How a capture is proved

What happens between a mount slewing and a record on chain — and, more usefully, what the system refuses to do. Each step below names the code that enforces it.

Where this stands tonight

0 of 1 instrument is wired to real hardware. Until that number moves, every frame the network produces is simulated and is marked as such everywhere it appears — including here. The steps above are built and enforced; what they are waiting for is first light.

  1. The mount says where it pointednode agent

    A phone photograph of the sky proves very little about where the camera was aimed — which is why verifying one takes a vision model, EXIF, a dedup hash, a reverse-image lookup and a visibility cross-check, and still returns a confidence rather than a fact. A node capture starts from the other end. The mount reports the coordinates it slewed to from its own encoders, and the agent records them beside the frame. The pointing is not a claim anyone made about the picture; it is what the instrument did.

  2. The frame is signed where it was takennode agent

    The agent signs the capture at the node, before it leaves the owner’s network. Stellar never receives node credentials and never addresses a mount or a camera: every command travels through the adapter, expires, is idempotent by command id, and is re-validated locally by the node against its own altitude envelope, horizon mask and Sun avoidance. A command the cloud approved and the node considers unsafe does not move the telescope.

  3. Provenance is declared by the adapter, never by the clientadapter.ts · capture route

    The capture endpoint asks adapterFor(node) what a frame taken this second is worth, and ignores the request body entirely — there is no field a client could set. It is asked at the moment of capture rather than read off the adapter once, because a node platform can be connected and still running its own simulator, and being wired to a telescope is not the same as that telescope being the thing that took the picture. Every uncertainty resolves downward: an unreachable node, a late heartbeat, a reply we do not recognise, all mean simulated.

  4. One gate decides what a frame is worthprovenance.ts

    admitToCollection() admits a capture only when its provenance is exactly "instrument", and returns the reason when it refuses. Minting, awarding Stars and writing an observation all pass through that one function rather than each surface remembering to check. A rule enforced in six places is a rule that will eventually be enforced in five.

  5. An admitted capture becomes an ordinary observationobservation_log

    Nothing about the record is special-cased. An admitted capture is written to the same observation log a phone photograph writes to, with the same verification columns and the same chain references — so the gallery, the feed, the passport and the share images keep working with no change at all. A stronger input, in the same shape.

  6. The oracle records it on chainstellar_observations

    The Proof-of-Observation program stores each observation as its own account, seeded by the hash of the frame — which means re-recording the same image fails at account creation, and dedup is a property of the chain rather than a query we remember to run. Attestations are oracle-signed and written gaslessly on the user’s behalf. The user signed up with an email and never touches a key.

What a simulated frame cannot do

The simulator is open to everyone and needs no account. It models the real optical train, the real slew times and the real safety envelope, and it refuses the same targets the instrument would, for the same reasons. What it produces is a teaching tool, not evidence.

  • noMint a Discovery Attestation
  • noAward a single Star
  • noBe written to the observation log
  • noBe sold, printed, or delivered as a photograph

Simulated captures are stored and shown, always labelled. They are never quietly mixed in with instrument frames.

Why the rail exists before the telescope does

In July 2026 a certify-all window put fourteen compressed NFTs on Solana mainnet carrying Verified: yes for observations that nothing had verified. They are still there; they cannot be unwritten, and the honest count of genuinely verified mints from that period is zero.

A simulator that could mint would be that same mistake, made deliberately and at scale. So the gate was built before the first instrument was wired, while it was still cheap to be strict — and the network was designed so that the only way to produce a record is to actually point a telescope at the sky.