Skip to content
Whitepaper · version 1.0 · 23 September 2026

Kerb: credit on the market’s clock.

The market-time risk layer for tokenized stocks on X Layer.

Authors
Xyndicate Labs
Standard
KTS 0.2, params 2026-09-22.1
Source
github.com/Franlinozz/Kerb
Formats
PDF
Abstract

Tokenized stocks trade around the clock; the markets behind them do not. When New York or Hong Kong is shut, no new reference price arrives and the onchain pool becomes the only exit. A lender that sizes credit against a price rather than against that exit lends more than it could liquidate at exactly the moments it would need to. Kerb measures the exit that is really there in X Layer pools, and how long a loan must survive before the next deep market, and publishes both as signed credit terms on X Layer mainnet every few minutes. Every term recomputes from its published inputs. A reference credit market, any contract, any agent and any developer read the same terms.

Terms posted on mainnet
15,967
Pool readings stored
302,790
Assets · markets
10 · 4
Contracts, Sourcify exact
34

Live figures, read when this page was rendered. Proof checks them.

1. The problem

Three clocks run under every tokenized stock. The exchange keeps its own calendar, with lunch breaks, holidays and early closes. Reference prices follow that calendar. Onchain liquidity follows neither: it moves with liquidity providers, incentives and the hour. Kerb’s first Market-Time Report measured 35,130 readings over one closed weekend on X Layer: seven of ten asset pools lost in-range liquidity, the largest by 49%.

A collateral value that ignores this is precise and wrong. The questions a lender must answer are whether the collateral could be sold, and how long the loan must hold before it could.

2. Design

Never lend more than you can liquidate.

Every choice follows from that sentence: measure the exit rather than assume it; tie each loan’s margin to the horizon it must survive; never move the liquidation line under an open loan; let anyone check every number; keep models out of anything that produces a number.

Clockmarket calendarsDepthtick-walk C(1%)Markconservative priceTermsKTS 0.2, signedKerb CreditKerbQuoteAgents (x402)API and SDK
Figure 1. Measurements become terms on X Layer mainnet; four kinds of consumer read the same terms.

3. Measurement

3.1 Clock

Each asset follows its underlying market’s calendar, resolved identically off chain and on chain in KerbClock. A regime machine names the state of each asset in a strict order: Halted, Stale, Corporate action, Reference closed, Pre-transition, Recovery, Thin, Normal, Deep. The first rule that holds wins.

3.2 Depth

Every minute the collector reads each pool’s price, in-range liquidity and initialised ticks. The engine walks the Uniswap V3 pool tick by tick in the direction of a sale and finds C(i), the largest sale that moves the price at most i. C(1%) is cross-checked against the OKX DEX aggregator at the same notionals; when the two diverge beyond tolerance, the smaller wins.

3.3 Mark

The Credit Mark is the lower of the reference median and the pool price along the whole path to the loan asset, less a haircut set by the regime. It is conservative by construction; it is not a mid-market price.

4. The standard (KTS 0.2)

The Kerb Terms Standard turns measurements into two loan-to-value limits and two debt limits. Each mode’s margin below the fixed liquidation threshold LT is tied to the horizon it must survive:

carryMargin = max(floorCarry, k · v · g(H_next_deep) + s) sessionMargin = max(floorSession, k · v · g(H_cure) + s) carryLTV = LT − carryMargin sessionMaxLTV = LT − sessionMargin debtCeiling = kCeiling · C(1%) maxPositionDebt = min(capAbs, capShare · C(1%))

g(H) is the 99th-percentile price gap over a horizon of H hours from five years of daily closes; v is a recent-volatility scaler; s is the measured exit cost at the reference liquidation size. Before a long closure, Carry tightens because its horizon grows, while Session Max, which only has to reach the next Last Call, does not.

