Skip to documentation
AnyLend docs
Browse documentation

Docs / Protocol reference

Protocol reference

This is the map for readers who want to move from the product surface into the Solidity contracts. The source of truth is the checked-in code and its generated ABIs; this page explains the responsibilities and boundaries.

Contract architecture

ContractResponsibilityImportant boundary
PoolFactoryRegisters pools, creates them through the deployer, manages approved modules, curation, and emergency factory pause authority.Permissionless creation is distinct from curated verification.
PoolDeployerFactory-only creation-code container for LendingPool.Its factory identity is immutable.
LendingPoolPer-pool deposits, shares, collateral, debt, interest, liquidation, recovery, reserves, and pause state.All token-moving writes use exact-delta and custody checks.
PoolVerifierComputes configuration hashes and validates canonical module, oracle, token, and ledger health.It attests current state; it does not control external governance.
OracleAdapterStores feeds and validates normalized prices, rounds, staleness, bounds, aggregators, and phases.Feed owner and market-data risk remain external.
InterestRateModelImmutable two-slope utilization/kink model used by a pool.Economic suitability still requires policy review.
PoolMathFull-precision share, asset, debt, and health-factor arithmetic.Rounding boundaries are explicit and tested.

Read surfaces

Integrations should use bounded registry reads and pin the factory address. The frontend reads a bounded pool directory, then verifies factory identity, pool identity, runtime code hashes, token metadata, and oracle state before displaying write controls.

PoolFactory.getPools(cursor, limit)
PoolFactory.isVerifiedPool(pool)
PoolFactory.verifiedPoolConfigHash(pool)
LendingPool.collateralToken()
LendingPool.borrowToken()
LendingPool.collateralLedgerHealthy()
LendingPool.borrowTokenLedgerHealthy()
Do not use an unbounded registry read in a production integration. The legacy allPools surface is retained for compatibility; use pagination and a bounded response budget.

State-changing surfaces

SurfaceFunction familyPreconditions to re-check
Lenderdeposit, withdrawToken approval, exact delta, custody health, pause state, caps, share quote, and minimum output.
BorrowerdepositCollateral, borrow, repay, withdrawCollateralWallet network, pool identity, oracle price, health factor, debt bound, ledger health, and current pause reasons.
Liquidatorliquidate, resolveBadDebtPreview against current debt/collateral and preserve recovery-specific custody rules.
GovernancesetApproved*, setVerifiedPool, ownership and pause controlsSafe roles, finalized state, proposal intent, and post-execution re-curation.

Accounting invariants