EST · MMXXVI
Home/Jurisdictions/Uae Vara/Token sale agreement drafting in United Arab Emirates (VARA, Dubai)
Token Offerings & Securities

Token sale agreement drafting in United Arab Emirates (VARA, Dubai)

Token sale agreement drafting in United Arab Emirates (VARA, Dubai). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring

A token issuer preparing to launch in Dubai quickly discovers that token sale agreement drafting under the VARA (Virtual Assets Regulatory Authority) regime is not a template exercise. The agreement must encode the token's legal classification, the applicable VARA activity licence held by the issuer or the platform facilitating the sale, the rights conferred on purchasers, and a disclosure architecture that mirrors the rulebook VARA enforces. Get that architecture wrong and a product launch can convert silently into an unregistered securities offering – the precise risk that the VARA regime was designed to surface and sanction.

Under the VARA regulatory regime, token sales in mainland Dubai require the issuer to hold or coordinate with a holder of the relevant VARA activity licence, to classify the token against VARA's defined virtual asset categories, and to reflect that classification faithfully in every sale document. Mis-classification – calling an asset-referenced or investment-style token a "utility token" because the marketing deck prefers that label – does not reduce regulatory exposure; it increases it. The legal substance of the rights conferred by the token governs, not the name attached to it. This page sets out the drafting discipline, the regulatory basis, the cross-border interactions that complicate every UAE-facing token sale, and the decision points that founders and general counsel need to resolve before a single agreement is signed.

What the VARA regime requires for token sales

VARA's activity-based licensing model means that any person conducting a virtual-asset activity in or from mainland Dubai must hold the licence that corresponds to that activity – and a token sale, depending on structure, can engage multiple VARA licence categories simultaneously. The offer and issuance of virtual assets is itself a regulated activity under the VARA rulebooks. An issuer offering tokens directly to purchasers in Dubai is not merely drafting a commercial contract; it is engaging in a regulated activity that VARA supervises for conduct, disclosure and consumer-protection purposes.

The rulebook framework VARA maintains requires, in substance, that token sale documentation reflect: the category of virtual asset being offered; the rights and obligations attached to the token; the issuer's identity, financial position and project details; risk disclosures calibrated to the asset category; and the mechanics of the sale, including pricing, allocation, lock-ups and any secondary-market arrangements. VARA's whitepaper and disclosure expectations are not identical to the MiCA (Markets in Crypto-Assets Regulation) whitepaper regime in the European Union – the two regimes share philosophical DNA but diverge on content requirements, approval processes and liability allocation. An issuer with EU participants in the cap table or on the purchaser list will need to reconcile both.

In our practice, the issuers who encounter the most friction are those who arrive with documentation drafted for a different jurisdiction – typically a BVI or Cayman structure built around a prior regime – and ask VARA-facing counsel to "localise" it. Localisation in that context is a misnomer. The VARA regime imposes substantive obligations on the agreement architecture itself, not merely on its governing law clause.

How does VARA classify tokens, and why does it matter for the agreement?

Token classification under VARA determines which rulebook applies, what disclosures the agreement must carry, and whether additional regulatory approvals are needed before the sale can proceed. VARA recognises multiple virtual asset categories; the ones most relevant to a token sale are payment tokens, utility tokens, asset-referenced tokens (functionally equivalent to the ART category under MiCA) and investment tokens (which attract the heaviest regulatory treatment, analogous to securities).

The classification analysis is substance-driven. VARA – like ESMA under MiCA, like the MAS under Singapore's Payment Services Act, and like the FCA in the United Kingdom – looks at what the token actually does, what rights it actually confers, and how it will actually behave in secondary markets. A token that pays holders a share of platform revenues is not a utility token regardless of what the whitepaper calls it. A token that is redeemable for a basket of fiat currencies is not a simple payment token. These distinctions matter because they determine the form of the sale agreement, the scope of representations and warranties the issuer must give, the liability provisions that must be included, and the remedies available to purchasers.

We assess classification against the substance of rights, not the marketing label. That assessment precedes the drafting instruction. An agreement drafted without a concluded classification opinion carries legal risk that accumulates silently until a regulator or a dissatisfied purchaser surfaces it.

