - optional
outputAssets - optional
unresolvedOutputAssetKeysandunresolvedOutputDisposition - optional
docsandreviewedAt - optional
notes - optional reviewed overlays
v9RouteCostTerms,v9RouteReviewTerms, andv9ComposedDexExit. Av9RouteReviewTerms.settlementModelis the canonical reviewed settlement fact for both the standalone producer and V9: conservative corrections remain admissible, while a favorable correction requires its cited review to remain inside the 365-day evidence window. The remaining V9 projections stay consumer-specific.
The public registry import lives in shared/lib/redemption-backstops.ts. The actual config inventory is split by route family under shared/lib/redemption-backstop-configs/ to keep review and change scopes small.
outputAssets records concrete holder-route outputs, not every reserve asset. Stable outputs use tracked stablecoin IDs; collateral outputs use canonical asset:<symbol> keys. Configured baskets are limited to 16 members, matching the ExitRouteOutput.assetKeys bound. Leave the field unset when the published route is incomplete or when its tracked and untracked members cannot all be represented: an incomplete subset must not turn an unresolved basket into a resolved one. When a complete reviewed route contains untracked assets, unresolvedOutputAssetKeys may preserve the exact identities for diagnostics; those keys do not resolve or score the output.
For offchain-issuer routes, a non-empty explicit outputAssets list with stable-single or stable-basket takes precedence over the legacy fiat default. It identifies the actual payout, not the input token's NAV denomination or reserve holdings. Physical-commodity delivery and unresolved commodity collateral retain precedence. Issuer rails never infer a payout from variantOf; unreviewed issuers without explicit stable outputs retain the legacy fiat projection, which is a compatibility default rather than new evidence of bank settlement.
The September 30, 2026 bounded payout review curates thBILL and MXNB's modeled Juno conversion rail as USDC/USDT, pathUSD, USYC Teller, pUSD and USDO as USDC, and StandX DUSD as USDC/USDT; HLUSD was already explicit. USDN is unchanged because current Noble material does not confirm the former Express USDC payout. Entry sources and dated notes own the evidence. Multiple listed outputs retain conservative stable-basket quality 80 and weakest-price semantics: they are not invented equal-weight portfolios or independently scored holder-choice branches. A single tracked payout has quality 100 at par, like fiat, but still requires captured price evidence; a missing price remains unresolved.
The September 30 OUSD promotion adds a Bridge verified-customer USD redemption route with documented eventual full-supply capacity. The October 1 review records Bridge's zero OUSD issuer fee as fixed 0 bps; settlement stays days with no reviewed completion SLA, because Bridge's two-business-day term bounds only post-compliance processing. Account and compliance restrictions, bank/partner/network charges, and unbounded final bank receipt remain disclosed. Its self-reported reserve mix cannot establish immediate executable capacity without an independent reserve report. The public Bridge redemption portal did not list OUSD at review, so retail portal access and chain-specific intake rails remain unverified. Tempo DEX swaps remain secondary-market liquidity rather than a second redemption backstop; a DEX alternative requires supported discovery and admitted exact same-notional execution evidence, as described in DEX liquidity.
Reviewed issuer routes. The source-reviewed issuer routes in shared/lib/redemption-backstop-configs/offchain-issuer/discovery.ts follow the thUSD bounded-terms-gap precedent: inherited supply-full is eventual-only diagnostic modeling, not a documented executable buffer, measured capacity or immediate supply-wide exit. Each entry retains its eligibility and named capacity, settlement and all-in cost gaps. A published reserve balance, fund AUM, initial subscription minimum, operational target or daily redemption ceiling is not promoted into a funded same-notional capacity floor. No reserve hot-buffer ratios or unpublished settlement durations are inferred.
Concrete token payouts are preserved: MoonPay PYUSDx terms admit only onboarded eligible-counterparty PYUSD payouts, not fiat or a permissionless unwrap; Coinbase's custom-stablecoin guide confirms ONED's external Base deposits and 1:1 USDC conversion; Ondo's investor guide names instant USDon and inventory-conditioned USDC, not GLD ETF-share or physical-gold delivery. GLDon retains both tracked outputs conservatively, rather than fabricating an equal-weight basket. USCC models its explicitly documented USDC payout choice; its separate USD wire option is not blended into a mixed payout basket.
EURW's redemption policy and Stable Mint terms §9 establish holder-wide par bank redemption after onboarding and zero issuer redemption fees. Third-party bank/network charges and undisclosed bank-credit completion timing remain gaps. Institutional and licensed-service-provider routes do not imply retail issuer access: FRNT's two-business-day submission provision does not promise final bank receipt, and Agant's immediate conversion description does not establish a numerical bank-credit SLA.
Fund routes preserve ordinary NAV redemption and restrictions rather than importing unlimited instant liquidity. BRSRV/JLTXX retain cash shareholder processing and suspension exceptions; FILQA models only the documented USD cash branch, not unenumerated distributor-approved stablecoins. chfSAFO retains CHF settlement, business-day cutoffs and the 25% redemption gate; neither EUR rails nor an unsupported CHF-to-USD conversion is credited. STBT's published T+0 USD 1M threshold is a limit, not funded capacity. Its 0% issuer redemption fee is not an all-in zero-cost promise under liquidation-loss and transaction-cost clauses. CUMIU retains its USD 1,000 Class I redemption minimum and distinct redemption/anti-dilution charges. FIUSD's historical client tariff and uMINT's historical distributor minimum/timing are not current binding guarantees; native uMINT production-redemption existence does not confirm today's settlement asset or PPM terms.
GoldZip documents 1,000-XGZ eligible physical-bar redemption after AML checks. XGZ retains physical-delivery-only output, unbounded fees/logistics/timing and sameNotionalEligible: false; the 0.01% sender transfer fee is not a redemption fee. No physical-to-USD composed capability is authored without bounded delivery evidence. Supercoin terms §7.1 place direct app redemption in the future and disclaim guaranteed exchange off-ramp price, liquidity and settlement. ZARsc therefore remains unconfigured with a dated reviewed disposition rather than borrowing the future app's two-business-day promise.
Reviewed channel suspension (local V10)
routeStatus: "suspended" requires a dated, sourced routeSuspension review naming the exact configured redemption:<asset-id>:<family> route. The registry rejects a different asset/family identity; capture-time admission rejects a later review. A suspended channel has null standalone immediate/eventual/scoring capacity and scores, and compiles into a diagnostic route with no executable request or curve. Public standalone status reasons, Safety Exit reasons and alternative-route diagnostics disclose the channel and reason. This is unavailable channel evidence, not a measured zero.
DEX observations, separately identified issuer routes and execution certificates keep their own scoring evidence. If there is no scored alternative, or the best measured alternative scores zero, a suspended channel cannot certify total exit failure: the portfolio retains the existing missing-same-notional-route bounded-unknown floor, without no-viable-exit-path or measured-adverse total-exit attribution. The other routes' own traces remain unchanged. This record never changes lifecycle, wind-down, holder rights or reserve evidence.
