Skip to content
CCPEDIAby Unity Nodes
#267Voting Live Pull Request600K CC requested

Funding Proposal by Jubilee: Privacy-Native NFT Marketplace & CIP-56 Reference Implementation for Canton

Jubilee-Market29-04-2026Last activity 4mo ago
token-asset-standardschampion-confirmed
References:CIP-0056CIP-0100CIP-0112

Development Fund Proposal Submission

Proposal file

/proposals/jubilee.md

Review update

The proposal has been updated in response to Tech Ops feedback to separate the marketplace from the NFT-focused standard and public-good infrastructure.

The revision makes four material changes:

  1. Separate workstreams: the open-source infrastructure and the Jubilee reference marketplace now have distinct scopes, milestone deliverables, and acceptance criteria.
  2. Current deployment status: the proposal now reflects Jubilee's progress since the original submission from testnet validation to a controlled private MainNet review deployment.
  3. Current economics and evaluation: the fee model now reflects the planned flat public-launch schedule, and third-party-dependent adoption figures are classified as reported operational targets rather than grant-disbursement conditions.
  4. Audit, release, and standards sequencing: MS1 now completes audit readiness and unlocks the capital used to commission both audits in MS2; the repository progresses from public architecture to core primitives, settlement modules, and then the full stable public-good release, with the full DAML contract suite and atomic payment distribution logic covered by the two independent audits; and the proposal documents the compatibility path from CIP-0056 V1 toward approved CIP-0112 V2.

The total working request and overall four-milestone structure remain unchanged, while individual deliverables and technical descriptions have been refined.


Summary

Jubilee is building open-source non-fungible asset and atomic settlement infrastructure for Canton, with the full DAML contract suite and atomic payment distribution logic independently audited, together with a production marketplace that serves as its first end-to-end reference implementation.

The proposal is organized into two connected but separately evaluated workstreams.

Workstream A — Open-source non-fungible asset infrastructure

Reusable Canton public goods released under Apache License 2.0:

  • an NFT-focused DAML implementation layer compatible with CIP-0056 V1, with a defined path for gradual adoption of CIP-0112 V2 features through its cross-version transition;
  • collection and issuance primitives, including supply caps, mint stages, allowlists, and per-wallet limits;
  • party-based ownership and transfer flows;
  • listing, offer, counter-offer, and cancellation primitives;
  • fully backed on-ledger offer escrow;
  • atomic Canton Coin payment distribution for seller proceeds, platform fees, and creator royalties;
  • a browser-encrypted self-custody wallet reference implementation;
  • a staged public repository: architecture and interface materials in MS1, core asset implementation preview in MS2, settlement-module preview in MS3, and the complete stable public-good release in MS4, with the full DAML contract suite and atomic payment distribution logic covered by the two independent audits;
  • developer documentation and integration examples;
  • two independent security audits covering the full DAML contract suite and atomic payment distribution logic. The self-custody wallet reference implementation is published separately and is not represented as part of the audited DAML scope. Third-party bridge code is also outside the audit scope.

Workstream B — Jubilee reference marketplace

Jubilee Markets is the production application used to validate those components end to end under MainNet conditions. It provides the creator, user, wallet, marketplace, bridge, and operator surfaces required to exercise issuance, ownership, discovery, offers, escrow, transfer, and atomic settlement in a complete application.

Since the original submission, Jubilee has progressed from testnet validation to a controlled private MainNet review deployment. Collection creation, minting, listing, purchasing, offers, counter-offers, cancellations, direct transfers, and atomic settlement are operational on MainNet under internal testing.

The first reference use case is intentionally art, PFPs, and digital collectibles because they are familiar to crypto-native users and provide the lowest-friction path to real adoption and repeated production validation. They are the starting point, not the limit of the infrastructure.

The longer-term objective is to reduce the engineering and audit burden for Canton teams developing other unique assets and rights, including certificates, licenses, memberships, tokenized documents, property-related rights, private-market positions, and other financial or real-world instruments. No specific regulated financial product or native fractionalization layer is included in the current grant scope.

The proposal spans four milestones over approximately 13 weeks. MS1 completes audit readiness and, upon acceptance and disbursement, provides the capital used to commission both independent audits immediately at the start of MS2. The reference collection launch is not dependent on the grant-disbursement schedule and may occur before audit completion. If so, exposure remains controlled through the collection's fixed 1,000-NFT supply and allowlist-gated access at launch. Audit completion and remediation of critical and high-severity findings gate removal of the allowlist for broad public onboarding, the audit-complete designation, and the final stable public-good release. The working funding request remains 600,000 CC, open to Committee calibration.


Scope separation

The two workstreams are technically connected but are now separated at the evaluation level:

WorkstreamPurposePrimary outputs
A. Open-source infrastructureDurable, reusable Canton public goodsCIP-0056 V1-compatible implementation layer, gradual CIP-0112 V2 feature-adoption path, issuance and ownership modules, marketplace primitives, escrow, atomic settlement, separate wallet reference, DAML/settlement audits, documentation
B. Reference marketplaceEnd-to-end production validation and adoptionJubilee MainNet application, reference collection, creator and user surfaces, external onboarding, bridge integration, and embedded OneSwap integration through Jubilee's built-in self-custody wallet

Each milestone identifies its Workstream A and Workstream B deliverables and acceptance conditions. A workstream-level funding allocation can be provided and calibrated with the Committee; the existing milestone totals remain the current working request, and this revision does not impose an unreviewed numerical split.


