Skip to content

Documentation

What Aftr is, and how to build on it

Written for four readers at once: anyone deciding whether to use Aftr, anyone who wants to read its data from their own contract, anyone assessing how far along it is, and anyone auditing it. Everything below is checkable — on chain, or in the repository.

Last updated 7 August 2026

01

What Aftr is

Aftr is infrastructure for real-world assets on Robinhood Chain. It is a layered system, not a single product: a data layer at the bottom that any contract can read, and products built on top of it — starting with an index vault.

Tokens tracking real equities already trade on that chain, held by tens of thousands of addresses and moving between wallets every day. What has not arrived is the infrastructure underneath them. These are equities: they close at four, they halt, they observe holidays. The primitives around them were built for assets that never close.

Aftr publishes market hours and price health on chain, so a contract that asks the right question gets an answer that fails safe instead of a number that looks fine.

02

Status — what is live and what is not

Stated plainly, because a roadmap that hides its gaps is a sales document.

ComponentStateNotes
Foundation contractsWritten, tested, not deployedRegistry, market hours, price oracle, access control
Off-chain servicesWritten, tested, not runningIndexer, data API, publishers, monitors
Terminal (screener, portfolio)Live, waiting for dataFills itself once contracts are deployed
Index vaultWritten, tested, not deployedHolds user funds — waits for an external audit
External auditNot startedA gate before the vault, not a formality
Markets, credit, derivativesNot startedLater floors; nothing is built out of order

03

The foundation layer

Four contracts. None of them holds money; all of them answer questions.

ContractAnswersUpgradeable
AssetRegistryWhat is this asset, legally and technically?Yes, via 48h timelock
MarketHoursIs this exchange open right now?Yes, via 48h timelock
PriceOracleWhat is the price, and is it trustworthy?Yes, via 48h timelock
AftrRolesWho is allowed to do what?No — never

AssetRegistry records the claim type of every asset. An instrument tracking a share price, a wrapped equity, a fund unit and a treasury are four legally distinct things, and the registry refuses to flatten them into one.

MarketHours models weekly sessions, daylight-saving shifts published a year ahead, holidays, half days and halts. It deliberately decides nothing — it only answers. What to do when a market is closed lives in the contract that asked.

AftrRoles cannot be upgraded because it is the root of trust. A root that can be swapped quietly makes every other safeguard meaningless.

04

For builders — reading Aftr from your contract

This is the part that a database could not do. Your contract can read Aftr from inside its own transaction, and get an answer that stops you rather than misleads you.

The oracle exposes two read functions, and choosing the wrong one is the mistake worth avoiding.

// Moving value? Use getPrice. It REVERTS when the price is stale,
// the feed is frozen, or the asset is halted.
(uint256 price, uint256 publishedAt, bool atClose) = oracle.getPrice(assetId);

// Only displaying? Use peekPrice. It never reverts and hands you
// the health flag so you can show the number and its condition.
(uint256 p, uint256 at, bool atClose_, bool healthy) = oracle.peekPrice(assetId);
// Market state, straight from the chain.
SessionState s = marketHours.state(calendarId);
// CLOSED · PRE_MARKET · REGULAR · POST_MARKET · HALTED

marketHours.lastClose(calendarId);   // last regular close, unix seconds
marketHours.nextOpen(calendarId);    // next regular open
marketHours.isAssetHalted(assetId);  // per-asset halt

There is also a read-only HTTP API for anything that is not a contract — asset lists, prices with their health, calendars and portfolios. It is open, needs no key, and is a mirror: if it disappears entirely, contracts reading the chain are unaffected.

05

The index vault

One deposit gives you a maintained basket of real-world assets as a single token. No yield is promised, because none is manufactured — the value is that the basket maintains itself and the share token is usable elsewhere.

Three design decisions matter more than the rest, and each exists because of a specific way vaults lose money.

  • Redemption returns a pro-rata slice of every asset held, never a single one. It uses no price feed at all, so withdrawals are never held hostage by an oracle — and early redeemers cannot get better terms than late ones.
  • Pausing stops deposits and never stops withdrawals. Halting deposits protects newcomers; halting withdrawals only moves risk onto the people already inside.
  • The first deposit permanently locks a small number of shares. Without that, a first depositor can donate tokens directly to the vault and take the second depositor's money through rounding.

The vault reads the foundation layer the same way any third party would: it calls getPrice when issuing shares, and refuses deposits when MarketHours reports the market closed. It is the first real consumer of its own infrastructure.

06

Governance and upgrades

ChangePathDelay
Contract implementationTimelock contract holds the upgrade role48 hours
Loosening a risk parameterTimelock48 hours
Tightening a cap or disabling depositsAdmin or guardianImmediate
Halting a market, asset or price feedGuardianImmediate

The guardian key is deliberately stripped of every ability except stopping. It can halt a market, halt an asset and freeze a price feed — it can never write a value, and it cannot lift a halt it placed itself. A stolen guardian key is disruptive, not destructive.

The upgrade role is held by a timelock contract rather than a person, so the delay cannot be skipped even by the multisig that proposes the change.

07

Risks we accept

Listed openly rather than discovered later.

  • Issuer dependency. Aftr does not issue assets. A change of terms, a halt, or a custody problem at an issuer reaches our users directly. Being asset-agnostic limits the blast radius; it does not remove it.
  • Price publishing is centralised today. A single key publishes prices. A deviation guard caps the damage per transaction and a guardian can freeze a feed in seconds, but these bound the loss rather than prevent it. Additional independent publishers come when credit products raise the stakes.
  • Upgradeable core contracts. Three of the four can be upgraded through a 48-hour timelock. That asks for more trust than immutability would; the delay is what makes it auditable.
  • A young chain. Robinhood Chain is weeks old. First-mover advantage arrives together with first-mover risk.
  • Smart contract risk. Nothing has been externally audited yet. That is why no contract holding user funds is deployed.

08

What Aftr never claims

These bind every page, post and document we publish. They exist because the space is full of confusion, and being the honest explainer is worth more than being the loud one.

  • That you own shares, or hold any shareholder right. Most assets here track a price; they are not equity carrying votes.
  • That Aftr issues or guarantees any asset. We are infrastructure; issuers are third parties.
  • Any yield figure as a promise.
  • Any affiliation with, partnership with, or endorsement by Robinhood. Aftr is built on Robinhood Chain — a public, permissionless network. That is the entire relationship.
  • That Aftr is regulated, licensed or supervised.