VNXAU, reviewed October 2, 2026. The June 19 primary notice suspended the legacy vnx.li platform exchange from June 30 at 18:00 CET and ended its remaining-balance withdrawal window July 31 at 18:00 CET. Only that legacy channel is reviewed suspended. VNX Global terms §6 separately describe discretionary, resource-dependent commodity-token exchange at my.vnx.io, including VNXAU for fiat or other digital assets. That channel has no admitted capacity, complete payout set or settlement maximum and earns no credit; it is not treated as suspended by the legacy notice. The Metals.io market diagnostic remains separate. No currently bounded physical-release timing or current reserve composition is established, and the production-capture smoke still publishes VNXAU NR, not F.
Output-key identity contract
Output identity is kind-specific and must remain stable from the configured route through the producer observation and Safety Score V9 review:
tracked-stablecoinoutputs use tracked stablecoin registry IDs. Unknown IDs are rejected rather than inferred from symbols.collateraloutputs use the reviewed non-trackedasset:<symbol>vocabulary derived from the redemption config registry. These keys are deliberate collateral identities, not aliases for tracked stablecoins.unresolved-assetoutputs may use only the exact keys declared byunresolvedOutputAssetKeys; they remain unresolved and are never promoted by a consumer.
The registry validator enforces configured identities, while the V9 review boundary rejects unknown identities and preserves a captured identity mismatch for diagnostics rather than rewriting the producer's observation. USD0 (usd0-usual) therefore keeps its reviewed mixed-collateral outputs asset:usyc, asset:m, and asset:ustbl; renaming them to tracked IDs or moving them to an unresolved namespace would silently break exact output matching and valuation.
July 2026 Output Reconciliation
The 2026-07-15 source pass made the following config-only evidence rulings. It did not change scoring weights or formulas.
| Route | Ruling | Primary evidence |
|---|---|---|
| nTBILL, nBASIS, nWISDOM | Stable basket: USDC + pUSD | Nest available vaults |
| nOPAL | Stable basket: USDC + pUSD + USDT | Nest available vaults |
| USSD | Stable single: frxUSD. The deployed BrandedCustodian's custodianTkn() returned Sonic frxUSD and redeemFee() returned zero at Sonic block 75,971,769; the broader supported-USD-asset wording describes upstream/cross-chain infrastructure, not this direct holder contract. | Sonic USSD docs, verified BrandedCustodian |
USDm (cusd-celo) | Stable basket: USDC + USDT, matching the two reviewed direct Celo V3 FPMM output pools measured by live reserve sync. | Mento V3 reserve, Mento V3 FPMM |
EURm (ceur-celo) | Stable single: USDm, represented by the approved tracked ID cusd-celo, matching the current Celo EURm/USDm counter-asset pool. | Mento V3 reserve, Mento V3 FPMM |
| ftUSD | Stable basket: USDC + USDT. The current buy flow names both inputs and the sell flow returns the selected input asset at the prevailing rate. Sonic USSD is reserve inventory, not a verified holder redemption output. | Flying Tulip ftUSD |
| hyUSD | Fail closed with routeStatus: unknown and no concrete outputs. Current docs distinguish V1's SOL-only LST pool from V2's SOL/BTC/USDC pools, but do not reconcile the active tracked deployment and complete routable output set. | Hylo multi-asset architecture, Hylo dynamic routing |
| dUSD | Remains an unresolved basket. dTRINITY marks 11 symbols redeem-eligible across three deployments, but Katana's vbUSDC and vbUSDT have no tracked Pharos IDs. The complete 11-member set is retained in unresolvedOutputAssetKeys; publishing only the nine tracked economic assets would falsely resolve it. | dTRINITY dUSD |
The 2026-07-26 follow-up resolved ZYS to the exact tracked ZSD output and made three other known-but-unpriceable routes explicit without promoting them: DLLR records ZUSD + DOC as an unresolved basket, wiTRY records untracked iTRY, and AZND remains an anonymous unresolved asset because Mu Digital's primary materials do not name the redemption settlement asset.
The 2026-07-19 second output pass made the following rulings over the routes that stayed unresolved after the first pass. It did not change scoring weights or formulas; the two passes share the same bar — a published output set must be complete enough that declaring it does not misstate the documented holder route.
| Route | Ruling | Primary evidence |
|---|---|---|
| AUDm, BRLm, CADm, COPm, GHSm, KESm, ZARm (broker pools), CHFm (FPMM) | Stable single: USDm (cusd-celo). Mento V3 CDP docs name USDm as the collateral asset of the FX-stable path, and every FX Broker/BiPoolManager exchange settles in USDm (the rebranded cUSD). The 2026-07-15 pass left these blocked on cusd-celo being untracked; it is now tracked and priced. | Mento V3 CDP, Mento BiPoolManager |
| USDai | Stable single: PYUSD via the burn-and-withdraw path; capacity now reads the same-run PYUSD balanceOf(hub) telemetry from the usdai-hub adapter, which fails closed on pause, identity, or liability-reconciliation drift. | USD.AI buy / stake |
| U | Rechecked 2026-08-27: remains unresolved. The terms define Eligible Assets as issuer-approved assets that may include USD, certain stablecoins, and other assets designated over time; they also allow United Stables to satisfy redemption with any eligible reserve asset, including cash, at its sole discretion. They do not establish a complete guaranteed payout composition. | United Stables terms |
| inALPHA | Type corrected nav → stable basket (USDC + pUSD), matching the four sibling Nest vault entries retyped on 2026-07-15; the payout assets were already declared and delayed-NAV settlement is unchanged. | Nest liquidity and redemptions |
| sAID | Type corrected nav → stable single: AID. The withdrawal pays AID (a tracked $1-target stablecoin); the unstaking-NAV conversion-rate and haircut caveats stay in the queued rules-based-nav execution model. | GAIB sAID docs |
| ACRED | Type corrected nav → stable basket: USDC + USDG, the off-ramps named on the current Securitize fund page for the quarterly repurchase cycle. | Securitize ACRED fund page |
| USDu | Type corrected stable-single → mixed collateral: SOL + BTC + ETH. The terms define redemption as burning USDu for a pro-rata share of the underlying collateral, and the delta-neutral design page names SOL, BTC, and ETH as the collateral classes; no single-stablecoin payout is documented. | Unitas terms of service, Unitas delta-neutral stability |
| EUR0 | Mixed collateral: asset:eutbl. The EUR0 product docs state permissioned redemption burns EUR0 to receive euTBL (Spiko EU T-Bills MMF) at par, and EUTBL is the sole EUR0 collateral entry in the tech docs. | Usual EUR0 product docs |
| SILK | Rechecked 2026-08-27: remains unresolved. Shade Lend lets a holder choose a vault and receive pro-rata vault collateral, but public issuer docs do not publish a canonical current vault whitelist. The set is governance-mutable, so the former sSCRT/wBTC/USDC subset was not a complete payout composition. | Shade Lend stability mechanisms |
| USDp (Parallel) | Mixed collateral: frxUSD, sfrxUSD, USDe, sUSDe, USDS, sUSDS, USDC, ygamiUSDC — the full documented Parallelizer backing set including the untracked Avalanche ygamiUSDC vault token. DAO-mutable. | Parallel USDp implementation |
| reUSD (Resupply) | Mixed collateral: crvUSD + frxUSD. Resupply docs state all reUSD collateral backing is crvUSD on Curve Lend or frxUSD on Frax Lend, and the redeemer chooses which pools to redeem against. | Resupply collateralized debt positions |
