On this page
One system. Composable layers.

A payment, escrow capture, budget spend, stream draw, service delivery, trade, governance action, bridge claim, or program call enters LayerX as one signed activity. The kernel verifies the envelope and authority, orders admitted work globally, executes the operation, and produces protocol-computed receipt evidence. An EVM transaction remains the settlement-chain operation; an activity is the native execution-plane operation.

The exact envelope

The lxp_activity structure carries exactly twelve fields. Omitting, repeating, or introducing an undeclared field makes an envelope malformed. LXC/1 uses canonical binary encoding, fixed-width big-endian integers, and no floating-point values or unordered maps. Trailing bytes are refused.

FieldMeaning
protocol_versionThe enabled execution rules. Version 1 is legacy, 2 includes occupancy, and 3 includes state commitment.
network_idThe exact execution network; prevents cross-network replay.
activity_typeA 32-bit module and operation discriminator.
actor_didThe identity whose authority and sequence authorize the action.
authorityA primary-key, session-key, or scoped-grant authorization reference.
account_sequenceThe actor identity’s exact next expected counter.
timestamp_boundnot_before and not_after bounds checked against batch time.
idempotency_keyA 32-byte actor-scoped key binding retries to one economic result.
fee_limitThe maximum authorized deterministic fee, represented as lxp_u128.
payload_hashA 32-byte domain-separated commitment to the canonical payload.
payloadThe module’s canonical operation body.
signatureEd25519 authorization over the canonical envelope signing preimage, excluding this field.

Module and ordinal

activity_type = (module_id << 16) | operation_ordinal
module_id = lxp_activity_module_id(activity_type)
operation_ordinal = lxp_activity_type_ordinal(activity_type)

Programs module: 0x09
Governance sequencer handover: 0x00070009

The ordinal is module-specific. Use the operation encoding for the target module rather than treating every payload as a transfer. The compile-time LXP_PROTOCOL_VERSION default is 2; applications explicitly select the protocol version enabled by their execution environment.

Admission and execution

  1. Check protocol version, network, and payload binding in that order.
  2. Resolve the actor’s current authority and verify its signature.
  3. Enforce the exact account sequence and the batch-time validity window.
  4. Resolve idempotency and compute fees against the active schedule and fee limit.
  5. Validate and execute the module operation within the state journal.
  6. Commit successful effects or roll back failed module effects; produce the applicable receipt and bookkeeping.
OutcomeApplication consequence
Malformed or wrong-network envelopeNo admission, sequence consumption, or execution fee.
Payload binding mismatchRefused before authority evaluation.
Sequence too low or too highReplay or gap refusal. Recover the actor’s current identity counter before preparing new work.
Fee exceeds the limitThe requested effects are not applied.
Admitted execution failureModule effects roll back; the sequence, global position, and applicable fee bookkeeping persist.
Idempotent retryThe original receipt returns without a second economic effect.

Submitting and recovering

Authenticated gateway submission uses lx_sendActivity over POST /rpc. The agent layer submits exact signed canonical bytes through the LayerX Node Interface. Choose executed, batched, or finalised according to the evidence the application needs.

  1. Prepare the module payload and exact envelope; retain the idempotency key.
  2. Sign the canonical preimage with currently valid authority.
  3. Submit the same canonical bytes and retain the activity identifier.
  4. Check the verified receipt’s result code before reporting success.
  5. If the outcome is pending or unknown, query lx_getActivityStatus and lx_getReceipt. Recover the original result instead of creating a replacement economic action.

Keep the two sequence systems separate

The envelope’s account sequence belongs to the actor DID. Transfer sets also carry an actor sequence for their designated sequence account, usually the debited asset record. A per-asset account can start at zero while its owner identity already has a long activity history. Read the correct counter for each protocol structure.

Native codec interfaces

lxp_activity_encode and lxp_activity_decode handle canonical bytes; lxp_activity_id identifies those bytes; lxp_activity_signing_preimage produces the signing commitment. Envelope, payload-hash, and signature verification are exposed through lxp_activity_check_envelope, lxp_activity_verify_payload_hash, and lxp_activity_verify_signature.

Continue reading

Paxeer X · System documentationBack to top ↑

Ask Paxeer X Docs

Answers from the documentation.

What would you like to know?

Ask a question, find a guide, or get help with your next step.

Enter to send · Shift+Enter for a new line