Roles
| Role | Always online | Uses | Does | If it cheats |
|---|---|---|---|---|
| user | no | browser | orders, funds, confirms receipt, opens disputes | ― |
| proxy shopper | yes | Go node + shopper-bot | quotes, buys on the user’s behalf, reports shipping; earns a fee | loses its share in the escrow’s ruling; the operator removes it from the list |
| escrow | no | browser or Go node | rules on disputes before T1 | the operator removes it from the list; depending on their terms, its bond is confiscated and used as compensation |
| operator | no | browser, Go node or psctl |
signs, per region, the list of trustworthy shopper × escrow combinations; receives reports | the coordinator revokes its delegation |
| coordinator | no | browser or psctl |
signs delegations to operators | users remove it from their settings (dismissal) |
User
- Open the web app, create a mnemonic (12 words), write it down, and choose a passphrase that encrypts the key.
- Enter the shop URL, the shop’s region and the items.
- Pick one of the offered shopper × escrow combinations and place the order.
- A quote arrives. If its rate differs from your own sources by more than 3% you get a caution; above 10% a strong warning.
- Accept and fund. The money is split between the multisig and the escrow’s upfront fee.
- When the item arrives, press “received” (after a screen showing the amount and recipient, your partial signature goes to the shopper).
- If it doesn’t arrive, open a dispute. The app gathers the evidence for you.
Proxy shopper
- Run the Go node with
role: shopperand connect shopper-bot (the browser automation tool). - Configure the payment methods, currencies, regions where you can pay cash, your fee and your shop risk policy.
- Card details live only inside shopper-bot; they are never given to the node or the network.
- If the user never confirms receipt and T1 passes, you can take the funds alone.
Escrow
- Rules only on disputes of orders that paid its upfront fee.
- It normally cannot read the delivery address. In a dispute, the shopper (or the user) hands it the decryption key.
- A ruling reaches both parties as a signed transaction; it becomes final once one of them countersigns.
Operator
- Signs its regions (one or more), the list of combinations, and the relays and chain endpoints it recommends.
- On a report, publishes a new version of the list without the offender. The bond follows the terms it agreed with the escrow.
Coordinator
- Issues delegations to operators. Revoking means publishing a new version with
revoked.
Getting listed (the registry)
The maintainer’s trust registry is the GitHub repository pad01g/proxy-shopping-registry. A merged pull request is the approval: after every merge, CI signs the new delegations and lists with the registry’s keys and publishes them (to the public Nostr relays and to https://pad01g.github.io/proxy-shopping-registry/events.json).
| You want to be | Add in a pull request | What the merge does |
|---|---|---|
| shopper | shoppers/<name>.json (pk, contact, description, cash regions, payments, the escrows you work with) |
the registry’s operator lists your shopper × escrow combinations |
| escrow | escrows/<name>.json (pk, contact, description, SLA days) |
shoppers can name you; your combinations appear |
| operator | operators/<name>.json (pk, contact, description, regions) |
the registry’s coordinator delegates to you; you then sign your own lists |
| coordinator | coordinators/<name>.json (pk, contact, description) |
you appear in the coordinator directory the apps offer to users (each user still chooses whom to trust) |
pk is your Nostr public key (64 hex chars): the web app shows it in Settings, and psctl keys --mnemonic-file …
prints it. Removing someone is a pull request that moves their file to revoked/ with a reason. The registry’s
README has the exact file formats and the commands.