Skip to main content
Each margin account is a separate contract holding real tokens and accounting state for its trader. It is controlled through AccountManager and registered controller callbacks; the owner does not have unrestricted arbitrary-call access.

Ledger and snapshots

The V2 ledger uses token contract addresses for plain assets and tracking symbols for external positions. This prevents similarly named test tokens from sharing a balance. Debt is represented by lending-pool shares; get_borrowed_token_debt resolves the pool and reads its debt value. Batched getters expose collateral lists, debt lists, ledger balances, and valuation snapshots. Blend underlying and LP USD caches reduce cross-contract calls on constrained execution paths. A cached valuation is not proof of a current market quote. Manager refresh methods update these caches; liquidation uses a separate valuation path.

Custody and callbacks

authorize_and_call permits registered controller execution. manager_authorize_and_call is the manager-controlled counterpart. update_tokens_in and update_tokens_out apply controller deltas to the collateral ledger. Swap credits may be capped at oracle input value, so a raw token balance and accounted collateral need not match. sync_tracking_for_target maintains external-position membership; Blend callbacks refresh underlying estimates. repay_borrowed_token_to_pool transfers account-held tokens and decrements collateral by the native amount actually paid, with a minimum native unit for positive dust repayment.

Closing and sweeping

sweep_to moves held direct collateral. transfer_held_token_to permits LP seizure during liquidation. sweep_to_split exists, but the current AccountManager liquidation path calls sweep_to, not the split helper. close_account on AccountManager performs external unwind and deactivation; repayment and liquidation alone do not close the account.

Function signatures

These signatures are copied from the reviewed Rust implementation. env is supplied by Soroban and is not a transaction argument. Result errors and panics must be handled by the caller; simulation does not guarantee later execution. Public methods include privileged and internal-contract callbacks, not just user entrypoints.

__constructor

deactivate_account

activate_account

remove_borrowed_token_balance

remove_collateral_token_balance

sweep_to

transfer_held_token_to

sweep_to_split

has_debt

set_has_debt

get_all_borrowed_tokens

get_asset_lists

get_collateral_ledger_snapshot

get_debt_snapshot

get_health_snapshot

get_valuation_snapshot

set_lp_usd_wad_cache

refresh_lp_cache_all

debt_usd_wad_cache

refresh_usd_valuation_cache

refresh_blend_underlying_wad

refresh_blend_cache_all

is_deposit_borrow_precheck

is_borrow_precheck

refresh_token_directory

get_assets

get_collateral_token_addrs

get_borrows

get_collateral_balance

migrate_ledger_to_v2

authorize_and_call

manager_authorize_and_call

update_tokens_in

update_tokens_out

sync_tracking_for_target

refresh_blend_cache_for_target

add_borrowed_token

record_new_borrow

remove_borrowed_token

get_all_collateral_tokens

add_collateral_token

remove_collateral_token

get_collateral_token_balance

set_collateral_token_balance

credit_borrow_collateral

credit_deposit_collateral

record_borrow_and_credit

apply_deposit_borrow_ledger

sync_tracking_collateral

get_borrowed_token_debt

clear_account_state

repay_borrowed_token_to_pool

is_account_active

upgrade

Source reference

  • Protocol_V1_Soroban_testnet/contracts/SmartAccountContract/src/smart_account.rs