| satUSD | Rechecked 2026-08-27: remains unresolved. River's redemption docs describe a $1 collateral exit from least-collateralized positions, while its FAQ names BTC, ETH, BNB, and other liquid staking tokens as collateral. The public materials do not enumerate the complete eligible LST inventory, so a BTC/ETH/BNB subset is not a complete payout composition. | River satUSD redemption docs, River FAQ |
| srUSDe | Stable basket: USDe + sUSDe. Strata's current FAQ identifies both as redemption outputs, with instant sUSDe settlement and a seven-day USDe cooldown. | Strata srUSDe market, Strata FAQ |
| UTY | Rechecked 2026-08-27: remains unresolved. XSY says the issuance contract redeems UTY for approximately $1 in value, but does not name the payout asset; its UTY overview says holders have no ownership rights over specific underlying assets. | XSY UTY peg-arbitrage docs, XSY UTY overview |
| AZND, wiTRY, DLLR, dEURO, NECT, scUSD, ZYS | Remain unresolved. AZND's payout asset is undocumented; wiTRY pays untracked iTRY; DLLR's Mynt basket includes untracked ZUSD; dEURO's permissionless collateral onboarding means no fixed documented output set (and its modeled redemption route is not described in current primary docs); NECT and scUSD primary sources name outputs only as examples; ZYS pays ZSD whose price feed is currently missing. | — |
| cUSD (Cap) | Stable basket remains USDC + WTGXX. The live Cap vault producer now preserves the complete proportional value weights and the reserve-value-per-cUSD output unit, with WTGXX valued from its tracked timestamped Chainlink NAV feed in the same run. The V9 consumer can therefore value this exact live basket without inventing a WTGXX peg row or a symbolic $1 assumption. | Cap vault, WTGXX Chainlink NAV feed |
| srUSD, wsrUSD (Reservoir) | Stable single: USDC. The modeled holder path composes the wrapper or srUSD exit into rUSD with Reservoir's downstream PSM, whose documented liquid redemption asset and capacity basis is USDC. The intermediate rUSD claim is not treated as the final unvalued output. | Reservoir savings, Reservoir PSM |
| pmUSD, reUSD (Re Protocol), USD3 (Reserve) | Already declare complete outputs; they stay unresolved only because an output leg lacks a current price (susds-sky, susde-ethena, and steakusdc-steakhouse have no peg row). Blocked on price coverage, not on output curation. | — |
September 2026 Noon Route Corrections
The 2026-09-22 Noon review corrected the two Noon route models below. It did not change scoring weights or formulas.
| Route | Ruling | Primary evidence |
|---|---|---|
USN (usn-noon) | Issuer-processed rail: settlementModel: "days" with an exact 7-calendar-day bound (settlementDelaySec: 604_800) read from Terms-of-Service §6's five-Business-Day processing commitment, rules-based-nav execution, and the §29 discretion to gate redemptions. Redemption is KYC-gated and the claim is unsecured debt of the issuer. Fees stay undisclosed-reviewed (the fees page is non-binding and publishes no schedule against §7's right to charge), and capacity keeps its 15% supply-ratio heuristic with the majority private-credit reserve rationale. | USN Terms of Service, Noon fees, Noon liquidity |
sUSN (susn-noon) | Request/claim rail with a live on-chain settlement bound: the registry async-request marker is removed, the reviewed settlementModel is days, and settlementDelaySec is the handler's live withdrawPeriod() (604,800 seconds today), with capacity = measured idle USN published as live-direct-bounded. The one-transaction whitelisted path is a documented fast path only; the modeled rail is the holder request/claim. Access and the 65-point route cap are unchanged. | Noon minting and redemption, sUSN staking vault, Noon WithdrawalHandler, WithdrawalHandler admin timelock |
October 2026 Output and Coverage Review
The 2026-10-01 pass distinguishes output identity from executable capacity, settlement, and same-notional comparability. A known payout does not prove an open route, a fee ceiling, or a completion SLA. No scoring capability or equal-weight portfolio is introduced.
| Route | Current ruling | Primary evidence |
|---|---|---|
| scrvUSD | Explicit single output crvusd-curve at the vault exchange rate. Direct Ethereum withdrawal has no delay or lock-up; cross-chain swaps remain separate market routes. This holder route does not resolve the separately inventoried scrvUSD/USDAF DEX output-valuation gap. | Curve withdrawal guide |
| apxUSD | Explicit single USDC output at Redemption Value: preferred shares are liquidated, not paid to the holder. Existing rules-based-nav execution applies; a V9 settlement terms gap withholds any unsupported atomic or bounded-time claim. | Apyx apxUSD product |
| U, UTY | Still issuer-undisclosed: eligible-asset examples or approximately $1 of value do not identify a complete guaranteed payout set. | United Stables terms §6.3, XSY peg arbitrage |
| HOLLAR, wiTRY, DLLR | Preserve untracked output identities rather than aliasing aUSDC/aUSDT to USDC/USDT, iTRY to wiTRY, or ZUSD to DOC. HSM and Mynt sales select one output; no pro-rata weights are inferred. Runtime governance/asset-registry reads and admissible external-output valuation remain prerequisites. | HSM referendum 367, Brix issuer audit scope, Sovryn Dollar |
| dEURO | Keep the complete reviewed bridge identities unresolved; current docs confirm balance-limited swaps into other Euro stablecoins, not redemption into a borrower's posted collateral. Unsupported members cannot be dropped to make the route scoreable. | dEURO stablecoin bridges |
| KAU, GGBR, PGOLD, XAUm, DGLD, CGO | Physical XAU delivery remains explicitly non-comparable with same-notional fiat exits. Existing units, minimum lots, and unbounded delivery charges remain; knowing the delivered metal does not make a physical shipment an atomic USD payout. GGBR's public app now quotes 5–7 business days of processing, not final delivery. | Kinesis physical redemption, Goldfish redemption, PGOLD physical guide, XAUm redemption, DGLD delivery, CGO terms |
| GLDT | Physical gold through the GLD NFT reverse swap is already structured. Its captured missing peg reference is a price-input prerequisite, not permission to replace delivery with fiat or rework the output identity. | Gold DAO physical redemption |
| GLDY | No primary minimum physical-delivery lot or complete cash-payout terms were established. Output stays unresolved; secondary primary-market listings cannot supply missing issuer terms. | Streamex GLDY |
| VNXAU | Route status is unknown: the current notice suspends platform exchanges from June 30 and ends remaining-balance withdrawals July 31. Historical one-gram tokens and one-kilogram delivery lots are not promoted as a currently usable rail. VNX Global's maintained fiat redemption docs cover VCHF/VGBP, not VNXAU. Output disposition is issuer-undisclosed, with no invented asset keys: no complete current payout set is established, so reviewed-external is not justified. | VNX suspension notice, VNX Global scope |
| eEARN | USDC output remains identified, but an operator-processed request/claim path has no proven finite completion bound. Idle USDC is not a settlement SLA. | eEARN vault |
The active-unconfigured disposition registry was re-reviewed against current primary pages, with failed-source outcomes explicitly separated from historical findings. Solomon's replacement USDv now has a reviewed defer disposition: the issuer confirms permissioned burning for an approved payout asset but does not publish complete payout identities, executable liquidity, fees, or a settlement bound. Reserve USDC/USDG and market swap pairs are not substituted for guaranteed redemption outputs. Solomon's direct mint/redeem page owns that distinction.