The cross-border dimension compounds the analysis. A Dubai-based issuer selling tokens to purchasers in the EU, the UK, Singapore or the United States does not operate in a VARA-only world. Each of those jurisdictions may impose its own classification test, its own disclosure obligations and its own restrictions on who may participate in the sale. The agreement must be structured to address these overlapping regimes – not by picking the most permissive, but by identifying the most demanding obligation in each relevant layer and building up from there.

What does a VARA-compliant token sale agreement contain?

A properly structured token sale agreement under the VARA regime contains several non-negotiable components, each driven by the regulatory architecture rather than by commercial convention alone.

Classification recitals. The agreement should set out the issuer's concluded classification of the token, the basis for that classification under the VARA framework, and the consequence for the agreement's structure if the classification were revisited by VARA. This is not boilerplate. It is the contractual record of the issuer's regulatory position and it provides a baseline for any future regulatory dialogue.

Offer mechanics and eligibility. The agreement must define who may participate in the sale. VARA's rulebooks impose restrictions on offering virtual assets to retail participants without additional conduct protections; for sales that include institutional or sophisticated purchasers, the eligibility criteria and the basis for relying on any applicable carve-out must be drafted with precision. Purchaser representations – that the purchaser is acting for its own account, that it meets any applicable sophistication criteria, that it is not a restricted person under VARA or applicable sanctions regimes – are substantive, not ceremonial.

Rights and obligations of the token. The agreement must describe, without ambiguity, what the token does and does not entitle its holder to. For utility tokens, this means a clear description of the product or service access right. For investment or asset-referenced tokens, the full economic entitlement must be described and the mechanism for enforcing it must be legally viable. Vague language here does not reduce liability – it increases it, because ambiguity tends to be resolved against the drafter.

Whitepaper incorporation and liability. The VARA rulebooks require that token sale documentation align with the issuer's whitepaper. The agreement should incorporate the whitepaper by reference with a specific version and date, and the liability provisions should address the relationship between the agreement and the whitepaper carefully. Where the whitepaper is also required to comply with MiCA (because EU purchasers are included), the drafting tension between VARA and MiCA whitepaper liability standards must be resolved explicitly.

Cancellation, lock-up and secondary market. VARA has expectations around lock-up periods for certain token categories and around the conditions under which an issuer may cancel or postpone a sale. These must be reflected in the agreement's mechanics. Any secondary-market facilitation by the issuer or an affiliated platform engages additional VARA activity-licence requirements and must be addressed in the agreement rather than deferred to a separate document.

Governing law, dispute resolution and enforcement. Most VARA-facing token sale agreements choose UAE law as governing law, with dispute resolution in the DIFC Courts or via DIAC arbitration. This choice has practical consequences. The DIFC Courts are a common-law jurisdiction sitting within a civil-law state; they have demonstrated willingness to grant freezing relief and disclosure orders in digital-asset disputes. Choosing a governing law and forum that has no track record with virtual asset disputes introduces enforcement risk that the agreement cannot eliminate after the fact.

CTA Bridge: The components above describe the standard drafting architecture. Your facts – the token's economic design, the jurisdiction of your purchasers, the VARA licence position, the banking structure – will change the analysis at multiple points.

To map the agreement structure for your token sale, contact OBOLUS at info@oboluslaw.com. We scope the classification analysis and the drafting instruction in a single engagement.

How do cross-border obligations interact with a VARA token sale agreement?

Every token sale with an international purchaser base requires the issuer to manage a stack of overlapping legal obligations, and the VARA agreement sits at the centre of that stack rather than at the top of it.

EU purchasers and MiCA. Where EU or EEA-resident purchasers participate in the sale, MiCA's requirements are engaged. MiCA imposes a whitepaper obligation for offers to the public of crypto-assets that do not qualify as financial instruments, and a separate, more demanding regime for ARTs and EMTs (e-money tokens). The MiCA whitepaper must be notified to the relevant NCA (national competent authority) in the member state of the issuer's EU entity, if one exists, or must be structured around an exemption. The VARA agreement and the MiCA whitepaper must be consistent; a rights description in the sale agreement that contradicts the whitepaper creates a liability exposure in both regimes simultaneously.

