Skip to main content

An open specification · Stewardship proposed to the Open Cap Table Coalition

GitHub spec@opencaptableprotocol.org
Open Cap Table Protocol

Questions

Direct answers.

Thirty questions on the protocol, its treatment of tokens and chains, its legal basis, what adopting it commits an operator to, and who governs it. Every answer here is carried by the specification.

The protocol

The protocol

What is the Open Cap Table Protocol?
A specification for keeping an issuer’s official share register on a distributed ledger as an append-only log of typed Open Cap Table Format events. The log is the register itself, not a copy of one, and positions are derived from it by any party entitled to read it.
What is the difference between OCF and OCP?
OCF answers how ownership is represented. OCP answers which record governs — how a register built on that data is written, authorized, read and carried between operators. OCP introduces no second data model.
What problem does it solve?
In private markets the register is documents, spreadsheets and vendor exports. In public markets it is a transfer-agent file alongside a depository omnibus. Neither is a single live book that many entitled parties can read and one accountable party can write, so every participant keeps its own view and reconciles after the fact.
Why is that a problem if nothing is illegal?
The consequence is not latency. It is the set of operations equity cannot perform: it cannot be pledged as collateral without a manual verification cycle, cannot settle against cash in a single step, cannot carry its own transfer restrictions, and cannot disclose itself in real time to the parties entitled to see it. For most of these the obstacle is not a prohibition on the operation itself. It is the condition of the records the operation depends on.
What does “constitutive” mean here?
That the onchain event log is the register, with no offchain master book behind it. A register that mirrors an authoritative book kept elsewhere reproduces the reconciliation problem it was meant to remove, because two records that can disagree eventually do.
Is OCP a marketplace, a clearing agency or a directory?
None of the three. It specifies the register. How a market participant determines which transfer agent keeps a given issuer’s book, and how it reaches that agent, is deliberately outside scope — specifying it would make OCP a network rather than a protocol.

Tokens and chains

Tokens and chains

Is a share on OCP a token?
No. The register carries ownership, because ownership is a legal fact with an accountable keeper. Tokens, where they exist, are instruments issued against a position on the register — an access credential, a trading handle, a collateral instrument — and never the register itself.
Why not just make the token the share?
Equity is not a bearer instrument. A share carries restrictions that travel with it — legends, holding periods, rights of first refusal, board consent, charter transfer limits — and can only move to an eligible holder. A token that can move freely cannot express those constraints; a token that cannot move freely has given up the property that made it attractive. There is also a contractual problem: if the token is the share, the token’s behaviour becomes the company’s obligation.
Which blockchain does OCP run on?
Whichever one matches the register’s disclosure profile. Canton is the first runtime because its sub-transaction privacy matches that of a securityholder file without additional machinery. Earlier versions ran on Ethereum, Optimism and Base, and a Rust implementation for account-based chains has been started. The runtime is a deployment decision, not a protocol decision.
Can the register be fully public?
Only where the entire visibility surface genuinely belongs in public, which is true of some fund structures and of very little private or listed equity. Publishing a securityholder file to a public block explorer is not a disclosure choice an issuer or its transfer agent may lawfully make.
Does listing change the architecture?
No. Whether a company is private or listed does not change the objects, the writer, or the constitutive log. What changes is which parties may see which fields. Listing changes the issuer’s reporting obligations and where price discovery happens; it does not make the securityholder file a public document.
Where is personal data held?
Off the ledger, in the operator’s systems. The protocol carries no identifying information into public visibility on any runtime. Off-ledger identity information is not a second ownership record: it resolves who a party is, not what that party owns.