Three prior blockers were corrected without inventing routes: QiDao's recovered PSM page confirms a three-day queue but not a numeric redemption fee or current capacity; LeverUp documents conditional, quota-based USDC redemptions rather than only borrower repayment; SoulPeg promises reverse wrapper conversion but still lacks a complete secondary-holder USDC withdrawal specification. These remain deferred pending deployed-route and capacity evidence.
The baseline V4-43 heuristic queue was reviewed without promoting reserve backing, liability ratios, or a one-off balance into a durable capacity floor. JPYC Prepaid v1's issuer config was removed: the issuer notice ends v1-to-v2 exchanges and states cash refunds are not planned; the redeemable funds-transfer JPYC is a different tracked token. Indigo's current assets API now lists only USDM and USDCx PSM outputs, so absent USDA is removed; its historical capacity ratio remains labeled heuristic, and raw minRedemptionOrderAmount: 10000 is not claimed to mean 10,000 tokens. Monetrix's moved redemption guide restores maintained evidence for the USDC request/claim route and its governance-adjustable cooldown, while the capacity ratio remains heuristic.
The removed USDA leg is specific to Indigo's current PSM, not a withdrawal of USDA's tracked identity or its separate Anzens issuer redemption config. Anzens terms still describe USDA redemption for fiat with account credit within two business days. Indigo output valuation regressions retain exact six-decimal Cardano deployments for USDM and USDCx and use an October scoring clock that admits the October-reviewed output facts; missing/adverse prices and stale evidence remain unscoreable.
Noon's moved liquidity, mint/redeem, fees, and binding USN terms were recovered through its current index. Operational pages publish a 20%-of-TVL daily limit, T+0 within 24 hours, and zero protocol fees excluding gas; the terms retain five Business Days, applicable swap fees, and extraordinary gating. TVL is not established as circulating USN supply, so the existing 15% capacity estimate stays explicitly heuristic rather than becoming an immediate buffer or a 20%-of-supply guarantee. capacityModel.dailyLimitUsd remains unset: a TVL percentage without a same-run TVL measurement is not a configured USD cap. The exact numeric quota is preserved here and in the cited primary source; config notes describe the unmodeled TVL-relative quota rather than asserting an unsupported numeric daily capacity limit.
Capacity Models
Capacity resolution is dispatched in worker/src/lib/redemption-backstop/capacity.ts, with per-model resolvers under worker/src/lib/redemption-backstop-capacity/ (supply-full.ts, supply-ratio.ts, fixed-usd.ts, reserve-sync.ts); worker/src/lib/redemption-backstop/sources.ts orchestrates the entry build and calls into it.
| Capacity model | Resolution |
|---|---|
supply-full | Exposes full current supply as eventualRedeemabilityScore, but leaves current scoring capacity empty because immediate buffer is not separately quantified |
supply-ratio | Immediate modeled capacity equals supplyUsd * ratio, optionally capped by a documented daily limit; this is heuristic unless the config explicitly opts into stronger confidence |
fixed-usd | Immediate modeled capacity equals a reviewed absolute USD buffer, clamped to current supply when supply is known; missing-supply rows keep the USD amount visible but use conservative absolute-tier scoring |
reserve-sync-metadata | Reads normalized reserve_composition.metadata.redemption.capacityUsd / capacityRatioOfSupply, from the latest fresh live snapshot only when the adapter explicitly exposes redemption-capacity telemetry and the snapshot carries scoring-grade freshness evidence. The telemetry must isolate assets immediately executable through the holder route; mixed reserve or accounting buckets remain contextual backing evidence. Degraded snapshots still fail closed by default, but specific lower-bound-only warning classes can be allowlisted per route when they indicate reserve completeness limits rather than broken telemetry. Routes can also fall back to a reviewed configured ratio or USD amount when public docs publish a hard primary-market buffer floor. Full-supply eventual capacity is emitted only when the config explicitly sets eventualCapacityModel: "supply-full" and carries reviewedAt plus supporting route sources. |
Rows may include capacityProfile, which separates immediateUsd, dailyLimitUsd, queuedUsd, eventualUsd, scoringUsd, scoringHorizon, and capacityProfileConfidence. Legacy immediateCapacityUsd, immediateCapacityRatio, and capacityScore remain populated for compatibility. Reserve-sync backing or total supply is not evidence that the holder route can eventually redeem all supply; eventual capacity therefore remains absent unless that route-level claim passes the explicit reviewed opt-in.
For positive current supply, immediateCapacityRatio = immediateCapacityUsd / supplyUsd and scoringCapacityRatio = scoringCapacityUsd / supplyUsd, after the applicable supply and daily-limit bounds. The issuer-reported ratio remains nested source diagnostic telemetry; it only infers a USD amount when the source omits one, never overrides the ratio of the finalized amount. Missing or zero supply leaves these ratios unavailable. This corrects the standalone capacity score and display; V9 does not consume CDP capacity ratios.
The internal evidenceObservedAt is the validated nested redemption.sourceTimestamp, or, for same-run-onchain / same-run-api telemetry without one, the producing reserve snapshot's fetchedAt. Exit observations use that clock for observedAt and age; entry updatedAt remains publication time. Missing evidence time cannot establish a scoreable live-direct observation. Documented-bound observations use their direct evidence time when available and otherwise retain the terms-review date. A retained 9h, 40h, or 47.9h snapshot is not age zero: V9's existing 8h redemption evidence budget rejects its current-evidence eligibility even while the reserve snapshot remains admitted. Nested source timestamps older than the stricter adapter/coin reserve source-age budget are rejected before persistence; the existing two-day reserve freshness fallback applies when neither declares a budget.
Live reserve adapters emit a nested metadata.redemption object for redemption-specific telemetry. The validator rejects malformed or unsupported redemption telemetry before persistence, including negative capacity, capacity ratios outside 0..1, negative fees, capacity fields from adapters that declare no capacity support, fee fields from adapters that declare no fee support, or direct-capacity tiers emitted by proxy-only adapters. The store-row decoder still reads legacy flat capacity/fee fields from historical rows (30-day retention) and maps them into the nested contract at decode time, but no producer writes them.
Sky DAI and USDS now use the live sky-makercore PSM USDC balance as their immediate redeemable bound when that telemetry is fresh, with the prior 33% reviewed heuristic retained only as fallback.
USDe uses the live ethena adapter's same-run reads of the EthenaMinting contract's own USDT/USDC balances as direct redemption capacity, gated on a usde() identity check and readable positive per-asset/global max-redeem-per-block guards. Those positive caps are route guards and diagnostics, not numerical caps on the multi-block payout buffer; any failed read withholds the telemetry entirely and the reviewed 0.5% fallback ratio takes over.
thUSD is modeled in stablecoin-redeem, consistent with usde-ethena, as an executed USDC/USDT rail with whitelisted-onchain access, whitelisted-primary holder eligibility and immediate settlement. This scope describes the executed on-chain burn/payout after Theo's operator submits the signed order, not an API-submission SLA or permissionless access. The theo-thusd-redemption adapter measures supported-asset Cash Wallet capacity as the sum of min(balance, allowance to ThUSDMinter) at one block, using reserve-sync-metadata / hot-buffer with no fallback ratio or USD amount. There is no assumed replenishment or permanent liquidity floor. This executed-rail curation is not a separate Safety Score version change. See Theo mint/redeem and verified minter source, reviewed 2026-09-30 at Ethereum block 26088429.