UK purchasers and FCA financial promotion rules. Communicating a financial promotion to UK persons without FCA authorisation or an applicable exemption is a criminal offence under UK law. The FCA has issued specific guidance on crypto-asset financial promotions. The VARA token sale agreement must be accompanied by a financial promotion compliance protocol if UK purchasers are in scope, and the agreement's eligibility representations must address UK residency explicitly.

US persons. US securities laws impose extra-territorial reach that no choice-of-law clause in a VARA agreement can extinguish. Where a token is or may be a security under the Howey test as applied by the SEC, the sale to US persons without registration or an applicable exemption (Regulation S, Regulation D) creates federal securities law exposure. The VARA agreement must include a US-person restriction that is legally effective, not merely aspirational.

Tax. The UAE imposes corporate tax on business profits above a defined threshold, and the tax treatment of token-sale proceeds – whether they constitute revenue, deferred revenue or equity proceeds – depends on the structure of the issuer entity and the rights attached to the token. The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer, derived from FATF Recommendation 15) applies to transfers connected to the sale. The agreement and the supporting KYC/AML process must be designed to capture the data the Travel Rule requires before the transfer, not after it.

Banking. UAE and international banks serving token issuers will conduct their own review of the token sale structure before providing payment services. A well-drafted sale agreement that documents the regulatory basis clearly – the VARA licence position, the classification rationale, the purchaser eligibility process – reduces the friction of that banking review materially. In our experience advising issuers, the absence of clear classification documentation in the sale agreement is the single most common cause of delayed or refused banking access.

What are the most common drafting mistakes in UAE token sale agreements?

The most consequential drafting errors in VARA-facing token sale agreements are structural, not typographical. They fall into three recurring patterns.

Classification deferred to the whitepaper. An agreement that says "the token is as described in the whitepaper" without restating the classification and its regulatory basis in the agreement itself creates a gap. If the whitepaper is amended after the agreement is signed – as it often is – the agreement's characterisation of the token becomes disconnected from the current regulatory position. The agreement should contain its own classification recitals that survive whitepaper amendment.

Eligibility provisions that are aspirational rather than operative. A representation by the purchaser that it is not a US person, is not subject to sanctions, and meets any applicable sophistication criteria must be backed by a verification process. An eligibility clause that relies solely on the purchaser's self-certification, without a documented KYC/AML process calibrated to VARA and FATF expectations, does not provide the legal protection the issuer believes it does.

Governing law chosen for convenience rather than enforceability. Some issuers choose offshore governing law – BVI, Cayman – because that is where the issuer entity sits. For a token sale that is regulated in Dubai, a governing law that has no connection to the regulatory regime creates an enforceability mismatch. UAE courts will apply UAE law and VARA's requirements regardless of what the agreement says. The governing law clause should reflect the regulatory reality, not the issuer's corporate structure preference.

A common assumption in the market is that a utility label on a whitepaper settles the legal classification of a token. It does not. VARA – like every major digital-asset regulator – applies a substance-over-form test. The agreement that uses the utility label while conferring investment-style rights creates a contradiction that a regulator will resolve in the regulator's favour. Correcting a mis-classified agreement after VARA has identified the issue is a more expensive exercise than classifying correctly at the outset.

Practical illustration: restructuring a token sale for cross-border compliance

In a recent engagement, a technology company preparing a token sale from a Dubai mainland entity approached us after an initial draft agreement, prepared by offshore counsel, had been flagged by its prospective banking provider as insufficiently documented on the regulatory side. The token conferred revenue-sharing rights linked to platform usage – a combination of utility and investment characteristics. The existing draft described it as a utility token and incorporated the whitepaper by a general reference without a version date. We reclassified the token as a hybrid instrument, restructured the agreement to include explicit classification recitals, rewrote the eligibility provisions to address EU, UK and US purchaser restrictions separately, and introduced a whitepaper incorporation clause that locked the description to a dated version. The revised agreement was accepted by the banking provider within weeks and the issuer proceeded to sale without further regulatory friction.

Which agreement structure fits your token sale profile?

Token sale agreement structures are not uniform. The right structure depends on the token classification, the purchaser base, the issuer's VARA licence position and the cross-border layer.

Profile A – Utility token, UAE-only purchasers, licensed issuer. The agreement can be a relatively streamlined sale-and-issuance instrument, with classification recitals, eligibility provisions focused on VARA requirements, UAE governing law, and DIAC or DIFC Courts dispute resolution. Timeline to first draft: typically a matter of weeks from instruction once the classification analysis is complete.

