Judge door
SandboxSeven stops, about three minutes, no login anywhere. Chain facts on these pages are read from Solana devnet, each with the slot and time it was read, and marked when the value is a cached read.
Sandbox only: test tokens on Solana devnet with no value. No real money moves.
Settled, then refused
Two recorded transactions on Solana devnet, both signed on an iPhone. These are not current reads: open each one on the explorer to check it yourself.
- Settled
A payment signed on an iPhone settled
A teammate's iPhone signed the note with its Secure Enclave key and showed it as a QR code. The merchant iPhone read it with its camera while both phones were offline. When the merchant phone came online, Solana's secp256r1 precompile verified the signature and the loka_vault program credited the merchant.
Signed on an iPhone (Secure Enclave key), paid offline by camera QR, Sat Oct 10 4:23 PM ET
Block time . Transaction 2SpG1YUR...ktskez17. Note id f4cba02c...29570cb9.
Check it on Solana Explorer(opens in a new tab) - Failed: SerialUsed (6011)
The same note, signed again on that iPhone, was refused
The app's Try to cheat control signed the same allowance and serial again, for a different merchant phone. The program refused it on chain with SerialUsed, error 6011, and moved no tokens.
Same allowance and serial signed again on that iPhone, refused by Solana: SerialUsed (6011), Sat Oct 10 4:31 PM ET
Block time . Transaction 3XtQtnHR...SLKjZc9n. Note id 5ecdc8dc...d34ac0da.
Check it on Solana Explorer(opens in a new tab)
Earlier test-key pair, Sat Oct 10 2:01 AM ET
The same check, run before the phones were ready, with a note signed outside the iPhone app with a test key.
- Settled
A test-key note settled
Solana's secp256r1 precompile verified the note's P-256 signature, and the loka_vault program credited the merchant.
Signed outside the iPhone app with a test key, Sat Oct 10 2:01 AM ET.
Block time . Transaction 5tEKu2mt...3PWD5rAa.
Check it on Solana Explorer(opens in a new tab) - Failed: SerialUsed (6011)
The same note, signed again, was refused
The same allowance and serial, signed again for a second merchant. The program refused it on chain with SerialUsed, error 6011, and moved no tokens.
Signed outside the iPhone app with a test key, Sat Oct 10 2:01 AM ET.
Block time . Transaction 2SQ8aiTm...S4Excohv.
Check it on Solana Explorer(opens in a new tab)
Step 1: Check a receipt in your browser
About 30 seconds
Open the verifier and press Try the published test receipt. Your browser checks the payer's P-256 signature, the merchant's acknowledgement and the settlement server's confirmation on the page, with nothing sent anywhere. That receipt is a labelled test vector made from public test keys, not a real payment.
Open /verifyStep 2: The program on devnet
About 40 seconds
The
loka_vaultprogram verifies the phone's signature on chain and holds the sandbox tokens. These facts come from a devnet read; the line under them says when it was read and how old it was when this page loaded.- Program id (devnet)
- HSgcxix3LGjdCQ7FGexBosdvzmHz7ZfHdkpyXYYteBGGProgram on Solana Explorer(opens in a new tab)
- Executable
- Yes, executable
- Upgrade authority
- 4RaquyuY9zseQTP5cTBoh8bmvMRvUyJzaHeMqKcbSksSMatches config/pins.json. One key; a 2-of-3 multisig is planned, not done.
- Last deployed
- Slot 509428340,
- Program size
- 364,384 bytes
- Vault (sandbox USDC)
- 16.25 sandbox USDCPinned devnet USDC mintOwned by the vault accountVault token account on Solana Explorer(opens in a new tab)
- Program accounts, by Anchor discriminator
- Config: 1
- Vault authority: 1
- Allowances: 9
- Merchants: 5
- Vault config
- Initialized for the pinned mintCluster 0 (devnet)
- Initialize transaction
- Succeeded
initialize_vault, slot 509428827, Initialize transaction on Solana Explorer(opens in a new tab)
Read from Solana devnet at slot 509732933, , 0 s before this page loaded.
Step 3: Watch the chain
About 30 seconds
Every transaction that touches the program, newest first, then each new one as it lands. Your browser reads devnet directly, so the feed keeps working even if our server is down.
Open /liveOr have your own phone ring when a payment settles: /call.
Or fund a payer phone with sandbox money, when the server runs it: /send.
Step 4: Proof
About 30 seconds
Each claim marked Live links to its evidence and says when that evidence was read; the verifier is Available to run yourself, and the rest say Not checked or Building. Then the vault's tokens against everything it owes, read at one slot, and what this team committed since hacking started.
Open /proofStep 5: Trust
About 20 seconds
What the program checks before it moves money, what the protocol does not promise, and who holds which key.
Open /trustStep 6: The iPhone app
About 10 seconds
TestFlight build 1 has been in Apple beta review since Sat Oct 10 12:05 AM ET, and the public link appears here once Apple approves. The team runs build 5, with the scanner fix, through internal TestFlight.
Status as of .
Step 7: The code and its checks
About 20 seconds
The repository is public. Each line below is the result GitHub reports for that workflow's job on main's latest commit, read by this site's server, so your browser loads nothing from GitHub. Select one to open it on GitHub.
github.com/StephenSook/loka-pay(opens in a new tab)- Passedios (package tests, app build, release checks)(opens in a new tab)
- Passedandroid (core tests, debug build, lint)(opens in a new tab)
- Passedprogram (secp256r1 feature check, anchor test)(opens in a new tab)
- Passedserver (typecheck, unit, integration, vectors)(opens in a new tab)
- Passedweb (lint, typecheck, build, Playwright)(opens in a new tab)
- Passedhygiene (gitleaks, scrub guard, prose gate, FACTS)(opens in a new tab)
Read from GitHub's API at main's latest commit fb0d991, : a cached read, 71 s old when this page loaded.