Reservoir rUSD, srUSD, and wsrUSD use the live reservoir adapter's same-run on-chain reads of the USDC Peg Stability Module (pinned address, underlying() identity check, underlyingBalance(), paused()) as the terminal-leg capacity bound with route status open/paused from the same reads; the balance-sheet USDC bucket stays diagnostic and a failed read withholds the redemption block, falling back to the documented 25 bps minimum PSM balance.
USDm uses the two reviewed V3 USDm/USDC and USDm/USDT pools, replacing destroyed V2 exchanges. Its observer pins one Celo block, verifies both token identities and output decimals, and requires actual balances to equal stored reserves for both tokens (donations or deficits otherwise change swap input accounting). The observer rounds input down and admits only the actual quoted output strictly below output reserves. Both token trading-limit packets must support that inventory under conservative headroom (no assumed reset or input-fee credit), and the same-block oracle quote must cover it; any missing or binding guard leaves capacity unresolved. Distinct pool addresses prevent double counting. The route reports the higher current lpFee() + protocolFee() across the two pools.
Mento FPMM pools (JPYm, CHFm, EURm) use the same bounded plural observer as USDm: each run verifies configured input/output identities and decimals, synchronized reserves and balances, actual quoted output, trading-limit headroom, and a combined lpFee() + protocolFee() cap of 200 bps.
cUSD now uses the live cap-vault onchain adapter for bounded current redemption capacity, scoring against unpaused available vault balances rather than full eventual basket redeemability. The producer also binds the complete USDC + WTGXX output weights and aggregate unit value to the same reserve snapshot, using the tracked timestamped WTGXX Chainlink NAV feed; output valuation fails closed if that source-bound basket fact is unavailable.
USD3 now uses the live 3jane-usd3 onchain adapter for fee-free, bounded USDC redemption capacity from availableWithdrawLimit(address(0)); credit NAV outside currently redeemable waUSDC liquidity is not scored as an immediate exit.
LUSD now uses the live liquity-v1 onchain adapter for bounded current direct capacity, scoring against TroveManager.getEntireSystemDebt() when the 4-hourly reserve snapshot is fresh and clean rather than the old static full-supply model.
BOLD, Base Dollar BD, feUSD, USDQ, NECT, and CDP use the live liquity-v2-branches onchain adapter for bounded current direct capacity rather than the old static full-supply model. BOLD and BD use their same-run TroveManager mechanism packets to include only branches explicitly reporting redeemable = true; those route predicates support current on-chain route status. Configs without a mechanism-redeemability packet still publish aggregate ActivePool debt as capacity, but their route status remains unknown / static-config unless an explicit shutdown observation establishes degradation. An unreadable required mechanism packet leaves the route unrated.
meUSD now uses the live liquity-native-active-pool onchain adapter for Mezo's native ActivePool shape, scoring against latest contract debt only when the same-run collateral, TCR/MCR, and fee telemetry is fresh and clean.
reUSD now uses the live resupply-pairs onchain adapter for bounded current direct capacity, scoring against aggregate RedemptionHandler.getMaxRedeemableDebt(pair) only when the same-run handler guard state shows permissionless redemptions are open. If the guard is closed above the threshold, the route is marked cohort-limited and does not enter V9 Exit.
Re Protocol reUSD now uses re-metrics instant redemption vault capacity from the official metrics payload as same-run API telemetry, retaining a reviewed fallback because redemptions above the instant vault capacity can spill to the queue.
fxUSD now uses f(x)'s protocol pool API debt balances as live proxy capacity, while USDaf uses Liquity-v2 branch ActivePool debt as bounded same-run on-chain capacity, with branch shutdown status and the live registry redemption fee. JupUSD uses Jupiter's public transparency API for current USDC/USDtb holdings and oracle route-status context, with the previous 10% reviewed buffer retained only as fallback.
M0 wrappers wM, USDSC, and USDnr use m0-wrapper-underlying capacity telemetry from the underlying M token balance. Balance-only wrapped-m paths remain unknown / static-config; the m-extension wrappers (USDSC on Soneium, USDnr on Ethereum) additionally require their reviewed SwapFacility and approved swapper route, which supplies current on-chain route evidence before whitelisted-primary direct capacity is emitted.
ERC-4626 single-asset wrappers such as fxSAVE, Spark savings wrappers, sUSDS, scrvUSD, and stcUSD use the live adapter's idle underlying ERC-20 balance as current direct redemption capacity when fresh reserve telemetry is available, rather than treating the full wrapper supply as immediately executable. Vaults whose redemption is atomic and unconstrained against an external savings module — currently sdai-sky (legacy Sky DSR pot routing), susdd-tron-dao-reserve (sDAI-fork pot/join exit in the USDD v2 Maker-fork core), and sdola-inverse-finance (unstakes from the fully liquid DolaSavings module), each leaving the vault's idle underlying balance at ~0 despite unconstrained same-block redemption — instead set redemptionLiquidity: { source: "atomic-full-backing" } to score the full convertible backing (ratio 1.0) as same-run live-direct capacity. sbold-k3-capital uses redemptionLiquidity: { source: "sbold-sp-withdrawable" } to read the BOLD amount withdrawable from its Liquity V2 Stability Pool positions through calcFragments(); it stays at documented-bound confidence because unswapped collateral gains are excluded and K3's collateral-health gate can temporarily restrict withdrawals. sfrxusd-frax is another explicit exception: local Ethereum withdrawal is disabled, so redemptionLiquidity: { source: "fraxtal-hop-withdrawable" } observes the Ethereum RemoteHop, Fraxtal Hop, and MintRedeemer path from finalized blocks. It pins all six upgradeable implementations, validates peers, token and oracle identities, verifies the three inventory views, caps capacity by Ethereum sfrxUSD supply, and checks that the Fraxtal Hop can fund the quoted return message. The packet remains diagnostic and non-scoreable because the holder's Ethereum transaction gas and a primary-source or measured completion-time upper bound are unavailable. Failed exact-route or sBOLD reads do not fall back to full NAV or the disabled local sfrxUSD withdrawal path. eearn-ember now uses a specialized fixed-block observer that pins its vault, validator, and protocol-config proxy/implementation identities, reads pause/queue/fee state, and emits zero 300-second capacity because the holder route is operator-batched; idle USDC is diagnostic only. sdusd-dtrinity pins the Ethereum dSTAKE token, router, collateral vault, exact active strategies and conversion adapters, then bounds atomic dUSD output by the live dLEND strategy maxWithdraw cross-checked against available dUSD liquidity and reads the current unstaking fee. Both observers fail closed on identity or required-state drift. Reviewed Yearn V3 vault configs can use redemptionLiquidity: { source: "yearn-v3-withdrawable" }, which measures totalIdle() plus each funded default-queue strategy's min(currentDebt, convertToAssets(maxRedeem(vault))) from the same on-chain run; if any funded strategy probe fails, the route does not fall back to full NAV. Reviewed Morpho vault configs can additionally use Morpho V2 liquidity or Morpho V1 liquidity.underlying as same-run API capacity after validating the exact vault, underlying asset, listed status, and chain id; Morpho V2 forceDeallocatableLiquidity remains contextual and is not scoring capacity.
