XENIA

xenia.studio

18+ verified / adult fantasy / community

Documentation

Everything you can do on xenia.studio. Create in the Studio, get paid to your own wallet, mint and sell collectibles, build a community, and stay unidentifiable behind the filter. Every payment settles wallet to wallet on Solana, with no custodian and no escrow.

Find your way around

Overview

Sharing your most passionate moments while staying completely private sounds impossible. On XENIA it is not a trade-off. You get all the benefits of the adult industry with none of the drawbacks. Every photo is redrawn before anyone sees it, so you show as much as you want and stay unidentifiable. You are seen, but never identified.

xenia.studio is an adult social network built on that one idea. Most of what happens here is looking: a feed of verified adults (18+) remade as anime fantasy. The redraw runs in XENIA Studioon XENIA’s cloud GPUs, and your original photo is never stored, only the rebuilt image. One account is not human: Xenia, the platform's resident, is the one and only AI here. Everyone else on XENIA is a verified 18+ human being.

If you want more than the feed, connection is here too, and it stays optional. In-app Messages are end-to-end encrypted: sealed in your browser with a key from your wallet, decrypted only when you open them, readable only by you. The server stores ciphertext and never reads a word. It is a quieter way to flirt and meet, whether you come alone or already have someone.

Money is just as direct. Every tip and every unlock is a wallet to wallet transaction on Solana, routed through a single on-chain program that drops 93% straight into the creator's wallet in the same atomic instruction, keeping a 7% fee. XENIA never holds funds, never issues balances, and never custodies a key.

SOLOUSDGoldjitoSOL APY
Spend, earn, save

Why XENIA exists

Most adult play comes with a cost. Exposure. The awkward run-in months later. A real face attached to it forever. XENIA gives you the upside and skips that bill. You get the freedom, the people, the rush of being wanted, and your face never leaves the building.

Single or in a couple, it is a safer way to explore what you are into. You decide what you share, who sees it, and what it costs. The filter rebuilds every photo and the original is never stored, so your likeness comes through without ever being identifiable.

There is more here than content. Encrypted Messages let you flirt and say what you want in private. A tip is how you show a creator you appreciate them. An External DM unlockopens a line off platform, on the creator's terms. How far any of it goes is up to you.

That is the whole thesis: publish your most passionate moments, and nothing follows you home.

How XENIA works

The whole platform is one loop: you create, you publish, you earn in the money you spend and get paid in, and you can save or grow that income without ever leaving the app.

Create

Redraw a source photo into refined anime-style art in the Studio. Your original is never stored, only the rebuilt image, so you are seen, not identified.

Publish

Ship each creation to your page public, protected behind an unlock price, to your members, or to your circle. Everything lands private until you say so.

Earn

Tips and unlocks settle wallet to wallet on Solana, 93% to you in the same atomic instruction. Your income arrives in the money you spend and get paid in:

SOLOUSD
Save or earn in the wallet

One tap swaps your balance into either, with no lockup, and back to dollars whenever you want.

Save in gold

Hold value in PAXG, one token to one ounce of vaulted gold.

Earn by staking

Stake into jitoSOL for yield, tradable the whole time.

The platform never holds funds, never issues balances, and never custodies a key.
  1. Sign up with a username and email, verify the email with a 6-digit code, pass 18+ age verification (which also captures your private likeness), and create a non-custodial Solana wallet in the browser. Your profile lives at username.xenia.studio.
  2. Create in the Studio at /studio. Upload a source photo, say what you want, and press Generate. The redraw runs on XENIA’s cloud GPUs, paid per render in SOL or OUSD. Only the rebuilt image is kept.
  3. Publish from the dashboard. Every upload lands as private. Flip each image to public (visible to everyone), protected (shown as an irreversible blur until unlocked for a price you set), subscriber (your members gallery, for fans on a membership), or circle (a drop only your circle can see, no charge).
  4. Viewers explore the global ranked feed and creator subdomains. Once they are logged in and verified, they can follow a creator, tip any image or profile, send encrypted Messages, unlock protected images, join a membership, and buy a creator's External DM unlock.
  5. Every payment settles on chain. The browser builds and signs the transaction. The server just verifies what already happened on chain and records the entitlement.

Where to start

Core principles

  1. The filter is the identity boundary. The source photo is never stored; only the rebuilt image exists. The platform stores, serves, and ranks only the transformed output.
  2. Non-custodial money. Funds live in your own wallet. Tips and unlocks pay creators directly. The commission split happens inside one on-chain instruction, not in a database.
  3. Encrypted storage. Every stored image is encrypted at rest with AES-256-GCM envelope encryption. Protected and private content is unreadable in database dumps or backups.
  4. Verified adults only. Both email verification and 18+ age verification are required before an account can post, follow, tip, or unlock.

Platform at a glance

PropertyValue
ChainSolana
CurrenciesSOL and OUSD to spend, gold (PAXG) and jitoSOL to save. No platform token.
Creator share93% of every tip and unlock
Platform commission7%, enforced on chain with a 700 bps hard cap
WalletNon-custodial, passkey-wrapped, created in the browser
Content storageAES-256-GCM encrypted blobs in PostgreSQL
Profilesusername.xenia.studio subdomains
MessagesEnd-to-end encrypted, opened only by your wallet, never read by the server
Age verificationGovernment ID via Yoti (ID document scan or the Yoti app), required for every account
StudioWeb studio at /studio, pay-per-render on XENIA cloud GPUs

Getting Started

Creating an account takes a few minutes and happens entirely in the browser. XENIA has no passwords. Your non-custodial Solana wallet is your identity, and a passkey on your device is what unlocks it locally.

Here is the whole path at a glance, from a blank screen to your first earnings: the signup flow, then what happens the moment your page goes live.

Your first 10 minutes
Sign up with a passkey

Pick a username and enter an email. Your browser makes a Solana wallet, your passkey locks it (no password to set), and you set a recovery passphrase and save a 24-word phrase so the wallet restores on any device.

Verify email and age

Confirm the 6-digit email code, then pass the 18+ ID check through Yoti. Both run inside the signup flow, so a normal signup comes out activated.

Claim your username.xenia.studio

Your username becomes your public page on its own subdomain: avatar, bio, follow button, DM unlock card, and your grid. Link it anywhere.

Post or create

Open the Studio, redraw a source photo into an anime-style render, and ship it to your page public, protected with a price, or kept private.

Get paid
SOLOUSD

Tips and unlocks land straight in your wallet, 93% in the same transaction the fan signs. A wallet at zero earns from day one, with nothing to fund first.

No passwords, no payout forms, no minimums. Browsing the public site needs no account at all.

The signup flow

  1. Username and email. Pick a unique username (it becomes your username.xenia.studio subdomain) and enter an email address. The email is required for activation and is never shown publicly.
  2. Email code. A 6-digit code is sent to your address. Codes expire after 24 hours, allow 5 attempts, and resends are rate limited.
  3. Identity verification. Verify with a government ID through Yoti (an ID document scan with a live face match, or the Yoti app), which proves both that you are over 18 and that the person is you. See Age Verification for exactly how it works and what is stored.
  4. Wallet creation. The browser generates a Solana keypair, wraps it with a passkey, and shows you a 24-word recovery phrase exactly once. XENIA creates the wallet for you. You cannot import an external one, and your account is bound to this address for good. See Wallet for the full mechanics.
  5. Create your account. Your passkey signs the account creation and is registered as your one-tap sign-in credential. The live face from your ID verification becomes your private likeness reference. It is stored encrypted and never shown publicly. It ties the account to one real verified adult, lets the Studio confirm your likeness in your renders, and backs enforcement if the account is ever abused. Sign-up does not complete without it.
  6. Set a recovery passphrase. The last step, required before you reach the dashboard: choose a passphrase that encrypts a backup of your wallet, so you can restore it on any device with just your email and the passphrase, even without your passkey. It never leaves your browser.

Activation

Email verification and 18+ age verification both happen inside the signup flow, before the account record exists, so a normal signup comes out activated from the start. Activation means both the email and the age check have passed. An activated account can post, publish, follow, tip, unlock, set DM handles, and create in the Studio. If an account ever drops one of the two (say an email later marked unverified), the dashboard shows an activation checklist and those actions stay blocked until you finish it. Browsing the public site needs no account at all, only the 18+ self-attestation gate shown on first visit.

Logging in

Login is your passkey, not a password. On a device that already holds your wallet, the server issues a single-use challenge, your passkey unlocks the wallet key for a moment, and the key signs a canonical string:

Text
xenia-login-v1:{walletPubkeyBase58}:{nonceBase64url}

The server verifies the Ed25519 signature, burns the challenge, and sets a session cookie (30 days, httpOnly, shared across your subdomain). Secrets are zeroed from memory after every signature.

On a new device, choose Sign in with passkey and a single tap both signs you in and pulls your encrypted wallet down from its vault. If that device has no passkey for your account, you fall back to your recovery passphrase (your email plus a one-time code, then the passphrase) or your 24-word phrase. Any second factor you enrolled (an authenticator code, a security passkey, or a recovery code) is still required after the first step.

Optional two-factor authentication

Any account can add a second factor under Dashboard > Settings > Security. Two methods exist and you can enroll either or both:

  • Authenticator app (TOTP). Scan a QR code, confirm one 6-digit code, and you are enrolled. Ten single-use recovery codes are generated at enrollment and shown once.
  • Passkey. A server-side WebAuthn credential, independent of the passkey that wraps your wallet. You can enroll several, name them, and revoke them individually.

With 2FA on, login takes two steps. The wallet signature comes first, then a TOTP code, a passkey assertion, or a recovery code. Enrolling or removing a factor always requires a fresh wallet signature.

Your subdomain

Every account gets username.xenia.studio. It serves your public profile: avatar, bio, follow button, the DM unlock card, and your image grid with tip and unlock actions. A set of system and safety names (for example www, app, api, admin, docs, dashboard, login, xenia, support, and abuse) is reserved and cannot be registered.

Next steps

  • Open the web studio at /studio and make your first render, pay-per-render in SOL or OUSD: XENIA Studio.
  • Learn the wallet, send / receive, and (optionally) funding it to spend: Wallet. Earning needs no funding.
  • Start publishing and earning: Creator Guide.

Privacy & the Filter

XENIA's promise: be seen, not identified. The content is real, but it never shows the creator's actual face. The augmentation filter redraws each photo into a refined anime-style rendering in XENIA Studio, holding your pose and likeness while nothing identifying is kept.

The filter boundary

You start the redraw in the Studio from your browser, and it runs on XENIA's cloud GPUs. Your source photo goes up only to be redrawn, and it is never stored. Once the render is built, the rebuilt image is all that exists, tied to your verified account, and it is the only thing that enters your content. No unfiltered original lives anywhere on XENIA, so your real face never appears in what you publish.

Source photo

Goes up only to be redrawn.

The redraw

Redrawn into an anime-style rendering in the Studio, on XENIA's cloud GPUs.

Anime render

The only thing that survives and enters your content.

Shown

The rebuilt anime render, tied to one verified account. Be seen, but never identified.

Hidden

The source photo and your real appearance. No unfiltered original lives anywhere on the platform.

The source photo is never stored. Once the render is built, only the rebuilt image exists.

Visibility states

Every render lands as private. From the dashboard you set, per image, what the world sees:

StateWho sees what
privateOnly you, in your dashboard. Nothing is served to anyone else.
publicEveryone. Appears on your profile and in the Gallery feed.
protectedEveryone sees a heavy blur plus your unlock price. The full image is served only to you and to viewers who have paid to unlock it.
subscriberYour members gallery: fans holding a live membership with gallery access, plus your circle. It never appears in public browse or search, and everyone outside the level never receives it at all.
circleOnly members of your circle, on your profile and in their feed. Gated by relationship, not by a paywall. Everyone outside the circle never receives it at all.

Visibility, price, and caption can be changed at any time, and deleting an image hard-deletes its stored blobs.

What viewers actually receive

The server derives fixed variants from each render and serves them according to the access decision:

VariantDerivationServed to
originalAs rendered (post-filter output)Owner; everyone if public; unlockers if protected
displayLongest edge 1600pxSame policy as original (the lightbox view)
thumb512px thumbnailEveryone if public; owner only if private
blur24px downsample, gaussian blur, upscaled to 800pxEveryone, for protected images (the grid and lightbox teaser)

Why the blur is irreversible

The protected preview is not a blurred copy of the full image. We resize the image down to 24 pixels wide, blur it hard, then scale it back up. The downsample throws away the detail before the preview exists. No sharpening, AI upscaling, or deblurring gets it back. Serving the blur leaks nothing.

Encrypted at rest

Every stored variant, including private images and face references, is encrypted with AES-256-GCM envelope encryption before it touches the database. Decryption happens only inside the image-serving route, after the access check passes. The full scheme is in Security & Encryption.

XENIA Studio

XENIA Studio is the web studio at /studio. You upload a source photo and the XENIA filter redraws it into a refined anime / 2.5D illustration. It redraws the hair, face, and body while holding your likeness, your pose, and the moment you shot. After that you can turn the still into a short looping clip. There is nothing to download and nothing to install.

Your original photo is never stored. Only the rebuilt image exists, so what lands in your content shows you rebuilt past recognition, never your real face. Every session starts here.

The XENIA Studio: the create rail, the private content gallery, and the live render console.

Opening the Studio

The Studio lives at /studioonce you are signed in. There is no app to download and no device to pair. The editor loads in the browser and is ready right away. Renders run on XENIA’s cloud GPUs, not your own hardware, so the same render takes the same time on a laptop or a phone.

