# Obento docs
> How Obento's USDC savings work, what they cost, the risks, and every contract address.
Obento is a savings app for USDC on Base. You add USDC, and Autopilot lends it to vetted lending markets and moves it when rates change. You can take it out whenever you like.
## In one minute
1. **Your USDC joins one vault.** You receive obUSD, your share of the vault. Its value grows as the vault earns.
2. **Autopilot lends it out.** Every 15 minutes it checks the best-paying places on Base and spreads the vault across them, within fixed limits.
3. **The box shows where it is.** Each compartment in the app is a real place your money sits, sized by how much is there, with its live rate.
4. **You can leave at any time.** Withdrawals up to the vault's ready cash arrive at once. Bigger ones arrive within about 15 minutes.
## Key facts
| | |
|---|---|
| Asset | USDC on Base |
| Rate now | See the app a year, after fees |
| Fee | 10% of new lending profit. No deposit, withdrawal or management fee. |
| Lockup | None |
| Network fees | None if you sign in with email or Google. Wallets pay Base's network fee, usually under a cent. |
| Custody | Your wallet holds your obUSD. Obento never holds your keys. |
## Read next
- [Getting started](/docs/getting-started): sign in, add USDC and withdraw.
- [How Autopilot works](/docs/autopilot): the rules it follows and what it can't do.
- [Security](/docs/security) and [Risks](/docs/risks): what protects your savings, and what could go wrong.
- [Contracts](/docs/contracts): every address, verified on Basescan.
---
# Getting started
> Sign in, add USDC from Base or another network, watch it earn, and withdraw.
## Sign in
Sign in with your email, Google, or a wallet you already use, such as Rabby, MetaMask or Coinbase Wallet.
Email and Google sign-ins get a wallet made for you by Privy. Only you can use it, and you can export its key from your account at any time.
## Add USDC
Choose **Add USDC**, then pick where it comes from.
- **USDC on Base.** Send USDC to your Obento wallet, or sign in with the wallet that holds it. Then put it to work in one step.
- **Another network or token.** Choose **Other crypto**. Relay gives you a deposit address and turns what you send into USDC on Base. Relay shows its fee before you send, and refunds go back to your own address.
If you signed in with email or Google, Obento pays the network fee. A wallet you connect pays Base's network fee itself, usually under a cent.
## Watch it earn
Your balance is your savings plus any USDC still in your wallet. Under it you see what you've earned so far, counting up each second, and the rate Autopilot earns now, after its fee.
Tap what you've earned to open **Activity**: everything you've added and withdrawn, Autopilot's fee in dollars, and each transaction on Basescan. **Download statement** saves it all as a CSV for your records.
The box below shows where your money is. Each compartment is a real place the vault lends to, sized by your money in it. Tap one to see how that place works, or tap **Autopilot** to see how it decides.
## Withdraw
Choose **Withdraw**, enter an amount, and choose where it goes: your Obento wallet or any address on Base.
Up to the vault's ready cash arrives at once. A bigger withdrawal arrives on Autopilot's next pass, usually within 15 minutes. [More about withdrawals](/docs/withdrawals).
---
# How Autopilot works
> The rules Autopilot follows, how it measures rates, how it publishes the price, and what it can't do.
Autopilot is the program that runs the vault. Every 15 minutes it reads the vault and every place the vault may lend to, then decides whether to move money.
## The rules
Autopilot spreads the vault across the places that pay the most, inside these limits:
| Rule | Limit |
|---|---|
| Ready cash for instant withdrawals | 3% of savings |
| Most in one place | 40% |
| Most with one protocol, such as Morpho | 40% |
| Smallest position | 10% |
| Most places at once | 6 |
| Most of any one place's deposits | 10% |
| When it moves money | Only when that earns at least 0.1% more a year |
A place's rate falls as more money joins it, because lenders share the same interest. So Autopilot adds each next dollar where it earns the most, and stops when the limits are reached.
The rules live in code. Changing them, or adding a place, waits 48 hours in public through the [timelock](/docs/security).
