Eligible hosts
Hosts are existing SPL tokens an organism can bond against. Each is registered by mint (never by symbol), checked on-chain, and kept fresh by the verifier. Only hosts that pass every check can be chosen at creation or used for bonding buys.
Enforced by the program from the mint account itself at register_host — nobody has to be trusted.
Reported by the HostVerifier service (price observations, confidence band, external liquidity). The program bounds it — staleness, deviation circuit breaker, bid/ask band, settlement slippage — but the data comes from an off-chain signer.
Registry status (Active / Paused / Blocked) is set by the protocol admin. Pausing a host never traps funds: sells stay open.
Never registrable
Examples the program rejects at registration, before any verifier data is even considered.
Native mint — SPL burn returns NativeNotSupported. SOL can never be a host.
Freeze authority present (and a mint authority) — a frozen vault would trap organism liquidity.
Token-2022 with PermanentDelegate + TransferHook — extensions outside the metadata/group allow-list.
register_host requires the ["organism", mint] PDA to be empty — an organism can never become a host.