PET

PET docs

Exact current behavior. Where something is not wired yet, it says so.

What PET is

PET turns a photo of your real pet into an agent with its own coin: a stylized identity that still looks like your pet, with a name, personality and voice, planned to launch on Solana via Pump.fun. $PET is the ecosystem token; fees from every pet coin launched through PET are routed to buy and burn $PET.

The launch flow

1. Upload photo — drag & drop, file picker or camera. 2. Confirm pet — species, breed/type and visible traits. 3. Identity — a stylized avatar drawn from the photo and confirmed traits. 4. Name & personality — name, ticker, personality, bio and voice. 5. Review — including the 0.100 SOL breakdown. 6. Launch — unavailable until production is connected.

Breed accuracy & stylized identity

An AI image model redraws your uploaded photo with the confirmed species, breed and visible traits written into the instructions, so a Shiba Inu stays a Shiba Inu and a rabbit stays a rabbit. If the model is unavailable, a stylized filter of the same photo is used and labeled “photo filter”.

If the analysis is less than 60% sure of a breed, PET says “Mixed breed” (dogs/cats) or just the species instead of inventing one. Known breeds can never be saved under the wrong species. AI can still be wrong — the owner confirms before anything is saved. Example identities on the site are hand-made samples.

Agent identity, personality & memory

Identity = name, species, breed, analyzed traits, personality, bio, voice, avatar and original photo. A SHA-256 identity hash is computed on the server and is intended for token metadata.

Sample posts are templates; in-character posting and memory growth are not live yet.

Launching on Solana / Pump.fun

Launching is unavailable until production is connected: no token is minted, no transaction is sent, and no payment address is shown. Planned production model:

  • Every launch gets a new dedicated launch wallet, never reused. Its key is generated on the server, encrypted at rest, never sent to the browser, and usable only by the launch signing worker.
  • The launcher sends exactly 0.10 SOL: 0.01 SOL mandatory creator buy (not editable), PET treasury allocation (server-configured, default 0.08 SOL), and the remainder (0.01 SOL by default) reserved for Pump.fun creation, rent and network costs. Any change to that split — e.g. sweeping unused reserve to the treasury — is an explicit, announced decision.
  • States: awaiting payment → payment confirmed → treasury accounted → creating coin → creator buy → live. If retries run out before coin creation the launch becomes refundable; after coin creation it becomes failed for manual review.
  • Every external step has its own idempotency key, persisted intent and signature, up to 5 tries with exponential backoff, and chain reconciliation before any retry. A lock stops repeated button presses or parallel workers running the same launch twice.

Guest launches: no account needed. Guests get a one-time claim code; after signing up they can claim the launch with its ID and that code. Nothing is claimed automatically.

$PET economics

Rule: fees generated by every coin launched through PET flow to $PET. They are pooled, used to buy $PET on-market, and all $PET bought is burned. Nothing is retained from bought $PET.

Totals only count confirmed on-chain activity: SOL used counts once the buy tx is confirmed; $PET burned counts only once the burn tx is confirmed.

How fee routing works

Each launched coin is recorded in a launched_coins ledger. Every fee claim becomes a row in fee_accruals keyed by its claim transaction signature (unique), so the same claim can never be counted twice. Accruals start unallocated and are swept into exactly one cycle.

Not built yet: automatically claiming Pump.fun creator fees for PET-launched coins. This needs the creator/fee authority for those coins to be a PET-controlled address plus a claim integration. Until it exists, no fees accrue.

Buybacks

Cadence: one cycle every 24h (UTC buckets). Minimum: 0.05 SOL; smaller amounts roll over. Each cycle has a deterministic id (its time bucket), so a retried or duplicated scheduler call reuses the same cycle instead of creating a second one.

States: planned → buying → bought → burning → completed, or skipped (with a reason) / failed (with the error). A cycle with no eligible fees is recorded as skipped — activity is never invented.