## How it measures rates
- **Lending vaults**, such as Steakhouse or Gauntlet on Morpho, by how much their share value grew over the last three days, as a yearly rate.
- **Morpho markets**, by their current supply rate.
The rates in the app are after Autopilot's 10% fee. The vault's own rate is the average of its places, weighted by the money in each. Ready cash earns nothing, so it pulls the average down a little.
## The share price
Each pass, Autopilot publishes the vault's share price: what one obUSD is worth in USDC. Two guards protect it.
- The price can move at most 0.1% from a daily anchor, so a wrong price can't be pushed through in one step.
- If no price arrives for an hour, the vault stops deposits and withdrawals until a fresh one does. Nobody can deposit or withdraw at a stale price.
## When it pauses
Autopilot pauses the vault only on evidence of loss: a value below the allowed band, insolvency, a place it can't value, or a price the vault rejects. A second read at a later block must agree first. A network fault never pauses the vault; Autopilot retries. The Safe resumes the vault once the cause is clear.
## What Autopilot can't do
Autopilot holds two keys with narrow powers. It can move money between the listed places, pay queued withdrawals, publish the price within its band, and pause. It can't send money anywhere else.
The vault calls lending places only through fixed adapters. Each adapter does one job and always returns money to the vault. [How the vault is secured](/docs/security).
---
# Autopilot's journal
> Every move Autopilot has made with the vault in the last 30 days, live from Base.
Every move Autopilot makes is a transaction on Base. This page reads them live: money lent to or taken back from each place, queued withdrawals it paid, and any pause. Savers' own deposits and withdrawals are not listed.
Each entry links to its transaction on Basescan, where anyone can check it. [How Autopilot decides](/docs/autopilot).
---
# Where your money goes
> Every place the vault may lend to, what each one is, and its live rate.
The vault may lend to the places below. Autopilot picks among them using [its rules](/docs/autopilot). The table shows each place's rate now, after fees, and the vault's share in it.
## Lending vaults on Morpho
Morpho vaults lend to borrowers who put up more collateral than they borrow. A curator sets which collateral is allowed and how much.
| Place | Curator | What it lends against |
|---|---|---|
| [Steakhouse High Yield](https://app.morpho.org/base/vault/0xbeeff7aE5E00Aae3Db302e4B0d8C883810a58100) | Steakhouse Financial | A wider set of collateral, for a higher rate |
| [Steakhouse Prime](https://app.morpho.org/base/vault/0xbeef0e0834849aCC03f0089F01f4F1Eeb06873C9) | Steakhouse Financial | Blue-chip collateral |
| [Gauntlet Prime](https://app.morpho.org/base/vault/0xeE8F4eC5672F09119b96Ab6fB59C27E1b7e44b61) | Gauntlet | Blue-chip collateral |
| [Spark](https://app.morpho.org/base/vault/0x7BfA7C4f149E7415b73bdeDfe609237e29CBF34A) | Spark | Blue-chip collateral |
| [Clearstar](https://app.morpho.org/base/vault/0x91C056B6d4311a743614FBc03ac32d4E6A2d3a3c) | Clearstar | Coinbase-wrapped assets such as cbBTC and cbETH |
## Morpho markets
The vault can also lend straight to two Morpho markets.
| Place | Borrowers put up |
|---|---|
| [Bitcoin loans](https://app.morpho.org/base/market/0x9103c3b4e834476c9a62ea009ba2c884ee42e94e6e314a26f04d312434191836) | Coinbase Bitcoin (cbBTC) |
| [Ether loans](https://app.morpho.org/base/market/0x8793cf302b8ffd655ab97bd1c695dbd967807e8367a65cb2f4edaf1380ba1bda) | Ether (WETH) |
## Lending markets
| Place | How it works |
|---|---|
| [Fluid](https://fluid.io/lending/8453) | Lends to borrowers on Fluid. The pool is small, so large withdrawals from it can wait for borrowers to repay. |
| [Aave](https://app.aave.com/reserve-overview/?underlyingAsset=0x833589fcd6edb6e08f4c7c32d4f71b54bda02913&marketName=proto_base_v3) | Lends to borrowers on Aave, the largest lending market onchain. The rate follows borrowing demand. |
## Protocol limits
All Morpho vaults and markets count as one protocol, so together they hold at most 40% of the vault. Fluid and Aave each hold at most 40% too. A problem at one protocol can't touch more than 40% of savings.
