Skip to main content
Extensions to the RWA templates that production tokenization needs beyond representing an asset. All are Stellar-only.

Revenue distribution: revenue-distributor

real-estate-token::declare_rental_distribution and mining-rights-token::declare_royalty only record an amount. The distributor actually pays holders.
  1. The asset token’s Manager calls create_distribution(creator, asset_token, payout_token, amount, claim_window_secs, memo). This takes a balance snapshot on the token and escrows amount of the payout token (for example a USDC SAC). Only the issuer can distribute, because the snapshot needs the token’s Manager auth.
  2. Each holder calls claim(holder, id) and receives amount × balance_at_snapshot ÷ supply_at_snapshot. Selling after the snapshot doesn’t forfeit that period’s payout.
  3. claim_many claims up to 20 periods at once. With a claim window set, the creator can reclaim anything left after the deadline. That includes shares held by contracts that can’t claim, such as an RFQ escrow.
For recurring income, create one distribution per period. Snapshots come from ankara-common. Every fungible template now exposes snapshot() (Manager), current_snapshot_id(), balance_of_at(id, snapshot) and total_supply_at(snapshot). A token that never takes a snapshot pays no extra storage.

Secondary liquidity: rfq-market

A single farm, invoice or building token will never have AMM depth. The RFQ market matches a seller with specific buyers instead:
  1. post_intent: the seller escrows amount of the RWA token and sets the payment token, a floor price and an expiry.
  2. submit_quote: buyers post firm quotes. The quoted price is escrowed, so every quote is fundable.
  3. accept_quote: the seller picks one. The asset goes to the buyer and the price, less an optional protocol fee (≤ 5%), goes to the seller, atomically.
  4. withdraw_quote refunds losing quotes. cancel_intent refunds an unfilled intent. Both stay available while the market is paused.
If the token has an identity verifier, the market contract’s address must be verified on it to hold the escrow. The buyer is checked as normal.

Land & property titles: disputes, liens, chain of custody

farmland-nft and real-estate-nft gain: Owners in the custody log are free-form strings, because prior owners usually pre-date the token. The flags are informational: they don’t block transfers.

Carbon credits: external registry reference

RetirementRecord now has an optional external_registry_id, which links a retirement to an independent verification body’s record (for example a Verra retirement serial). Set it at retirement with retire_with_registry_ref(...), or attach it once later with set_retirement_registry_ref(index, id) (Manager, write-once).
RetirementRecord gained a field. Carbon tokens deployed before this change should be upgraded before new retirements are written. Existing retirement records don’t carry the field.

Coupon-bearing instruments

The design decision is recorded in packages/contracts-stellar/design/coupon-instrument.md. In short: a new bond-token template, not an invoice-token extension, with coupons paid through revenue-distributor.