Control center · Solana Devnet

Approve once.
Stay in control.

The payment-authorization layer for AI subscriptions, paid research, trading signals, automation bots, and metered APIs. Every future charge stays inside a visible budget and evidence boundary.

VERIFIED · MAY SETTLEBLOCKED · NEVER STARTEDFROZEN · ZERO MOVED
PROTECTED ALLOWANCEDEVNET READY
6.00 TESTremaining from an 8.00 weekly cap
Active serviceAlphaBrief
Merchantmerchant:alphabrief
Next charge2 TEST
Period cap8 TEST
Latest decisionBAD OUTPUT CONTAINED

Pre-production boundary: this public site never moves funds. Browser policy receipts remain simulated, while the linked AlphaBrief delivery, v2 settlement, and bad-output freeze are real Solana Devnet evidence using a project-created test mint—not canonical USDC or Mainnet.

One tap · mixed evidence

Run the judge path without blurring truth levels.

NO SILENT SIGNING

The browser runs the same ordered review as Android: deterministic policy outcomes, live AlphaBrief signatures, then independent Program and balance verification. The final wallet-approved 0.00001 SOL commercial settlement is available only in the Android app and always pauses for one explicit Solflare approval.

1
VERIFIED → BLOCKED → FROZEN
Deterministic local policy replay
SIMULATED
2
AlphaBrief public proof
Settlement + bad-output freeze signatures
LIVE RPC
3
Program state + balance matrix
Onchain failures and token deltas
LIVE RPC
4
Commercial micro-settlement
0.00001 SOL + accepted report evidence hash
ANDROID WALLET
Ready. This run performs no browser write operation.
AlphaBrief · real service commerce

A delivered report—not another template.

LIVE DEVNET VERIFIED

A subscriber purchased a substantive 508-word risk brief. An independent verifier checked merchant binding, delivery identity, time, freshness, substance, required sections, sources, and source URLs. Only then did Delegated Settlement v2 move 2.0 project test tokens without the user signing the charge. A later bad output failed three checks, created immutable freeze evidence, and moved zero tokens.

Today · verified spend2.00 TESTOne delivered AlphaBrief
This week2.00 / 8.00
25% of policy cap
Upcoming charge2.00 TESTProjected; evidence required
Safety stateFROZENBad output contained
1
Purchase service
Dedicated v2 allowance created for AlphaBrief
PUBLIC TX
2
Deliver + independently verify
508 words · 3 sources · 8/8 checks passed · evidence d6cb…345c
READ REPORT
3
v2 automatic settlement
Executor + verifier; subscriber authority absent from charge
+2.0 TEST
4
Bad output → FROZEN
Substance, sections, and sources failed; zero token movement
ZERO MOVEMENT
Daily Habits safety action
Preview a one-tap local pause. This browser action never changes onchain state.
DELIVERY

Service received

Content and source quality are bound before payment.

WEEKLY REPORT

2.00 spent · 0 blocked

1 verified delivery · 1 frozen anomaly · 25% budget used.

ALERTS

Android local notifications

Upcoming charge, budget pressure, merchant anomaly, settlement, freeze, and pause events.

Asset boundary: the 6-decimal mint is project-created on Devnet. “TEST” deliberately replaces “USDC” in this live proof.

Machine-readable evidenceAllowance accountAccepted evidence PDA
Delegated Settlement v2 · Solana Devnet

Approve once. Settle later without the user online.

FULL MATRIX VERIFIED

The deployed v2 Program closes the central recurring-payment gap while keeping the public v1 evidence readable. The user's token account delegates a hard lifetime limit to an allowance-scoped PDA; a later charge needs both the configured executor and an independent verifier, but not the user's signature. Every accepted charge or freeze creates an immutable evidence PDA keyed by the full evidence hash.

Step
Required signer
Onchain boundary
Create allowance once
User authority
SPL delegate PDA + lifetime cap
Settle delivered service
Executor + verifier
Nonce + evidence PDA + 3 budget caps
Freeze bad output
Verifier
Immutable bad-result evidence record
Rotate operators
User; user + current verifier
Role separation remains enforced
Restore after dispute
User + verifier
Dual-signature unfreeze
Revoke permanently
User authority
SPL delegate removed

The transferred asset is a project-created Devnet test mint, not canonical USDC. The Program is upgradeable and unaudited; no Mainnet or production claim is made.

Inspect machine-readable evidenceRead exact v2 specificationInspect Program source
Commercial proof, not a toy demo

Five businesses. One allowance protocol.

Choose a service to load its merchant, charge limit, period budget, and evidence requirements into the verifier below.

