How it works
What it does
When the shop you want to buy from only accepts cash or a specific payment method, you pay with crypto (currently BTC signet and USDC) and a proxy shopper buys the item for you and ships it.
The money goes into a 2-of-3 multisig per order (user, shopper, escrow).
- When the item arrives, the user and the shopper sign to pay the shopper.
- If there is a dispute, the escrow decides the split together with one of the other two.
- Even if someone stops responding, timelocks make sure the money ends up with one side.
Architecture
Browser (proxy-shopping-web) Go nodes (proxy-shopping-go)
keys and signing in the browser shopper / escrow / operator / relay
│ WSS (outbound only) │ WSS │ libp2p
▼ ▼ ▼
Nostr relays (named by the operators) ◀──▶ network of Go nodes
= always-online entry point + mailbox (gossipsub; NAT traversal via circuit relay v2 and DCUtR)
- Users run nothing. Opening the public web app is enough to join. Keys are created in the browser and never leave it; every authorization (signature) happens in the browser.
- Users behind NAT can connect too, because the connection to a Nostr relay is outbound.
- Messages for people who are not always online (users, escrows, operators, coordinators) wait, still encrypted, on Nostr relays acting as mailboxes. Each message goes to several relays.
- Only the shopper needs to be always online. It runs a Go node and a browser automation tool (shopper-bot) that operates the shops.
How trust flows
coordinator (the user trusts its public key)
└─ delegation: "this operator may publish lists"
└─ list: "in this region, this shopper and this escrow can be trusted together"
- The user trusts only the coordinator’s public key. Trust extends from there to operators and to shopper × escrow combinations.
- Lists are versioned and never expire. Removing someone means publishing a new version.
- A user “dismisses” a coordinator by removing it from their settings.
Fees
| To whom | Enforceable? | How |
|---|---|---|
| shopper | yes | included in the quote |
| escrow (upfront) | yes | paid directly to the escrow together with the funding. An escrow has no duty to arbitrate orders without the upfront fee |
| escrow (dispute) | yes | taken from the split of the ruling |
| operator / coordinator | no | agreed outside the protocol, e.g. listing fees. What a list sells is “being found” |
The escrow’s bond and its confiscation are not part of the protocol. They are treated as terms the operator and the escrow agree on themselves; a reference contract is provided.
Cash-only shops
A shop’s location is a region code (e.g. JP-13-13104 = Shinjuku, Tokyo).
A shopper declares the regions where it can go and pay cash, and only takes orders for shops there.
Shop risk
Before taking an order the shopper scores the shop: is it on the shopper’s allowlist, is it HTTPS, and is its checkout a known payment gateway. Sending card details to an arbitrary site is risky, so orders for low-scoring shops are declined.