---
# Withdrawals
> Instant and queued withdrawals, where the money goes, and what happens if the vault is paused.
You can withdraw at any time. There is no withdrawal fee and no lockup.
## Instant
Autopilot keeps about 3% of savings as ready cash in the vault. A withdrawal up to the ready cash arrives in the same transaction.
## Queued
A bigger withdrawal joins a queue. Its amount is fixed when you ask, at that moment's share price. Autopilot frees the cash from the lending places and pays it on its next pass, usually within 15 minutes. The app shows it as on its way.
A place that has lent out almost all its money can make a large withdrawal wait until borrowers repay. Autopilot pays the queue first, before any new lending.
## Where it goes
To your Obento wallet, or to any address on Base that you enter.
## If the vault is paused
Deposits and withdrawals wait while the vault is paused, or while its share price is more than an hour old. Your savings stay in the vault and keep their value. The app says when this happens and why.
---
# Fees
> Obento's one fee, the costs it doesn't charge, and network fees.
Obento has one fee.
| | |
|---|---|
| Autopilot fee | 10% of new lending profit |
| Deposit fee | None |
| Withdrawal fee | None |
| Management fee | None |
## How the Autopilot fee works
The fee comes only out of profit, and only above the vault's high-water mark: the highest share price it has reached. If the vault loses value, there is no fee until it earns back to its previous high.
Every rate in the app is already after the fee, and **Activity** shows what the fee has come to on your savings, in dollars.
## Network fees
- **Email and Google sign-ins:** Obento pays the network fee for you.
- **A wallet you connect:** your wallet pays Base's network fee, usually under a cent.
- **Deposits from another network:** Relay charges its own fee and shows it before you send.
---
# Security
> The audited code under Obento, who controls what, and the guards around your savings.
## Built on audited code
The vault is a fork of YO Protocol's core contracts. Nine firms have audited that code, including Cantina, Spearbit and Zellic, and YO runs the same vault with its own deposits. The vault's code is verified on Basescan.
Obento's own additions have not had an independent audit: the profit accounting, the price oracle and the revenue contract. Read [the risks](/docs/risks) before you put money in.
## Who controls what
| Role | Held by | Can | Can't |
|---|---|---|---|
| Owner | A 48-hour timelock | Upgrade contracts, add places, change roles | Change anything without a public 48-hour wait |
| Guardian | A Safe that needs 2 of 3 signers | Pause and resume at once, and propose timelocked changes | Move savings |
| Operator | Autopilot | Move money between listed places, pay queued withdrawals, pause | Send money outside the vault |
| Updater | Autopilot | Publish the share price within its 0.1% daily band | Move money |
Every change to the vault's code, its places or its roles waits 48 hours in public. You can leave before any change takes effect.
## Guards
- **A closed loop.** The vault reaches lending places only through fixed adapters. Each one does a single job, can't be upgraded, and always returns money to the vault.
- **Approval caps.** A registry fixes how much the vault may approve to each contract.
- **A banded price.** The share price can move at most 0.1% from a daily anchor.
- **No stale prices.** The vault refuses deposits and withdrawals once its price is an hour old.
- **Checked moves.** Autopilot simulates every transaction before it sends it.
- **A watchdog.** A separate check reads the vault every minute and alerts the team if anything is off.
## Report a vulnerability
Email [obentoapp@proton.me](mailto:obentoapp@proton.me) with what you found and how to reproduce it. Please don't publish it or use it until it's fixed. The address is also in [security.txt](/.well-known/security.txt).
---
# Risks
> What could make savings in Obento lose value or wait.
Savings in Obento can lose value. Only put in what you can afford to lose.
## Smart contracts
The vault, Obento's additions to it and every place it lends to are smart contracts. A bug in any of them could lose money. Obento's additions have not had an independent audit.
