Pick your token, set two prices, sign three times. Our bot quotes both sides on SaturnSwap's order book from an address only your wallet can empty. We take 0.20% of what a fill pays out, and nothing when nothing fills.
You can leave whenever you like. Here is a whole live book going back to its owner's wallet, with no signature from us: close ↗ deposit back ↗ total cost 0.93 ₳
Of what a fill pays out. Nothing fills, nothing charged.
Refundable. You get it back when you close.
We pay it every time the bot moves your price.
Connect the wallet holding the token. Everything else on this page is read from it.
Your instances are read from the chain — the ceremony's own validator carries the numbers it was built with, so there is nothing for you to look up or type. The manual entry below is only for the case where a registration transaction cannot be read.
Connect the wallet that owns the instance. Its address is one of the ceremony's own parameters, so a different wallet derives a different instance.
Never send funds to this address with an ordinary wallet transfer. It is a script address: a plain send arrives without the datum the validator requires and is permanently unspendable — by us, by you, and by the wallet you own it with. The only safe funding is the transaction this page builds for you, which attaches the beacons and attaches its price datum.
Everything below is optional reading.
Your exit is unilateral. Your own wallet can cancel every order and pull your funds back at any time. It needs no signature, cooperation, or notice from us, and we never hold that key — the two transactions at the top of this page are exactly that, done on mainnet.
An audit is a photograph — one firm, one week, one commit, and a PDF that ages badly. In a year when AI has been finding DeFi bugs faster than auditors ship reports, a stamp from eighteen months ago is not a defence. So we run a red team against this protocol every week, using the same adversarial kit we point at our insurance contracts.
No third-party audit — deliberately. We would rather spend that budget attacking the thing every week than buying a certificate once. The source is public: come and try it.
Before a single client book existed we ran four of these ourselves on mainnet, with our own ADA, specifically to find the sharp edges while it was still our money at risk. Four we found, and what we changed so you never meet them:
The validator bounds where value can go. It does not bound everything, and the honest list of what remains is short but real:
Five of the nine parameters behind your vault are ours to publish and yours to check. They are filled in for you so you cannot mistype one, and listed here so you can compare them against a source that is not this page.
addr1v9wr69p2tx8dx2lat8rzznahxh4xhfl075yzm8uxmth4tvcf3lx47 An enterprise mainnet address (header 0x61), payment key hash 5c3d142a598ed32bfd59c6214fb735ea6ba7eff5082d9f86daef55b3. It receives this fee and nothing else — no change, no payouts, no treasury.20 The validator declares its own ceiling, const max_fee_bps = 500, and refuses to build above it whatever we ask for.cea98dfce26e0ffbf5ab892edcb8f8ab8b794d5390f80ec0b9aafed3 Check it on chain: the key funds its own enterprise address addr1v882nr0uufhql7l44wyjah9clz4ck72d2wg0srkqhx40a5c6g5gjp, whose payment credential IS this hash, and whose transaction history on mainnet is entirely this key signing for itself. The count moves every day the keeper runs, so check the credential rather than a number we would have to keep up to date.11928a3ac3b65edbf103ea6bb3362e39b879a36f02897df31c40917b You do not have to take this from us — the beacon policy below commits to it. Fetch that policy's script from any mainnet indexer and this hash appears inside it as an applied parameter. The two values check each other.8a199a17ef4517215945aaf3c8c5204c60fd94d34c46d341e99c8fcf Fetch the script for this policy id from any mainnet indexer and read the error strings inside it: they say "Two-way swaps must have exactly three kinds of beacons", "Wrong asset1_beacon" and "Wrong asset2_beacon". A one-way policy says "One-way" and "Wrong offer_beacon" instead — that is how you tell the two deployments apart, and they are otherwise indistinguishable.Paste the params file or ceremony receipt you were given. This panel echoes back what it claims — the bound script hash, your floors, your payout address, your escape-hatch key — and hands you the command that turns those claims into checked facts. The check runs on your machine against the public source; this page plays no part in it.
Nine parameters define your instance of the validator. The guided flow fills in seven of them — five are ours and published, two are read from your wallet — and asks you only for your prices. This form assembles the same nine by hand, which is what you want if the key that can pull your funds back lives somewhere this browser will never see it. Either way the setup is identical and the independent verifier is the thing that settles it. Nothing you type here leaves your browser.
Step 1 — your wallet
Connect the wallet holding the token you want quoted. We read your key hash and payout address from it — you do not need a terminal or a key file.
Want the escape hatch on a different key than the wallet you connected? Derive its hash yourself with cardano-cli address key-hash --payment-verification-key-file payment.vkey and replace the value above — the payout address must be controlled by that same key.
Step 2 — the prices you are agreeing to
These are prefilled from our published manifest below so you cannot mistype one — a transcription error here is permanent. Cross-check them against the manifest, and against a channel this page does not control, before you run the ceremony.