PlatformVM Architecture

How the P-Chain manages validators, staking, and Avalanche L1 creation inside AvalancheGo.

PlatformVM (P-Chain) runs on Snowman++ and controls validators, staking rewards, Subnet/L1 membership, and chain creation. Source lives in vms/platformvm and its block/tx types in vms/platformvm/platform, where codec.go registers every type in the order that determines its wire TypeID.

At a glance:

  • Snowman++ engine drives PlatformVM block production; mempool feeds Standard/Proposal/Atomic blocks.
  • Validator registry, Subnet/L1 membership, warp signing, and atomic UTXOs are persisted in the node database.
  • P-Chain APIs expose validator state, Subnet/chain creation, staking ops, and block fetch.

Helicon activates on Mainnet on September 22, 2026.

Helicon does not deprecate or disable any existing transaction type. Current validators and delegators continue to work unchanged. It adds auto-renewed staking as an option and lowers the minimum Primary Network staking duration from two weeks to 48 hours. See Helicon Upgrade.

Responsibilities

  • Validator registry & staking: Tracks Primary Network validators and delegators, uptime, staking rewards, and validator fees. Starting with Helicon a validation can be auto-renewed per cycle rather than expiring at a fixed end time, see Helicon Upgrade.
  • Subnet/L1 orchestration: Creates Subnets and chains (CreateSubnetTx, CreateChainTx), converts Subnets into L1s (ConvertSubnetToL1Tx), and maintains Subnet and L1 validator sets (including permissionless add/remove and warp-authorized L1 validator changes).
  • Warp messaging: Signs warp messages for cross-chain communication on Avalanche L1s.
  • Atomic transfers: Handles import/export of AVAX to/from other chains via shared memory.

Consensus & Blocks

  • Uses Snowman++ via the ProposerVM (stake-sampled single-proposer slots; no post-Durango open-building fallback).
  • Blocks are built by vms/platformvm/block/builder; block types include Standard, Proposal (with Commit/Abort options), and Atomic blocks.
  • State sync is supported for faster bootstrap; bootstrapping peers can be overridden via CustomBeacons in the P-Chain ChainParameters.

Key Transaction Types

TransactionPurpose
AddValidatorTx, AddDelegatorTxDisabled since Durango (ACP-62). Issuing one is rejected outright, with ErrAddValidatorTxPostDurango / ErrAddDelegatorTxPostDurango. Use AddPermissionlessValidatorTx / AddPermissionlessDelegatorTx instead. The type IDs (0x0c, 0x0e) stay registered so nodes can replay pre-Durango history
AddSubnetValidatorTxAdd a validator to a Subnet (validator must also be on Primary). Permanently disabled on a Subnet once it has been converted with ConvertSubnetToL1Tx
AddPermissionlessValidatorTx / AddPermissionlessDelegatorTxValidate or delegate on the Primary Network or on a permissionless Subnet; this is the current path for both
RemoveSubnetValidatorTxRemove a validator from a permissioned Subnet
CreateSubnetTxCreate a new Subnet and owner controls
CreateChainTxLaunch a new blockchain (VM + genesis) on a Subnet
TransferSubnetOwnershipTxHand a Subnet's owner controls to a new owner (ACP-31)
ConvertSubnetToL1TxConvert a Subnet into an L1 with its initial validator set (ACP-77)
RegisterL1ValidatorTxAdd a validator to an L1, authorized by a warp message from the L1's validator manager
SetL1ValidatorWeightTxChange an L1 validator's weight (a weight of 0 removes the validator)
IncreaseL1ValidatorBalanceTxTop up an L1 validator's continuous-fee balance
DisableL1ValidatorTxDeactivate an L1 validator and reclaim its remaining balance
AddAutoRenewedValidatorTxJoin the Primary Network with a cycle duration (period) and auto-compound share instead of a fixed end time (ACP-236, Helicon)
SetAutoRenewedValidatorConfigTxChange an auto-renewed validator's cycle duration or auto-compound share. A period of 0 is how the validator exits after the current cycle (Helicon)
RewardAutoRenewedValidatorTxSettle rewards at a cycle boundary and start the next cycle. Issued by block builders, not by the operator (Helicon)
ImportTx / ExportTxMove AVAX to/from other chains via atomic UTXOs
RewardValidatorTxMint rewards after successful staking periods
TransformSubnetTxDisabled since Etna. Legacy Subnet transform, rejected with "TransformSubnetTx is not permitted post-Etna". Its type ID (0x18) stays registered for the same reason

P-Chain APIs

  • Exposed at /ext/bc/P with namespaces such as platform.getBlock, platform.getCurrentValidators, platform.issueTx, platform.getSubnets, platform.getBlockchains. The full set is in the P-Chain API reference.
  • Helicon adds no new methods, but platform.getCurrentValidators gains three fields on auto-renewed validators: validatorAuthority, nextPeriod and autoCompoundRewardShares. They are absent on every other validator, so their presence identifies an auto-renewed validation.
  • Health and metrics are surfaced via the node-level /ext/health and /ext/metrics.

Configuration

Default chain config location:

~/.avalanchego/configs/chains/P/config.json
{
  "state-sync-enabled": true,
  "pruning-enabled": true
}
  • Subnet and chain aliases can be set in ~/.avalanchego/configs/chains/aliases.json.
  • Upgrade rules and Subnet parameters are read from the chain config and network upgrade settings (upgrade/).
  • Minimum staking durations can be overridden with --min-stake-duration (delegators, and validators before Helicon) and --helicon-min-stake-duration (validators from Helicon onwards). Both are read only on custom networks: on Mainnet and Fuji the node ignores them and uses the genesis values. Development networks commonly shorten them so validator lifecycle tests do not have to wait hours.

Developer Tips

  • When testing new Subnets/VMs, pass CreateChainTx genesis bytes and VM IDs via platform.issueTx.
  • For permissionless Subnets, ensure the Subnet's config enables the relevant validator/delegator transactions before issuing them.
  • Use platform.getBlock to inspect Proposal/Commit/Abort flow if debugging staking or Subnet/L1 updates.

Is this guide helpful?