Authority, supply and change
Nobody here has any power over your artifact.
This page lists every party that touches PATINA and the exact edge of what each one holds. Most of the entries are about what cannot be done.
Nothing below is a claim about value. It is a map of powers, a list of the numbers that are frozen, and a live read of founding concentration, published during the window rather than after it.
01 Supply
There is no supply plan.
The Firstlight cohort is whatever the window produced. Nobody picked a number, because there was nothing to pick.
Anyone can claim, as many times as they can fund, for as long as the window is open. When it closes, no new founding artifact can exist.
Artifacts can still be created outside the founding era, with a lower carrier floor. They are not Firstlight Seals and never will be.
- Price
- None. Bitcoin Universe charges nothing to mint. You pay miners, and nobody else.
- Cap
- None. A cap would create a race, and a race is what the aged commit exists to prevent.
- Founding window
- 4032 blocks for commits, plus 4032 blocks of grace to reveal a commit that already landed inside it.
- Founding carrier floor
- 100 000 sats of the minter's own bitcoin, which stays theirs.
- Open era carrier floor
- 10 000 sats, for artifacts created after the founding era.
- Burn, buyback, emission
- None of them exist. There is no token and nothing to emit.
02 Allocations
Nobody was given anything.
Six categories that usually hide a number. Every one of them is zero, and the honest limit of that claim is written under the table.
| Category | Amount | Note |
|---|---|---|
| Team allocation | 0 | No pre mint, no reserved claims, no advantage in the window. |
| Treasury or reserve | 0 | There is no treasury. |
| Investors | 0 | Nothing was sold. There is nothing to sell. |
| Airdrop or allowlist | 0 | There is no list. The protocol has no concept of an account. |
| Protocol fee on mint | 0 | Miner fees only. |
| Protocol fee on transfer | 0 | A transfer is an ordinary Bitcoin spend. |
The honest part
People who build this can still mint like anyone else, from their own coins, in the same window, under the same rules, with no head start. We are not going to claim otherwise.
What we can promise is that no claim is reserved, and that the concentration figures below are published while the window is open rather than after it.
03 Concentration
Founding membership can be farmed, so the count is published live.
Somebody with enough bitcoin to park can claim a great many seals. Rather than let you discover that later, this panel asks the indexer now.
Counters and distribution
LiveChecking for a connected indexer.
- Artifacts alive
- Artifacts relic
- Founding total
- Rings engraved
- Deepest live stretch
- Endowment held
How to read those figures
Concentration on Bitcoin is a measurement of outputs and addresses, not of people. One holder can spread claims across many addresses, and several people can share one.
Read the numbers as a floor on concentration, never as a headcount. When no indexer answers, the panel says so instead of showing a number.
04 Authority
Who can do what, and where each one stops.
Read the third column first. The limit is the part that decides what an authority is worth.
| Party | Can | Cannot |
|---|---|---|
| Bitcoin Universe | Publish the specification, run an indexer, ship transaction building tools in its app, turn its own surfaces off. | Pause the protocol, freeze an artifact, reverse a spend, change anyone's depth, mint on your behalf, or move your coins. |
| Indexer operators | Read the chain, publish state, refuse to serve anyone. | Change what the chain says. A wrong indexer is provably wrong against a node. |
| Miners | Include or exclude transactions, and reorganise recent blocks. | Alter an artifact without spending its carrier, which needs the holder's key. |
| Holders | Spend the carrier at any moment, route the artifact with KEEP, sign attestations. | Move an artifact without ending its stretch, or remove a ring once it is engraved. |
| Anyone at all | Build markers, broadcast them, and index them, with no permission from us. | Add a Firstlight Seal after the window has closed. |
05 Change control
What is frozen, and what we are free to change.
The frozen column is not a policy. Those values are baked into how a marker is read, so touching one produces a different protocol rather than a newer one.
Frozen
Consensus surface- Marker magic, version byte and both opcodes.
- All eight tier thresholds.
- The commit minimum age of 144 blocks.
- Window length and grace length, 4032 blocks each.
- Both carrier minimums and the successor minimum.
- The maximum of 8 KEEP entries.
- Every hash derivation and domain tag.
