Skip to main content
Corridor is a modular TypeScript monorepo with one Rust service. Its central design rule is that every lane runs through the same engines. A shielded supplier batch and a public naira payout differ only in the path the planner chooses, not in which subsystem handles them.
Corridor system architectureCorridor system architecture

Fig. 01 · Clients, control plane, execution legs, observers and books. One engine per concern serves every lane.

The layers

Turns a request (corridor, purpose, privacy, source, destination, environment) into an ordered list of legs by searching a graph of venue/asset positions. It rejects any payout not funded from the Tempo hub and any collection that does not land on it, and it is the only place privacy is decided: a shielded payout must end in the zcash_ironwood venue. Routing →
Runs a plan as durable steps in Postgres. Each leg has forward and optional compensate. Steps retry with backoff, a lease keeps one worker per saga, and a failure compensates completed steps in reverse order. Failures after money has left Corridor’s control stop at manual_review instead. Saga →
Each leg kind (tempo.transfer, across.bridge, partner.payout, near.swap, zcash.shieldedBatch, …) moves value on one venue and returns the ledger entries that describe what it did. Legs are idempotent: before sending, they look for the movement by its reference. Chains & partners →
Double-entry, append-only journal on Postgres. Postings balance per asset, accounts can be flagged no-overdraft, and each external movement is booked exactly once through a unique (venue, external_ref). Ledger →
Observers turn chain logs, partner webhooks and viewing-key scans into one Observation shape. The matcher joins them with ledger entries on the external reference, and a vault check compares each vault’s on-chain balance with the books. Reconciliation →
The operator’s view: hub balances, venues, sagas with explorer links, pre-funding forecast, reconciliation, shielded batches with FROST approvals, and auditor disclosure exports. Console →

Design principles

Privacy is a venue, not a feature

Shielded payouts are a path through the same graph into zcash_ironwood, booked in the same ledger, reconciled by the same matcher.

The hub is enforced, not suggested

Every dollar is settled, held and reconciled on Tempo. The planner refuses anything else.

One reference, every chain

A 32-byte reference rides in each chain’s native memo field, so no indexer is needed to reconcile.

Book from the chain

Gas, funding and deliveries are booked against the log or output that proves them, never against what the code intended.

Code map