Payment evidence
Internal intent, ChangeNOW exchange ID, expected input, deposit address, provider status, refunds, and reconciliation state.
DOES NOT DIRECTLY GRANT ACCESSPAYMF
Checking the requested route. No payment or Telegram action runs from this loading screen.
PAYMF PRODUCT DOCUMENTATION
Products, payments, access, privacy, and launch requirements documented in plain language.
01 / SYSTEM MAP
PAYMF separates commercial state, financial evidence, and delivery state so a provider outage cannot silently rewrite who deserves access.
Internal intent, ChangeNOW exchange ID, expected input, deposit address, provider status, refunds, and reconciliation state.
DOES NOT DIRECTLY GRANT ACCESSThe durable right to receive a product. Activated or revoked only by explicit policy transitions.
CANONICAL ACCESS DECISIONTelegram invite, membership, removal, ban, retries, drift, and the external evidence returned by the bot.
DELIVERY STATE, RECONCILEDOne clear creator route.Landing CTAs open creator onboarding. Production Studio keeps the requested route through Privy sign-in, then a private setup check sends first-time owners to one serialized setup or returns established creators to Studio. Email and External Wallets are the only advertised Privy methods because they are the only enabled methods; Google remains unavailable until its provider flow is configured and verified. The current Privy project is still development-only, now allowlists only the canonical https://paymfer.xyz origin, and does not enable Privy transaction MFA, so production login is not claimed. Server verification material is configured, but production promotion, login/logout/wallet checks, and the explicit MFA decision remain launch evidence. If one identity belongs to multiple creator workspaces, PAYMF shows an explicit chooser with public labels, roles, scoped references, and eight-hour encrypted capabilities—not creator IDs. The selected key is tab-scoped, sent only to creator APIs and creator-owned Telegram channel/connect routes, never buyer identity or worker endpoints. Live RBAC is re-proved on every request; PAYMF never guesses by database order. Creation and finalization expose no creator, storefront, product, channel, or user row ID. Demo data is never substituted.
02 / DISCOVERY + ACQUISITION
Discovery lists approved, checkout-ready storefronts that creators choose to publish. A direct storefront link does not automatically create a public listing.
Creators choose category, public tags, and whether to disclose a storefront-wide live-entitlement count. Product responses never carry hidden audience counts; the listing disappears when no active offer retains fresh Telegram capabilities.
Newest, lowest entry price, or disclosed live access. Server search and category totals cover the eligible catalog; encrypted 15-minute keysets load older pages without exposing database IDs. No paid placement or fabricated trend score exists.
Percentage or fixed USDC discount, product scope, first-payment eligibility, start/expiry, and a global cap. Reservation is serialized before ChangeNOW contact.
One claim per account and product, buyer/product-scoped replay, one immutable delivery contract, and a one-to-30-day entitlement. The private result exposes timing plus a scoped incident trace—not raw row IDs. Expiry queues removal; conversion always requires a fresh buyer-funded checkout.
No auto-debit and no fake urgency.Promo code, list price, integer discount, net provider amount, access term, and every ordered Telegram gate are locked into offer snapshot v3. Trials never create a subscription, deposit, or future charge authority.
03 / TELEGRAM ACCESS
The entitlement ledger decides who has access. The Telegram adapter invites, removes, verifies, reports, and retries without inventing success.
Paid access requires a matched provider-final ChangeNOW settlement. A free trial instead requires durable one-claim eligibility and a ready Telegram gate.
A durable PAID or TRIAL entitlement becomes the source of truth. Payment, promo, or trial-claim state never masquerades as delivery state.
A transactional outbox schedules a Telegram grant with an idempotency key and bounded retries.
The bot DMs an expiring join-request link to the paid Telegram identity; unmatched users are declined.
Webhook updates and scheduled checks confirm the member is in the correct room.
Refund, cancellation-effective, expiry, failed renewal, removal, or ban schedules an audited revoke.
