Live on Starknet mainnet

Pay everyone privately. Prove you paid everyone.

Fund one payroll run on Starknet. Recipients claim on Starknet, an EVM chain, or Solana — with no on-chain link between payer and recipient, and no service holding the list.

run · privacy boundary
The payer funds one run into the privacy pool. Recipients claim from it on Starknet, an EVM chain, or Solana, with no link recorded between the two sides.Payerfunds onceTOTALSPRIVACY BOUNDARYSTRK20 pool+ Payroll ledgerno identities crossStarknetEVM chainSolana
49Cairo tests
27Enforced failure modes
3Chains recipients can claim on
0Addresses stored on chain
The boundary

What a block explorer gets. What it never gets.

Both columns describe the same payment. That gap is the product.

Recorded on chain

  • That a run exists, and its id
  • The headcount and budget it promised
  • Running totals as commitments fund and clear
  • That some commitment was claimed
  • The token, and whether the run closed

Never learned

  • Which recipient maps to which commitment
  • What any named person was paid
  • The link between the payer and the run
  • Which claim belongs to which recipient
  • Any address of any party — not in state, not in events
Guarantees

Four things the contract will not let you do.

Each is a Cairo test that turns red the moment the guarantee is removed. That is the difference between a property and a promise.

Sequence

Four calls, start to finish.

  1. Open the runThe payer fixes the headcount and the exact total on chain before funding anything. Neither can be raised later.
  2. Two approvers sign offFunding is refused until two distinct approvers each prove knowledge of their own secret — enforced by the contract, not this interface.
  3. Fund each recipientEvery commitment travels through the privacy pool, so the chain sees totals move and nothing about who is being paid.
  4. Recipients claimEach gets an encrypted Waku notification carrying the secret that authorises their claim. No server ever holds it.
On chain

Deployed, and checkable right now.

Nothing here is a screenshot. Every value resolves on a public explorer.

strk20.json
Network
SN_MAIN
Mainnet txs
3 recorded and re-verified on chain
Notifications
Waku · round trip proven against the live fleet

The deployed class predates the on-chain approval quorum described above; a redeploy is tracked in the repo. Read this as what is live, not as what the source proves.

Limits

What is not live yet.

You cannot submit a run from this site. Payroll.privacy_invoke accepts only the STRK20 pool as its caller, so a run has to travel through the pool inside a proved private transaction — and the mainnet proving service for that is not published yet. The pages here build the exact call and show it, then stop.

The EVM and Solana claim legs are implemented against the real APIs and are not yet exercised end to end. Where a demo and the repo disagree, believe the status table.

Start

Try the parts that work.

Claim a payment

Paste a claim secret. The page looks for its encrypted Waku notification — the same one the payer sends when a commitment is funded. No sign-in needed.

/claim →

Run a payroll

Sign in without a seed phrase, collect the two approvals the contract requires, and inspect the exact call that would be submitted.

/admin →