Profile B – Hybrid or investment token, international purchasers including EU, UK. The agreement requires a multi-layer structure: VARA classification recitals and eligibility provisions at the base; a MiCA-aligned rights description for EU purchasers; FCA financial-promotion compliance protocol for UK persons; US-person restriction drafted to Regulation S standard; Travel Rule data-capture mechanics built into the sale process. Timeline to executable draft: longer, reflecting the additional regulatory layers, but the incremental time spent at the drafting stage eliminates the enforcement exposure that arises later.

Profile C – Stablecoin or asset-referenced token. The VARA rulebook imposes the most demanding requirements on asset-referenced tokens, including reserve and redemption disclosures that must be reflected in the sale agreement, not just the whitepaper. The MiCA ART regime applies separately to EU participants. This profile requires the most extensive drafting engagement and should not be approached as a variant of a standard utility-token agreement.

If a prior application stalled, a banking provider raised concerns, or a prior draft was flagged by VARA, a second read of the documentation can identify the structural cause. Contact OBOLUS at info@oboluslaw.com to scope a review engagement.

Self-assessment: is your token sale agreement VARA-ready?

Before instructing counsel, a founder or general counsel can apply a preliminary checklist to the existing draft or to the proposed structure.

  • Has the token been classified against the VARA virtual asset categories on a substance-over-form analysis, not solely on the basis of the marketing description?
  • Does the agreement contain classification recitals that are independent of the whitepaper and will survive a whitepaper amendment?
  • Are the eligibility provisions backed by a documented KYC/AML process calibrated to FATF Recommendation 15 and the Travel Rule?
  • Does the agreement address EU, UK and US purchaser restrictions separately and operatively?
  • Is the governing law and dispute forum consistent with the regulatory regime under which the token sale is conducted?
  • Does the agreement address lock-up periods, cancellation mechanics and secondary-market facilitation in a manner consistent with the applicable VARA rulebook?
  • Has the banking provider reviewed and accepted the agreement's regulatory documentation?

A "no" or "uncertain" answer to any of these questions identifies a gap that counsel should address before the sale opens.

Related at OBOLUS

FAQ

Is my token a security?

Token classification is a substance-over-form analysis applied by each relevant regulator. Under the VARA regime, the question turns on the rights the token actually confers – economic entitlements, governance rights, and transferability characteristics – rather than on the label used in the whitepaper or marketing materials. A token that pays holders a revenue share or confers ownership-like rights will attract investment-token or security treatment in most major regimes, regardless of how it is described. Classification should be concluded by counsel before any agreement is drafted or any marketing communication is issued.

Do I need a MiCA whitepaper?

A MiCA whitepaper is required if you are offering crypto-assets to the public within the EU or EEA and the assets do not qualify as financial instruments under existing EU financial law. The obligation is triggered by the offer to EU-resident purchasers, not solely by the location of the issuer. A Dubai-based issuer with EU participants in its token sale must address MiCA compliance in parallel with VARA compliance. The two whitepapers have different content requirements, different approval or notification processes, and different liability regimes. They should be prepared on a co-ordinated basis, not sequentially.

How should an airdrop be structured legally?

An airdrop – a distribution of tokens without direct monetary consideration – is not automatically exempt from regulatory requirements. Under both the VARA regime and MiCA, the question is whether the distributed tokens constitute virtual assets subject to applicable offer or marketing rules, and whether the distribution constitutes a public offer. Airdrops to a broad, unrestricted audience carry the highest regulatory risk. A legally sound airdrop structure defines the eligibility criteria for recipients, excludes restricted persons (US persons, sanctioned jurisdictions), documents the classification of the distributed token, and is accompanied by appropriate disclosure. Counsel should review the structure before distribution, not after.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance obligations that surround them. Digital assets are the whole of our practice. We advise on the substance of rights, not the marketing label, and we assess every token sale structure for the cross-border regulatory layer that the VARA documentation alone does not resolve. To discuss your token sale, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Roman Levitt, Technology & DeFi Counsel – specialist in token structuring, smart-contract legal architecture and regulatory classification across the VARA, MiCA and common-law regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours