Skip to main content
A round is one signing event: a deterministically selected group of nodes fetches the source’s API, agrees on one value, and produces a single aggregate Schnorr signature. The result is an attestation, a self-contained object that verifies unchanged on Solana, EVM and Starknet.

The attestation

An attestation is a payload plus a signature.

Payload

Signature

A registry holds at most 256 nodes, so one 32-byte word covers every signer. The number of set bits must be at least signaturesRequired.

The signed message

Two properties follow from this layout:
  • The signer set is committed. signersBitmap is inside the message, so nobody can pick a different set of signers after the fact.
  • There is no chainId. The same signature is valid on every supported chain.
Every signer must also belong to the round’s selection set, which verifiers re-derive from sourceId, registryVersion and timestamp / 1000.

What verification proves

A successful verification proves that enough selected nodes from the named registry version signed exactly this payload. It does not prove the value is fresh enough, that it has not been used before, or that it is the source you expected. Those checks are yours: see the consumer checklist.

Round timing

The caller never supplies a timestamp. The gateway stamps each round with its own clock, rounded down to a 100 ms tick:
The tick (ROUND_TICK_MS = 100) is a protocol constant. Nodes reject a round whose timestamp is off the grid or outside their clock window.
  • One round per tick per feed. A source at one quorum and registry version runs at most one round per tick, so at most 10 rounds per second.
  • Requests in the same tick share the round. Nodes run it once and every caller receives the same attestation. Each caller still pays for its own request.
  • One request per tick per consumer. A second request from the same consumer (or x402 payer) for the same source and quorum inside one tick gets HTTP 409. Nothing is reserved; retry after one full tick (100 ms plus a little jitter).
  • No idempotency key. A retried request is a new round and spends quota or a payment again.
  • Selection uses whole seconds. Selection reads timestamp / 1000, so the committee for a source is the same for all ten ticks of a second.
Chain clocks, maxAge, epochs and registry activation times are all in seconds. Compare them with timestamp / 1000.

Where an attestation goes

The SDK and MCP server return the attestation together with ready-made verifier arguments for each chain. The SDK’s TypeScript shape is in the SDK reference.