- The reason code registry and its order.
Changing any of these means a different protocol under a new version byte, not an update to this one. Existing artifacts keep reading under the version byte they were written with.
Can change
Presentation and tooling- This website, its wording and its layout.
- The app's interface, and which features it exposes.
- Indexer implementation details and performance.
- Which networks are enabled in Bitcoin Universe's own tools.
- Documentation, examples, and the test vector suite growing.
None of these can move a threshold, alter a depth, or change what an existing marker means. They change what you look at, not what is true.
Deviations get written down
Any departure from the frozen baseline is recorded in docs/deviations.md in the protocol repository, rather than quietly shipped. The boundary itself is specified, not improvised.
06 Kill switches
What the switches reach, and what they do not.
The important sentence
The protocol cannot be paused. A PATINA marker is an ordinary Bitcoin transaction. Anyone can build one, anyone can broadcast one, and anyone can index one.
Every switch below controls only Bitcoin Universe's own construction and broadcast surfaces.
| Switch | Turns off | Does not touch |
|---|---|---|
| PATINA_ENABLED | The PATINA module in the Bitcoin Universe backend, including the read proxy and the transaction planning helpers. | Existing artifacts, the chain, other indexers, other wallets. |
| VITE_PATINA_ENABLED | The PATINA tab in the app's interface. | Anything at all outside that interface. |
| PATINA_INDEXER_URL | Points the app at a different indexer, or at none. | What the chain says. A different indexer reading the same chain gives the same answer. |
| PATINA_NETWORK | Selects which network the app's tools operate on. | Anyone else's choice of network. |
| PATINA_MAINNET_AUTHORIZED | Blocks mainnet transaction construction inside Bitcoin Universe entirely unless it is set, and a deployment record naming at least two approvers exists. | Mainnet itself. Anyone else can construct and broadcast a valid marker with their own tools. |
Nobody can save you
There is no freeze, no clawback and no support ticket that reverses a spend. Once a carrier moves, its stretch is over and the ring is written.
Nobody can stop you
If every Bitcoin Universe service disappeared tomorrow, your artifact would still be exactly what it was: an unspent output at a known height, readable by anyone who runs the index.
07 Custody
What Bitcoin Universe never holds.
The app builds unsigned transaction plans and a plain review summary. Everything after that is your key and your decision.
- Your keys
- Never transmitted, never stored, never requested. You sign, and nothing is broadcast without that signature.
- Your coins
- No custody at any point. The carrier stays in your wallet from the moment it is created.
- Outpoints you check
- The safety endpoint that tells a wallet whether an outpoint is a carrier or a commit stores nothing.
- An account
- There is nothing to register. The protocol has no idea who you are, which is also why it cannot limit anyone to one seal.
08 Known risks
The short version of what can go wrong.
- Depth is not provenance. It proves the outpoint has not moved. Keys can be sold off chain, so it cannot prove one person held it throughout.
- Founding membership can be farmed. Anyone with bitcoin to park can take many seals. There is no per person limit, because there are no persons here.
- Buying resets. A transfer spends the carrier. You inherit the rings, not the depth.
- Your wallet can reset it by accident. A coin selection algorithm that does not know about carriers will happily spend one as change.
- An indexer can be wrong or offline. Check against a node, and prefer an index you run.
- Reorgs can unmake recent facts, including founding status near a window edge.
- Nobody owes this anything. No liquidity, no market, no floor, no buyer.
09 Go and check
Take none of this on trust.
- I want the rule, not the summary The upgrade boundary Exactly which fields are frozen, what a change to any of them would produce, and how an implementation declares what it reads.
- I run infrastructure Incidents and their reach What an operator can do when an indexer goes wrong, and the short list of things no incident response can touch.
- I want to check a claim Verify an artifact Read depth off your own node, decode a marker by hand, and cross check two indexers against each other.
- I want the mechanism How the protocol works Markers, commits, carriers and rings, with the byte level rules that every implementation has to agree on.
- I want the downside first Risks in full Every failure mode we know about, what it costs, and what you can do about it before it happens.
- A word here is unfamiliar Glossary Carrier, stretch, ring, marker, commit, endowment, relic, and the rest, each defined once.