Law and supervision

Law and supervision

Does OCP require a new regulatory framework?
No. The system-operator role is held by a registered transfer agent, which places operations inside the Exchange Act Section 17A perimeter. SEC staff confirmed in May 2025 that a registered transfer agent may use distributed ledger technology as its official master securityholder file, with no offchain duplicate required.
Is an onchain register the stock ledger under Delaware law?
Yes. DGCL § 224 expressly permits corporate records, including the stock ledger, to be kept on one or more distributed electronic networks or databases. Under § 224 the onchain event log is not evidence about the stock ledger — it is the stock ledger.
Does operating OCP make you a clearing agency?
No. Exchange Act § 3(a)(23)(B) excludes any person acting solely by reason of the § 3(a)(25)(E) book-entry function. Nothing in the protocol aggregates, nets, or interposes a central counterparty.
How do regulators inspect the register?
Through Observer parties: read-only visibility into a contract and all subsequent updates, with no ability to exercise any choice against it. The grant can be scoped to the whole register, one issuer’s cap table, or a defined subset. That is better access than produce-on-demand recordkeeping, and the authority verifies the records itself rather than receiving the agent’s account of them.
How are errors corrected?
By compensating event, never by silent overwrite. The erroneous transaction stays on the register and a subsequent typed OCF transaction records the correction with a reference to what it corrects, a reason code, and the authorizing documentation in the operator’s own books. The audit trail is enriched rather than edited.
What is still unsettled?
Regulation Crypto Assets, proposed 18 August 2026, does not address custody, trading-platform registration, transfer-agent rules, or whether an onchain record may serve as an issuer’s official register. OCP does not depend on that framework. Whether Canton archival or pruning constitutes erasure under GDPR Article 17 is also unsettled, and the specification does not assert that it does.

Operating and adopting

Operating and adopting

Must the operator be a third party?
No. An issuer acting as its own transfer agent holds the system-operator role for its own register, which the Exchange Act contemplates directly. What the protocol requires is that the role be held by an entity with legal accountability for the records it maintains.
Why not remove the operator entirely?
Because a register is a legal record, and someone must be answerable when it is wrong — to the issuer, the holder, the examiner and the court. Accountability of that kind cannot be assigned to a protocol, which cannot be examined, sanctioned, compelled to produce records, or made to compensate anyone. It attaches to a legal person or it does not exist.
Is an issuer locked in?
No. The register extracts as an OCF manifest and rebuilds on any conformant runtime or under any other operator. Succession is specified in four steps — extraction, verification by recomputation, re-establishment of grants, and continuity of the log across the seam. Adopting OCP is reversible, and the mechanism is specified rather than promised.
What happens if the operator’s key is compromised?
Unauthorized submission becomes possible; silent alteration does not. Every write is a new event signed by both the issuer and the operator, and visible to the issuer. Remediation follows the correction model, and the compromise itself is evidenced by the record.
What happens if the network is discontinued?
This is the case the chain-agnostic design exists for. The register is extracted as an OCF manifest and reconstituted on another conformant runtime by the succession procedure, with the substitution being of runtime rather than of operator.
Who can be an operator outside the US?
Registrars, central securities depositories, custodians and other entities holding the equivalent statutory or contractual function, under their own regimes. The protocol does not require US incorporation.

Governance and status

Governance and status

Who owns OCP?
The specification, the reference implementation and the SDK are open source and published. The authors intend to bring the specification to the Open Cap Table Coalition as a contribution and to seek its stewardship of the onchain extension. A protocol that could only be operated by its author would fail the test it sets itself.
What is Fairmint’s role?
Fairmint employs both authors, is an SEC-registered transfer agent, and operates OCP in production for the issuers it administers. That deployment is evidence the protocol runs. It is not a definition of the protocol, and nothing in the specification requires an implementer to run Fairmint’s stack.
What is specified but not yet live?
Positions of record — the published, reservation-aware position view committed atomically with the write — are specified in chapter 3.4 and are part of the open work. The balance-integrity guarantees of chapter 8 are live.
How is the specification versioned?
As an artifact separate from any implementation of it. Version 1.0 was published August 2026 and supersedes 0.1 through 0.9, which were pre-release drafts and should not be implemented against.
Under what licence?
The specification, the reference implementation and the SDK are open source and published.
How do I raise a correction or an objection?
spec@opencaptableprotocol.org. Substantive changes are recorded in the revision history of subsequent versions.

Not answered here

Ask

Corrections, objections, proposed changes and implementation reports are welcome at spec@opencaptableprotocol.org. Substantive changes will be recorded in the revision history of subsequent versions.