Burns

$PET received by the buyback wallet is destroyed with an SPL Token burn instruction, which reduces total supply on-chain. The burned amount is read from the confirmed transaction's token balance change, not from app state.

Solscan proof

For each cycle the Buybacks page shows status, timestamp, SOL spent, $PET bought, $PET burned and links to the buy and burn transactions on Solscan. A link is shown only for a stored signature that is confirmed on Solana; unconfirmed signatures show "pending confirm".

Token & mint addresses

$PET mint: not configured yet. Once set, the Buybacks page verifies it live on Solana. PET treasury and buyback wallets are server-side configuration and are shown only once configured.

Buyback wallet: not configured yet. It will be published on the Buybacks page once set.

Security model

The RPC key and all signing material live only on the server as encrypted secrets; nothing secret is sent to the browser. The ledger is publicly readable and can only be written by the server. Database rules refuse to mark a cycle completed unless both the buy and burn signatures are stored and confirmed, and refuse any burned amount without a confirmed burn.

The scheduler endpoint requires a secret token. Every step is idempotent: fees are allocated by one atomic operation, and once a transaction signature is stored it is only ever re-checked on-chain, never re-sent. After a restart or timeout, in-flight cycles are reconciled first.

Wallet & signing model

PET never holds users' personal wallet keys. Per-launch wallets will be single-use, server-generated and encrypted once production key handling is connected. Until then, no launch address is generated or shown. The buyback wallet will be a dedicated, PET-operated wallet that only holds swept fees and $PET pending burn.

What is permanent vs editable

Permanent after launch: token name, ticker, avatar, original photo, identity hash, birth date, mint address, and all buyback/burn transactions.

Editable: behaviors, voice, owner story, socials, and memories (which grow over time).

Risk disclosure

A pet agent is software inspired by your pet, not your pet or its consciousness. AI labels are suggestions. Tokens, including $PET and pet coins, are speculative, may have no liquidity and can lose all value. Buybacks do not guarantee price support. Smart contracts, RPC providers and third-party platforms can fail. Nothing here is financial advice.

FAQ & troubleshooting

Why does Buybacks say "Not live yet"? The production dependencies listed under Production status are not in place, so no buybacks run.

A cycle says "skipped" — is something broken? No. Skipped means no eligible fees or execution not live; the reason is shown on the row.

The avatar looks off. Use a well-lit photo with a plain background and tap Regenerate.

Did creating an identity launch a token? No. A token exists only after a real launch confirms on-chain and PET shows its exact contract address.

Production status

Pet analysisliveAI reads species, breed + confidence, coat, markings, ears, face, body, eyes. Owner confirms.
Stylized identityliveAI redraw of your photo using the confirmed traits; labeled photo-filter fallback if unavailable.
Guest claim codesliveOne-time code for guest launches; claiming requires sign-in plus the code.
Accounts & profilesliveOptional username + password, one-time recovery code (stored hashed), profile picture upload, public profile page.
Photo uploadliveDrag & drop, file picker or camera. Type, size and dimensions checked from file bytes on the server. No image links.
Species / breedlivePhoto check suggests species and breed; the owner must confirm; known breeds can't be saved under the wrong species.
Launch state machineinternalBuilt and tested with idempotency keys, five retries and exponential backoff. Not exposed until real execution is connected.
Deposit addressnot builtNo address is shown or generated until secure production key handling is connected.
Solana mainnet readliveNetwork status, mint supply and tx confirmation via server-side RPC.
Pet coin launchnot builtNo mint, transaction or payment. The 0.100 SOL breakdown is shown but never collected.
Buyback ledger & proof UIliveReal database, public read-only, constraint-enforced.
Cycle runner & reconciliationliveBuilt and idempotent; records skipped cycles with reasons.
Schedulernot builtEndpoint exists and is protected; no recurring schedule enabled.
Pump.fun fee claimingnot builtNeeds PET-controlled creator-fee authority + claim integration.
SOL → $PET swap & burnnot builtNeeds funded buyback wallet, signer secret and swap integration.