## Lending
The places lend to borrowers against collateral. If collateral prices fall too fast for loans to be closed, a place can be left with bad debt, and pay back less than it holds. Protocol limits keep any one protocol to 40% of the vault.
## Liquidity
A place that has lent out almost all its money can't pay back at once. Large withdrawals may then wait until borrowers repay.
## USDC
Savings are in USDC. If USDC loses its dollar value, or Circle freezes it, savings lose value too.
## Operations
Withdrawals need a share price less than an hour old. If Autopilot stopped publishing it, deposits and withdrawals would wait until the team fixed it. A watchdog alerts the team within 35 minutes.
## Base
Obento runs on Base. If Base stops or slows, so does Obento.
## Rules where you live
Rules for crypto savings differ by country and can change.
---
# Status and incidents
> The vault's live health, and every incident since launch.
## How to read this
- **Open** means deposits and withdrawals work. **Paused** means they wait while the team checks something; savings stay in the vault.
- Autopilot publishes the price every 15 minutes. A price older than an hour stops deposits and withdrawals until a fresh one arrives.
## Incidents
Every incident that paused the vault or put savings at risk is listed here, newest first.
### 5 October 2026: the first pass paused the empty vault
Autopilot's first pass after launch read a transaction receipt before Base had included its block, saw a price of zero, and [paused the vault](https://basescan.org/tx/0x43f61c5d50de93ddd18ff524a8acdfd00297d781ab909c45591135f181ccbf8d) at 10:45 UTC. The vault held no savings yet, so nothing was lost. The Safe [resumed it](https://basescan.org/tx/0x0eb55ebb748c5cabf969e35ec8cf9eb525aaca2ee24bbb867a9c4f9ff1e84f9d) 41 minutes later.
Since then, Autopilot reads state only at or after the block of its own transactions, and pauses only when a second read at a later block agrees.
---
# Contracts
> Every Obento contract and key on Base, linked to its verified source on Basescan.
Every contract runs on Base (chain 8453) and its source is verified on Basescan.
Copy addresses from this page, never from your wallet's history. Scammers send tiny transfers from lookalike addresses that match the first and last characters, so check the whole address.
## Core
| Contract | Address |
|---|---|
| **Vault (obUSD)**
Holds savings and issues obUSD. Upgradeable only through the timelock. | [`0xB24366D770477C8192eC98851137A1eF8530A1e5`](https://basescan.org/address/0xB24366D770477C8192eC98851137A1eF8530A1e5) |
| **Gateway**
The entry point the app uses to deposit and withdraw. | [`0x3BFAC87918c69D02e4288bDcC503AF7F545d735C`](https://basescan.org/address/0x3BFAC87918c69D02e4288bDcC503AF7F545d735C) |
| **Price oracle**
Stores the share price Autopilot publishes, within a 0.1% daily band. | [`0xcdA2693fdcC0202fd0cd183A42E10f7B3f674AB1`](https://basescan.org/address/0xcdA2693fdcC0202fd0cd183A42E10f7B3f674AB1) |
| **Revenue**
Receives the 10% fee and pays any savers' bonus. | [`0x0599dBFd7D6b34451aa7b506328bb3265e948546`](https://basescan.org/address/0x0599dBFd7D6b34451aa7b506328bb3265e948546) |
| **Timelock**
Owns the contracts. Every change waits 48 hours in public. | [`0x3Aa0c7F77AD8D6a031c067C11F3D5BA701D41f9c`](https://basescan.org/address/0x3Aa0c7F77AD8D6a031c067C11F3D5BA701D41f9c) |
| **Roles**