Since v4.32 these ERC-4626 paths also assert current route openness: the adapter probes the vault's paused() surface (plus isShutdown() for Yearn V3) in the same run and emits routeStatus: "open" only when the capacity read is clean, positive, and no probe reports a halt — a probed true emits "paused", a revert reads as "no pause surface" rather than as evidence, zero capacity stays "unknown", and warnings still force "degraded". This supplies the current-open attribution the V9 exit pillar requires before a live-direct atomic observation is score-eligible; the specialized observers (eEARN, sdUSD, sfrxUSD) keep their own richer route-state contracts. An observer that supplies its own telemetry keeps ownership of its capacity kind, so the generic "positive delay means documented-bound" downgrade does not apply to it.
The V9 adapter applies that current-open gate even when the producer observation is non-score-eligible, so the discounted non-atomic redemption path cannot credit a live-direct atomic/immediate route whose openness is unknown, static-only, or halted.
susn-noon adds a dedicated executable-redemption observer because the Noon rail settles after the WithdrawalHandler's own period rather than a vault-configured cooldown. The observer first reads the staking vault's withdrawal-handler pointer from its pinned namespaced storage slot — the vault exposes no ABI getter — and fails closed when that pointer is unreadable or no longer matches the reviewed handler, so a setWithdrawalHandler swap cannot redirect the read. One same-run Multicall3 packet then verifies the USN asset identity and decimals, and reads totalAssets(), the vault pause flag, the vault's idle USN balance, the handler's usn() identity, and the handler's live withdrawPeriod(). Capacity is the smaller of idle USN and totalAssets(), published with capacityKind: live-direct-bounded, freshnessKind: same-run-onchain, and the handler's period as settlementDelaySec (604,800 seconds today); route status is open, paused, or degraded from those same reads, with a paused vault or a vault holding no idle USN publishing a measured zero. An unreadable or out-of-range withdrawPeriod() fails the adapter closed, leaving the route unrated rather than substituting a fixed delay, and any period change is behind the handler's 48-hour GenericTimelock and applies retroactively to requests already in flight.
GHO now uses tracked swappable GSM backing as a live lower bound even when reserve sync is degraded solely by aggregated residual issuance outside the configured GSM set, because that warning reflects reserve completeness rather than invalid tracked telemetry.
wsrUSD continues to prefer live Reservoir USDC balance telemetry when available, but now falls back to Reservoir's documented 25 bps minimum USDC PSM balance instead of remaining unrated when the live feed lacks a trustworthy source timestamp.
Reviewed bounded primary-market liquidity buffers published by protocols or issuers, such as DOLA's USDS PSM share or JupUSD's USDC buffer, can also use documented-bound ratio semantics when the underlying source is explicit enough to avoid pretending the ratio is merely a blind heuristic.
Reviewed route docs alone are not enough to promote delta-neutral or strategy-backed rails into documented-bound full-supply semantics; those routes still need either an explicitly published immediate buffer bound or fresh live reserve telemetry.
The resulting row is tagged with one sourceMode:
dynamicwhen fresh latest-success authoritative live reserve snapshot metadata is availableestimatedwhen static supply models or configured reserve-sync fallback ratios are usedstaticwhen the route remains configured but the current snapshot could not resolve a usable score, including failure-safe rows written after per-coin sync errors
Provider / Source Definitions
Provider identifiers are defined in shared/lib/redemption-backstop-providers.ts and describe where the capacity number came from, what confidence defaults apply, and whether the source can ever survive a severe-depeg gate.
| Provider | Capacity source | Default source mode | Default confidence | Default semantics | Severe-depeg scoreability |
|---|---|---|---|---|---|
supply-full-model | Full supply model | estimated | heuristic | eventual-only | Not scoreable |
supply-ratio-model | Configured supply ratio | estimated | heuristic | immediate-bounded | Not scoreable |
fixed-usd-model | Fixed reviewed USD buffer | static | documented-bound | immediate-bounded | Not scoreable |
reserve-sync-metadata | Live reserve metadata | dynamic | dynamic | immediate-bounded | Requires strong live-direct route |
reserve-sync-fallback | Reviewed fallback ratio | estimated | heuristic | immediate-bounded | Not scoreable |
sync-error | Failure sentinel | static | heuristic | immediate-bounded | Not scoreable |
reserve-sync-metadata readback can refine confidence to live-direct or live-proxy when the configured adapter declares direct or proxy redemption-capacity telemetry. Proxy and queue telemetry can provide context or lower-bound capacity, but they cannot qualify as severe active-depeg live-direct evidence.
Each row also carries:
resolutionState:resolvedwhen the route produced a usable scoremissing-cachewhen the stablecoins snapshot did not contain the asset or its current supplymissing-capacitywhen the route is configured but current runtime inputs could not produce usable capacityfailedwhen a route-specific resolver failedimpairedwhen the route shape is known but current market or route-availability evidence either contradicts broad par redemption or cannot establish whether an open downside incident is still severe; impaired rows havescore = nullandmodelConfidence = low
routeStatus:openfor normal resolved routes without current impairment evidencedegradedwhen fresh authoritative current evidence confirms severe market-implied impairmentunknownwithrouteStatusSource: market-impliedwhen an open downside incident lacks current authoritative evidence; this withholds the score rather than restoring the static route claimpaused,cohort-limited, and otherunknowncombinations remain available to explicit route-availability sources and backward-compatible legacy rows- whitelist or approved-holder gates should normally be modeled through
accessModel/holderEligibility; usecohort-limitedonly when current route evidence shows impairment beyond that reviewed eligible cohort - unknown route status remains a low-confidence signal unless the capacity evidence is direct live telemetry or a source-reviewed documented bound
routeStatusSource:static-configfor normal config-derived statusmarket-impliedfor both confirmed severe current-depeg impairment and unresolved current-evidence currency on an open downside incident- reviewed adapters may emit
protocol-apioronchainonly when the current run evaluated a route-specific executable predicate; capacity, balance, collateral, TVL, backing, or configuration evidence alone does not qualify operator-noticeis reserved for an explicit reviewed notice; no standalone operator override or route-status feed is wired in the cron path today- merge precedence is live adapter evidence, then static config, with the market-implied overlay applied last unless a strong live-direct route is explicitly open; output impairment or uncertainty cannot use that exception
holderEligibility:- derived from the route access model by default: permissionless onchain routes are
any-holder, whitelist routes arewhitelisted-primary, issuer API routes areverified-customer, and manual routes areissuer-discretionary
- derived from the route access model by default: permissionless onchain routes are
capacityConfidence:live-directfor live reserve-sync capacity sourced from direct current redemption telemetrylive-proxyfor live reserve-sync capacity inferred from a live proxy liquidity bucket rather than a protocol-native redemption-limit feeddynamiconly as a legacy / unresolved reserve-sync bucket when older stored rows lack the richer live-capacity classificationdocumented-boundwhen a bounded model is explicitly configured that way after source review, including reviewed full-supply redeemability where official issuer or protocol terms establish eventual redemption of outstanding supplyheuristicby default forsupply-full,supply-ratio, and inferred legacy rows without stronger evidence
- Reserve-sync capacity now ignores degraded snapshots, weak fee-only adapters, and snapshots that do not carry scoring-grade freshness evidence by default. The only exceptions are route-specific lower-bound warning classes that explicitly preserve a trustworthy redeemable-capacity floor while keeping reserve sync itself degraded for completeness review.