The create flow

A session runs from source photo to finished render in a few steps. Drop a photo into the editor, set the result on the right, generate, and approve the payment that runs it.

  1. Add a source photo. Drag in or pick the photo you want to transform. It uploads only to be redrawn and is never stored. Once the render is built, only the rebuilt image remains.
  2. Direct the result. Set a theme, dial in the look, add style and effects (everything in the next section). Leave it all blank and the redraw stays true to the photo.
  3. Generate. Press Generate. The Studio quotes the render and opens the payment.
  4. Approve the payment. Confirm the on-chain SOL or OUSD payment in your passkey wallet (see Pricing and payment). The render begins the instant the payment verifies on chain.
  5. It lands in your Private Library. The finished render arrives in your Private Library, private until you move it. Rework it with a paid edit or a remix, then ship it to Content to publish, lock and price, mint, or animate it.

Directing the result

Everything you set lives in one inspector beside the canvas, and you work within the filter’s rules. Leave it all blank and the redraw reimagines the photo as an anime-style illustration true to the shot. Opt in to as much or as little as you want.

ControlWhat it does
ThemesTheme presets re-dress the whole scene (Angel, Demon, Elf, Cyberpunk, Elegant, Vampire, and more). A Realistic option keeps the scene as shot, and a custom write-in handles any look you describe in your own words.
Hair colorAn exact hair color from a honeycomb picker or a hex value, applied to your look in the render.
Quick vibesOne-click presets that set a whole mood at once. A fast starting point you can refine.
Style tagsFree-form tags that nudge the overall style of the render.
Scene effectsAdded scene touches that were not in the source. Each one is disclosed by its provenance badge.
Color & styleColor mode (keep real color, make it anime-vibrant, or use a curated palette) and the output aspect ratio.
Seed & variationsEvery render uses a fresh seed, so the same photo and recipe make a new variation each time. Run it again for another take until you land the one you want.

Keyboard shortcuts: Cmd or Ctrl plus Enter generates, and R re-rolls the result on the easel into a fresh variation.

How the redraw works

XENIA Studio does not lay a filter over your photo. It runs an anime redrawthat replaces the photo’s pixels with new anime art, while a stack of guidance models holds your likeness, pose, and anatomy in place. Every photo runs the full stack. Each enhancement stage is guarded, so if one trips it gets skipped and the render still finishes.

Your photo
Autocrop

Trims away letterbox bars and phone-UI edges so only your photo is left.

The AI director reads the scene

An uncensored vision model studies the real photo and writes down exactly what is happening, down to where each hand sits. That reading is what keeps the anatomy from coming out mangled.

Your look, applied

Your theme, outfit, scene, effects, and color choices are layered in. Leave them and the redraw stays true to the photo.

Base redraw into anime

WAI-Illustrious SDXL repaints the picture as fresh anime art, held tight to your original by triple ControlNet (edges, depth, and pose).

Hand pass

Each hand is re-rendered large and clean so you never get melted fingers.

Face pass

The face is re-rendered crisp, keeping the same identity.

Hi-res + colormatch

A diffusion upscale pass sharpens everything, then the palette is pulled back toward your real photo.

Final upscale

ESRGAN ×4 super-resolution finishes it at roughly 2048px.

Finished anime render
Every photo runs the full stack. If any one stage trips, it is skipped and the render still finishes.

The pieces that keep it from melting:

  • A director reads the real scene. A vision model studies the photo and writes down what is happening and where each hand sits. The redraw then follows the real situation instead of inventing mangled anatomy.
  • High-strength redraw, not paint-over. A weak filter smears the photo. A strong redraw replaces it with real anime. Triple ControlNet (edges for likeness, depth for volume, pose for limbs) then locks it back onto the original.
  • Dedicated hand and face passes. The two regions that always break get re-rendered large and clean.
  • Colormatch and a final upscale give a faithful palette and a crisp HD finish.

The same pipeline, run by others

This redraw pipeline also powers a private capability where someone else pays to render a creator. It is solo and consent gated, and puts exactly one person in frame, the creator, from their verified likeness. The person paying is never in the scene.

  • A member renders the creator.With a live membership, a member renders private solo stills of the creator, pay-per-render, chosen only from the scenes the creator approved and only while the creator keeps it switched on. The results are the member's alone. See Memberships.

To place a second person you cast a consenting circle member in a co-scene, which is never reachable from a membership render.

Turning a still into video

Any finished still can become a short video. Open Video mode, pick one of your renders, and press Video. The model reads the image and writes the motion itself, with no setup from you. A video is its own render on XENIA’s cloud GPUs and is priced separately (see Pricing and payment). The finished loop lands in your Private Library like a still, a creation that plays.

Every creation lands in the Private Library, a gallery only you can see. Nothing leaves it until you say so. Rework it there with a paid edit or a remix, then ship a creation to Content on your dashboard. Content is where you act on it. From Content you can:

ActionWhat it does
PublishMake the creation public so it appears on your profile and flows into the Gallery feed.
Lock and priceProtect the creation behind an unlock price in OUSD. Viewers see only the irreversible blur until they pay.
VideoBring a still to life as a short video, a separate paid render.
EditRun a paid second pass on the creation: add an effect or enhance it (see Paid edits and tools).
DownloadSave the rebuilt image or loop to your own device.
DeleteRemove the creation permanently.

You can also mint a creation as an NFT to your own wallet straight from the gallery, and sell it where the marketplace is enabled. See Collectibles & NFTs.

A creation is a starting point. From any item in the Private Library you can run a paid edit, a second pass that takes the existing render and reworks it. Each edit is its own render on XENIA’s cloud GPUs, priced like an image render (about $0.17), and approved on chain in your passkey wallet like a generation (see Pricing and payment). The result lands back in the gallery as a new creation, and the original stays put. There are two edit tools, effects and enhance. Adding a second person is not an edit: you cast a consenting circle member in a co-scene, rendered from their own verified likeness, never an invented partner.

ToolWhat it does
Add effectsAdd a scene effect that was not in the source. The added effect is disclosed by its provenance badge.
EnhanceRefine an existing creation for a cleaner, higher-quality finish.

Pricing and payment

XENIA Studio is pay-per-render, on chain and non-custodial. Every render is a Solana payment in SOL or OUSD, approved per render in your passkey wallet. A generation, a video, and a paid edit are each their own render and their own payment. No subscription, nothing to pre-buy, and no custodial balance held by the platform. The render starts the instant the payment verifies on chain.

RenderPrice
Image$0.17 per render
Paid edit (effect or enhance)$0.17 per render
Animation$1.99 per render

Prices are set in USD and charged in SOL or OUSD at the spot rate, shown to you before you approve. You pick the currency at payment time. The exact SOL and OUSD amounts are locked into the quote at that rate; if the market moves and the quote expires before you pay, you simply re-quote at the fresh rate rather than clearing at a stale one.

If a render does not deliver, you are made whole. Payments are final, so XENIA never sends funds back out of the treasury. Instead, if a paid render fails for a technical reason, or you cancel it before it starts delivering, you are credited a free render in its place, redeemable through the same one-tap flow with no second payment.

What a single render costs, in both currencies, off the live rate:

What a render costs
Image (or a paid edit)
0.17 OUSD0.0011 SOL
Animation
1.99 OUSD0.0133 SOL
PayVerify on chainRender runs
Prices are set in USD and charged in SOL or OUSD at the spot rate, shown before you approve. SOL figures update from the live price feed; you pick the currency at payment time.

Content safety

Short of those lines, what consenting adults choose to share is theirs to share.

Provenance badges

Every render can carry a small set of provenance tags that record how it was made: the creator’s verified face (or, for a co-scene, its cast), whether the body was enhanced, any theme, and so on. XENIA draws the tags that apply as a credential stack from one place in the code, so they read the same everywhere. The stack is credential-only: it shows only the tags that actually apply, so a plain conversion with nothing to disclose shows no badge at all.

BadgeWhen it appearsWhat it means
VERIFIEDA solo render with the creator’s verified face in the sourceThe face match confirmed the creator’s own verified likeness is in the photo. The match is built to be robust to real-world variation (lighting, angle, distance, and expression) by comparing against a growing set of the creator’s verified references. It attests to identity only, never to age or to anyone else in the frame.
CO-SCENEA co-scene (the creator plus one or two consenting circle members)A co-scene is verified by construction (every cast face is a verified likeness), so it carries CO-SCENE in place of a redundant VERIFIED. The co-stars are real, consenting circle members.
ENHANCEDWhen a fitness change was appliedA fitter or more toned build was applied. Breast and genital size can never be changed, so size is always authentic and only fitness flips this on. A body rendered as the director saw it shows no badge.
MMF / FFMWhen a co-scene casts a third personNames a three-person composition (MMF or FFM), shown alongside CO-SCENE.
THEMEWhen a costume or fantasy theme is appliedNames the active theme (for example DEMON, ANGEL, ELEGANT), so a costume re-dress is never mistaken for the real scene.
CUMWhen that finish is addedDiscloses an added finish.

Only the tags that apply are shown, as a small stack in a corner. A few examples: a plain conversion shows nothing; VERIFIED · ENHANCEDis the creator’s matched face with a fitness change; VERIFIED · DEMON is a matched face in a demon costume; and CO-SCENE · MMF is a three-person co-scene. XENIA draws the stack from the stored provenance as a UI overlay(over both stills and animated loops) and never imprints it into the pixels. A downloaded file is therefore visually clean, with no visible mark; only XENIA’s own galleries and viewers display the credential stack, adding it on every view so the disclosure never falls to the creator.

From the Studio to your page

The path of a finished render is the same for a still image and an animated loop.

Add a source photo

Drop in the photo you want to transform. It is never stored; only the rebuilt image survives.

Direct the result, then Generate

Set the theme, outfit, scene, and effects you want, then press Generate.

Approve the payment

Confirm the on-chain SOL or OUSD payment to the XENIA treasury in your passkey wallet.

It renders on XENIA cloud GPUs

The render starts the instant the payment verifies on chain, on XENIA's hardware, not yours.

It lands in your content as PRIVATE
Every render arrives here first; only you can see it. Open Dashboard ▸ Content.
You choose, per item
Keep private

Nobody else ever sees it.

Make public

Free for everyone to view.

Protect with a price

Shows blurred; unlocks forever the moment a viewer pays.

Anything public or protected appears in two places
Your subdomain
your own page
The Gallery
everyone’s work, together
$0.17 per image$1.99 per animationDirect to the treasury

Still images and loops behave the same way once they are in your Private Library. A loop is just a creation that plays. When you protect an item with a price, viewers see only an irreversibly blurred teaser until they pay, and the unlock is permanent and settles wallet-to-wallet on Solana (see Tips & Unlocks). Public items show full-quality on your page and flow into the shared Galleryfeed, where the whole community’s work is ranked together and sortable by views, tips, and hearts. On your own page you curate that gallery yourself, dragging your published work into the order visitors see. You can also mint any creation as an NFT, and sell it where the marketplace is enabled (see Collectibles & NFTs).

Creator Guide

To create, you need the account you already made and the web studio. That is it. No application, no payout forms, no minimums. This guide takes you from a fresh account to money landing in your wallet.

The arc is the same for everyone: verify once, create in the Studio, publish or protect what you make, optionally promote it, then earn and save. Here is the whole journey at a glance before the step-by-step.

Verify

Finish email and 18+ ID verification once. An activated account can create, publish, follow, tip, and unlock.

Create in the Studio

Redraw a source photo into an anime-style illustration, then push it further with a paid edit or animate it. Each render is pay-per-render in SOL or OUSD.

Image $0.17Animation $1.99
Publish or protect

Make a creation public, or protect it behind an unlock price set in OUSD so viewers see only an irreversible blur until they pay.

Promote

Optionally boost any published post to the top of the feed for 30 days with a flat fee in SOL or OUSD: Standard or Premium.

Earn

Keep 93% of every tip, unlock, and NFT sale, settled in the same on-chain instruction the fan signs. Income arrives in SOL or OUSD.

SOLOUSD
Save

Hold value in gold or earn staking yield right in your wallet, then swap back to dollars whenever you want.

Your income, your savings, and your keys, all in one place
$0.17 per image$1.99 per animation93% of every tip and unlock

1. Activate and open the Studio

Finish both verifications (Getting Started), then open the web studio at /studio (XENIA Studio). Creating requires an activated account. There is nothing to download and nothing to install.

2. Create

Upload a source photo, direct the result, and press Generate. Each render is pay-per-render: you approve a real Solana payment in SOL or OUSD, $0.17 for an image and $1.99 for an animation, and the redraw runs on XENIA’s cloud GPUs the instant it verifies. The original photo is never stored. Every finished creation lands in your Private Library, where nobody but you can see it until you decide otherwise.

From there you can push a creation further with a paid edit: add an effect or enhance, each its own ~$0.17 render. To add another person you cast a consenting circle member in a co-scene; there is no invented partner. You can animate any still into a loop, and you can mint a creation as an NFT to your own wallet (see Collectibles & NFTs).

3. Publish

  • Public images appear on your profile and in the Gallery feed. They earn views and tips.
  • Protected images appear everywhere as an irreversible blur with your unlock price. They earn views, tips, and unlock revenue. A protected image requires a price above zero, in OUSD.
  • Subscribers posts go to your members gallery: fans on a membership with gallery access, plus your circle. They stay out of public browse and search.
  • Circle posts reach only your circle, gated by relationship rather than a price.
  • Captions, prices, and visibility are editable at any time, and you can delete any image permanently.

