Skip to main content
AccountManager authenticates margin owners, manages account lifecycle, coordinates lending and risk checks, and routes external actions through registered controllers. Earn deposits call lending pools directly.

Account lifecycle

create_account deploys or reactivates a SmartAccount for the trader and updates Registry ownership records. close_account requires owner authorization, no outstanding debt, and a ledger later than activation. It unwinds external positions, sweeps direct tokens to the owner, deactivates the account, and records it for reuse.

Collateral and borrowing

Deposits, withdrawals, and borrows use WAD amounts. Token transfers use each token’s native decimals. Deposits credit the amount actually transferred after conversion. Borrow proceeds remain in the SmartAccount; gross debt includes any origination fee, while credited collateral is the net receipt. deposit_and_borrow combines same-asset operations. deposit_and_borrow_cross supports distinct collateral and debt assets. deposit_borrow_and_deploy_blend accepts the legacy encoded Blend Deposit action and executes the combined operation atomically. The frontend may instead use multiple transactions. The asset cap defaults to 5, and can be changed by the admin. Token eligibility and pool resolution use Registry configuration. Borrow and withdrawal checks require health strictly above 1.1.

Repayment, settlement, and liquidation

repay takes arguments in the order amount, symbol, SmartAccount. It clamps repayment to debt, updates pool shares, and transfers repayment tokens from the SmartAccount through remove_borrowed_token_balance. It does not automatically fund repayment from the owner’s wallet. settle_account unwinds external positions into the account, attempts repayment of recognized debt legs, and returns whether debt is cleared. It neither sweeps remaining collateral to the wallet nor deactivates the account. Use withdrawal or close_account afterward. liquidate requires the liquidator’s authorization and allowances for each underlying debt token to AccountManager. It takes a liquidation snapshot, rejects healthy accounts and unpriceable plain collateral, repays full recognized debt from the liquidator, exits Blend directly to the liquidator, transfers held AMM LP tokens, and sweeps remaining direct collateral to the liquidator. There is no partial-repayment input or enforced debt-plus-bonus seizure cap. The 10% bonus reported by get_liquidation_config is not a separate payment calculation in this path. Liquidation does not deactivate the account.

External execution

exec uses the typed ExternalAction interface. It calls Registry’s batched get_exec_gate, checks the controller’s can_call, executes through the SmartAccount, applies signed WAD token deltas, and enforces asset and controller TVL caps. The current path checks Registry directly; it does not require a facade round-trip. Live post-execution and post-borrow health validation is controlled by get_exec_live_gate (default true, admin configurable). Borrowing uses SmartAccount prechecks, then conditionally calls RiskEngine on the resulting state; the combined deposit/borrow path uses the same flag. Do not promise that every external action always runs a live health check. execute is the legacy XDR adapter; exec_fn is the function-name adapter. Use the typed path for new integrations.

Administration

Admin methods cover two-step admin transfer, WASM upgrades, SmartAccount upgrades, pause state, asset cap, collateral eligibility, tracking minter authorization, valuation-cache refreshes, and the live execution gate. Manager pause blocks borrowing, combined deposit/borrow, collateral withdrawal, external execution, and liquidation. Standalone collateral deposit, repayment, settlement, and explicit close do not check this pause flag; their other authorization/configuration checks still apply. These controls are separate from pool and RiskEngine pause flags.

Function signatures

These signatures are copied from the reviewed Rust implementation. env is supplied by Soroban and is not a transaction argument. Result errors and panics must be handled by the caller; simulation does not guarantee later execution. Public methods include privileged and internal-contract callbacks, not just user entrypoints.

__constructor

get_liquidation_config

get_admin

upgrade

upgrade_smart_account

refresh_blend_underlying_cache

refresh_lp_usd_cache

refresh_usd_valuation_cache

create_account

close_account

deposit_collateral_tokens

withdraw_collateral_balance

borrow

deposit_and_borrow

deposit_and_borrow_cross

deposit_borrow_and_deploy_blend

repay

liquidate

settle_account

propose_admin

accept_admin

set_paused

is_paused

set_max_asset_cap

get_max_asset_cap

get_iscollateral_allowed

set_iscollateral_allowed

generate_salt

get_inactive_accounts

exec

set_exec_live_gate

get_exec_live_gate

authorize_tracking_minter

execute

exec_fn

Source reference

  • Protocol_V1_Soroban_testnet/contracts/AccountManagerContract/src/account_manager.rs