LIMEN
TESTNET
simulator

Derivation, without a chain to write to

Take a transaction, derive the boundary that permits exactly it, and watch that boundary refuse everything adjacent. Every refusal here is adjudicated by this repository’s own evaluator. Nothing on this screen installs anything, and no boundary drawn here has been enforced by a network.
COMPUTED LOCALLYTESTNET ONLY
  1. 01

    Get a transaction

    on-chain

    Either a real transfer submitted to Stellar testnet from a disposable demo account, or one of the flows shipped with this repository. No wallet and no funded account of your own, either way.

    or start from a shipped flow

    Shipped flows were never observed on a live network. The ones marked refused are declined somewhere in the pipeline on purpose — a simulator that can only succeed is not evidence about anything.

  2. 02

    Observe it

    on-chain

    Read back into an observable flow: through Soroban RPC for a testnet hash, from the repository for a shipped one.

  3. 03

    Derive the boundary

    computed locally

    The minimum context rule and policy set that permits exactly that flow, composed from audited OpenZeppelin primitives.

  4. 04

    Try to exceed it

    computed locally

    Adjacent transactions, one mutated dimension each. Every one must be refused.

  5. 05

    Read the policy

    computed locally

    The exact policy configuration that was derived, and the unsigned payload.

  6. 06

    Ask whether it could be installed

    computed locally

    What Limen derives and what an OpenZeppelin smart account can hold are different languages. Lowering either translates the boundary or refuses it and names the constraint.

The demo account is disposable and holds trivial funds; it is rate-limited and its compromise is uninteresting by design. Steps 3 through 6 run entirely in your browser using the same @limen/core and @limen/chain packages the test suite runs — the page executes exactly the code CI gates on.