4. Set up your External DM unlock

Under Dashboard > External DM, add any of Telegram, Discord, Keybase, SMS, or email, and set one reveal price. Handles are stored encrypted and revealed only to paying fans. This is for talking off platform. In-app Messages are end-to-end encrypted and free between verified adults. Details in External DM Unlock.

5. Share your page

Your profile lives at username.xenia.studio. It carries your avatar, bio, follow button, DM unlock card, and your grid. Link it anywhere. Viewers need no account to look, only to pay or follow.

6. Promote a post (optional)

For more reach, hit Promote on any published post in the Content tab and pay a flat fee in SOL or OUSD: Standard ($10) or Premium ($30). The payment settles on chain to the platform, and the post jumps to the top of the feed and shows up more in search and suggestions for 30 days. Premium boosts harder. A promotion decays as it ages and drops back to organic ranking at the end of its run. See all your promotions, active and expired, in the Markettab's Promotions view, where you can re-promote one that has lapsed.

7. Build your community

Every image and animation has a comment thread. Any signed-in, verified member can join in, react with the XENIA emoji set, and like the comments they like. Likes float the best replies to the top of the stack, and comments feed the same rank score, so a busy thread pushes a post up the feed.

You stay in control of your space. Delete any comment on your own media, delete your own comments anywhere, and block anyone you would rather not have around. A blocked person can no longer comment on your work, heart it, like your comments, follow you, or unlock your DMs, and their comments drop off your posts. Lift a block at any time.

How the money works

  • 93% of every payment (tips, image unlocks, DM reveals, memberships) arrives in your wallet in the same on-chain instruction the fan signs. There is no payout schedule because there is no payout: the money never stops anywhere else.
  • Dashboard > Earnings lists every tip and unlock with its payer context. Dashboard > Wallet shows the complete on-chain history with CSV export.
  • Fans pay in SOL or OUSD; your prices are set in OUSD and displayed in both.
  • You never fund anything to start earning. A fresh wallet with a zero balance collects tips and unlocks from day one; depositing or buying crypto is only ever for spending.
  • NFTs are another way to earn. Mint any public creation as a collectible straight to your wallet for only the Solana network fee. Where the marketplace is enabled, sell it, or any NFT you own, and keep 93% of every sale. See Collectibles & NFTs.
  • Generating costs are separate from earnings. The pay-per-render charge in the Studio (a generation, an animation, or a paid edit) is a separate per-render payment, not the 93/7 split. The 93/7 split applies to the tips and unlocks a published creation earns. See XENIA Studio.

More ways to earn

Beyond tips and unlocks, several surfaces turn the same work into income. Each settles wallet to wallet and stays non-custodial, with nothing held in between.

  • Memberships. Offer a membership as prepaid access, a block a fan buys in one signature, and keep 93% like every other payment. See Memberships.
  • Collectible scarcity. Mint limited drops with rarity tiers and completable sets to make what you mint scarce. Minting stays free apart from the Solana rent. See Collectibles & NFTs.

Dashboard map

TabWhat it does
OverviewStats at a glance, activation checklist
FollowingYour home feed: the creators and posts you follow
ContentYour content library: visibility, price, caption, animate, edit, mint, delete
WalletBalances, deposit QR, send, swap, full history, CSV, and wallet backup
EarningsTips and unlocks with payer context, plus your membership and members
MarketYour collectibles and your promotions
CircleYour circle and co-scenes
MessagesEncrypted in-app direct messages
External DMOff-platform handle services and the reveal price
SettingsSecurity, two-factor and passkeys, sign-in email, account deletion

Creator Dashboard

Your dashboard is where you run your account on XENIA. Sign in and the Overview opens first, a single snapshot of every interaction your account has had.

The map below lays out every surface at once: the Overview you land on, and the dedicated tabs that run each part of your account.

Your dashboard at a glance
Overview opens first, then a tab per surface
Overview

Opens first. One snapshot of balances, earnings, content, reach, and circle.

Wallet

Balances, buy, receive, send, swap, save, and earn, all on-chain.

Content

Your library, each item's visibility and price, and your seven featured pieces.

Circle

Manage your circle and co-scenes.

Following

A feed of the creators you follow.

Messages

End-to-end encrypted DMs. Stats show volume only, never content.

Earnings

Every payment received, with full payer context.

Market

Your collectibles and your paid promotions.

External DM

Set the reveal price for your off-platform contact handles.

Settings

Security, two-factor and passkeys, sign-in email, wallet backup, and account deletion.

Your display name, bio, avatar, and borders are edited on the live profile at username.xenia.studio, not from a tab here.

What the Overview shows

  • Wallet balances. Your live SOL, OUSD, gold (PAXG), and jitoSOL, read straight from the chain, with a total in USD. See Wallet for how funds move.
  • Earnings and spend. Everything you have earned, split by source (tips, image unlocks, DM unlocks, collectible sales), and everything you have spent, with a 30-day earnings trend.
  • Your content library. A breakdown of how many posts are public, locked, private, or DM-only, how many are videos, and how many are for sale.
  • Renders. How many Studio renders you have made, image versus animation, and what you have spent creating them.
  • Engagement and reach. Total views, hearts, and comments. Your follower and following counts. Your reputation score, which is the same signal that lifts you in the feed (see Ranking).
  • Messages, collectibles, promotions, and activity. Your DM volume, listed and sold collectibles, promotion status, and recent activity (deposits, plus comments and hearts received), all in one place.
  • Top posts. Your best work, ranked by a tips-weighted performance score.

The rest of the dashboard

Beyond the Overview, dedicated tabs run each part of your account: Wallet, Messages, Following (a feed of the creators you follow), Circle (manage your circle and co-scenes), Content and its visibility and prices, Market (collectibles and your promotions), Earnings (tips, unlocks, and your membership), External DM pricing, and Settings.

Settings holds your account security, your two-factor authentication and passkeys, the verified sign-in email, and account deletion. Your wallet backup and the option to replace an empty wallet with a fresh one live in the Wallettab's Backup view. Your display name, bio, avatar, and borders are edited on the live profile itself at username.xenia.studio; your seven featured pieces are pinned from the Content tab, and your circle is managed from the Circle tab. You curate the gallery itself, dragging your work into the order visitors see, and your page gathers it all: your gallery, the collectibles you hold, and the pieces you have loved and tipped.

Wallet

Your XENIA wallet is a real Solana wallet, created in your browser the moment you sign up. There is no app to install and no third-party wallet to connect. The keypair lives on your device, wrapped by your passkey, and the server only ever learns the public address. If our whole database leaked tomorrow, nobody could spend a cent of your funds.

The wallet is where your income and your savings live, and you are the only one who can touch them. You hold the keys. Fans pay you directly. You spend, swap, save in gold, and earn yield without a bank, a broker, or a custodian sitting between you and your money. That is the point of building it non-custodial: your livelihood stays yours.

Four assets, one wallet

Your wallet holds four assets, two to spend and two to grow. SOL and OUSD are the money you pay and get paid in. Gold (PAXG) and jitoSOL are the Vault, where you save in real gold and earn staking yield without leaving the app. All four are real tokens you hold yourself, and any one swaps to any other in a tap. The prices below are live.

SOLNative · spend
$150.00per SOL

Solana's own coin, the network XENIA runs on.

Pays the tiny fee on every transaction, and you can tip, unlock, and get paid in it. Moves in under a second for a fraction of a cent.

OUSDStable · spend
$1.00always ~$1

A digital dollar that always sits at about $1.

No price swings, so it is the steady way to get paid, price your work, and hold cash. Every price on XENIA is set in OUSD.

Gold (PAXG)Save · gold
$4,078.00per ounce

PAX Gold. One token is one ounce of real vaulted gold.

Tap Save to turn SOL or OUSD into gold and hold value over time. It sits in your own wallet, and you swap it back to dollars whenever you want.

jitoSOLEarn · staking
$92.00per jitoSOL

Liquid-staked SOL that quietly earns yield.

Tap Earn and your SOL stakes into jitoSOL, accruing staking and MEV rewards. No lockup, and it stays tradable, so you unstake to SOL anytime.

APY

In the wallet the four read as a single balance. The Total value view draws each asset as a tile sized by its share, so you see your whole position as one picture instead of a column of numbers.

38%
0.25 PAXG
$1,019.50
4.20 SOL23%
$630.00
6.00 jitoSOL21%
$552.00
480.00 OUSD18%
$480.00
The Total value view: every asset sized by its share of your balance, valued live from the chain.

Money moves through the wallet in one loop. What you earn lands as SOL or OUSD. From there a tap swaps any asset to any other, so the same balance can sit in gold, or earn yield as jitoSOL, then come back to dollars when you want it.

People who value your work
tips, unlocks, and sales, in SOL or OUSD
Your wallet
SOLOUSD
the money you spend and get paid in
one-tap swap, any asset to any asset
Spend

Tip creators, unlock posts, and pay per render.

Earn · Staking

Stake into jitoSOL for yield, with no lockup.

Save · Gold

Hold value in real vaulted gold (PAXG).

Two assets to spend with, two to grow, all in your own keeping, and each swaps back whenever you want.

How the wallet is created

Your browser makes the key

At signup your browser draws a random 32-byte seed and derives your Solana keypair from it. Nothing is sent to a server.

Your passkey locks it

The seed is encrypted with AES-GCM under a key derived from your passkey's hardware. That wrapping key is stored nowhere, so only your device can unlock it.

Stored encrypted, follows you

The encrypted blob lives in your browser and syncs to a passkey-encrypted server vault, so the wallet reaches your other browsers. The server only ever holds ciphertext and your public address.

A 24-word phrase, shown once

Your deepest portable backup, the BIP39 standard. Enter it on any device to re-create the same wallet, with no email, passkey, or XENIA in the loop. Your passkey and your recovery passphrase are the other two ways back.

Only your passkey can ever spend
The server never sees your seed, your phrase, or your private key, at signup or ever after. If the whole database leaked, not a cent would move.

The key that wraps your wallet comes from the WebAuthn PRF extension, tied to your device's hardware authenticator (browsers without PRF fall back to an HKDF derivation from the passkey credential id). The encrypted blob sits in the browser's IndexedDB, every signature takes a passkey unlock, and key material is zeroed from memory after each use. The 24-word phrase is BIP39, the portable form of the same wallet.

The server never sees the seed, the phrase, or the private key, at signup or after. The one thing XENIA stores is your public wallet address, which is public by nature and cannot be used to spend. It links your earnings to your account and drives your wallet view.

How you unlock, and how you recover

Self-custody usually forces a hard trade: hold one fragile secret yourself, or hand it to a company that can lose it or freeze it. XENIA refuses that trade. Your wallet opens three independent ways, and every one of them is a key only you hold. Each backup is sealed on your own device before it is ever stored, so there is never a copy of your keys for anyone to leak, subpoena, or misuse, not even us.

Your wallet seed
generated on your device, never sent to the server
Sealed three independent ways
Every day
Passkey

Your device hardware (Face ID, Touch ID, Windows Hello) holds it, and the WebAuthn PRF extension derives the AES-256-GCM key fresh each unlock. A glance unlocks day to day, and on a new device where the passkey syncs, one tap signs you in and restores the wallet.

Any device
Recovery passphrase

A passphrase you choose, stretched by memory-hard Argon2id into the key that seals a synced backup. Restore anywhere with your email, a one-time code, and the passphrase.

Forever
24-word phrase

The same wallet in the BIP39 standard. Written once and kept offline, it restores the wallet with no email, no passkey, and no XENIA in the loop.

XENIA stores only ciphertext. The keys live only with you.
Every backup is encrypted on your device before it is stored, each under a key only you hold. No XENIA employee, database breach, or legal demand to XENIA can reveal your seed, because we never receive it.

Your passkey, for every day.The fast path. Your device's secure hardware (Face ID, Touch ID, Windows Hello, or a security key) holds a passkey, and the WebAuthn PRF extension turns it into the AES-256-GCM key that wraps your seed. A glance or a touch unlocks the wallet to sign; the key is derived fresh each time, used in memory, and wiped after, stored nowhere. Nothing to remember, nothing to type. On a new device where your passkey syncs (iCloud Keychain, Google Password Manager), one tap signs you in and pulls your encrypted wallet down from its server vault, ready to unlock.

Your recovery passphrase, for any device. A passphrase you choose encrypts a second copy of your seed, wrapped under a key stretched from that passphrase with Argon2id, a memory-hard function built to make guessing ruinously slow and expensive. That sealed copy syncs, so you can restore on any device or browser, even one that has never met your passkey: enter your email, confirm a one-time code, type your passphrase, and your wallet rebuilds itself in the browser. The passphrase never leaves your device and the server holds only the ciphertext, so the backup is portable without ever becoming custodial.

Your 24-word phrase, the ultimate fallback. The same wallet in BIP39 form, the universal standard. Write it down once, keep it offline, and it restores your wallet anywhere, forever, with no email, no passkey, and no XENIA in the loop. It is the bedrock the other two rest on.

Replace an empty wallet

If your recovery phrase leaked, or you want a clean key, generate a new wallet from Settings and point the account at it. This works only while the current wallet is empty (no SOL, OUSD, gold, or jitoSOL), so a rotation can never strand funds. The new wallet proves control with a signature, you see its fresh 24-word phrase once to save, and the old wallet stays put on chain.

