Approve once.
Stay in control.
The payment-authorization layer for AI subscriptions, paid research, trading signals, automation bots, and metered APIs. Every future charge stays inside a visible budget and evidence boundary.
Pre-production boundary: this public site never moves funds. Browser policy receipts remain simulated, while the linked AlphaBrief delivery, v2 settlement, and bad-output freeze are real Solana Devnet evidence using a project-created test mint—not canonical USDC or Mainnet.
Run the judge path without blurring truth levels.
The browser runs the same ordered review as Android: deterministic policy outcomes, live AlphaBrief signatures, then independent Program and balance verification. The final wallet-approved 0.00001 SOL commercial settlement is available only in the Android app and always pauses for one explicit Solflare approval.
Deterministic local policy replay
Settlement + bad-output freeze signatures
Onchain failures and token deltas
0.00001 SOL + accepted report evidence hash
A delivered report—not another template.
A subscriber purchased a substantive 508-word risk brief. An independent verifier checked merchant binding, delivery identity, time, freshness, substance, required sections, sources, and source URLs. Only then did Delegated Settlement v2 move 2.0 project test tokens without the user signing the charge. A later bad output failed three checks, created immutable freeze evidence, and moved zero tokens.
Dedicated v2 allowance created for AlphaBrief
508 words · 3 sources · 8/8 checks passed · evidence d6cb…345c
Executor + verifier; subscriber authority absent from charge
Substance, sections, and sources failed; zero token movement
Preview a one-tap local pause. This browser action never changes onchain state.
Service received
Content and source quality are bound before payment.
2.00 spent · 0 blocked
1 verified delivery · 1 frozen anomaly · 25% budget used.
Android local notifications
Upcoming charge, budget pressure, merchant anomaly, settlement, freeze, and pause events.
Asset boundary: the 6-decimal mint is project-created on Devnet. “TEST” deliberately replaces “USDC” in this live proof.
Approve once. Settle later without the user online.
The deployed v2 Program closes the central recurring-payment gap while keeping the public v1 evidence readable. The user's token account delegates a hard lifetime limit to an allowance-scoped PDA; a later charge needs both the configured executor and an independent verifier, but not the user's signature. Every accepted charge or freeze creates an immutable evidence PDA keyed by the full evidence hash.
The transferred asset is a project-created Devnet test mint, not canonical USDC. The Program is upgradeable and unaudited; no Mainnet or production claim is made.
Five businesses. One allowance protocol.
Choose a service to load its merchant, charge limit, period budget, and evidence requirements into the verifier below.
AgentCloud
Monthly operating allowance for an autonomous AI research agent.AlphaBrief
Pay for a delivered research report only after its content hash is bound.SignalWire
Capped trading signals with a publisher identity lock.AutoPilot
Bounded bot fees separated from trading principal and authority.DataPipe
Meter paid API usage without exposing an unlimited approval.Designed around real mobile categories.
Blueprints show the adapter and evidence contract each integration would require.
Honest boundary: these are unofficial integration blueprints based on apps featured by Solana Mobile. They are not partnerships and are not presented as live third-party integrations.
Helium Mobile BLUEPRINT · UNOFFICIAL
Recurring mobile plan and add-on data allowance.
Parallel Colony BLUEPRINT · UNOFFICIAL
Game season pass, AI actions, and bounded item budgets.
Amp Pay BLUEPRINT · UNOFFICIAL
Merchant subscriptions and repeat mobile purchases.
Moonwalk / Perena BLUEPRINT · UNOFFICIAL
Membership, challenge entry, stable-asset workflow fees.
Normal charge
Merchant, token, program, evidence, and limits all match.
Over the cap
The request exceeds the selected service's per-charge allowance.
Merchant changed
The destination no longer matches the authorized merchant.
This replay is SIMULATED. A real Android MWA wallet and Devnet Memo proof are now recorded separately; the browser replay never disguises simulated receipts as settlement.
Buy an AlphaBrief report, then attack the payment flow.
The browser hashes delivered content, creates a five-minute charge request, verifies the policy, signs a merchant webhook, and unlocks the report. Retrying the identical request is idempotent; reusing its evidence under a new request is BLOCKED.
LOCKED
NOT CREATED
READY
One policy, two honest device modes.
Verified coverage: 26 TypeScript tests + 20 Android tests + 20 Rust tests. The Android Daily Habits dashboard adds upcoming charges, today/week spend, budget and merchant alerts, local pause, delivery/payment timeline, notifications, and a weekly safety report. Browser and Android local calculations remain explicitly labelled; no simulated hash is presented as a chain transaction.
Built to survive restarts, retries, and evidence review.
Restart-safe reference store
Policies, idempotency fingerprints, nonces, evidence hashes, spend, and revocation state can be persisted atomically.
Replay-aware verification
Signed callbacks enforce timestamp tolerance, replay rejection, and overlapping secrets during key rotation.
Portable audit evidence
The app decodes strict v2 state, builds governed control instructions, and exports JSON audit history with a SHA-256 fingerprint.
Deployment boundary: Delegated Settlement v2 is live and fully matrix-verified on Devnet. Android exposes the public proof but does not yet broadcast every v2 authority control from the mobile UI. Production still requires canonical assets, audit, multisig/timelock governance, protected signing, and Mainnet review.
Verify the wallet proof without trusting us.
This is the previously recorded Phantom/MWA Memo transaction. The button queries Solana Devnet RPC directly and reports the chain's confirmation status, slot, and execution result.
One allowance. Five transitions. One real token transfer.
The deployed Program validates policy and evidence before invoking the SPL Token Program. VERIFIED transfers exactly 1 test token; BLOCKED and FROZEN move zero. The mint is a project-created Devnet test token, not canonical USDC.