AI

AgentCloud

Monthly operating allowance for an autonomous AI research agent.
0.50 / 12 TEST
Run receipt + output hash
R

AlphaBrief

Pay for a delivered research report only after its content hash is bound.
2 / 8 TEST
Report URI + content hash
S

SignalWire

Capped trading signals with a publisher identity lock.
0.25 / 5 TEST
Signal hash + publisher signature
AP

AutoPilot

Bounded bot fees separated from trading principal and authority.
1 / 20 TEST
Order receipt + verifier hash
API

DataPipe

Meter paid API usage without exposing an unlimited approval.
0.05 / 10 TEST
Usage root + metering receipt
Seeker integration lab

Designed around real mobile categories.

Blueprints show the adapter and evidence contract each integration would require.

Honest boundary: these are unofficial integration blueprints based on apps featured by Solana Mobile. They are not partnerships and are not presented as live third-party integrations.

Helium Mobile BLUEPRINT · UNOFFICIAL

Recurring mobile plan and add-on data allowance.

Monthly cap → merchant binding → signed service-period receipt → settlement

Parallel Colony BLUEPRINT · UNOFFICIAL

Game season pass, AI actions, and bounded item budgets.

Season expiry → category caps → item delivery evidence → explicit high-value confirmation

Amp Pay BLUEPRINT · UNOFFICIAL

Merchant subscriptions and repeat mobile purchases.

Merchant-scoped allowance → checkout pre-flight → receipt hash → revocable repeat payment

Moonwalk / Perena BLUEPRINT · UNOFFICIAL

Membership, challenge entry, stable-asset workflow fees.

Expiry or program allowlist → fee-only cap → fulfillment or transaction evidence
01 · verified

Normal charge

Merchant, token, program, evidence, and limits all match.

02 · blocked

Over the cap

The request exceeds the selected service's per-charge allowance.

03 · frozen

Merchant changed

The destination no longer matches the authorized merchant.

Browser Evidence Verification
This replay is SIMULATED. A real Android MWA wallet and Devnet Memo proof are now recorded separately; the browser replay never disguises simulated receipts as settlement.
Choose a scenario above to produce a receipt.
Browser reference integration · simulated receipt v2

Buy an AlphaBrief report, then attack the payment flow.

The browser hashes delivered content, creates a five-minute charge request, verifies the policy, signs a merchant webhook, and unlocks the report. Retrying the identical request is idempotent; reusing its evidence under a new request is BLOCKED.

Content

LOCKED

Request

NOT CREATED

Replay guard

READY

The report preview remains locked until the receipt and webhook both verify.
No request yet.
Native mobile readiness

One policy, two honest device modes.

Capability
Android + MWA wallet
Seeker
Mobile Wallet Adapter
AVAILABLE
AVAILABLE
Devnet signing
AVAILABLE
AVAILABLE
Seed Vault
SEEKER ONLY
AVAILABLE
Genesis Token
NOT AVAILABLE
AVAILABLE

Verified coverage: 26 TypeScript tests + 20 Android tests + 20 Rust tests. The Android Daily Habits dashboard adds upcoming charges, today/week spend, budget and merchant alerts, local pause, delivery/payment timeline, notifications, and a weekly safety report. Browser and Android local calculations remain explicitly labelled; no simulated hash is presented as a chain transaction.

v0.16 live commercial settlement + mobile controls

Built to survive restarts, retries, and evidence review.

MERCHANT

Restart-safe reference store

Policies, idempotency fingerprints, nonces, evidence hashes, spend, and revocation state can be persisted atomically.

WEBHOOKS

Replay-aware verification

Signed callbacks enforce timestamp tolerance, replay rejection, and overlapping secrets during key rotation.

ANDROID

Portable audit evidence

The app decodes strict v2 state, builds governed control instructions, and exports JSON audit history with a SHA-256 fingerprint.

Deployment boundary: Delegated Settlement v2 is live and fully matrix-verified on Devnet. Android exposes the public proof but does not yet broadcast every v2 authority control from the mobile UI. Production still requires canonical assets, audit, multisig/timelock governance, protected signing, and Mainnet review.

Live evidence · Solana Devnet

Verify the wallet proof without trusting us.

This is the previously recorded Phantom/MWA Memo transaction. The button queries Solana Devnet RPC directly and reports the chain's confirmation status, slot, and execution result.

Not checked yet. This verification makes no write operation.
Program-enforced SPL settlement · Solana Devnet

One allowance. Five transitions. One real token transfer.

The deployed Program validates policy and evidence before invoking the SPL Token Program. VERIFIED transfers exactly 1 test token; BLOCKED and FROZEN move zero. The mint is a project-created Devnet test token, not canonical USDC.

Allowance accountBRqgbZzd…Q7E5x
Devnet test mint3KVq4nkU…Thn5de
Not checked yet. This reads five signatures, three transaction balance records, and the final allowance account.
HomeServicesReviewEvidence