- Immutable fully on-chain systems and reviewed direct issuer / direct redeem routes can use
documented-boundwitheventual-onlysemantics when protocol mechanics or issuer terms establish full-system redeemability directly, even if no separate immediate buffer is measured capacitySemantics:immediate-boundedwhen the model is intended to represent a current redeemable buffereventual-onlywhen the route is scored as eventual redeemability rather than immediate same-size liquidity. Current V9 applies the unified Exit route ladder: reliable reviewed non-atomic issuer/protocol/eventual routes require output, evidence, failure-domain, and capacity gates and receive the applicable delay/confidence discounts. The DEX-gated primary-market bonus was historical V7.05 behavior, not a current scoring path.
capacityBasis(orthogonal tocapacityConfidence: basis describes the model shape, confidence the evidence strength — consumers must read both; apsm-balance-sharebasis can be live-measured or a heuristic guess):- typed evidence basis such as
issuer-term-redemption,full-system-eventual,psm-balance-share,strategy-buffer,hot-buffer,daily-limit,fixed-buffer,live-direct-telemetry, orlive-proxy-buffer fixed-bufferidentifies a reviewed fixed USD buffer (capacityModel.kind === "fixed-usd"), distinct from live-direct or live-proxy telemetry- reserve-sync fallback ratios use the configured
basiswhen present, otherwise route-family defaults such aspsm-balance-share,strategy-buffer, orhot-buffer; they are not labeledlive-proxy-bufferunless live proxy telemetry produced the capacity
- typed evidence basis such as
- Live reserve telemetry fields are additive display/provenance context, not Safety Score eligibility by themselves:
capacityKinddescribes the adapter-declared evidence shape, such aslive-direct-bounded,live-queue,live-proxy-validated,documented-bound,documented-eventual, orheuristicfreshnessKinddescribes the adapter-declared redemption freshness evidence, such asverified-source-timestamp,same-run-onchain,same-run-api,reviewed-static, orunverifiedsourceTimestamp,sourceUrls,settlementDelaySec,queueDepthUsd,dailyLimitUsd,minRedeemUsd, andliveHolderEligibilityare carried through the API/UI when emitted by live reserve adapterssettlementDelaySecis raw nonnegative telemetry: a measured0is an atomic route, not a missing value. The projected exit-route observation window (settlementHorizonSec) is a separate strictly positive integer, so a live positive integer delay becomes the horizon and a zero or absent delay takes the reviewedsettlementModelceiling instead of publishing an invalid zero-second horizon.
feeConfidence:fixedfor bounded bps schedulesformulafor disclosed formulas such as Liquity-style base-rate feesundisclosed-reviewedwhen docs were reviewed but only descriptive fee information is available. It asserts that no bounded number is published — never that the fee is zero
feeModelKind:fixed-bps,formula,documented-variable, orundisclosed-reviewed
modelConfidence:high,medium, orlowrollups used by the API and detail page to communicate fidelitylowfor heuristic-capacity routes, unresolved rows, impaired rows, unclear holder eligibility, stale docs without current route-status evidence, or unknown route status without direct live telemetry or source-reviewed documented-bound capacityconfidenceDetailscan expose the component evidence scores and rollup reasons- the route-status freshness component reaches 100 only for
opencurrentonchain/protocol-apievidence with positive executable capacity; an open route with zero or missing capacity is capped at 70
routeExitCorrelation:independent-issuer-rail,same-stablecoin-pool-backing,same-protocol-liquidity,wrapper-to-parent-dependency, orunknown- retained as legacy diagnostic/display metadata; it has no current scoring effect
- V9 Exit derives route independence from disjoint failure domains and physical-resource keys instead of this tag
Decision (2026-09-21, documented-zero versus undisclosed fees). A reviewed zero or closed fee schedule is a disclosed number and must be encoded as a fixed 0 bps fee carrying the statement that establishes it, not as undisclosed-reviewed. documentedVariableFee still defaults feeConfidence to undisclosed-reviewed, so fourteen shipped offchain-issuer configs currently publish feeConfidence: "undisclosed-reviewed" with feeBps: null beside feeModelKind: "documented-variable" — which also holds their reserve-sync pair below modelConfidence: "high". Separating the two is per-entry source curation, not a mechanical sweep: each of the fourteen needs its reviewed text re-read before its fee is restated. Until that pass lands, the conservative label stands and the published rows understate, never overstate, what the issuer disclosed.
Docs / Notes
docsprefers explicit config-reviewed sources first (docs[]+reviewedAt), then live-reserve display links for reserve-sync routes, then the coin metadata'sproofOfReserves.url, then preferred public links (Docs,Proof of Reserve,Transparency,Website)docs.provenancedistinguishes reviewed route docs from fallback live-reserve, proof-of-reserves, or generic project-link sources so detail pages do not overstate evidence qualitydocs.reviewedAtis the route-review date, not a claim that the rendered fallback link itself was the reviewed source; the detail card now shows review date and provenance togetherdocs.sources[]records structured provenance for what the linked source supports (route,capacity,fees,access,settlement)- The registry check ratchets aggregate source-support coverage and emits per-config warnings when a
documented-boundcapacity route lacks explicitrouteorcapacitysupport. These warnings are backlog controls, not hard CI errors, until the remaining documented-bound source-support gaps are cleaned up. feeDescriptioncarries docs-backed fee text when the route fee is fixed, conditional, dynamic, flat-fee-based, or publicly undisclosednotesmerges config notes plus runtime notes such as stale reserve metadata expiry, conservative fallback use, or live fee fallbackcapsAppliedrecords any score caps triggered during scoring
Cost Modeling
feeBpsis still used only when the route has a bounded fixed basis-point fee that can be represented cleanly in the score model- Explicit issuer statements that redemption charges no fee are modeled as a fixed
0bps schedule rather than as an opaque or variable fee. This applies to the reviewed Spiko funds, Midas mF-ONE, JTRSY, YLDS, EUROP, EUSD, and USD3 routes; the registry validates the complete reviewed ID tables so additions and removals cannot silently drift. - Formula-based routes can also populate
feeBpsfrom fresh latest-success live reserve snapshot metadata when the protocol exposes a current on-chain redemption rate; the route still remains labeled asfeeModelKind = formula - Every on-chain rate probe must explicitly pin the return-value decimal scale; missing scale fails configuration validation rather than silently publishing an unknown fee
- Reviewed fixed-fee routes may also consume fresh authoritative live fee telemetry when the protocol exposes the current active redemption fee and the static config is only a safe fallback bound
feeModelKinddistinguishes fixed-fee routes from documented formulas, documented variable schedules, and reviewed-but-undisclosed fee railsfeeDescriptionis used to surface:- dynamic formulas such as Liquity-style
min 50 bps + baseRate - conditional fee schedules such as borrower-vs-non-borrower redemptions
- flat minimums or bank/network charges that do not map cleanly to one global bps number
- cases where public docs were reviewed but no numeric redemption-fee schedule is published
- dynamic formulas such as Liquity-style
- If live formula telemetry is missing, the route falls back to the reviewed-formula bucket rather than pretending a fixed fee is known
costScoreuses the active-user scenario by default when v4 fee-shape inputs are present; optionalcostScenarioScoresexposes retail, active-user, and institutional route-size scores
Database Schema
Migration: worker/migrations/0000_baseline.sql in the current post-squash tree, plus 0094_redemption_backstop_runs.sql for completed-run snapshot manifests and 0120_redemption_backstop_run_rows.sql for the manifest-scoped current row store. Historical introduction lives in the pre-squash lineage recorded in worker/migrations/MANIFEST.md.
redemption_backstop
Current snapshot table, one row per configured stablecoin.
