Metaplex has launched MPL-3643, a permissioned token standard for real-world assets and tokenized securities on Solana. It lets issuers put compliance rules like investor eligibility, jurisdiction limits, lockups, and holder caps directly into the asset. Metaplex announced it on September 29, 2026, and it is live on Solana mainnet in a limited-access alpha.
MPL-3643 is Solana's counterpart to ERC-3643, the Ethereum standard for permissioned tokens. Metaplex's pitch is that issuers can bring regulated assets to Solana natively, without wrapping them, and still have them work with the wallets and DEXs Solana users already have.
What is MPL-3643?
MPL-3643 is a suite of four Metaplex programs that sit on top of a standard Token-2022 mint. The token itself is an ordinary Token-2022 token with a compliance layer above it, so existing Token-2022 support in wallets, explorers, and DEXs carries over.
The four programs split the work:
Identity Registry manages investor claims, the trusted attestors who issue them, and which attestors each token trusts.
Compliance Module enforces an offering's rules, including holder caps, jurisdictions, lockups, and volume limits.
Gate Program decides whether a wallet can be thawed or should be frozen, through the sRFC 37 interface.
Lifecycle Manager handles vesting, yield distributions, corporate actions, and recovery.
Identity runs on the Solana Attestation Service. Each wallet holds claims organized by topic, such as KYC, AML, residency, accreditation, and sanctions screening. Names, documents, and detailed KYC results stay offchain, and the chain records only the wallet, the topics, the attestor, and the expiry.
With an investor's consent, an existing KYC verification can be shared with a new issuer offchain, so the investor doesn't resubmit documents for each offering. Each issuer still keeps its own data, its own regulatory responsibility, and its own onchain claims.
How MPL-3643 enforces compliance
MPL-3643 enforces compliance when an account is frozen or thawed. Every token account starts frozen, through Token-2022's DefaultAccountState extension. The mint's freeze authority is held by Token ACL, the sRFC 37 program, which calls the Gate Program to decide whether a wallet qualifies. Only a wallet that meets the issuer's rules can thaw its account and hold the asset.
If a wallet later falls out of compliance, for example because its KYC claim expires, anyone can run a permissionless "crank" that re-freezes it.
Most of the Compliance Module's rules are checked at that thaw-and-freeze boundary:
Country allow and deny lists
Caps on total holders, and on investors who control several linked wallets
Lockups and blackout windows
Restrictions on jurisdiction pairs and trading venues
Rules that have to see each transfer, like caps on affiliate trading volume, run through an optional transfer hook. Issuers have to choose it when they create the token, because a transfer hook can't be added to a mint later. Tokens that skip it carry no extra compute cost on transfers after an account is thawed.
Issuers can also enable recovery, which makes the Lifecycle Manager the token's permanent delegate, a program address with no private key. A recovery request needs separate proposer and approver roles, waits out a timelock, and executes only inside a fixed window against a specific account.
How is MPL-3643 different from ERC-3643?
MPL-3643 follows ERC-3643's compliance model but moves where the check happens. ERC-3643 checks compliance inside the token's transfer function, so every transfer calls the rules. MPL-3643 checks when an account is thawed, so most transfers between already-approved wallets are ordinary Token-2022 transfers.
Metaplex's docs map each ERC-3643 component to its Solana equivalent:
ERC-3643 (Ethereum) | MPL-3643 (Solana) |
|---|---|
ERC-20 token contract | Token-2022 mint plus Token ACL |
Identity Registry | Identity Registry program |
ONCHAINID | Wallet-keyed claims backed by the Solana Attestation Service |
Trusted Issuers Registry | Trusted attestor accounts |
Compliance contract | Compliance Module plus Gate Program |
Tokeny, which created ERC-3643, says about $28 billion in assets have been tokenized with it.
Early integrations and alpha access
Solflare, Phantom, Raydium, Orca, and Jupiter are named as early integrations. Trading support depends on each venue, specifically whether it handles tokens with transfer hooks and whether it chooses to list permissioned assets. Raydium already runs permissioned AMM pools that restrict trading to approved wallets.
After issuance, the Lifecycle Manager lets issuers pay yield to holders, set vesting schedules, and run corporate actions onchain. Metaplex charges protocol fees in SOL, including 0.063 SOL to configure an asset and 0.034 SOL to activate a holder account.
Metaplex is taking alpha access requests from issuers, tokenized securities venues, tokenization platforms, and developers who want to issue or support RWAs on Solana. The TypeScript and Rust SDKs, @metaplex-foundation/mpl-permission and mpl-permission, come through alpha onboarding. The programs haven't been audited yet, and Metaplex lists MPL-3643 as experimental.
Metaplex built MPL-3643 on the freeze authority that Solana wallets and DEXs already handle, which is how it can claim composability on day one. The real test is the first security issued natively on Solana under it, and the unaudited alpha has no announced issuer yet.