Skip to content
VestiarionDocs

Overview

Contracts on Arc testnet

The contracts Vestiarion deploys and the Circle contracts it calls, with their addresses on Arc testnet.

Vestiarion moves money on Arc testnet through two contracts of its own, which each workspace deploys for itself, and through contracts Circle runs. Every address below opens on Arcscan.

Vestiarion's contracts

Both were written for Vestiarion and are not audited. Their source is in the repository's contracts/ folder, compiled with Solidity 0.8.37, the optimizer on at 200 runs, for the paris EVM version. A workspace that uses one gets its own copy, deployed through Circle's Smart Contract Platform from a deployer wallet of its own. The app shows the copy's address: the escrow's on Contractors → Milestone escrow, and the spending limit's, with the agent's wallet, on Treasury, under the agent's spending limit, On Arc.

VestiarionEscrow

Locks a milestone's USDC for a contractor before the work starts. See Lock a milestone in escrow.

  • Only the workspace's operating wallet, the payer, can call it.
  • fund(id, payee, amount, refundAfter) locks an amount for a payee. release(id) pays it to that payee. refund(id) returns it to the payer, and only from refundAfter. Each hold ends once, released or refunded.
  • It has no owner and cannot be upgraded.
  • It emits Funded, Released and Refunded.
  • An owner or admin deploys it with Set up escrow, signed in the ledger as escrow_deployed.

VestiarionSpendingLimit

Makes the agent's spending limit binding on Arc. See Enforce the limit on Arc.

  • The agent's payments leave the operating wallet through pay(to, amount, ref), and only through it: the agent's own wallet holds no money. The operating wallet approves the contract for what it may draw.
  • pay refuses anything past the daily figure (the current UTC day) or the 7-day figure (that day and the six before it), and pays each ref once.
  • Only its owner, the operating wallet, changes the figures, with setLimits. It cannot be upgraded.
  • It emits Paid and LimitsSet. spentToday() and spentThisWeek() read what it paid.
  • An owner or admin deploys it with Enforce on Arc, signed in the ledger as spending_limit_enforced.

Deployed

Both run in production in testnet-2, our own test workspace:

ContractAddressDeployedDeploy transaction
VestiarionEscrow0x74af203fec3f121ff1cd3a763092d1211487702bOct 1, 20260x550727a6…1860
VestiarionSpendingLimit0x9da3c47f73ea9399ac566806a189b0bf47b7d4baOct 3, 20260xf48ee082…e4ff

The workspace's wallets around them:

WalletAddressWhat it does
Operating0x97f85033bbd83870a841cf7153f35b387746b6b6Pays invoices and buys USYC. The escrow's payer, and the spending limit's owner and the treasury it draws from.
Reserve0xa8a4ced0cda82b24d11e0386f066eb8c27fd4887Holds the USYC and sells it.
Agent0xa79bd77b00143ced32a81d1fb8215d7dca21526aCalls pay on the spending-limit contract. It holds no money.
Escrow deployer0x2590cc3c26f691af6b7203bd283eb055160a1a6cDeployed the escrow.
Spending-limit deployer0x10e8f32d53bdcae4b48cb391c0bb84374b7565f3Deployed the spending-limit contract.

Circle's contracts Vestiarion calls

On Arc testnet:

ContractAddressWhat Vestiarion does with it
USDC0x3600000000000000000000000000000000000000Arc's USDC ERC-20 interface, 6 decimals: every payment, escrow lock and approval.
EURC0x89B50855Aa3bE2F677cD6303Cec089B5F319D72aPays invoices in EURC.
USYC0xe9185F0c5F296Ed1797AaE4238D26CCaBEadb86CCircle's tokenized money market fund, which the reserve wallet holds.
USYC Teller0x9fdF14c5B14173D74C08Af27AebFf39240dC105ABuys USYC with deposit, only in its daily window, and sells it with redeem, at any hour. mintPrice says whether buying is open.
USYC Entitlements0xCC205224862C7641930c87679E98999d23C26113Asked with canCall whether each wallet is allowlisted, before the reserve is turned on.
Gateway Wallet0x0077777d7EBA4688BDeF3E311b846F25870A19B9Holds the USDC the operating wallet deposits for Gateway payouts and the service budget.
Gateway Minter0x0022222ABE238Cc2C7Bb1f21003F0a260052475BMints a Gateway payout on the payee's chain, named in each burn intent.
CCTP TokenMessengerV20x8FE6B999Dc680CcFDD5Bf7EB0974218be2542DAABurns USDC for a payout to another chain. Circle's Forwarding Service submits the mint there.

A payee on another chain is paid in that chain's USDC: