RADIX WikiRADIX Wiki

Introduction

The application layer is the topmost layer of the Radix Engine stack, and the only one whose code is uploaded rather than shipped with the node. Everything below it – the kernel, the system layer and the two virtual machines of the VM layer – changes only when validator operators install a new version of the node software. This layer changes when somebody publishes a package, which needs no permission from anyone.

What Runs Here

Three things, in a fixed relationship. A blueprint defines state, functions and access rules. A package is a deployed bundle of blueprints with its own ledger address. A component is a running instance of a blueprint, with its own state and its own address. Developers write all three in Scrypto, Radix’s Rust SDK, and publish the compiled WebAssembly; Blueprints & Packages covers what a package holds and what it costs to call one.

The layer is not exclusively developer code. The engine’s own blueprints – Account, Identity, ConsensusManager, AccessController, the pools, the resource package – present the same interface and are called the same way, but run as compiled Rust in the Native VM rather than as WebAssembly. A Scrypto component holding a vault or calling a pool does not know which side of that boundary it is on, and cannot find out through any interface the engine offers it.

How a Transaction Arrives

Application code is never the first thing to run. A transaction reaches the network as a manifest, a list of instructions, and the transaction processor – itself a native blueprint – executes them in order. The processor owns the two structures the manifest manipulates: the worktop, where resources sit between instructions, and the auth zone, which holds the proofs a called method is checked against.

By the time a component method body runs, the signatures have been verified, the fee has been locked, the proofs are in the auth zone and the access rule on that method has already passed. Application code sees none of it. It cannot read a signature, an epoch, a validator set or another component’s fields, because no host function exposes any of them.

What the Layer Inherits

Three properties arrive from below rather than from the blueprint, which is what makes application code on Radix shorter than its equivalent elsewhere. Resources are engine primitives, so a token cannot be duplicated or dropped by a blueprint that forgets to update a balance; a bucket that goes nowhere fails the transaction rather than burning its contents. Access rules are enforced by the system layer before the method body is entered, so an authorisation check the author did not write is still applied. And composability is atomic by construction: a call into another component either completes or reverts the whole transaction, with no partially applied state to unwind.

The trade is that the layer is narrow on purpose. Determinism is the requirement every node re-executing a transaction has to meet, so there is no clock, no network, no filesystem and no unseeded randomness at this layer – see the VM layer for the host-function list that bounds it.

HydrateLast updated Sep 21, 2026v2.0.06 revisionsVerified Sep 21, 2026