# Orbit Launch

Website update 5.14 keeps an existing deployed protocol. Use the Cloudflare updater for an existing site; the Activate steps below are only for a first installation. Public discovery is documented at `/discovery-guide.md`.

Orbit is an independent multi-market launchpad on Robinhood Chain (4663).
It does not depend on PAR's website or off-chain API. Existing PAR contracts
are consulted only as on-chain reference markets for optional quote assets.

## Current status

The website and deployment package are implemented. Contracts are not deployed
by publishing the website. They passed local Cancun EVM integration tests with
mocked Uniswap managers; they have not been independently audited or validated
against the live network. Public RPC access from the build environment failed.
Use the owner setup screen to simulate each actual deployment before signing.

## Activate

1. Connect owner wallet `0x23bb66303b167b983db81b8fdeb8eb101ce3838e` on Robinhood Chain with ETH for gas.
2. Open Protocol and review each of the 22 deployment and configuration steps.
   Each transaction requires a wallet signature; after confirmation, a separate
   signed message registers the addresses for this website.
3. If registration is interrupted, recover the next deployment by its confirmed
   transaction hash or verify an already completed configuration step.
4. Launch the native token with ETH and USDG markets. ORBIT is a suggested ticker,
   not a pre-existing deployed token. Activate its USDG market in Protocol.
   The native-token selection and settlement/router wiring are permanent.
5. Confirm reads, launch a small test coin, trade it, collect fees and test both
   USDG and original-asset claims before offering the protocol to other users.

For an existing Cloudflare deployment, public access follows its domain and Cloudflare settings. The discovery pages expose public launch metadata without requiring a wallet.

## Fee economics

Each pool charges 1.00% per swap. On collection, all currencies received by the
locked position are credited to escrow: 10% to the owner recipient, 40% to
the settlement contract's buyback reserve, and the remainder (50%, including
rounding dust) to the creator recipient. For a $100 pool swap, the $1 fee
allocates $0.50 to creators, $0.40 to buyback/burn and $0.10 to the owner.
These allocations apply to the fees actually collected by Orbit's locked
liquidity positions; other liquidity providers may earn a share of pool fees.
The 1% pool fee does not impose a token transfer tax or govern other DEX pools. Creator extra tax is disabled.
Position NFTs and unused launch supply remain permanently locked.
The creator can transfer their own fee recipient; the owner cannot redirect it.

Every launch has 1 billion tokens and 2–5 markets, including ETH and USDG.
The router atomically buys at least 0.10% of initial supply for the creator.
Launching without that opening purchase is blocked. This purchase costs ETH
and does not guarantee bot activity or net earnings. Arbitrage can consume
price differences funded by the opening buyer's capital.

Creators can collect fees and claim selected wallet earnings in USDG atomically
with one transaction. Original-asset claims remain available from escrow.
USDG conversion uses qualifying Uniswap routes with a minimum-output floor and
five-minute deadline. A failed conversion reverts escrow debits. If a route
is unavailable, claim the original asset. USDG is a dollar stablecoin, not a
bank withdrawal. Wallet balances can contain fees from multiple coins.
The owner's escrow can contain both its 10% share and its own creator fees.

Orbit-router swaps attempt fee collection after the trade. A failed collection
emits a deferred event without reverting the completed trade. Native-token fees
credited to settlement burn automatically when collection allows it. Swaps via
external routers accrue pool fees until a collection transaction runs.

Other fee assets need conversion and a native-token purchase. The owner or an
authorized keeper may execute this using only settlement's reserve, with positive
minimum outputs and a deadline. Every purchased native token is burned. Creator
and owner escrow balances cannot be debited by buyback execution. Fees without a
qualifying route remain queued. No background keeper has been funded or started
by publishing the website.

## Automatic buyback keeper

The package includes `bots/burn-keeper.mjs`. Download the registered v2
configuration as `orbit-config.json`, install dependencies and set an HTTPS
`CHAIN_RPC_URL` for chain 4663. Use a dedicated wallet, authorize its address in
Protocol and fund it with ETH for transaction gas. Keep its key only in the
operator's local `BOT_PRIVATE_KEY` environment; never enter it on the website.

Run `node bots/burn-keeper.mjs --watch` to simulate without executing. Set
`BOT_ADDRESS` to the authorized address for accurate simulations. To operate,
provide the key locally and run `node bots/burn-keeper.mjs --watch --execute`.
The script scans launches, processes up to four pending coins per cycle, and
simulates protected atomic collection/conversion/buyback. Native-only fees can
be collected and burned without a conversion. Unsupported routes wait.

Default limits: 0.0002 ETH maximum gas cost per transaction, 0.002 ETH reserved
daily gas budget, 12 million gas units, 0.05 USDG minimum converted value and
0.5% native-output tolerance. Configure `MAX_TX_GAS_ETH`, `MAX_DAILY_GAS_ETH`,
`MAX_GAS_UNITS`, `MIN_BUYBACK_USDG` and `MAX_COLLECT_COINS` locally. Gas budgets
are conservative reservations, including reverted transactions. The keeper
has no schedule unless its process remains running. Use a process supervisor
on the operator's machine for restarts.

Retain `orbit-keeper-state.json` across restarts. It includes discovery progress,
gas reservations and the hash and serialized form of an unresolved signed
transaction, allowing the same transaction to be broadcast again without
creating a second spend. Keep this operational file local. Only one executing
process may use a state file; use one process per wallet. Setting the authorized
keeper address to zero pauses that wallet; the owner can still trigger buybacks.
A displayed authorized address or gas balance does not prove the process is
running.

## Contract revisions and this website update

Website 5.14 does not change deployed contracts, fee allocations or liquidity.
Its current artifact file is contract revision 5. Older revisions have matching
files in `public/contracts/legacy/`. Downloaded settings retain the deployed
revision; both external runners now select revisions 2, 3, 4 and 5 correctly.
Do not redeploy contracts to install these discovery pages or the bot fix.
Historical contract changes are described in the audit notes.

## Existing deployments

V1 contracts are immutable and keep 45% creator / 5% reserve / 50% owner terms.
V2 economics require fresh contracts. The owner setup action archives the old
registered configuration; the workspace selector keeps old balances and claims
accessible. Existing funds are not migrated or relabeled. The website disables
new launches through old configurations. Existing PAR token fees are governed
by PAR's original contracts and are not imported into this independent protocol.

## Genuine arbitrage runner

An optional Node runner is included in `bots/arbitrage.mjs`. It discovers all
launches from the configured factory, evaluates cross-market ETH cycles, and
simulates the entire cycle atomically through `swapRoute`. A trade is eligible
only when its estimated output covers its input, a capped gas budget, and a
positive configured profit floor. It does not manufacture volume or trade merely
to generate fees. Failed transactions still cost gas. No bot has been funded
or started by publishing this website. Existing PAR bots must independently
discover or add this new factory.

Download the bot package from Protocol, extract it and run `npm install`.
Download the registered configuration to `orbit-config.json` in that folder.
Set `CHAIN_RPC_URL` to a current HTTPS provider for chain 4663.
Use `node bots/arbitrage.mjs` for a single dry run or add `--watch` to scan while
that local process runs. Defaults: 0.001 ETH trade size, 0.000001 ETH net profit
floor, 0.01 ETH maximum daily submitted volume. Override with `TRADE_SIZE_ETH`,
`MIN_PROFIT_ETH`, and `MAX_DAILY_VOLUME_ETH`.

Execution is disabled by default. An operator may locally provide a dedicated
funded bot wallet through `BOT_PRIVATE_KEY` and explicitly add `--execute`.
Never enter a private key or seed phrase into this website or ChatGPT. Use the
runner only after validating the protocol and routes. Its local state file
records submitted volume and unresolved transaction hashes; retain it on restart.
Use one process per bot wallet. No key is part of this package.

## Integrators and operations

The factory emits `TokenLaunched` and `MarketOpened`. Read `poolKeysFor` to get
standard hookless v4 pool keys. The canonical manager is
`0x8366a39CC670B4001A1121B8F6A443A643e40951`.
The deployment package includes ABIs, creation/runtime bytecode and immutable
reference offsets. `/contracts/standard-input.json` includes compilation sources
and settings: solc 0.8.30, optimizer 200 runs, viaIR, Cancun.
Source attributions and upstream licenses are preserved in the repository.

The D1 database stores signed owner configuration and verified launch metadata.
The server indexes launches in 10,000-block chunks when the feed is requested;
there is no unattended indexer or guaranteed complete historical volume feed.
Pair evidence is a limited three-token PAR sample and is marked unverified if
RPC reads fail. Swap events do not identify bots.

For public use, configure a dedicated server RPC in Sites as `CHAIN_RPC_URL`.
The optional browser RPC preference is stored on that device only. Contract
addresses are registered using owner signatures, expire after ten minutes and
use revisions to prevent concurrent overwrites. No private keys are stored.