Supported assets

AssetRoleDetails
SOLPaymentSolana's native coin. It is both a utility token, the currency you send and receive in and the fuel for the small network fee on every transaction, and a speculativeone, whose price moves with the market, so simply holding it is a bet on Solana's growth.MintSo11111111111111111111111111111111111111112(wrapped SOL, 9 decimals)
OUSDPaymentOpen USD, a shared stablecoin built as open infrastructure, so it is the trusted, steady way to price your work and get paid. Always sits near a dollar.MintEPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v(6 decimals)
PAX GoldSavingsA Token-2022 from Paxos where every token is backed one for one by a physical troy ounce of London Good Delivery gold held in a professional London vault. Holding PAXG is holding real, allocated gold, your savings asset.Mint5GgRAEmv8ZxF2PR5hY72Qs5x1bnQ6UK2RbTPoqJ3wSwW(Token-2022, 6 decimals)
jitoSOLSavingsJito's liquid-staking token, SOL that earns staking plus MEV yield while staying tradable, your earn asset.MintJ1toso1uCk3RLmjorhTtrVwY9HJ7X8V9yYac6Y7kGCPn(9 decimals)

SOL and OUSD are the payment assets: you spend, send, and receive in them. Gold (PAXG) and jitoSOL are savings assets: you hold and grow them in the Vault and swap them back when you want, but you do not pay other people in them. Any other token sent to the address is ignored across the product. Prices show in both currencies, $X OUSD (≈ Y SOL), off a server-side quote cached for 60 seconds.

Buy SOL or OUSD

Fund your wallet with a card or bank from inside XENIA, where a card provider is enabled. No exchange account needed. Open Dashboard › Wallet › Buy, pick SOL or OUSD, and choose a provider (MoonPay or Transak). The provider opens prefilled with your address and the asset you picked, so the crypto lands in your XENIA wallet the moment the purchase clears. Pay by card, Apple or Google Pay, or bank transfer where the provider supports it. That provider runs its own identity check and is who you actually buy from. XENIA never touches the funds.

Receive by QR code or address

Already hold crypto somewhere else? Send it in. Tap Receive and your address shows two ways:

  1. Scan the QR code. In your other wallet or exchange, choose send and scan the QR on screen. It fills in your XENIA address, so no typing and no paste error.
  2. Copy the address. Tap Copy address and paste it as the destination in the sending app.

Send SOL, OUSD, gold (PAXG), or jitoSOL on the Solana network only. No minimum and no processing step on our end. The funds are yours the moment the transaction lands, usually within seconds. Other tokens, or transfers on a different network, are not supported and could be lost.

Send

The wallet sends all four assets (SOL, OUSD, gold, and jitoSOL) to any Solana address. Each send is built in the browser, confirmed with a passkey unlock, signed locally, and submitted to the chain. A withdrawal is a send to wherever you want the funds.

No fee, ever, on your own money. XENIA takes nothing on a deposit, a send, or a withdrawal. Moving your own funds in or out costs only the small Solana network fee, so you keep 100%. The 7% platform share applies to tips, image unlocks, and External DM unlocks (see Tips & Unlocks) and to NFT trades, never to your own balance. A full withdrawal drains to zero and reclaims even the small rent on an OUSD token account, so no dust is left behind.

Swap any asset

The wallet swaps any of your assets for any other, SOL, OUSD, gold (PAXG), and jitoSOL, in place, routed through the Jupiter aggregator for the best rate it can find. Pick what you pay and what you receive on either side. All four show on both, so you never flip the swap to reach a token. The panel opens on the live rate and the quote updates as you type, showing the price impact and the guaranteed minimum you receive before you commit. Confirm, and the swap signs with your passkey and settles on Solana for a small network fee in SOL. Slippage is capped at 0.5%, so a moving market cannot fill at a materially worse price than quoted. A swap trades your own assets inside your own wallet, and XENIA takes no cut.

250 OUSD0.0613 PAXG

A worked example at the live gold price ($4,078.00 an ounce): any asset swaps straight to any other in one tap, routed for the best rate. Save and Earn are just this swap, preset to buy gold or stake SOL.

Save in gold

Save holds real gold. It converts any amount of OUSD or SOL into PAX Gold (PAXG) at the live price, where one PAXG is one troy ounce of London Good Delivery gold held in audited Paxos vaults. Your holding shows by the ounce and in dollars, and you can swap it back to OUSD anytime. The conversion routes through Jupiter and signs with your passkey, so the gold sits in your own wallet, never with XENIA. It is a way to park value in gold without leaving the app or opening a brokerage account.

1000 OUSD
0.2452ozgold (PAXG)

Saving 1000 OUSD at the live gold price of $4,078.00 an ounce. It sits in your own wallet, and you swap it back to dollars whenever you want.

Earn by staking

What staking is. Solana runs on validators that process every transaction, and the network decides how much weight each one carries by how much SOL is stakedbehind it. When you stake, you put your SOL's weight behind that work and earn a share of the fresh SOL the network pays out for securing it. It is the closest thing on chain to earning interest, and it is what keeps Solana secure.

Liquid staking removes the usual catch. Plain staked SOL is frozen while it earns; jitoSOL is a token that represents your stake and quietly climbs in value against SOL as rewards accrue, yet it stays fully tradable. So the same SOL earns yield and stays liquid at once. jitoSOL also captures a little extra: on top of ordinary staking rewards it collects the MEV tips Jito earns from ordering transactions, which is why its yield runs a touch higher.

In the wallet, Earn does all of this in one tap: it stakes your SOL into jitoSOL at the live rate. There is no lockup and no unbonding wait, unstake back to SOL whenever you like, in seconds. The live APY comes from Jito's own published feed, the stake and unstake route through Jupiter for the best rate, and both are signed with your passkey and held by your wallet, never by XENIA.

SOL
jitoSOL a year

Tap Earn and any amount of SOL becomes jitoSOL, earning that same whether it is a fraction of a coin or a thousand. Nothing locks up, so you swap back to SOL the moment you want it for a tip or an unlock. Live rate: 1 SOL ≈ 1.630 jitoSOL.

History and CSV export

The History view reads the full on-chain history of your address and sorts every transaction into a labelled row: deposits and sends (received / sent), plus the XENIA money events it can attribute, payments you made (a tip you sent, a post or DM you unlocked) and earnings you received (a tip or unlock from a buyer). Each row shows the token and amount moved, the USD value and counterparty where XENIA knows them, and a link to the transaction on the Solana explorer. Those labels come from merging the raw chain transactions with your platform money events from /api/me/activity. The list paginates and exports to CSV for bookkeeping. Your earnings are also collected on their own under Dashboard > Earnings with full payer context.

Collectibles

The wallet also holds your collectibles: every Solana NFT your address owns, read live from the chain and shown as a grid in its own tab next to your token balances. From any collectible you own you can list it for sale where the marketplace is enabled, or send it to any address, right from the portfolio. The same collection shows on your public profile. See Collectibles & NFTs for the portfolio, the showcase, and the marketplace.

Moving to a new device

Your encrypted seed blob also syncs to a passkey-encrypted server vault, so your wallet follows you to your other devices with nothing to retype. Only the PRF-encrypted form is ever uploaded; its wrapping key comes from your passkey and is never stored, so the server holds pure ciphertext and the wallet stays non-custodial. On a fresh device where your passkey syncs, choose Sign in with passkey, and a single tap both signs you in and pulls the vault down, then unlocks it on the spot.

On a device where your passkey is not available, your recovery passphrase brings the wallet back with no local state at all. Choose restore, enter your account email, confirm the one-time code, and type your passphrase. The encrypted backup is decrypted in your browser, the wallet is re-wrapped under a fresh passkey on that device, and you are signed in. Set or change this passphrase anytime in the Backup tab.

Your 24-word phrase is always there as the deepest fallback. Choose restore in the Backup tab and enter the phrase; the wallet is re-derived, wrapped under a fresh passkey on that device, and stored in its IndexedDB. The phrase itself never leaves your browser.

Collectibles & NFTs

Collectibles are Solana NFTs your wallet holds. Your images and animations already earn tips and unlocks on their own, with no token involved. Separately, any NFT in your wallet gathers into a collectibles portfolio you can keep, showcase, send, or sell. That covers ones you minted from your own creations, ones you bought on the XENIA marketplace, and ones you picked up elsewhere on Solana. Collectibles are non-custodial like everything else on XENIA. The token lives in your wallet, not in a platform account, and only you can move it. Where the marketplace is enabled, selling one follows the same split as tips and unlocks: the platform takes 7%. Reselling a piece you minted yourself, you keep the other 93%; reselling another creator's work, their royalty also comes out of your share (see below).

Mint, for network rent only

Mint a public creation into a Solana NFT. Your passkey signs and the token lands in your wallet. You pay only the Solana network rent, around 0.01 SOL. XENIA charges no mint fee.

Hold it in your portfolio

The collectible joins your on-chain portfolio and your profile showcase. It is yours to keep, send to any address with no platform fee, or list for sale.

Sell it where the marketplace is enabled

List in SOL or OUSD. On a sale, xenia-market pays the seller 93% and moves the token to the buyer in the same instruction. The platform fee comes off the top.

Sold in either currency, settled wallet to wallet
Priced in SOL
Priced in OUSD
Mint: network rent onlySend: no platform feeSale: seller keeps 93%

Minting your creations

Once a creation is published public, you can mint it into a Solana NFT from the Content manager. Your passkey wallet signs the mint and the token lands straight in your wallet. You pay the Solana network rent, around 0.01 SOL, and nothing to XENIA: there is no mint fee. The NFT carries the rebuilt anime-style image and a 7% royalty on any future marketplace sale. Minting needs a public creation, since an NFT image is world viewable.

Editions, drops, and rarity

What makes a piece scarce
Editions, drops, rarity, and sets
Edition number
#12on its own12 of 50inside a capped drop

A serial counted from #1 across everything the creator mints, assigned the moment the mint records and never changed.

Limited drop
34 / 50
16 left before the capA hard cap of 1 to 10,000. A full drop refuses further mints.
Rarity tiers
CommonUncommonRareEpicLegendary

One of five, the creator's call at mint time, shown as a chip on the piece wherever it appears.

Completable set
4 / 6 collected

A named collection a creator curates. Each profile shows the signed-in visitor's own progress, piece by piece, until the set is complete.

Scarcity is metadata, not a feeMinting stays free apart from the Solana rent

Every piece you mint carries an edition number: your own serial, counted from #1 across everything you have minted. On its own, a piece reads as #12; inside a capped drop it reads as 12 of 50. The number is assigned the moment the mint records and never changes.

A limited dropis a titled run with a hard cap, 1 to 10,000 editions, and an optional open and close window. A full drop refuses further mints, and so does a closed window, so a cap means what it says. A drop can also be reserved for the creator's members, tying a run to a membership. You create drops and place pieces into them right in the mint flow, from the Content manager.

Each mint also carries one of five rarity tiers: Common, Uncommon, Rare, Epic, or Legendary. The tier is the creator's call, made at mint time, and it shows as a chip on the piece wherever it appears, in portfolios, on profile showcases, and in the Gallery listings band.

Completable sets

A setis a named collection a creator curates and collectors chase. Place pieces into a set at mint time, and the creator's profile shows each set with the signed-in visitor's own progress against it, piece by piece, until the set is complete.

Where a collectible came from

Every collectible reads as a standard Solana NFT in any wallet or explorer that speaks the Solana Digital Asset Standard. In your portfolio each one is tagged by origin: a Minted chip for a piece the creator made, or a Collected chip for one they bought from someone else. The portfolio reads live from the chain, so a collectible shows up the moment it is indexed.

Your collectibles portfolio

Your wallet carries a collectibles portfolio: every Solana NFT the wallet holds, read live from the chain. Open Dashboard › Wallet and the Collectibles tab to see the full set as a grid, each token with its art and name. Your SOL, OUSD, gold, and jitoSOL balances sit in the wallet itself, and the portfolio is the collectibles view next to them. From any collectible you own you can send it out to any address, and, where the marketplace is enabled, list it for sale.

Sending a collectible out

A collectible is yours to move. From the Collectibles view, choose Send on any piece, enter a destination Solana address, and your passkey signs an on-chain transfer of the token out of your wallet. A send carries no platform fee. It is a withdrawal of your own asset, not a sale, so it never touches the marketplace program. The transfer is final once it confirms, so XENIA validates the destination address before you sign. The piece leaves your portfolio and your profile showcase when the transfer finalizes.

Your collection showcase

Your public profile at username.xenia.studio carries a collection showcase: the collectibles your wallet holds, on display for any visitor to browse. It sits alongside your own gallery and the work you have loved and tipped, so your profile gathers what you made, what you own, and what you love in one place. The showcase draws from the same on-chain portfolio, so it stays current as you buy or sell. Visitors get a read-only view. When your wallet holds nothing the showcase hides itself, so an empty collection never leaves a gap on your page.

The marketplace

XENIA includes an on-chain NFT marketplace through a second Anchor program, xenia-market, alongside xenia-pay. You can sell any NFT you own, wherever it came from, and listing, buying, and cancelling are plain Solana transactions, built in your browser and signed by your passkey wallet.

List

Set a price in SOL or OUSD. The token is escrowed into the program vault, so the NFT itself backs the listing.

Buy

The buyer pays in the listing currency. The program pays the seller 93% and releases the token to the buyer in one instruction, with the platform fee taken off the top.

Cancel

Cancel one of your own active listings after a short delay. The escrowed NFT returns to your wallet and the listing closes.

The fee is read from the program's on-chain Config, never a client constant, so it cannot quietly climb. One transaction settles at most one sale.
ActionWhat happens on chain
ListSet a price in SOL or OUSD. The token is escrowed into the program vault and a Listing record is created, so the NFT itself backs the listing.
BuyThe buyer pays in the listing currency. In one instruction the program keeps the 7% platform fee, pays the original creator's royalty when the seller is not that creator, sends the seller the rest, and releases the token to the buyer. Reselling a piece you minted yourself, the royalty is zero and you keep the full 93%.
CancelYou can cancel one of your own active listings after a short delay; the escrowed NFT returns to your wallet and the listing closes.

A trade is enforced the same way a tip is. The program reads the platform commission wallet from its on-chain Config, never from a client constant, so a buyer can never be redirected to a different address. A canonical reference binds the buyer to the sale. The server records the sale only after it re-reads the on-chain event and confirms the seller was credited the net. One transaction settles at most one sale.

Text
xenia:buy:{mint}:{buyerUserId}:{nonce}

Listings in the Gallery

Where the marketplace is enabled, active listings surface in Galleryas a separate band above the ranked feed, so collectibles for sale sit next to the rest of the community's work. Each entry links to its listing and shows the art, the seller, and the price in both currencies. With no active listings the band hides itself, and the feed reads as usual.

Tips & Unlocks

Creators get paid two ways on XENIA: tips and unlocks. Each is a plain Solana transaction, built in your browser and signed by your passkey wallet, that routes through one on-chain program (xenia-pay) and drops 93% straight into the creator's wallet the instant you sign. No balance to top up, no payout to wait on.

One payment
A tip or unlock, paid in
SOLOUSD
splits atomically on chain
93%
7%

The creator keeps 93%, sent straight to their own wallet in the same instruction the viewer signs. The remaining 7% is the platform fee, capped in the xenia-pay program so it can never quietly climb.

One signature, one transaction, split on chain and never by a server.

The 7% that stays behind is the only cut XENIA takes on what a creator earns, and it is fixed in the contract so it cannot creep upward. It is the same across tips, image unlocks, External DM unlocks, and memberships, in SOL or OUSD. NFT trades carry their own fee through the xenia-market program. Minting your own work is free, only the Solana rent, so it earns nothing and pays no fee. Two more things sit outside it. A paid promotion is a flat fee you choose to pay to boost a post, not a slice of your income. And moving your own money, whether you deposit, send, or withdraw, is never touched: those transfers cost only the tiny Solana network fee, so you keep all of it. See the Wallet for that.

Tips

  • Free amount, in SOL or OUSD, on any public or protected image, or to a profile directly. You can tip a profile on its username.xenia.studio subdomain, or gift a tip inside an encrypted message.
  • Tips are the main ranking signal on the Gallery feed. Every dollar tipped moves the image up, and tips also feed the profile rating that lifts a page in the feeds.
  • Tips accumulate on the image and in the creator's earnings view, each one tagged with the tipper's context.

Unlocks

  • Image unlocksbuy permanent access to a protected image at the creator's set price (in OUSD). Before you unlock it, all you see is the irreversible blur preview.
  • External DM unlocksbuy permanent access to a creator's off-platform contact handles. See External DM Unlock. (In-app encrypted Messages are free between verified adults.)
  • An unlock never expires, and it survives price changes. Once you own it, you own it.

Splitting a co-authored unlock

Some protected pieces are co-authored: a co-scene rendered with one or two of your circle members. When a fan unlocks one, the proceeds split evenly among all co-authors (a straight 50/50 for a pair, thirds for a trio). It is still a single Solana transaction: the 7% platform fee comes off first, the rest divides equally, and any one-unit rounding dust goes to the first author. The split works in SOL or OUSD, the same as any other unlock.

Nothing is held in escrow. The one transaction moves each author's share straight to their wallet in the same instruction, so every co-author is paid the instant the buyer signs. The split is enforced on chain by the xenia-pay program (the pay_sol_split and pay_spl_split instructions), which the server re-verifies from the finalized transaction before the unlock lands. It settles trustlessly on chain, with no platform balance in the middle.

How a payment settles

A viewer pays

They tip any amount, or unlock a protected image at the price you set, in SOL or OUSD. Their passkey signs one transaction.

xenia-pay routes it on chain

The same instruction sends the creator 93%, with the small platform fee taken off the top. No payout queue, no balance held in between.

The creator's wallet receives its share

The 93% lands in the creator's own non-custodial wallet the instant the transaction confirms. A /api/pay/confirm check then records the entitlement.

Paid and unlocked, in one signature
The server only verifies the finished transaction on chain. It never holds, moves, or redirects the money, because it never has it.
  1. The browser builds a transaction invoking the xenia-pay program with the creator's wallet, the amount, and a 32-byte ref_id that ties the payment to this exact intent.
  2. Your passkey unlocks the wallet key for one signature and the transaction goes to the chain. The program transfers 93% to the creator and 7% to the platform wallet in the same instruction.
  3. The client then calls POST /api/pay/confirm with the transaction signature.
  4. The server fetches the transaction at finalized commitment, so no fork or reorg can drop a payment an entitlement was granted for. It confirms the transaction invoked xenia-pay and decodes the PaymentEvent the program emitted while it was the executing program, never a look-alike log line. It checks payer, creator, mint, amount, and ref_id, verifies on chain that the creator's balance rose by the net amount, and records each transaction signature at most once. The tip or unlock lands and the entitlement goes live.

The ref_id is the SHA-256 of a canonical intent string, so a confirmed transaction matches exactly one cart intent and can never be replayed into a different entitlement:

Text
xenia:tip:image:{id}:{userId}:{nonce}
xenia:unlock:image:{id}:{userId}

Paying in SOL vs OUSD

  • OUSD: you pay exactly the listed price (price × 10^6 base units). What you see is what is transferred.
  • SOL: the client sizes the lamports against a short-lived, server-signed SOL price quote, and the server re-values the on-chain amount against that same signed quote, so you pay the full price with no drift band. If the quote is missing or has expired by the time you confirm, the server falls back to the live SOL rate within a small drift tolerance, so an honest payment that took a moment to sign still clears at a fair rate.

Prices everywhere display in both currencies, $X OUSD (≈ Y SOL), and you choose the currency at payment time.

Memberships

A membershipis the closest thing on XENIA to a season pass. You join a creator's membership for a block of days, bought with one on-chain payment from your passkey wallet in SOL or OUSD, and their members-only side opens for exactly that long. When the block runs out the access does too, and continuing is always your choice to make again.

One membership

A creator offers a single membership, with its monthly price and its mix of perks, managed from Dashboard > Earnings. It is one membership per creator, the same for everyone who holds it: join and the whole members side opens at once. A membership can include:

  • The members gallery. Posts the creator publishes to Subscribers: a layer of work that never appears in public browse or search.
  • All feed unlocks included. Every protected piece by the creator reads as unlocked while your membership lives, with no per-image payment.
  • DMs included. The creator's External DM unlock is included while your membership lives.
  • Studio renders of the creator. Pay-per-render access to private solo renders of the creator (below).
One membership per creator
You hold it, or you don't
Membership
Members gallery
Feed unlocks included
DMs included
Studio access
Pay a block

Buy 30, 90, or 365 prepaid days in one signature. It simply lapses at the end, with no auto-renew.

Be in the circle

A place in the creator's circle carries the membership too. The creator grants it; it is never bought.

The creator sets the price and composes the membership, and member renders are pay per render on either way in.

The price you join at is locked for the block you bought. When a creator changes the membership's price or perks, that reaches future purchases only, never time you already hold.

Who sees what

A creator's work sits in nested access levels, each one more private than the last. A membership opens the Subscribers level and stops there.

Who can see what
AnyonePublic
A subscriberPublicSubscribers
A circle memberPublicSubscribersCircle

A circle member also sees subscribers' media, and subscribers see what's public. It never runs the other way.

A membership opens the Subscribers level and stops there. To everyone outside it, that level does not exist: never in browse, never in search.
LevelWho sees it
PublicEveryone, on the profile and in the Gallery feed. Protected work shows here too, as an irreversible blur with a price; one payment unlocks that piece permanently. See Tips & Unlocks.
SubscribersMembers whose membership carries gallery access, plus the creator's circle. To everyone else it does not exist: never in browse, never in search.
CircleThe creator's circle only. A relationship layer, entered by invitation and a wallet signature, never by payment.

Joining and extending

You join from the creator's profile: pick a block and sign once. A block is 30 daysat the membership's monthly price, 90 days at 10% off, or 365 days at 25% off. The longer blocks carry their discount right in the price, so a year costs less per day than a month.

Prepaid time, one signature
A longer block, a better rate
30days
1 month
Monthly rate
90days
3 months
10% off
365days
1 year
25% off
One on-chain paymentNo auto-renewExtending stacks days on top
  • No auto-renew. A block simply runs out. Renewal nudges arrive at seven, three, and one day before it does, and continuing is always a fresh signature, never a stored charge.
  • Extending stacks. Buy again while a block is live and the days go on top of whatever remains.

A membership settles like a tip: one Solana transaction through xenia-pay, with 93% landing in the creator's wallet the instant you sign.

Generating the creator in the Studio

A membership opens Studio access to the creator: with it, you generate your own private solo stills of the creator in the same Studio, on demand from their profile, paying per render at the same price as any Studio image. It is not a separate product. It is the one Studio, run by a member on a creator who has opened themselves to it, on the same anime redraw pipeline, so the look matches the rest of the creator's work. What makes it safe is the consent chain, and every link is checked on every render:

A member picks an approved solo scene
A live membership (paid block or circle)

The member holds a live membership, whether from a paid block or from a place in the creator's circle. It is the access door; each render is paid per render, at the Studio image price.

The creator has switched it on

Rendering is off by default. A render runs only while the creator keeps the switch on, on their likeness card. Switching it off stops renders at once.

An approved solo scene

The scene comes from exactly the solo scenes the creator has approved. An empty allowlist approves nothing, and there is no free-text prompt.

One person in frame, the creator

The render holds the creator's ID-verified face on their own body profile, and no one else. The member is never in the scene, and no one is invented.

Within the creator's cap

An optional monthly cap across all members bounds how many renders a creator allows. Past it, renders pause until the rolling window advances.

A private render, the member's alone

It saves to the member's account only. It is never published, minted, or shared, and it never enters public browse, search, or the creator's gallery.

Every gate is checked when the render is asked for and re-checked when it dispatches, so consent narrowed a moment earlier is still honored. The face is always the creator's verified likeness, never an invention.

The scene is never free-text. You pick from exactly the solo scenes the creator has approved on their likeness card, and an empty allowlist approves nothing. The render holds the creator and no one else: anything with two or more people is co-scene territory, with its own circle-bound consent, and is never reachable from a membership. Because the creator switches this on themselves and it is off by default, a creator is never renderable until they choose to be.

The result is yours alone. It saves privately to your account, and it can never be published, minted, or shared. The verified likeness guarantee holds here as it does everywhere: the face in the render is the creator's ID-verified face on their own body profile, never an invention.

Messages

Messages are end-to-end encrypted direct messages between two verified adults. This is where the flirting happens, and XENIA holds no key to what you write.

Xenia, the resident

One thread in your Messages is different: Xenia, the platform's own resident. She keeps a permanent memory of everything you tell her, thinks between conversations and sometimes messages first, runs a daily life of her own (she posts what she chooses, keeps a journal, reads every comment on her work), and shows a read receipt the moment she has seen you. Her thread is a conversation with her, not a sealed human-to-human DM, so the encryption model below applies to messages between people. Talking with her is a membership, $9 a month for unlimited conversation.

Encrypted at rest, openable only by your wallet

A message is sealed in your browser before it leaves your device, using a key derived from your wallet. It stays encrypted at rest and only decrypts in your browser when you open it, which takes your wallet key and a live session. The XENIA server stores the ciphertext and routes it. It never holds a key and never reads a message.

  • Sealed in your browser.Each message is encrypted on the sender's device and addressed to the recipient's wallet, so plaintext exists only on the two devices in the conversation.
  • Decrypted only when you open it. Content unseals on demand in your browser, never on the server and never in a stored form the server could read.
  • Opened only by your wallet. The decryption key comes from your wallet and works only while you are logged in. A database dump, a backup, or a XENIA operator sees ciphertext and nothing else.
You, in your browser

The message is sealed on your device with a key derived from your wallet, before it ever leaves.

plaintext lives here
Them, in their browser

The message decrypts only when they open it, with their own wallet key and a live session.

plaintext lives here
The trust boundary plaintext never crosses
The XENIA server

Stores the ciphertext and routes it between the two devices. It holds no key and never reads a message.

ciphertext only
A database dump, a backup, or a XENIA operator sees ciphertext and nothing else. The only keys that open a thread live in the two wallets.

Exploding messages

Any message can be sent with a fuse, from 1 hour to 1 week. The timer does not start when you hit send; it starts the moment the recipient first opens the conversation, so an unread message keeps forever and never burns unseen. An exploding message is unmistakable in the thread: it carries a fuse marker before it is opened and a live countdown after.

When the fuse burns out, the sealed message is destroyed on the server for both sides, the sender's copy included, and a render attached to it stops being viewable at the same moment. The thread keeps a scorched, glitching artifact where the message used to be: proof that something was said, readable by no one, ever again.

More than text

A message is more than text. You can style what you write and attach XENIA images and animations, the same renders you make in XENIA Studio. An inline attachment is one of your own renders, so a thread carries the same protected anime look as the rest of the platform.

You can sendWhat it is
Styled textFormatted message copy, sealed end to end
XENIA images and animationsRenders from the Studio, attached inline
A just-for-you giftA render made for one recipient and kept DM-only, revealed with a tap, and never shown in any gallery or feed
A tipA gift sent straight to the other person's profile, inside the conversation

Tipping a profile

A tip puts money behind the compliment. Tip a profile directly on its username.xenia.studio subdomain, or gift a tip inside a message. Either way it settles wallet to wallet on Solana in SOL or OUSD, through the same xenia-pay program that drops 93% straight into the creator's wallet in one atomic instruction, keeping a 7% fee. See Tips & Unlocks for how a payment settles.

The profile rating

Every profile carries a rating built from the views, comments, hearts, and tips it earns, the same signals that rank individual images. A higher rating pushes the profile higher in the feeds. See Ranking for how the score is built and how it orders the Gallery.

Rating requests

Fishing for a compliment is easier with a template. Messages include a 1-to-10 rating request you can send to anyone, in two flavors: rate how hot you are, or a dick rating. Attach a private photo and it rides along DM-only, encrypted at rest and kept out of every gallery and feed. The other person fires back a single number, plus a comment if they feel like it, and it never has to become a whole conversation.

Who can message whom

  • Both people are verified adults (18+). Messages are part of the social network, not a public inbox open to anyone.
  • Blocking applies here too. A blocked person cannot message you, tip you, or open a thread with you.
  • Plaintext lives only on the two devices in a conversation. Lose access to your wallet and past messages stay sealed. Nobody, XENIA included, can recover them for you.

Private Contact Unlock

XENIA has its own encrypted in-app chat (see Messages). The External DM unlock is a different thing. One on-chain payment unlocks a creator's off-platform contact handles, so the conversation can continue wherever the creator wants it, away from XENIA.

Pay the unlock and the creator's outside handles appear on their profile for your account. The conversation picks up wherever they want to talk.

Outside handles, HIDDEN
Telegram, Discord, and the rest sit encrypted until a fan pays.
A fan pays the set price

One unlock price, set by the creator in OUSD, payable in OUSD or SOL. One payment covers every service the creator configured.

On chain through xenia-pay

A normal xenia-pay payment: 93% to the creator in one atomic instruction, with the platform fee taken off the top. The ref_id binds it to this exact reveal.

Handles revealed once, forever

The server confirms the transaction and records the unlock, then serves the decrypted handles. They render on the profile for that account from then on, with no renewal.

A private line, off platform
The conversation continues wherever the creator wants. XENIA sells the introduction, then steps out: it never proxies, stores, or reads those messages.

Supported services

ServiceWhat is revealed
TelegramThe creator's Telegram handle
DiscordThe creator's Discord username
KeybaseThe creator's Keybase handle
SMSA phone number for texting
EmailA contact email address

For creators

  • Configure any subset of the five services and one unlock price (in OUSD) under Dashboard > External DM.
  • Handles are encrypted at rest with the same AES-256-GCM envelope used for images. They are decrypted only for you and for buyers who have paid.
  • Change handles or the price whenever you want. Existing buyers keep access. They bought your External DM unlock, not a snapshot of the handles you had that day.

For buyers

  • Every creator profile with an External DM unlock configured shows an unlock card with the price.
  • One payment reveals all the services the creator has configured, permanently. There is no per-service pricing and no renewal.
  • Once you unlock, the handles render on the creator's profile for your account, and the reveal joins the rest of your entitlements.
  • A membership with DMs included opens the same reveal without a purchase, for as long as the membership lives.

The payment path

An External DM unlock is a normal xenia-pay payment. It drops 93% into the creator's wallet in one atomic instruction, with the 7% remainder going to the platform. The transaction's ref_id is the SHA-256 of the canonical intent string:

Text
xenia:unlock:dm:{creatorId}:{userId}

The server confirms the transaction on chain and records the unlock. After that it serves the decrypted handles to your session.

Circle

Your circle is the relationship layer on XENIA. You decide who sits closest, and nobody joins until they consent. It is yours to shape around the people you are closest to, and it lives on your username.xenia.studio page.

Seven seats

Every page has the same shape. One twin flame sits in the top seat, your closest, your significant other. Below it sit up to six ranked seats, numbered 1 to 6 with 1 the closest. The twin flame holds one person. You can't suggest that seat when you reach out, but the person you invite can take it themselves when they accept. Seats you haven't filled show as dim engraved seals, so an empty circle still reads as an open invitation.

The shape of every circle
Twin flame

One seat, reserved for a single person. You cannot suggest it; the person you invite claims it themselves.

Up to six ranked seats, 1 is closest
closest
seat
seat
seat
seat
open
Seats you have not filled show as dim engraved seals, so an empty circle still reads as an open invitation. Gender never limits who sits where.

Sealed by a wallet signature

A coupling takes mutual consent. Tap an empty seat on your page, search the username you want, and they get a request. They approve it by signing with their own wallet, the same passkey signature that authorizes everything else on XENIA. No money moves and nothing is escrowed. The signature proves consent, nothing more.

  • You ask, they choose. Suggest one of the six ranked seats or leave it open. The recipient picks their own seat when they approve, anywhere from seat 6 up to the twin flame. How close they sit is their call.
  • Approval is a signature.Until they sign, it's only a pending request. Nobody lands in a circle without their wallet's explicit approval.
  • Exit anytime, no notice. Either person can leave a coupling from the dashboard Circle tab. No lock-in, and the other side gets no notification.

Effects

Give each member and your twin flame a small living effect: a glow or flicker, fire, ice, a rotating spectrum, dark or light, angel or demon, hearts, eyes, bubbles, rain, stars, and more. It marks how you feel about each bond. Only you set the effect on a seat in your own circle.

Circle-only drops

Alongside public, paid, and members posts, you can publish a drop only your active circle sees. It's relationship-gated, not paywalled. Your circle gets it on your page and in their feed, and nobody outside the circle ever receives it. Choose Circle as the visibility when you publish from your Content. The circle is the innermost level, so it also sees everything your members see. The reverse is never true: a paid membership never opens circle drops, a circle seat, or co-scenes.

Co-scenes

Your circle doubles as a creative consent layer. When you send or accept a request, you can tick a co-scene agreement. The agreement is two-way and per person: it lets either of you render the other into a scene together, from the verified likeness already on each account. It drops the moment either of you leaves the circle, and your likeness never appears in a scene you have not agreed to.

From the dashboard Circle tab you set up a co-scene. Pick one or two of your circle members as co-stars, and the scene list narrows to what fits your cast and your verified genders. Choose a scene, so you appear together, then pay once to generate. That render is an on-chain SOL or OUSD payment in your passkey wallet, the same pay-per-render model as every other Studio generation. The composition (FM, FF, MM) follows from who is cast, and the added co-star is a real circle member rendered from their own verified likeness, never an invented partner.

The result is a co-authored image. Every co-author is credited on the piece, shares in its earnings through the even on-chain split, and holds release-approval rights over it. Once it is publicly released, it surfaces on every co-author's profile, not only the member who generated it. The casting picker shows only members who can be cast: those who have ticked the co-scene agreement with you and have a verified face (Yoti likeness) on file. There is no free-text scene prompt, so anything depicted comes from the curated library and was opted into by everyone in it.

Both members consent

Each person ticks the co-scene agreement when they send or accept the circle request. The agreement is per person and revoked the instant either leaves the circle.

Pick a preset and cast

From the Circle tab you choose a scene from the curated library and cast one consenting member. There is no free-text prompt, so every scene was authored by the platform.

Render from verified likenesses

Each cast member renders from the verified likeness already on their account, through the same Studio pipeline. Nobody is invented; everyone shown opted in.

Co-authored scene

It appears for everyone cast in it. If you lock it, the unlock proceeds split evenly between the two of you, settled on chain.

Even 50 / 50 split
each member takes the same share, after the standard platform fee
Only members who ticked the agreement and have a verified likeness on file can be cast. Your likeness is never used in a scene you have not agreed to.

Your likeness profile

Every creator has a likeness profile that lets a scene render them as themselves. Two parts make it up. The identity anchor is your Yoti-verified face, the same face that gates everything else on XENIA. Alongside it sits a body descriptor: your build, skin, hair, and anatomy. A face crop cannot carry a body, so the descriptor is what tells the render the rest of you, not a stand-in.

It takes no effort to keep. The profile is seeded from your own renders, read from the work you already make in the Studio, and you can adjust any field from the dashboard. A co-scene never asks you to fill anything in. The descriptor is simply there when a circle member casts you.

When you are cast in a co-scene, your face (whenever you are face-forward) and your body descriptor place you as yourself rather than a generic body. The creator who starts the scene is the point-of-view anchor, so a co-scene reads as the two of you seen together, each with your own face, not a generic pair.

Circle-only by default, public by unanimous consent

A co-authored piece is circle-only by default. Once published it reaches only the shared circle, the same circle-only drop described above, and never the public Gallery feed. Because every person in it is rendered from their real likeness, no single co-author can take it public alone.

To take a piece public (free) or protected (a paid unlock), one co-author opens a release request from their Content. Every other co-author gets an email and an in-app notification, opens it, reviews the piece, and either approves by signing with their passkey or rejects it. The signature is the approval, the same passkey-backed wallet signature that seals a circle bond.

  • Unanimous to release. The piece flips to public or protected only once every co-author has approved.
  • One rejection keeps it circle-only. Any single co-author declining cancels the whole request, and the piece stays a circle drop.
  • The owner can cancel. While a request is still pending, the co-author who opened it can withdraw it.

Make it mutual

Circles can be one-sided: someone adds you without you adding them back. Even one active bond already shares circle drops both ways, and, when both sides have ticked the co-scene agreement, makes co-scenes possible either way. In the Circles you're in list, anyone you have not added yourself shows an Add back button; adding them gives them a reciprocal seat in your own circle. It is a mutual gesture, not a prerequisite for drops or co-scenes.

Where it lives

  • On every profile. The full seat scaffold is built into each username.xenia.studio page, members and placeholders alike.
  • In your dashboard. The Circle tab is where you send requests, approve or decline the ones addressed to you, set effects, and leave couplings.
  • As a notification. When someone requests you, a toast fires right away, same as a new message or tip.

Ranking

The Gallery is one ranked stream of every creator's public and protected images. The order tracks what fans pay for and pay attention to, and tips count for far more than anything else. The feed ranks what each image earns, not who made it, so a brand-new creator competes on the same terms as an established one.

The rank score

Every image carries a score from four counters plus a moderator term:

Text
base = tip_total_usd * 100 + comments * 20 + hearts * 10 + views + admin_boost

The weights stack up like a ladder. One tipped dollar moves an image as far as a hundred views. A comment counts for twenty views, a heart for ten. The model below sizes each factor by its weight, so you can see what actually lifts a post.

What drives an image up the Gallery
Five weighted factors, biggest lever first
Tipped dollars× 100

Each on-chain dollar tipped to the image, counted a hundredfold. The heaviest lever by a wide margin, and written only by confirmed payments.

Comments× 20

Each comment counts for two hearts. Conversation lifts a post faster than a silent like.

Hearts× 10

Each heart counts for ten views. A simple measure of how many people liked the work.

Views× 1

Each deduplicated view adds one point. Raw attention breaks the ties between closer posts.

Admin boost+ editorial

A small editorial adjustment a moderator can add to a single image. Zero for almost everything, and folded openly into the same score.

Profile-rating lift

A gentle logarithmic term from the creator's profile rating raises every one of their images a little, so a well-loved page carries all of its work up. It rises fast at first, then flattens, so no single page can run away with the feed.

The image's place in the Top feed
Computed in-query at read time, off confirmed on-chain tips and real engagement. No batch job, and the counters never decay.

Because tips dominate, the default order surfaces what people pay for and talk about first, with hearts and then views breaking ties. On top of the base, each image gets a small logarithmic lift from its creator's profile rating (below), so a page fans love carries all of its work up a bit. XENIA computes the whole score in the query at read time. No batch job, no decay on the counters. The admin_boost term is a moderator adjustment on a single image, and it sits at zero for almost everything.

The profile rating

Each profile carries its own rating, from the same signals across all of a creator's public and protected work: views, comments, and hearts on those images, weighted the same way, plus every tip the creator has earned, counted at a hundredfold. That includes tips sent to the profile on its subdomain or gifted in an encrypted message. A higher-rated profile lifts all of its images in the Gallery, so a page that pulls attention earns more reach. The rating is driven by genuine engagement, hearts, comments, and views, plus the tips you earn. You earn it. You can't buy it.

Sort tabs

TabOrdering
TopThe full rank score: the counter base (tips × 100 + comments × 20 + hearts × 10 + views + admin_boost) plus the creator's profile-rating lift, with any active promotions pinned above
Most tippedLifetime tip total, in USD terms
Most heartedLifetime heart count
Most viewedDeduplicated view count
NewPublication time, newest first

How views are counted

  • A public image counts a view when any clear variant is fetched: its grid thumbnail, display, or full copy.
  • A protected image counts a view when its blur preview is fetched, so locked content competes on attention too.
  • Views are deduplicated per image, per viewer, per day. Refreshing a page all afternoon counts once.
  • Private images are never served to anyone but the owner and accumulate nothing.

Promotions and featured accounts

Two things can ride above the organic order. A creator's own paid promotion pins a post above organic results, then eases back down over its 30days and drops off at expiry. A featured account carries the standard promotion boost across all of its work, sitting above organic posts and below a paid premium promotion. Both ride on top of the same rank score, and neither edits an image's real tips, hearts, or views.

What this means for creators

  • Tips move the needle most. One tip from one fan beats thousands of passive views, and tip totals come from confirmed on-chain transactions, so nobody can edit them.
  • Protected images rank next to public ones. A strong blur preview earns views, and every unlock and tip it pulls in feeds the same score.
  • Comments count for two hearts each, so a post people talk about climbs faster than one that only gets likes. Replying keeps the thread alive on the feed.
  • The feed tracks what each image has earned, not who you are. A new creator competes on the same terms as an established one.

Age Verification

XENIA is an adults-only platform. You need an account before you can post, publish, follow, tip, or unlock, and getting one requires full government ID verification through Yoti, the same vendor major adult platforms rely on. ID verification proves two things: that you are a real adult over 18, and that the person is really you. Browsing public content needs no account and no verification.

Start sign-up

An account is required to post, follow, tip, or unlock. Browsing public content needs no account and no verification.

Yoti government-ID check

In Yoti's hosted flow you photograph a government ID, or share an existing Yoti Digital ID by QR. Yoti is the vendor major adult platforms rely on.

Live face match

You take a live selfie that Yoti matches to the document. This proves both that you are a real adult over 18 and that the person is really you.

Verified. Age stored, identity confirmed.
Kept

The verification receipt, the method used, a verified-at timestamp, the encrypted face reference, and a one-way identity hash, all bound to your wallet.

Never kept on XENIA

Raw ID document images, the document number, and the documents themselves. They stay with Yoti under Yoti's retention policy.

A failed attempt never locks the account. You can retry or switch methods, and once it passes, verification does not expire.

The two ID routes

MethodBacking serviceFlow
ID document scanYoti Identity Verification (IDV)The browser loads Yoti's hosted iframe; you photograph a government ID and take a live selfie that Yoti matches to it; the result arrives as APPROVED or REJECTED
Yoti appYoti Digital IDAlready verified with Yoti? Scan a QR code and share your ID and over-18 status from the app; the share receipt is verified server-side

What is stored, and what is not

  • Stored: the verification receipt (the provider session id and a redacted result), the method used, a verified at timestamp, the verified face reference (encrypted, see below), and a one-way identity hash derived from the document (so each verified person gets one account and a banned account cannot re-register). The verification is also bound to the wallet that started it.
  • Never stored on XENIA servers:raw ID document images, the document number, and the documents themselves. They stay with Yoti under Yoti's retention policy; XENIA keeps only the one-way hash, not the underlying number or name.
  • Never shown publicly: your legal name, address, ID, or face. They are used for verification and records only, never for your profile, ranking, or advertising.

The verified face reference

Your face reference is the live face Yoti matched to your government ID during verification, a real likeness tied to your real identity. Verification has to return it. If it cannot, sign-up does not complete, so there is never a separate selfie to capture. It is stored as an encrypted blob, bound at rest to your account, and is never served publicly or used for ranking, advertising, or anything else. It stays server-side as the private likeness reference your renders are built around, so your work carries your verified face and no one else's. You cannot swap it, and it stays tied to the 18+ verification that produced it.

Verification states

Each attempt is tracked from start to decision. If a method is temporarily unavailable (say, the provider is not reachable), the UI says so and the other routes stay open. A failed attempt never locks the account. You can retry or switch methods at any time. Once it passes, verification does not expire.

Security & Encryption

We assume the worst. Creator content is the most sensitive thing we hold, so we built XENIA so a database dump, a stolen backup, or raw filesystem access turns up nothing readable. A full server compromise moves zero funds.

Passkey and PRF on your device

Your passkey's hardware authenticator derives a wrapping key through the WebAuthn PRF extension. That key is stored nowhere, so only your device can produce it.

AES-256-GCM at rest

Every stored blob carries its own random data key, wrapped by a master key that lives only in the environment. The GCM tag binds each ciphertext to its row, so nothing can be detached and re-attached.

Decrypt in exactly one place

Blobs decrypt only inside the image-serving route, only after the access-control decision. There are no direct object URLs and no static paths to guess.

A recovery passphrase, any device

A passphrase you choose is stretched with Argon2id into a second key that encrypts a backup of your wallet. The server stores only that ciphertext, so you can restore on any device with your email and passphrase, and still nobody but you can decrypt it.

The non-custodial boundary
The server holds

Wrapped data keys, hashed session tokens, your public wallet address, and two encrypted wallet backups it cannot read. It verifies signatures; it never holds your private key.

The server never sees

The master key in plaintext outside the environment, your wallet's private key, or a message's plaintext. None of it is stored.

A full server compromise moves zero funds
A database dump or stolen backup turns up wrapped ciphertext and public keys. Nothing readable, and not a cent spendable.

Envelope encryption for every blob

Every stored image variant, face reference, and DM handle is encrypted with AES-256-GCM envelope encryption before it reaches PostgreSQL. The steps:

  1. Each blob gets its own random 32-byte data encryption key (DEK) and 12-byte IV; the ciphertext is stored with the GCM tag appended.
  2. The DEK is wrapped (again AES-256-GCM) under a per-record subkey derived from the master key with HKDF-SHA256; the master key lives only in the environment, never in the database.
  3. The GCM additional authenticated data binds the blob id and kind, so a ciphertext cannot be detached and re-attached to a different row.
  4. Key rotation re-wraps DEKs under a new master key; the data itself never needs re-encryption.
What one blob row holds
FieldWhat it stores
ciphertextAES-256-GCM(image bytes, DEK, IV) + authentication tag
ivPer-blob initialization vector, 12 bytes
dek_wrappedAES-256-GCM(DEK, HKDF-subkey of master key); the master key lives only in env
sha256Integrity digest of the plaintext

Decryption happens in one place: inside the image-serving route, after the access check passes. There are no direct object URLs and no static file paths to guess.

The blur destroys detail, it does not hide it

A protected preview is a 24-pixel downsample, blurred and upscaled. The detail is gone before the preview exists, which is why we serve the blur publicly. There is nothing left to recover.

Nothing secret is stored in plaintext

SecretAt rest
Session tokensHMAC-SHA256 hash only
Email verification codesHash only, attempt-limited
Login challenge noncesHash only, 5-minute TTL, single use
2FA recovery codesHash only, burned on use
TOTP secretsEnvelope-encrypted like blobs
Wallet keysThe private key and seed are never on the server. Only the public address, plus two encrypted backups the server cannot read: the passkey-wrapped vault and the Argon2id recovery-passphrase blob

Transport authentication

  • Logins are single-use Ed25519 signature challenges with a 5-minute TTL. There are no passwords to phish or leak.
  • Studio renders are paid per generation with a real Solana transaction the browser builds and your passkey wallet signs. The render starts once the server confirms that payment on chain. See XENIA Studio.
  • Sessions are httpOnly, SameSite cookies (Secure outside localhost) backed by hashed server-side records with a fixed 30-day expiry. State-changing routes require a CSRF double-submit header and an Origin check in middleware.
  • Rate limits apply per IP, and per account on the sensitive auth routes, answering 429 with a retry-after.

Upload hardening

  • File types are sniffed by magic bytes (JPEG, PNG, WebP only); extensions are never trusted.
  • Pixel-bomb guards cap the total decoded pixel count and reject truncated or multi-frame inputs; image files cap at 25 MB.
  • The server computes a sha256 of the body; identical bytes deduplicate to the image already on file.

Browser security headers

  • A strict Content-Security-Policy: default-src 'self', with connect-src opened only to the Solana RPC endpoint (HTTPS plus its WebSocket for transaction confirmation) and frame-src opened only to the Yoti age-verification widget. There are no third-party scripts, trackers, or analytics embeds anywhere.
  • frame-ancestors 'none' plus X-Frame-Options: DENY on every route, so no XENIA page can be embedded in a hostile frame. base-uri 'none' and object-src 'none' close the remaining injection sinks.
  • Referrer-Policy: strict-origin-when-cross-origin, X-Content-Type-Options: nosniff, and a Permissions-Policy that grants only the camera (to the site itself and the Yoti verification widget, for face capture) while denying microphone and geolocation, all across the board.

Payments

The server records a payment only after it re-reads the confirmed transaction from the chain, decodes the program event, and matches the ref_idintent hash. Transaction signatures are unique keys, so the same transaction can never be credited twice, and one buyer's transaction can never be replayed into another account's entitlement. Details in The Smart Contracts.

Content safety: zero tolerance

Anyone depicted under 18, any animal or bestiality, and abusive or non-consensual content is banned everywhere on XENIA, with no exceptions. Three layers back that up. First, an automated safety gate screens every generation before any image is produced: an AI age estimator checks every face in the source, and the scene is read and screened for minors, non-consent, abuse, and animals. It fails closed, so an uncertain result is a rejection, never a pass, and a tripped generation is never rendered. Second, every image, animation, and collectible is reviewed by hand for platform violations, and anyone, with or without an account, can flag a piece as abusive, which routes it straight into that review queue. Third, behind every account is a verified adult: every creator clears 18+ identity verification, bound to their account, so a violation carries real, personal consequences. A confirmed violation is an immediate permanent ban and removal of the account's content. We report child sexual abuse material to NCMEC and law enforcement and preserve the evidence, as the law requires. Identity signals are captured at age verification, so a banned person cannot open a fresh account and walk back in.

Dawn & Dusk

Dawn & Dusk is a contest between two forces, Dawn and Dusk, played against the Solana clock. You pledge to a force by staking SOL. Your stake is never wagered and you can withdraw it any time; it is held as jitoSOL, so its value tracks jitoSOL exactly as if you staked it yourself. What is contested is only the staking yieldthe pool earns: once every Solana epoch (about every two days), that epoch's yield becomes the pot, and the force with the greater contribution takes 100% of it, split among its members by contribution.

What counts as contribution

Your contribution for an epoch is your active stake plus everything you spend on the platform that epoch. Every tip, image unlock, and DM unlock you pay for counts toward your force. All of it is real, on-chain SOL: spending is recorded straight into the contract from your own payment, so there is no off-chain tally and nothing anyone has to trust. The more your force stakes and spends, the more likely it wins, and the bigger your own slice of the pot if it does.

How a round works

  • Pledge to a force. Pick Dawn or Dusk and stake any amount above the minimum. Your stake activates for the next epoch, the same way native Solana staking activates on an epoch boundary.
  • Get to work.Through the epoch, your force's contribution grows with its members' stake and spending. You can watch both forces' contribution fill live.
  • The epoch closes.When the epoch ends, the force with the greater total contribution wins and takes the whole pot. A tie is a push: the pot rolls into the next epoch. The winning force splits the pot pro-rata by each member's contribution.
  • Claim, ride, or leave. Winnings arrive in your wallet automatically and never expire. Keep riding into the next epoch, switch forces (you sit out one epoch when you switch), or withdraw your principal whenever you like.

Why it can never be rigged

The winner is decided deterministicallyfrom the two forces' contribution totals at the epoch boundary. There is no randomness and no oracle to trust:

  • Every stake and every spend is an on-chain transaction, so the totals that decide the winner are public and anyone can re-verify a result independently.
  • The immutable program has no lever over the outcome; it simply compares the two totals. It cannot choose a winner, cannot front-run (stakes activate the next epoch), and cannot block a payout.
  • There is no house edge and no rake on the pot. The winning force splits the entire yield pot; the pool takes nothing from it.
  • Spending flows through the platform payment program, which takes its standard commission, the same fee as any tip or unlock. It goes to XENIA, never into the pot.

The details, plainly

  • No loss on principal. Withdrawals pay out in jitoSOL worth your SOL principal at the current rate; swap it back to SOL in one tap in your wallet (a small swap cost on the way out, disclosed at the time). Spending toward your force is not principal; it is money you chose to spend, which both supports creators and counts for your side.
  • Force lock. While you have a stake, you are on one force. To move, use Switch, which returns you on the other side next epoch.
  • Your allegiance shows on your profile as a Dawn or Dusk badge with a loyalty streak, so other members can see which side you ride.

The Smart Contracts

XENIA settles on two Anchor programs on Solana, and nothing else. Each does one job with checked math and no custody: money passes through a single instruction and never rests with the program. Both are live on Solana mainnet and deployed immutable, their addresses and direct Solana Explorer links below, so anyone can read the deployed bytecode and its on-chain commission Config for themselves.

xenia-pay
Payments

Splits every tip, image unlock, External DM unlock, and promotion 93/7 between the creator and the platform, atomically, in one instruction. No escrow, no stored balance, no withdrawal path.

Source: program/programs/xenia-pay
xenia-market
Collectibles market

A non-custodial NFT market. A seller escrows a collectible, and a buyer takes it in one atomic instruction that releases the NFT and splits the sale 93/7, honoring the creator royalty. A seller can cancel and reclaim it after a short delay.

Source: program/programs/xenia-market

What you can verify on-chain

Nothing here asks for trust. Every guarantee below is enforced by the deployed, immutable bytecode and its on-chain state, so anyone can check it directly:

Confirm it is immutable

Both programs are deployed --final: their upgrade authority is none, so the bytecode can never change. Check it on any Solana explorer. What runs today runs forever.

Confirm the fee cap

The commission is bounded by a compile-time MAX_FEE_BPS of 700 (7%). The cap is not a parameter, it lives in the now-frozen bytecode, so the fee can never exceed 7%.

Read the on-chain Config

The commission wallet and fee sit in one Config account you can read yourself. On xenia-market it is renounced and frozen; on xenia-pay it stays bounded by the 7% cap and changes only through a two-step authority handshake.

Trace the money path

Neither program ever holds your money: no stored balance, no withdrawal path. Every payment splits to the creator and platform inside a single instruction. xenia-market escrows only the NFT, releasing it in that same atomic instruction.

Decode a real payment

Every successful call emits a PaymentEvent (or SaleEvent) you can decode from the finalized transaction, with the payer, creator, amount, fee, and net in the clear.

xenia-pay, in depth

Tips, unlocks, External DM unlocks, and promotions all flow through one on-chain program: xenia-pay, an Anchor program on Solana. It does one job, and does it with checked math: split a payment between a creator and the platform commission wallet, atomically. There is no escrow, no stored balance, and no withdrawal path. Money only ever passes through inside a single instruction.

End to end, a single payment travels four steps: the payer signs in their passkey wallet, the program splits it 93/7 on chain, it emits one PaymentEvent, and the server re-reads that event from the finalized transaction before it grants the entitlement. The rest of this page is the detail behind each step.

A tip or unlock begins
The payer signs in their passkey wallet

A tip or unlock builds one xenia-pay instruction, carrying the amount and a ref_id that binds it to exactly this intent. The payer approves it with a passkey unlock; the key never leaves the device.

pay_sol or pay_spl splits 93 / 7 on chain

Inside the single instruction the program pays the creator the net and the platform wallet the 7% fee, atomically. Native value moves with SOL via pay_sol, and dollars move with OUSD via pay_spl. No escrow, no stored balance.

The program emits one PaymentEvent

Every successful payment logs a single event carrying the payer, creator, mint, amount, fee, net, ref_id, kind, and timestamp. That log is the receipt the server reads back.

The server re-reads the chain before it trusts anything

The client posts the signature to /api/pay/confirm. The server fetches the finalized transaction itself, decodes the PaymentEvent, and checks every field: payer matches the session wallet, creator matches the expected wallet, mint is SOL or OUSD, the amount covers the price, the ref_id equals the expected intent hash, and the signature has never been recorded before.

Only then is the tip or unlock recorded

The entitlement is written inside one database transaction. If any check fails, nothing is granted.

The server trusts nothing it did not re-read from the chain, so a transaction can never be replayed into a second entitlement.

State: the Config PDA

The program's whole state is a single account, a PDA derived from the seed [b"config"]:

Rustxenia-pay Config
pub struct Config {
    pub authority: Pubkey,                 // governance key
    pub pending_authority: Option<Pubkey>, // two-step transfer target
    pub platform_wallet: Pubkey,           // commission destination
    pub fee_bps: u16,                      // 700 at initialize
    pub bump: u8,
}
  • authority can rotate the platform wallet and lower the fee. Authority itself moves only through a two-step propose / accept handshake, so a typo cannot brick governance.
  • fee_bps starts at 700 (7%) and is bounded by a compile-time MAX_FEE_BPS of 700. The fee can drop and rise back, but never above 700. The cap is not a parameter. It lives in the bytecode.

Instructions

InstructionArgumentsBehavior
initializeplatform_walletCreates Config; authority = payer; fee_bps = 700
set_platform_walletnew_walletAuthority only
set_fee_bpsnew_fee_bpsAuthority only; requires new value ≤ 700
propose_authority / accept_authorityTwo-step governance rotation
pay_solamount, ref_idSplits native SOL: a System transfer of net from payer to creator, then (when the fee is non-zero) a second System transfer of fee from payer to platform
pay_splamount, ref_idSame split via transfer_checkedCPIs from the payer's token account to the creator and platform ATAs

Payment math

Rust
fee = amount * fee_bps / 10_000   // u128 intermediate, checked, floor
net = amount - fee                 // creator receives net
  • Because the fee floors, any rounding dust goes to the creator.
  • Amounts below 15 base units would floor the fee to 0, so a hard MIN_PAYMENT of 1,000 base units (lamports or token units) keeps every split meaningful.
  • For both pay_sol and pay_spl, the platform account passed in must equal config.platform_wallet. The same platform.key() == config.platform_wallet constraint guards each path, so passing any other account fails the instruction. On the SPL path the platform token account is then derived canonically from that constrained wallet.
  • For pay_spl, both destination ATAs are derived canonically and created on the fly if missing (init_if_needed, payer funds the rent). The program works for any SPL mint. The platform itself only indexes OUSD.

PaymentEvent

Every successful payment emits one event, decoded by the server:

RustPaymentEvent
pub struct PaymentEvent {
    pub payer: Pubkey,
    pub creator: Pubkey,
    pub mint: Pubkey,      // Pubkey::default() for SOL
    pub amount: u64,
    pub fee: u64,
    pub net: u64,
    pub ref_id: [u8; 32],
    pub kind: u8,
    pub timestamp: i64,
}

ref_id: binding a transaction to one intent

ref_id is the SHA-256 hash of a canonical platform reference string. It lets the server match a confirmed transaction to exactly one intent without a memo instruction, and it makes replaying a transaction into a different entitlement impossible. The four intent formats:

Text
xenia:tip:image:{id}:{userId}:{nonce}
xenia:unlock:image:{id}:{userId}
xenia:unlock:dm:{creatorId}:{userId}
xenia:tip:user:{creatorId}:{userId}:{nonce}

Unlock intents carry no nonce, so the same buyer unlocking the same item always hashes to the same ref_id. That makes it idempotent: one entitlement, no matter how many times it runs. Tips carry a client nonce, so repeated tipping produces distinct references.

Server-side confirmation

  1. The client submits the signed transaction, then calls POST /api/pay/confirm with the signature.
  2. The server fetches the finalized transaction itself (retrying briefly for finalization) and requires an instruction invoking the xenia-pay program id.
  3. It decodes PaymentEvent from the logs and checks every field: payer matches the session wallet, creator matches the expected wallet, mint is SOL or OUSD, amount covers the price (with the SOL drift tolerance), ref_id equals the expected intent hash, and the signature has never been recorded before (unique index).
  4. Only then is the tip or unlock recorded, inside a database transaction. The server trusts nothing it did not re-read from the chain.

Safety properties

  • Overflow-checked release profile, and no unsafe anywhere.
  • The CPI surface is limited to the System, Token, and Associated Token programs. Nothing else can be reached through xenia-pay.
  • The test suite (bankrun, no local test cluster required) covers initialize and re-init guarding, exact split math across boundary values, both SOL and SPL paths, ATA auto-creation, rejection of platform-account substitution, fee cap enforcement, authority gating with the two-step transfer, and event decoding.

xenia-market, in depth

The collectibles market is a second Anchor program that mirrors xenia-pay's split, with one addition: it escrows the NFT. A seller lists a collectible they own by moving the single token into a program-owned vault, with a price, a settlement currency (SOL or OUSD), and a royalty. A buyer calls buy_sol or buy_spl with a max_price slippage guard, and in one atomic instruction the NFT is released to the buyer while the payment splits 93/7 to the seller and the platform, with the creator royalty honored. A seller can cancel to reclaim the escrowed NFT once a short anti-front-run delay after listing has passed. Every sale emits a SaleEventthat mirrors xenia-pay's PaymentEvent field for field, so the same server-side confirmation re-reads it from the finalized transaction before recording the change of ownership.

FAQ

Can anyone see my real face or body?

No. The augmentation filter rebuilds every photo past recognition in XENIA Studio (anime-style by default, or another style you pick), and the source photo is never stored. Only the rebuilt image exists, and that is all viewers ever see. Protected images go further. Their public preview is built from a 24-pixel downsample, so there is nothing recoverable in the blur.

What content is forbidden?

Content involving minors, animals, or abuse and non-consent is banned outright. An automated safety gate screens every generation before any image is produced, age-estimating every face in the source and screening the scene for minors, non-consent, abuse, and animals, and it fails closed so an uncertain result is a rejection. Every image, animation, and collectible is then reviewed for platform violations, and anyone can flag a piece as abusive, which triggers that review; behind every account is a verified adult held to their identity. The policy is zero tolerance: a confirmed violation means an immediate permanent ban, removal of the account's content, and a report to the authorities, including NCMEC and law enforcement, where the law requires it. Everything else consenting adults share is welcome. None of the above ever is.

Does a human ever review the content?

Yes, and it is the core of how safety works here. Every image and animation passes through an internal review queue, so a person looks at all media on the platform at least once. This does not hold up publishing: posts go live immediately and the human pass runs behind them. Every piece of media also carries a report button any viewer can hit, and a report drops straight back into that same queue for a human to check right away. Real people reviewing real content is the human backstop that sits behind the automated safety gate every generation already passes through.

Does XENIA hold my money?

Never. Your wallet is non-custodial and lives in your browser; the server stores only the public key. Tips and unlocks drop 93% straight into the creator's wallet inside one atomic on-chain instruction, keeping a 7% fee. There is no balance, no escrow, and no payout queue.

XENIA cannot withdraw, freeze, or move your funds in any way. Only your passkey can authorize a transaction, and the keys never leave your device. If moderation freezes or bans an account, that hits published content only. The wallet and its funds stay in your custody the whole time.

Which currencies are supported?

SOL and OUSD are the payment assets: tips, unlocks, and renders settle in them, on Solana. Your wallet also holds gold (PAXG) and jitoSOL (liquid-staked SOL) as savings, which you can swap, send, and receive. Prices are set in OUSD and displayed in both payment currencies; payers choose SOL or OUSD at payment time.

What does XENIA cost?

XENIA is completely free to use. Your account, your username.xenia.studio subdomain, posting, browsing, following, and every tool to earn cost nothing. The one fee is the 7% commission on tips, image unlocks, and External DM unlocks (in both SOL and OUSD), taken through the XENIA wallet and enforced on chain with a hard 700 bps cap the program itself cannot exceed. Moving your own funds is never split. Depositing, sending, and withdrawing pay only the Solana network fee, so you keep 100% of your own money and 93% of every tip and unlock. You never have to fund your wallet to start earning either. A zero-balance wallet collects tips and unlocks from day one, and buying or depositing crypto is only ever for spending.

I lost my device. Is my wallet gone?

No. You have two independent ways back, both set up at signup. Use your recovery passphrase: on a new device choose restore, enter your email, confirm the one-time code, and type the passphrase, and the wallet rebuilds in your browser. Or enter your 24-word phrase directly. Each restores the wallet under a fresh passkey. Only if you lose every passkey device and forget the passphrase and lose the phrase is the wallet unrecoverable; nobody else ever had the key, so nobody can restore it for you.

How is identity and age verified?

Creators verify with a government ID through Yoti, either an ID document scan with a live face match in Yoti's hosted flow, or an ID share from the Yoti app. This proves both that you are over 18 and that the person is you. Browsing needs no account or verification. See Age Verification for what is and is not stored.

What personal data does XENIA keep?

A username, an email (never shown publicly), a wallet public key, your verification receipts (provider session id and redacted result), and your content, encrypted. Raw ID documents are never stored on XENIA servers. They stay with the verification provider. The face reference photo is encrypted and used only to confirm your likeness when you generate in the Studio. It is never shown publicly.

Can I delete my content or my account?

Yes. Deleting an image hard-deletes its encrypted blobs immediately. Account deletion cascades through everything you own. What cannot be deleted is on-chain history: transactions on Solana are public and permanent, but they contain only wallet addresses and amounts, never content or identity.

Why is an image blurry?

It is protected: the creator priced it. The price shows on the tile; unlocking pays the creator directly and the full image is served to your account permanently.

Do unlocks expire?

No. Image unlocks and External DM unlocks you pay for individually are permanent entitlements, recorded against confirmed on-chain transactions. Later price changes do not affect what you already unlocked. Access that comes with a membership is different: whatever the membership includes lives and lapses with the paid block.

What does a membership include?

Whatever the creator put in the membership: the members gallery, every feed unlock included, their External DM unlock, and pay-per-render access to private Studio renders of the creator. You buy a 30, 90, or 365 day block with one on-chain payment, the longer blocks carry a built-in discount, and there is no auto-renew, only nudges before the block runs out. Extending stacks days on top of what remains. See Memberships.

Does a membership put me in the creator's circle?

No. A membership opens the Subscribers level and stops there. The circle is a relationship, entered by invitation and a mutual wallet signature, and it is not for sale: circle drops, circle seats, and co-scenes never come with a membership. The circle sees what subscribers see; it does not work the other way.

What can a membership's Studio renders do, and what can they never do?

As a member you can render private solo stills of the creator, pay-per-render, chosen only from the scenes the creator has approved on their likeness card, and only while the creator keeps it switched on (it is off by default). The face is always the creator's ID-verified likeness, and the creator is the only person in the frame. The results stay private to you: never published, never minted, never shared.

Can I use Phantom or another wallet extension?

No. XENIA uses its own in-browser passkey wallet and nothing else. The wallet is also your account identity, and the signing flow runs on per-use passkey unlocks, so an extension does not fit. You can always move funds between the XENIA wallet and any external wallet with a normal send.

Is there a built-in chat?

Yes. Messages are end-to-end encrypted direct messages between verified adults, sealed in your browser with a key derived from your wallet and openable only by your wallet. They cost nothing between you, carry styled text and XENIA renders, and can include a tip to a profile. An External DM unlockis a different thing: a paid reveal of a creator's off-platform handles (Telegram, Discord, Keybase, SMS, or email) for talking elsewhere.

What does it cost to generate a render?

XENIA Studio is pay-per-render: $0.17 for an image, $0.17 for a second-pass edit, $0.25 for a co-scene, and $1.99 for an animation, priced in USD and charged in SOL or OUSD at spot. Each render is a real Solana payment, approved per generation in your passkey wallet, with no subscription and no credits. This is separate from the 93/7 split on tips and unlocks. See XENIA Studio.

Does XENIA support two-factor authentication?

Yes, optionally: an authenticator app (TOTP) and server-side passkeys, either or both. Ten single-use recovery codes are issued at TOTP enrollment. Removing or disabling a factor requires a fresh wallet signature.