KTS 0.2 parameters as live
ParameterLive valueMeaning
k2.5Stress multiplier on the horizon gap
floorCarry, floorSession5%, 3%Smallest margin each mode may keep
kCeiling0.75Debt ceiling as a multiple of C(1%)
capAbs, capShare$25,000, 25%Largest single position
Reference liquidation size$10,000Size at which exit cost s is measured
Loosen step, cooldown2%, 30 minHow fast terms may loosen

5. A worked example

At the New York close on 21 September 2026 the horizon KOx’s Carry must survive grew from 17 h 31 m to 41 h 26 m, spanning the night and the next session’s gap. The stressed gap over that horizon rose from 3.63% to 5.41%.

KOxBefore 20:00 UTCAfterCause
Carry55.60%51.57%Horizon −4.11 pts, loosening cap +0.08, exit cost 0.00
Session Max61.20%54.47%Margin left its floor as the cure horizon grew

The causes sum to the posted move exactly. Across 2,186 attributed changes in the record, the unexplained residual is zero. Every asset page shows its own changes with their causes.

6. The covenant

A Carry loan needs no attention. A Session Max loan borrows more now and accepts a covenant: when Last Call opens, before the market weakens, the position must come back to its Carry target. If the owner does not act, anyone may cure it, repaying only the difference for a small bonus in collateral, while liquidity is still there. The liquidation line never moves; sessions move only how much may be borrowed and when a cure is due.

7. Attestation and guardrails

The attester signs each report (EIP-712) and posts it to KerbTerms with the keccak256 of its complete input bundle; every Kerb transaction carries the ERC-8021 Builder Code kt0hl6xyhlx8xmt. KerbTerms enforces what the attester cannot change: bounded LTVs, a fixed liquidation line per asset, tightening at once and loosening in steps after a cooldown, and a maximum report age after which terms are unusable. Anyone can fetch a bundle by its hash and recompute the terms with one command.

8. Consumers

ConsumerHow it reads Kerb TermsWhere
Kerb CreditCarry or Session Max, Last Call, a public cure table, a standing demo position every cycleX Layer testnet
ContractsKerbQuote: max borrow, cure deadline, usability in one view call. KerbMarkFeed: the Credit Mark as a Chainlink-shaped feed that fails closedX Layer mainnet
AgentsKerb Credit Check and Exit Check, one cent in USDT0 per call over x402; a free MCP serverX Layer mainnet
DevelopersA public API with no key, an SDK and an open hourly datasetapi.usekerb.xyz

9. Evidence

  • The full credit lifecycle (deposit, Session Max borrow, Last Call, a stranger’s cure, repay, withdraw) has run in real browsers on the live site with fresh wallets.
  • The first paid agent call settled in USDT0 on X Layer mainnet on 23 September 2026.
  • KerbQuote and ten Credit Mark feeds are deployed on mainnet; their valuation equals Kerb Credit’s to the wei, in fuzz tests and live.
  • Every deployment is a Sourcify exact match; the latest term is recomputed live on Proof.

10. Limits

Kerb is unaudited. One attester signs the terms. The reference price is issuer data with an independent check, not a verified oracle report. Credit runs on testnet with mirror collateral: the production tokens are restricted in some jurisdictions, and lending real money needs an audit first. Input bundles are served by the Kerb API since the free pinning quota ran out on 21 September. See the risk disclosure.

11. What comes next

  1. A verified oracle reference (Chainlink Data Streams) as the first rung for the Mark.
  2. Several attesters with a threshold, and an audit.
  3. Curator integrations that set supply caps from measured depth.
  4. Real collateral, where the law and the audit allow.

References

  1. Kerb Terms Standard 0.1 and the 0.2 amendment: docs/KTS-0.1.md, docs/v2/KTS-0.2.md.
  2. Market-Time Report #1: usekerb.xyz/research/1.
  3. API reference with captured responses: docs/API.md.
  4. Contracts, posts and the live recompute: usekerb.xyz/proof.