How the bridge works.
PONTE is a live pixel world of Robinhood Chain. This Codex covers how it is built, where every number comes from, how $PONTE fees will buy back and burn, and how the bridge becomes a full metaverse on the chain.
StatusWhat is live and what is planned
| Piece | Status | Notes |
|---|---|---|
| The bridge (dApp at /bridge/) | Live | Districts, thirteen landmarks, charts, chat, share cards |
| In-app swaps (the Statio) | Live | Best route across Robinhood Chain pools via KyberSwap; approve and sign in your own wallet |
| Live chain data | Live | Pools, prices, trades, the PONS burn, blocks and gas |
| $PONTE on pons | Next | CA posted only on ponte.markets and @pontemarkets |
| Lucerna Pontis (buyback and burn) | Planned | Split and schedule published before it switches on |
| Founding Bridge Pass | Planned | Terms published before the mint |
| Forum (wallet-signed calls, crews) | Planned | EVM signatures verified server-side |
| Insulae (claimable blocks), Via Appia (open API) | Vision | See the metaverse plan below |
ArchitectureOne edge Worker, read-only to the chain
Everything runs on one Cloudflare Worker at the edge. It serves the pages, answers the API, holds the chat room and reads the chain. It never holds user funds and never signs for users.
Chain reads go through a private Chainstack endpoint with public fallbacks, reached over a private Worker-to-Worker link so no RPC key is ever exposed to the page.
Code layoutWhere everything lives
public/ index.html the Fabula: landing, roadmap, the gate into the bridge landing.js live ribbon, pixel vignettes, the road, the gate ponte-scene.js the bridge scene and the Arch P (shared with the brand system) bridge/index.html the dApp shell app.js UI: districts, landmark cards, wallets, charts, chat, share cards world.js the isometric renderer: Roman city fabric, towers, traffic, signs core.js palette, tower heights, landmark painters, the statue music.js the soundtrack, generated live in the browser docs/index.html this Codex worker.js routing, security headers, www redirect, chat upgrade api.js data adapters: districts, tokens, candles, trades, PONS, perps, holdings chatroom.js the city chat room (Durable Object, hibernating WebSockets)
The Worker is bundled with esbuild and deployed through the Cloudflare API; static files ship as Worker assets. Every animation is a pure function of time, so any frame can be reproduced for video.
Data and districtsEvery number has a source
| On the bridge | Means | Source |
|---|---|---|
| Tower height | Market cap | CoinGecko on-chain |
| Lit windows | Buyers in the last 24 hours | CoinGecko on-chain |
| Vicus Novus · Launch Quarter | Newest pools, most of them pons launches | New pools on Robinhood Chain |
| Via Ascendens · Rising Row | Up in the last hour, with at least $5K volume | Trending and top pools |
| Forum Magnum · Exchange Quarter | Market cap above $2M | Top pools by volume |
| Turres · Stock Skyline | Tokenized stocks | CoinGecko stock-token category |
| Aestus Humilis · Low Tide | Down 50% or more in 24 hours | Same pools as above |
| Lucerna · the PONS burn | PONS at the burn addresses | Robinhood Chain, read directly |
Public APIRead-only JSON, cached at the edge
| Route | Returns |
|---|---|
/api/ponte | $PONTE live: CA, price, market cap, 24h volume, holders (pending until launch) |
/api/city?d=trenches|pump|old|stocks|down | Towers for a district |
/api/token?id=0x… | A token with its pools and links |
/api/ohlcv?pool=0x…&tf=5m | Candles (Uniswap v3 and v4 pools) |
/api/trades?pool=0x… | Trades over $250 |
/api/lamp | PONS price, market cap and burned supply |
/api/perps | Perp venues with volume and open interest |
/api/swap/route, /api/swap/build | Swap quotes and ready-to-sign transactions (non-custodial) |
/api/network | Block and gas |
/api/holdings?wallet=0x… | A wallet's Robinhood Chain tokens, for the gold glow |
Fees, buyback and burnLucerna Pontis · planned
$PONTE launches on pons. Per the pons docs, every pons pool charges a 1% fee; current launches split it 70% to the creator and 30% to the protocol, and the creator's share accrues in both the token and WETH inside the locked position. That creator share is what powers the bridge.
How the lamp will burn
- A keeper wallet, born in the vault. A dedicated wallet is generated inside Cloudflare's secrets store and never exported. It is set as $PONTE's creator payout wallet on pons, so creator fees route to it.
- Claim on a schedule. A cron Worker claims the accrued creator fees on a fixed interval, published before switch-on.
- Burn the token side. Fees that arrive as $PONTE go straight to the burn address. No swap needed.
- Buy back with the WETH side. The burn share of WETH buys $PONTE in its own pool through the pons swap router, with capped slippage and size, then burns it.
- Prove it. Every claim, swap and burn is written to a public receipt log and shown on the bridge with its transaction. The burned total is always read from the chain: supply at the burn address.
| WETH-side split | Proposed | Goes to |
|---|---|---|
| Buyback and burn | 50% | $PONTE bought and sent to the burn address |
| Pontifices | 30% | Founding Bridge Pass holders, claimable on-chain |
| Operations | 20% | Data, infrastructure and building the bridge |
Safety rails
- A kill switch and a dry-run mode; the first runs only simulate.
- Per-run caps on size, slippage and price impact.
- The keeper holds only fees, never treasury funds, and one keeper per mechanism.
Founding Bridge PassPontifices · planned
A limited NFT for the first to cross. Holders share in the WETH side of creator fees through an on-chain claim, sized by the Pontifices share above. Supply, price, chain contract and claim mechanics are published before the mint, and the contract is reviewed before mainnet. Nothing on this site is an offer.
The metaverse planFrom a map to a place
Today the bridge is a live map. The plan is to make it a place on Robinhood Chain that projects and people own parts of:
| Stage | What it adds | How it works |
|---|---|---|
| Forum | Identity and voice | Wallet-signed calls and crews; signatures verified at the edge, no gas |
| Insulae | Ownership | A registry contract maps each block of the bridge to an owner. A project claims its token's tower by signing with the wallet that deployed it, which pons records on-chain. |
| Billboards | A market inside the market | Billboards rented in $PONTE, with the rent burned |
| Via Appia | Openness | A public API and an embeddable bridge for any app on the chain |
"Official" here means on-chain and verifiable: ownership lives in a public registry anyone can read. It does not mean endorsed by Robinhood or pons.
SecurityThe laws, applied
- Read-only wallet connect; every trade is signed by the user in the platform's own app.
- Keys live only in Cloudflare's secrets store; nothing secret is shipped to the page.
- Strict security headers, address and input validation on every route, rate-limited chat with filters.
- Any contract (registry, pass) is reviewed before mainnet; until then it is labelled planned.