Key columns:
stablecoin_id— PKscoreeffective_exit_scoredex_liquidity_scoreaccess_scoresettlement_scoreexecution_certainty_scorecapacity_scoreoutput_asset_quality_scorecost_scoreroute_familyaccess_modelsettlement_modelexecution_modeloutput_asset_typeprovidersource_modeimmediate_capacity_usdimmediate_capacity_ratiofee_bpsqueue_enabledupdated_atmethodology_versiondetails_jsonsnapshot_run_id
details_json now also stores routeFamily, provider/source provenance, immediate-capacity fields, optional live telemetry fields, fee fields, resolutionState, routeStatus, routeStatusSource, routeStatusReason, routeStatusReviewedAt, holderEligibility, capacityConfidence, capacityBasis, capacitySemantics, feeConfidence, feeModelKind, modelConfidence, and feeDescription alongside docs, notes, and free-form capsApplied markers such as market-implied-depeg-evidence-uncertain. The v4.42 uncertainty state therefore uses existing JSON fields and requires no typed column or D1 migration.
snapshot_run_id links current rows to a completed redemption_backstop_runs manifest when written by the post-0094 worker. API and report-card readers prefer the latest valid completed run. If the newest completed manifest is incomplete or its rows are unreadable, readers try recent earlier completed runs before returning 503. The true-legacy MAX(updated_at) fallback is retired: with no valid completed run, readers fail closed to 503 (fresh local databases 503 cleanly until the first completed sync).
redemption_backstop_history
Daily history table keyed by (stablecoin_id, snapshot_date). No runtime reader consumes it today; rows are retained for 90 days for future track-record use and pruned in bounded batches by the same retention pass that prunes run manifests.
Stored fields:
scoreeffective_exit_scoredex_liquidity_scoreupdated_atmethodology_versiondetails_jsonsnapshot_run_id
The cron writes immutable redemption_backstop_run_rows first, writes daily history, and marks the run manifest completed only after the immutable row count and bounds are valid. The legacy current-mirror refresh is retired: readers (including the depeg-resolver context, which uses a narrow store reader over the latest valid completed run) consume immutable run rows exclusively, and the redemption_backstop table is frozen in place pending a separately coordinated destructive cleanup.
redemption_backstop_runs
Completed-run manifest table used to prevent mixed-generation current snapshots from being treated as fresh.
Stored fields:
run_id— unique generated run identifierstarted_atcompleted_atstatus(running,completed, orfailed)expected_countwritten_countmethodology_versionmin_updated_atmax_updated_atmetadata_json
The sync inserts a running row before writing immutable run rows, writes history after those rows are complete, and marks the manifest completed only after the immutable row count and update bounds are valid. If immutable row, history, or completion writes fail after the manifest is started, the writer best-effort marks the manifest failed with phase-specific failure metadata before rethrowing. Readers prefer the latest valid completed run, use its max_updated_at for response freshness, and use its methodology_version for API methodology attribution. If no completed run exists, they return 503; the legacy current-mirror write and the MAX(updated_at) fallback are retired.
Run manifests and immutable run rows are pruned after successful writes with a 14-day retention window. The prune keeps the just-written run and the latest completed run even when either is older than the cutoff, so current API reads stay intact. Retention failures are recorded as completed-run warnings instead of failing the already-written snapshot.
The orphan run-row pass (rows whose manifest no longer exists) derives its candidate run ids from a covering-index DISTINCT snapshot_run_id scan and is bounded per distinct orphan run, instead of walking the whole run-row table with a correlated manifest probe per row. An empty pass therefore stays a cheap index scan rather than a ~28k-row table walk on every retention run.
API Endpoint
GET /api/redemption-backstops
File: worker/src/api/redemption-backstops.ts
- Returns
503with{ "error": "Redemption backstop snapshot unavailable" }when no valid completed run can be read cleanly from immutable run rows (including before the first completed sync on a fresh database); partial manifested current rows are not treated as authoritative - The response metadata carries
snapshotSource: "run-rows"; snapshots are read only from immutable rows for a valid completed run - Otherwise returns the current map plus methodology metadata from
buildRedemptionBackstopsSnapshot(db), withmethodology.versionattributed from the latest completed run manifest andcurrentVersionpreserved as the live code version - Cache profile:
standard(public, s-maxage=300, max-age=60) with freshness headers based onupdatedAt
See API Reference for the exact response shape.
Frontend Consumers
src/hooks/api-hooks.tsexportsuseRedemptionBackstops(), wired throughFRONTEND_API_QUERY_DESCRIPTORS.redemptionBackstopsinsrc/lib/api-query-descriptors.tswith theCRON_RESERVE_SYNCproducer interval (4-hour reserve lane cadence)src/hooks/use-stablecoin-detail-view-model.tsfetches the map and passes the coin-specific entry into the stablecoin detail view modelsrc/components/stablecoin-detail/redemption-backstop-card.tsxrenders oneStandalone route scorewith a route-specific title (Issuer redemption routeorRedemption route), source freshness, route family, source mode, resolution state, route status, model confidence, access/settlement/output/capacity blocks, eventual-only vs immediate-bounded capacity messaging, explicit redemption-fee summaries keyed offfeeModelKind, reviewed docs/source context, component subscores, and contextual methodology hint / footer actions.src/lib/stablecoin-detail-view-model.tsincludes redemption freshness in the detail-page stale-query rail/coverageconsumesuseRedemptionBackstops()throughsrc/lib/coverage/redemption.ts. It distinguishes scored route-family states from low-confidence heuristic routes, resolved-but-unscored routes, configured-but-unrated routes, impaired routes, no route, andData n/afeed-unavailable states. Within impaired rows,degraded/market-impliedmeans confirmed current severe evidence, whileunknown/market-impliedmeans the open incident lacks current authoritative evidence; both remain unrated and cannot inflate public strong-coverage counts. The Redemption quick filter includes configured/resolved route states but excludesData n/a.
The maintenance coverage audit requires a durable reviewed disposition for every active asset without a route config. shared/data/coverage-dispositions/redemption-coverage-dispositions.ts records evidence URLs, reviewer/date, rationale, the exact blocker and evidence still needed, and a route family only when official evidence proves that family. add means the holder route is evidenced but configuration still needs the listed capacity/status inputs; needs-research, defer, and hard-reject remain legitimate coverage outcomes and do not create a scoreable route. The audit rejects stale registry rows and keeps heuristic configured routes visible until hard capacity evidence replaces them.
There is currently no dedicated list page or standalone public methodology section for redemption routes; the primary user-facing surface is the stablecoin detail page. Contextual hints identify the route score as standalone and link to the Safety Scores methodology section for the separate V9 Exit model.