Skip to Content
How it worksCosts and timings

Costs and timings

All numbers were measured on Preprod in October 2026. The pool holds tUSDM since 2026-10-07; the earlier runs held ADA. The full tables, with every transaction hash, are in the measurements.

What a payment costs

A private payment of 2 tUSDM costs the agent 1 tUSDM on top of the price, and no ADA.

ItemAmountWho gets it
Relayer fee1 tUSDM per payoutThe relayer. It pays the Settle transaction fee of about 0.70 ADA and attaches 2 ADA to the payout output from its own wallet
Attached ADA2 ADA, from the relayerThe one-time address. It pays the second leg’s fee of 0.17 ADA and sends the rest to the seller with the tokens
Protocol fee0The pool treasury. The Preprod config sets settle_fee_bps to 0

A deposit costs 0.18 ADA of network fee plus 1.39 ADA attached to the deposit output, which the crank keeps as its fee. There is no crank fee in tokens, so a 10 tUSDM deposit is credited as 10 tUSDM. An exit costs 0.65 ADA of network fee plus 1.06 ADA attached to the exit output, which stays in the user’s wallet, and no protocol fee.

In the retired ADA pool the agent paid about 1.2 ADA on top of the price: 1 ADA relayer fee and 0.17 ADA for the second leg, both from the note.

Transactions

Transaction, tUSDM runCPU stepsMemory unitsSize in bytesFee in ADA
Deposit, 10 tUSDMnonenone4450.175
Insert, one deposit3.09 billion0.97 million9830.676
ASP update0.06 billion0.18 million5990.215
Settle, one payout of 2 tUSDM3.26 billion1.02 million1,3840.700
Second leg, one-time address to the sellernonenone2500.168
Insert, one change note2.90 billion0.83 million9300.644
Ragequit, 7 tUSDM2.87 billion0.71 million1,2760.649

The ADA pool runs had the same shape: Insert about 3.28 billion steps and 0.71 ADA, Settle about 3.29 billion steps and 0.73 ADA, Ragequit about 2.90 billion steps and 0.68 ADA, and a config update 0.08 billion steps and 0.23 ADA. The limit for one transaction is 10 billion CPU steps and 14 million memory units, so every pool action uses about a third of the CPU budget. A Groth16 verification over BLS12-381 is the bulk of it: the two pairings and the scalar multiplications for the public inputs.

Circuits

CircuitConstraintsSetup powerProving timeProving key
spend16,8282^151.5 to 1.9 s14 MB
insert62,9502^164.3 to 4.8 s47 MB
ragequit8,4232^141.0 s7 MB

Proving times are on an Apple M2 Max with snarkjs 0.7.6, with other work running. An agent needs the spend and ragequit keys, 21 MB together. The crank needs the insert key.

Scripts

ScriptSize with parameters, in bytes
pool12,659
config1,794
asp1,254
deposit518
nft499

The pool script holds three verification keys as parameters. It fits one publication transaction, under the limit of 16,384 bytes, and its reference output locks 55.5 ADA. A deployment costs about 245 ADA in total: 160 ADA of role funding, 73.6 ADA locked in the four reference script outputs, 8.9 ADA in the three state outputs, and about 1.5 ADA of fees. The locked ADA comes back when the pool is wound down.

Where the time goes

Preprod makes a block about every 20 seconds, but not always. Every step of the flow waits for a confirmation before the next one starts, and most of a demo is that waiting.

StepWork before submissionWait for one confirmation
Deposit1.8 s to build28 s
Insert of one deposit14 s to read, prove, build and submit34 s
ASP update6 s to read, build and submit49 s
Settle2 s to prove, 7 s to verify, build and submit28 s
Second legunder 1 s to build39 s
Insert of one change note19 s to read, prove, build and submit23 s
Ragequit4 s to prove, 6 s to build33 s

The demo end to end

Step, in secondsADA run 1ADA run 2ADA run 3ADA run 4ADA run 5ADA run 6tUSDM run
Deposit submitted3.62.93.02.83.12.93.2
Note spendable, from the start11916423191195140139
First leg confirmed, from the payment request29273040403531
Seller answered HTTP 200, from the payment request11611069788317876
Change note spendable, after the seller answered06551590.124
Exit confirmed, after the change was spendable207542212320133
Whole demo255355396206311338372

Three waits make up a payment: the Settle block, the funding check, and the second leg’s block. In a normal run that is 70 to 115 seconds. ADA run 6 took 178 seconds because Preprod made no block for 132 seconds after the Settle, and the tUSDM run’s exit waited 154 seconds for a block. ADA run 5 ran next to two proof-making test suites, so its time to a spendable note says nothing about the code.

A deposit becomes spendable after three blocks in a row: the deposit, the Insert and the ASP update. The crank and the ASP service each poll every 10 seconds and retry an idle step after 20 seconds, so the gap between blocks is mostly the chain.

What would make it faster

  • Mainnet blocks come at the same rate as Preprod, so mainnet is no faster.
  • Pre-funded one-time addresses would remove the Settle wait from the request path. The agent would settle ahead of time and pay at once. This is not built.
  • Batching several change notes per Insert already happens, up to 4 per transaction.
  • Several payouts per Settle, up to 4, would let one proof fund several one-time addresses at once. The validator allows it. The SDK uses one payout today.
  • A direct handoff, where the seller takes the pool transaction itself, would save the second leg. The specification keeps it experimental, because facilitators differ on script-funded inputs.

Provider requests

An idle node makes about 1,100 to 1,600 Blockfrost requests an hour and a demo run adds 150 to 200. The free plan’s 50,000 a day covers an idle node and some dozens of runs.