NEP-330: Contract source metadata
NEP-330 contract source metadata on NEAR: the contract_source_metadata view, version, source link, implemented standards and build info for verifiable builds.
Intermediate5 min read3-question check
A deployed NEAR contract is just Wasm bytes. NEP-330 adds one view method, contract_source_metadata(), that tells anyone where the source lives, which version is deployed, which standards it implements, and how to rebuild it — so the Wasm can be checked against the source.
All fields are optional, but the more you fill in, the more useful the contract is to explorers, wallets and auditors.
{
"version": "1.0.0",
"link": "https://github.com/example/my-token/tree/9c16aaff3c0fe5bda4d8ffb418c4bb2b535eb420",
"standards": [
{ "standard": "nep330", "version": "1.3.0" },
{ "standard": "nep141", "version": "1.0.0" },
{ "standard": "nep145", "version": "1.0.0" },
{ "standard": "nep148", "version": "1.0.0" }
],
"build_info": {
"build_environment": "sourcescan/cargo-near:0.x.y-rust-1.xx.0@sha256:<digest>",
"source_code_snapshot": "git+https://github.com/example/my-token?rev=9c16aaff3c0fe5bda4d8ffb418c4bb2b535eb420",
"contract_path": "",
"build_command": ["cargo", "near", "build", "non-reproducible-wasm", "--locked"],
"output_wasm_path": "/home/near/code/target/near/my_token.wasm"
}
}| Field | Meaning |
|---|---|
version | Version or commit of the deployed code. |
link | Where to find the source (repository URL or IPFS CID). |
standards | List of { standard, version } the contract claims to implement, e.g. nep141 1.0.0. |
build_info.build_environment | The Docker image (pinned by digest) the Wasm was built in. |
build_info.source_code_snapshot | Exact source reference, e.g. a git URL with the commit rev. |
build_info.contract_path | Path of the contract crate inside that repository (empty for the root). |
build_info.build_command | The exact command, as an array of arguments, run inside the image. |
build_info.output_wasm_path | Where that command writes the Wasm inside the image. |
Adding it with near-sdk#
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.24;
import {ERC165} from "@openzeppelin/contracts/utils/introspection/ERC165.sol";
import {IERC721} from "@openzeppelin/contracts/token/ERC721/IERC721.sol";
// ERC-165: ask "do you support interface id X?" one id at a time.
// Source verification (Etherscan etc.) happens off-chain.
abstract contract MyNft is ERC165 {
function supportsInterface(bytes4 id) public view virtual override returns (bool) {
return id == type(IERC721).interfaceId || super.supportsInterface(id);
}
}use near_sdk::near;
// near-sdk generates the contract_source_metadata() view.
// version / link default to NEP330_VERSION / NEP330_LINK env vars,
// falling back to the crate's Cargo.toml version and repository.
#[near(contract_state, contract_metadata(
version = "1.0.0",
link = "https://github.com/example/my-nft",
standard(standard = "nep171", version = "1.0.0"),
standard(standard = "nep181", version = "1.0.0"),
))]
#[derive(Default)]
pub struct Contract {}supportsInterface(id) ↔ the standards array: one call returns every standard (with version) the contract claims.
NEP-330 also carries what Etherscan-style verification needs (source snapshot, build image, command), but on-chain and in a standard shape, so anyone can re-run the build.
Check yourself
3 questions · progress saved in this browser