# Execution and gas costs within a Tempo Zone

A Tempo Zone executes transactions against its private state using Tempo's gas accounting and a fixed set of system contracts. Transactions pay gas in an enabled TIP-20 token; deposits and withdrawals also incur separate processing fees.

For deposit and withdrawal flows, see the [bridging specification](https://tempo.xyz/developers/docs/protocol/zones/bridging). For balance visibility and access control rules, see the [accounts specification](https://tempo.xyz/developers/docs/protocol/zones/accounts).

## Fee Tokens

Tempo Zones reuse Tempo fee units and gas accounting. A transaction can select an enabled, initialized TIP-20 token through `feeToken`. If it omits this field, the zone uses its creation-time default token. The zone fee manager accepts the selected token directly without Fee AMM conversion; it does not require USD currency. Token pause and compliance policies still apply.

## Deposit Fees

Deposits charge a fixed processing fee in the deposited token:

```text
fee = FIXED_DEPOSIT_GAS × zoneGasRate
```

`FIXED_DEPOSIT_GAS` is fixed at 100,000 gas. The portal admin configures `zoneGasRate` through `ZonePortal.setZoneGasRate()`. The fee is deducted from the deposit amount and paid to the admin on Tempo. Deposits must also cover the configured failed-deposit bounce-back fee; use `calculateDepositFee()` and `calculateBouncebackFee()` on the portal to read both amounts.

## Withdrawal Fees

Withdrawals charge a processing fee in the withdrawn token:

```text
fee = (WITHDRAWAL_BASE_GAS + gasLimit) × tempoGasRate
```

`WITHDRAWAL_BASE_GAS` is 50,000 gas. The user specifies `gasLimit` for callback execution, with `0` for a plain withdrawal and a maximum of 10,000,000. The sequencer configures `tempoGasRate` through `ZoneOutbox.setTempoGasRate()`, bounded by the portal admin’s `maxTempoGasRate`. Use `calculateWithdrawalFee(gasLimit)` to read the fee. It is charged in addition to the requested withdrawal amount and is separate from the zone transaction gas fee.

## Fixed Gas Costs

The TIP-20 selectors below have a fixed precompile charge of 100,000 gas, separate from transaction intrinsic gas. Fixed charges prevent gas-based information leaks tied to storage state. On a standard EVM chain, gas varies based on whether a transfer writes to a previously empty storage slot, revealing whether the recipient has received tokens before. During the current permissioned phase, public transfer calls still revert with `Unauthorized()`.

| Function | Gas Cost |
|----------|----------|
| `transfer(to, amount)` | 100,000 |
| `transferFrom(from, to, amount)` | 100,000 |
| `transferWithMemo(to, amount, memo)` | 100,000 |
| `transferFromWithMemo(from, to, amount, memo)` | 100,000 |
| `approve(spender, amount)` | 100,000 |
| `permit(...)` | 100,000 |

Inbox/outbox token movement and fee collection use internal system paths rather than the public transfer selectors.

## Contract Creation Disabled

Contract creation is restricted to protocol-allowlisted deployers. The allowlist is currently empty, so users cannot submit deployment transactions or execute `CREATE` or `CREATE2`. Each Tempo Zone runs a fixed set of system contracts and predeploys.

## Token Management

Issuer TIP-403 policy is anchored by the finalized Tempo checkpoint imported into TempoState. Zone execution reads and applies that checkpoint's policy to token operations.

The portal admin manages which TIP-20 tokens are available on a Tempo Zone:

| Function | Behavior |
|----------|----------|
| `enableToken(token)` | Enables a TIP-20 token for bridging and gas payment. Irreversible. |
| `pauseDeposits(token)` | Stops new deposits for the token. Withdrawal processing remains available unless the portal is paused. |
| `resumeDeposits(token)` | Restarts deposits for a previously paused token. |

In the T13 source, `enableToken` also requires a submitted batch to initialize the processed enabled-token cursor, and at most eight token enablements can remain unprocessed. Earlier runtimes use different admission limits.

Once enabled, a token cannot be disabled. Withdrawal availability still depends on the portal pause state, access controls, and the token’s compliance policy. Tokens on the Tempo Zone use the same address as their Tempo Mainnet counterpart. `ZoneInbox` mints on deposit, `ZoneOutbox` burns on withdrawal. No mechanism exists to create new tokens on the Tempo Zone.