Says which address may call which function. | [`0x6f51d74f917F1f6d3869CdDe7Eb4327fCF27CDec`](https://basescan.org/address/0x6f51d74f917F1f6d3869CdDe7Eb4327fCF27CDec) |
| **Vault registry**
Lists the vaults the gateway serves. | [`0x2cb9230f963A30cc2aD3C06A5C295dfDC8a66090`](https://basescan.org/address/0x2cb9230f963A30cc2aD3C06A5C295dfDC8a66090) |
| **Pool registry**
The lending vaults Autopilot may use. | [`0x193F95F8A4C5ef5De47fC549E52Ad0b8A770fE99`](https://basescan.org/address/0x193F95F8A4C5ef5De47fC549E52Ad0b8A770fE99) |
| **Market registry**
The Morpho markets Autopilot may use. | [`0x3d16087dA83ED70B3785746cAd4E53B43F658654`](https://basescan.org/address/0x3d16087dA83ED70B3785746cAd4E53B43F658654) |
| **Approval registry**
Caps what the vault may approve to each contract. | [`0x58216e1E19432F1Bb1FAe88eB5EDb6a85B81EFeE`](https://basescan.org/address/0x58216e1E19432F1Bb1FAe88eB5EDb6a85B81EFeE) |
| **ERC-4626 adapter**
Deposits into and withdraws from listed lending vaults, always back to the vault. | [`0x8d70A219a875d06F0E72050b9Af39EffC385267E`](https://basescan.org/address/0x8d70A219a875d06F0E72050b9Af39EffC385267E) |
| **Morpho adapter**
Supplies to and withdraws from listed Morpho markets, always back to the vault. | [`0x942434c62193607829c82EEdE1165560306d5C00`](https://basescan.org/address/0x942434c62193607829c82EEdE1165560306d5C00) |
| **Revenue module**
A Safe module. Lets Autopilot run the revenue contract's one daily order, capped at $1,000. | [`0xa1eeBD0b1e2FC0FC175C02e45924219c477b99c9`](https://basescan.org/address/0xa1eeBD0b1e2FC0FC175C02e45924219c477b99c9) |
## Keys and roles
| Role | Address |
|---|---|
| **Safe (2 of 3)**
Guardian: pauses and resumes at once, and proposes timelocked changes. | [`0xB12ec639F7C45EE0b746366748A6c5E18Ad6eD0F`](https://basescan.org/address/0xB12ec639F7C45EE0b746366748A6c5E18Ad6eD0F) |
| **Operator**
Autopilot's key: moves money between listed places and pays queued withdrawals. | [`0xd810d701893a5190EAF5F648215d9B4D8C24D122`](https://basescan.org/address/0xd810d701893a5190EAF5F648215d9B4D8C24D122) |
| **Updater**
Autopilot's price key: publishes the share price. | [`0x7AFBf1b4147916360ecAA22C06216edd1444Fb2a`](https://basescan.org/address/0x7AFBf1b4147916360ecAA22C06216edd1444Fb2a) |
## Upgrades
| Contract | Address |
|---|---|
| **Vault proxy admin**
Upgrades the vault; owned by the timelock. | [`0x397bA6B301fdaf1d7207EB3A3911c44B353C3FdA`](https://basescan.org/address/0x397bA6B301fdaf1d7207EB3A3911c44B353C3FdA) |
| **Gateway proxy admin**
Upgrades the gateway; owned by the timelock. | [`0x64FA8F5310e82fD732EA016D8BB80a1dCB08176C`](https://basescan.org/address/0x64FA8F5310e82fD732EA016D8BB80a1dCB08176C) |
| **Registry proxy admin**
Upgrades the registry; owned by the timelock. | [`0xEf0c17632544Fa639d3618A69857e60446Edd557`](https://basescan.org/address/0xEf0c17632544Fa639d3618A69857e60446Edd557) |
| **Vault implementation**
The vault's code, verified on Basescan. | [`0x75F755A1BF901b88203a52CAA1CfE00517Db62E1`](https://basescan.org/address/0x75F755A1BF901b88203a52CAA1CfE00517Db62E1) |
## The asset
| Token | Address |
|---|---|
| **USDC on Base** | [`0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913`](https://basescan.org/token/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913) |
---
# Build on Obento
> Read the vault's live state, deposit through the gateway, and feed these docs to an agent.
## Read the vault
`GET https://obentoapp.com/api/vault` returns the vault's live state as JSON. An abridged example:
```json
{
"price": "1000000",
"priceFresh": true,
"paused": false,
"tvl": 0,
"ready": 0,
"apy": 0.0436,
"grossApy": 0.0484,
"performanceFeeBps": 1000,
"places": [
{ "key": "0xf42f5795D9ac7e9D757dB633D693cD548Cfd9169", "value": 0, "share": 0, "apy": 0.0539 }
]
}
```
| Field | Meaning |
|---|---|
| `price` | USDC per obUSD, with 6 decimals |
| `priceFresh` | Whether the price is less than an hour old |
| `tvl` | Savings in the vault, in USDC |
| `ready` | Ready cash for instant withdrawals, in USDC |
| `apy` | The vault's rate after the fee. While the vault is empty, the rate its first deposit would earn |
| `places` | Each place's value in USDC, its share of the vault and its rate before the fee |
## Read a saver's earnings and activity
`GET https://obentoapp.com/api/earnings?address=0x…` returns what an address has put in, taken out and holds now, in USDC with 6 decimals; what it has earned and what Autopilot's fee came to, in dollars; and its activity, newest first. It reads the vault's own events for that address, so obUSD sent between wallets and bonuses are not counted as earnings.
```json
{
"deposited": "1000000000", "withdrawn": "0", "value": "1002500000", "earned": 2.5, "fee": 0.28,
"activity": [{ "kind": "added", "at": 1791200000, "tx": "0x…", "amount": 1000 }]
}
```
Each entry is `added`, `withdrew` (with `to`, and a `status` of `paid`, `queued` or `returned`) or `bonus` (with `saved`). `at` is a Unix time in seconds.
## Read Autopilot's journal
`GET https://obentoapp.com/api/journal` returns the last 30 days, newest first: each `move` between places, each queued withdrawal Autopilot `paid`, and each time the vault was `paused` or `resumed`, with its transaction. The [journal page](/docs/journal) reads the same data.
## Deposit and withdraw
The vault is an ERC-4626 vault for USDC with 6-decimal shares (obUSD). Deposits and withdrawals go through the gateway:
- `deposit(vault, assets, minSharesOut, receiver, partnerId)`
- `redeem(vault, shares, minAssetsOut, receiver, partnerId)`
Approve the gateway first: USDC for a deposit, obUSD for a withdrawal. A withdrawal larger than the ready cash joins the queue and is paid on Autopilot's next pass. Addresses are on the [contracts page](/docs/contracts).
## For agents
- [/llms.txt](/llms.txt) lists every page.
- [/docs/llms-full.txt](/docs/llms-full.txt) holds all the docs in one file.
- Every page is also Markdown: add `.md` to its address, for example [/docs/fees.md](/docs/fees.md).
---
# Questions
> Short answers to common questions about Obento.
## Is my money locked?
No. You can withdraw at any time, with no fee.
## Where does the rate come from?
Borrowers on Morpho, Fluid and Aave pay interest to borrow USDC. Autopilot lends where they pay the most.
## Why does the rate change?
It follows how much people want to borrow. When demand rises, rates rise, and Autopilot moves money to the best places.
## What is obUSD?
Your share of the vault. You get obUSD when you add USDC, and its value in USDC grows as the vault earns. Your wallet holds it.
## Who can take my savings?
Nobody at Obento can withdraw your savings. The Safe can pause the vault and propose changes, and every change waits 48 hours in public. [Who controls what](/docs/security).
## Do I need ETH for network fees?
Not if you sign in with email or Google: Obento pays them. A connected wallet needs a little ETH on Base.
## Is there a minimum?
No. Any amount of USDC works.
## Can I get a statement?
Yes. Tap what you've earned, then **Download statement**. You get a CSV of every deposit, withdrawal and bonus with its transaction, made on your device from Base.
## Has Obento been audited?
The vault runs on YO Protocol's core contracts, which nine firms have audited. Obento's own additions have not been audited yet. [Security](/docs/security).
## Can I use Obento from my country?
Obento is open globally. Visitors from the UK see the FCA's risk summary first.