Clarifications for reviewers

Is this grant primarily funding an art or PFP collection?

No. The collection is the first production reference use case and adoption vehicle. The grant's durable output is open-source infrastructure that other Canton teams can evaluate and reuse, with the full DAML contract suite and atomic payment distribution logic covered by the two independent audits.

Why start with collectibles?

A new infrastructure layer needs a real production environment in which issuance, ownership, escrow, trading, and settlement can be exercised repeatedly. Collectibles are familiar to users, already have a crypto-native adoption base, and provide a practical starting point without requiring the proposal to depend on hypothetical institutional demand.

What broader use cases can the infrastructure support?

The same primitives may support applications involving unique certificates, licenses, memberships, documents, property-related rights, private-market positions, and other financial or real-world instruments. Each future application would still need its own economic model, legal structure, compliance logic, and product-specific functionality.

Does the current grant include fractionalization?

No. Native fractionalization is outside the current grant scope, but it aligns with the broader direction this infrastructure is intended to support. The current proposal establishes the underlying issuance, ownership, transfer, escrow, and settlement primitives first.

Why keep both workstreams in one proposal?

The marketplace is the production environment that validates the public-good modules. Separating their scopes and acceptance criteria makes the distinction explicit while preserving the implementation relationship required for end-to-end testing.


Checklist

  • Proposal file added under /proposals/
  • Marketplace and infrastructure workstreams separated
  • Milestones and funding amounts defined
  • Separate deliverables and acceptance criteria included for both workstreams
  • Third-party-dependent adoption figures classified as operational targets
  • Alignment with Canton priorities described
  • Out-of-scope financial products and fractionalization clarified
  • Public repository staged from MS1 architecture, through MS2 core primitives and MS3 settlement modules, to an MS4 stable public-good release with the full DAML contract suite and atomic payment distribution logic independently audited
  • CIP-0056 V1 compatibility and the gradual CIP-0112 V2 cross-version transition distinguished

Notes for reviewers

Status: In Review; champion confirmed.

We are submitting under CIP-0100 as an external contributor team with a confirmed Tech & Ops Committee champion.

Items the Committee may want to focus on:

  1. Public-good value beyond the marketplace. The core grant output includes audited, reusable asset, escrow, and settlement components, alongside a separately released wallet reference implementation, rather than a closed Jubilee-only implementation.
  2. Token-standard alignment. Jubilee currently vendors and implements the CIP-0056 V1 DARs: NFToken and NFTokenV2 (amount = 1.0) implement Holding, and JubileeTransferFactory implements TransferFactory. For the allocation surfaces, Jubilee deliberately does not reimplement the standard; its atomic settlement flows exercise Splice's official CIP-0056 V1 AllocationFactory and Allocation implementations directly for the Canton Coin legs, and every backed offer locks the buyer's committed CC in a standard Allocation. CIP-0112 V2 is designed for a high level of backward compatibility with CIP-0056 V1 and supports a gradual cross-version transition. The proposal therefore defines a gradual V2 feature-adoption path rather than treating the current V1 implementation as a mandatory replacement.
  3. Atomic settlement and backed offers. Platform fee, creator royalty, seller proceeds, and asset ownership settle in one atomic operation. Offers are backed by CC committed on-ledger before they become actionable by a seller.
  4. Audit sequencing, scope, and launch controls. MS1 completes audit readiness and, once accepted and disbursed, provides the capital used to commission both audits immediately at the start of MS2. The audits cover the full DAML contract suite and atomic payment distribution logic. Third-party bridge code is outside the audit scope. The reference collection may launch before audit completion because its timing is not dependent on grant disbursement; in that case, exposure remains limited by the fixed 1,000-NFT supply and allowlist-gated access. Both audits and remediation of critical/high findings are required before the allowlist is removed for broad public onboarding and before the final stable public-good release is published.
  5. Production progress. Since the original submission, Jubilee has moved from testnet validation to controlled MainNet review and has provided MainNet transaction evidence for the principal marketplace flows.
  6. Current fee model. The review build uses 0.1 CC placeholder fees per completed sale and per minted NFT. The planned public-launch schedule is a flat 3 CC per completed sale and 3 CC per minted NFT, with no percentage-based platform commission.
  7. Acceptance design. Technical deliverables under Jubilee's control remain binding. Transaction-volume figures and external participation are reported operational targets rather than acceptance conditions, avoiding incentives for artificial activity while preserving measurable adoption reporting.
  8. Production maturity. The team has shipped DAML contracts and production-side infrastructure, including deployment, email, waitlist, monitoring, and operational systems.
  9. Staged open-source release. The public repository opens in MS1 with architecture and interface materials, adds the core asset implementation preview in MS2 and settlement-module preview in MS3, and publishes the complete stable public-good release in MS4 under Apache License 2.0. The full DAML contract suite and atomic payment distribution logic are covered by the two independent audits.

Funding

The total working request remains 600,000 CC across four milestones. The amount is intended to level-set the review conversation rather than impose a rigid allocation. Jubilee remains open to calibrating milestone amounts and a workstream-level allocation with the Tech & Ops Committee and Foundation reviewers.

Live demonstration

We are happy to provide Committee members or reviewers with a walkthrough of the private MainNet review implementation and the referenced on-ledger transactions.

← Back to Proposals