04 / MONEY RAIL
ChangeNOW is the primary checkout provider. Public checkout presents Solana USDC first, with Base USDC and Ethereum USDC. Robinhood Chain is designed into the registry but provider-waiting because it is not currently listed by ChangeNOW. Creators inspect modeled versus partner-reconciled accounting in the read-only Revenue ledger; it never claims payout.
Credential is not settlement proof.The existing ChangeNOW Partner key matches PAYMF's server configuration, and a read-only catalog request currently advertises the four live rails above. Robinhood USDG remains absent. The account has no completed exchange or realized-profit evidence, so PAYMF still requires a controlled value-limited create, settlement, refund, access, and partner-reconciliation exercise before launch.
Acquire the product-commerce lock, re-check fresh gates, resolve idempotent/open replay, then atomically consume the versioned buyer, buyer/creator, refund-wallet, and creator velocity policy. A new intent snapshots those controls plus a named 1–90-day late-settlement policy, price, access duration, and every ordered delivery target before provider contact.
Ask ChangeNOW for one managed exchange and deposit address; ambiguous outcomes stay locked for operator reconciliation.
Persist the exact provider address, amount, asset, network, exchange ID, and expiry. The expiry derives the immutable late-settlement deadline; buyer-visible terms never expose the internal policy.
The scheduler conditionally claims one durable 60-second intent lease before fetching ChangeNOW by exchange ID. Failures release into bounded backoff; expired rows remain eligible only through their stored provider-expiry deadline, and closed terminal leases use a database-only repair lane.
A matched finished status verifies the latest offer snapshot and the current creator-member ban under the moderation lock. Active bans preserve confirmed money but leave access revoked and queue no grant; otherwise PAYMF retires obsolete delivery and queues one account-bound grant per current destination. Missing bundle targets fail closed without partial delivery.
Payment polling without intent IDs.The checkout screen receives a member-scoped reference and a random 24-hour encrypted status capability—not the PaymentIntent row ID. Polls use a dedicated redacted header on a constant self route; PAYMF authenticates the buyer, decrypts the target, re-proves ownership, and selects only normalized payment/access state.
Payout-route changes are delayed, not instant.The first route is recorded before creator approval. A later change needs one fresh Privy session to request, keeps the current route active through cooling-off, then needs a separately scoped fresh session to activate future exchanges. Existing exchanges are immutable; cancellation is immediate and defensive. These actions move no funds, and PAYMF does not claim email or Telegram notification delivery.
Monthly means renewal checkout.The lifecycle worker sends one durable, account-bound renewal link before the paid-through date. Buyers can inspect and cancel that future renewal in the access center; ChangeNOW never auto-debits, and current access remains live through the paid-through boundary. Creators inspect each normalized money-to-delivery path in Orders, which excludes addresses, hashes, provider payloads, and secrets. If an invite expires, Access can queue account-bound redelivery only after PAYMF rechecks entitlement, identity, ban, original gate, and fresh bot capabilities.
Self-service without row IDs.Access uses member-scoped references for entitlements, gates, subscriptions, and receipts. Cancellation and Telegram redelivery use a random 30-minute encrypted capability in a dedicated header on a constant self-action route; the URL/body reveal no target row. PAYMF still authenticates the member and re-proves ownership plus current state before mutation.
Provider events move forward, never backward.A late final settlement can rescue one expired or failed attempt, and one matched provider refund can reverse that settlement. Repeated terminal events and late pending/failure regressions remain normalized evidence but replay no money, access, promo, or revenue effect. A refund before settlement closes only that attempt and cannot revoke an older paid-through period. Dashboard and Members totals are bounded PostgreSQL aggregates under repeatable-read consistency; USDC and USDT stay in separate lanes with no assumed conversion. Older Members pages use creator- and filter-bound encrypted keyset cursors, never exposed database IDs or unstable offsets.
Promo controls cannot race checkout.Creator Offers uses scoped promotion references and a 30-minute actor/creator-bound header capability on a constant self route. PAYMF authenticates before recovering the target, and activation/deactivation takes the same database lock as checkout reservation. Demo remains local, and no promotion row ID enters the action path or body.
05 / TOKENOMICS / PROPOSED V0.2
Ticker: PAYMF. Proposed fixed supply: 1,000,000,000. No token has been minted, and every parameter below remains a design target requiring legal, security, governance, and treasury approval.
Where could platform revenue go?The proposal routes a governed share of reconciled platform revenue to token buybacks after a public policy, jurisdiction-specific legal analysis, treasury controls, governance approval, and audit. Nothing is active yet. Holding PAYMF alone creates no dividend, yield, revenue right, or guaranteed value.
06 / SECURITY BOUNDARIES
Server-only provider secrets, environment separation, and a new Privy session plus one-use grant for payouts, refunds, team roles, owner exports, Telegram identity change, subject access/portability exports, authoritative field correction, privacy review, and deletion-execution evidence. Team roster actions also use a separate 30-minute owner/creator-bound header key so no collaborator row ID enters the browser path; it cannot replace the fresh-session grant. A relink refuses while any old gate grant remains non-revoked; token refresh alone is insufficient.
An enforced CSP permits local assets plus Privy's documented authentication, WalletConnect, RPC, and challenge origins, not ChangeNOW or Telegram APIs. Script attributes, foreign forms, objects, framing, and unlisted connections are denied. Cookie-authenticated writes need exact-origin proof. Privy bearer requests are separately limited to current-origin PAYMF API routes, send no ambient cookie or referrer, and refuse redirects before authorization is attached.
Authenticated ChangeNOW polling and secret-protected jobs stay server-side. Inbound JSON is capped by actual bytes. Telegram receipts retain a payload hash and identifier-free evidence flags, not invite URLs, IDs, usernames, callbacks, or command tokens. Bot-native account creation locks privacy fingerprints before suppression checks and commits the buyer plus one-use checkout together. Checkout IDs survive only while the link is active; connection setup keeps a request only while pending and stores HMAC actor evidence when consumed. Outbound provider calls use exact official origins, refuse redirects, and parse only byte-bounded valid JSON. Deployment DNS and egress controls remain required.
Authenticated creator, member, operator, payment, Telegram, checkout, identity, and step-up responses—plus secret-authenticated metrics and workers—use private, no-store, must-revalidate, no-cache, expired-date, and nosniff headers on success, preflight refusal, and normalized failure. One-use grant tokens get no weaker path. The session probe exposes no Privy DID, raw session identifier, wallet, email, or adapter error. Token-bearing bot checkout pages add no-referrer and no-index controls; deployed proxy logs must still redact their path.
Buyer Access and Creator Orders derive full-ledger confirmed totals through PostgreSQL, grouped by exact currency inside the same repeatable-read snapshot as their bounded records. Buyers can continue entitlement and receipt lanes independently; Orders and Revenue continue by creator/filter scope. Every 15-minute keyset is random-nonce authenticated ciphertext, never a readable database ID. Orders replaces payment, entitlement, grant, event, and refund IDs with creator-scoped 80-bit evidence references. Exact live and receipt counts stay separate from page-scoped attention, and no asset conversion is claimed.
Unique provider IDs, deterministic job keys, transactional outbox writes, and safe duplicate acknowledgements.
Scoped bot permissions, tenant isolation, wallet allowlists, creator RBAC, non-delegable owner authority, step-up team mutations, and audited overrides.
07 / OPERATIONS
Production workers leave durable heartbeats. A separate secret-protected endpoint pages operators, the private Operator gets a smaller read-only summary, and creator Attention shows tenant-scoped problems without exposing high-risk provider or Telegram evidence.
Health rejects split modes, invalid boundaries, and weak or reused secrets. Six expiring launch gates then require one operator to record and another to accept.
A checkout-ready creator submits owner declarations into a durable pending queue. A separately stepped-up operator can approve, return, or restrict new-sales eligibility with predefined evidence. Every sales path requires the complete approval record, not an enum alone. Restriction blocks new discovery, trials, renewals, Telegram product selection, and checkout reservations without rewriting existing paid access. This is not KYC, sanctions screening, endorsement, or a return claim.
Creators route ambiguous money, delivery mismatch, refund review, open support, and gate drift from one read-only room. Private paging separately flags failed polls, stale reconciliation leases, expired payments with missing or historical unversioned coverage evidence, an open legacy refund with no immutable intake-policy evidence, and provider refunds that have not converged. The bounded local-repair lane never contacts ChangeNOW, extends a stored deadline, invents policy evidence, or fabricates a successful poll.
Allowlisted operators can inspect aggregate runtime state and normalized ambiguous-payment evidence. Payment list/detail selectors omit buyer wallets, payout routes, provider references, deposit addresses, asset IDs, and payloads; the stepped-up server mutation re-loads that evidence only for direct ChangeNOW matching. No observability secret, run, retry, Telegram, acknowledgement, or status authority enters the browser.
Retryable join work temporarily keeps only the member ID Telegram needs, never a username; terminal jobs clear their request body. Invite digests exist only while a grant is invited, and confirmed revocation clears the bound member. The access recovery queue keeps that binding through failed removal, then re-arms only from current grant truth, never from a captured payload.
Checkout or trial roots follow settlement, entitlement, grant, and Telegram jobs. Buyers, creators, exports, and operators see different scoped references. A hashed server-only index lets the allowlisted Operator resolve one exact audience reference into normalized evidence; raw traces, identities, provider bodies, and Telegram payloads stay server-side.
Critical money, provider, webhook, worker, and recovery failures share redacted fingerprints and opaque references. The allowlisted Operator can inspect a narrower DTO and add a step-up resolve/reopen annotation; no stack, body/header, payload, credential, address, Telegram ID, Privy DID, fingerprint, or raw trace enters the browser.
A leased worker reads the private metrics contract, suppresses unchanged alert sets, and signs only normalized state-change keys for a separate HTTPS sink. No caller supplies alerts; sink response bodies are discarded and dispatcher failures cannot recursively page themselves.
Deletion requires a stable blocker-free inventory, every required processor/backup receipt, a reviewer other than the recorder, and the isolated worker. Plan drift invalidates before local fields change; the browser cannot execute pseudonymization.
The creator Revenue ledger separates expected proceeds, modeled protocol fee, partner-reconciled state, and reversals. Private metrics page after seven pending days; no balance, payout, withdrawal, or token-holder claim is inferred.
Missing bot permissions degrade the channel and stop new checkout delivery until capability reconciliation proves the gate is safe. One-current-link setup and bounded probes prevent flooding; disconnect revokes pending setup authority, and stale inspection, membership, migration, or offer activation cannot reopen a detached gate.
Production requires a named/versioned elapsed-day policy before the lifecycle worker can purge old terminal setup, identity-link, or bot-checkout sessions in 500-row-per-class batches. Status and cutoff are rechecked inside the transaction. The read-only operations view shows policy and due counts only; money, entitlement, access, audit, moderation, support, privacy, legal-hold, and backup evidence is never selected.
Evidence and recovery stay separate.GET /api/health?deep=1 proves database reachability plus the required UTC PostgreSQL session; a non-UTC session fails readiness instead of shifting accounting days. GET /api/operator/readiness projects private two-person evidence. GET /api/internal/metrics reports aggregate alerts, creator-review age, trace/index gaps, exception severity/age, and privacy-execution health. GET /api/operator/operations gives the allowlisted Operator a smaller secret-free read-only projection without run, retry, reconciliation, Telegram, acknowledgement, or status authority. GET /api/operator/access projects redacted dead letters; its separate stepped-up re-arm endpoint can queue only the existing row after fresh truth checks, never run the worker or contact Telegram synchronously. GET /api/operator/traces/[reference] resolves one audience-scoped incident reference into a bounded read-only chain without returning the raw trace. The allowlisted Operator can inspect that chain, decide creator new-sales eligibility, annotate exceptions, review a deletion plan, and re-arm an eligible access dead letter, but cannot silently change money/entitlement time, replay a captured request, or pseudonymize a subject. POST /api/workers/alerts can deliver signed state after real sink credentials; POST /api/workers/privacy can apply only a pre-reviewed local plan and contacts no processor. Public status remains pre-launch. None of these surfaces can deploy, invent screening/processor action, or manufacture an incident/SLA.
Operator privacy without database row IDs. The restricted queue emits 80-bit OPRIVACY-…, SUBJECT-…, and EXECUTION-… evidence references plus separate 30-minute operator-bound capabilities for review, execution inspection, and execution mutation. Constant /api/operator/privacy/self routes authenticate before decrypting x-paymf-operator-privacy-key, then re-prove the record and preserve the existing step-up, idempotency, locking, and four-eyes rules. The capability header is action authority and must be redacted at the edge; it cannot run the privacy worker or replace processor, backup, or legal evidence.
08 / DATA PORTABILITY
The owner Data Vault exports useful commerce evidence without turning raw provider bodies, full financial identifiers, Telegram infrastructure, or private notes into a downloadable liability.
Member, accounting, and audit ledgers support CSV or JSON. A combined versioned bundle is JSON only, capped at 5,000 rows per ledger and ten MiB.
Only the immutable owner can generate a file after returning through a different Privy session. Admins can inspect disclosure history but cannot export.
Repeatable-read projections mask financial identifiers, redact risky free text, and neutralize formula-prefixed CSV cells before serialization. Creator Members never selects or searches wallets: staff see keyed member/evidence references, while a 30-minute creator-bound row key carries exact entitlement/subscription/payment context only in a redacted header. Constant actions authenticate before decryption and accept no raw target ID. Dashboard activity also uses creator-scoped opaque references and fixed categories instead of raw audit target IDs or reasons.
Creator and verified-subject paths return private no-store responses and retain no artifact or public URL. Durable receipts keep schema, hash/count, truncation, and byte evidence - not exported rows.
Implemented boundaries.GET/POST /api/creator/exports powers the creator Data Vault. GET/POST /api/member/privacy powers verified intake and withdrawal in the buyer access center; every new request snapshots a versioned owner/counsel-approved internal response target. The browser receives subject-scoped PRIVACY-… / NOTICE-… references instead of database IDs. Withdraw, export, correction, and acknowledgement use distinct 30-minute account-bound capabilities in a redacted header on constant self routes, and sensitive actions still require their separate fresh-session grant. Historical rows remain visibly unconfigured, country code never creates a statutory deadline, and legal hold does not silently pause the target. POST /api/member/privacy/self/export produces a separately stepped-up bounded access/portability JSON snapshot and retains only a hash/count receipt. POST /api/member/privacy/self/correction synchronizes an enumerated email/wallet target only from Privy, or verifies a guarded Telegram relink. The separate relink consumes a different-session grant, revokes older pending tokens, refuses while any gate binding survives, and stores no session Telegram ID or username; no browser or operator replacement value is accepted. Every lifecycle event atomically publishes predefined versioned in-platform copy; explicit subject acknowledgement remains separate from request state and never claims email or Telegram delivery. Operator completion requires the matching export or correction evidence. The allowlisted operator can record a bounded deletion plan and opaque receipts; a different operator reviews it; only the isolated worker can pseudonymize eligible local fields. Statutory deadlines, real processor responses, backup expiry, approved retention, independently delivered subject communication, and controlled production evidence remain launch gates.
09 / BUILD A–Z
A phase advances only when its operating and security criteria are met. “Shipped” means observable, reversible, and documented.
PAYMF brand, opt-in public creator directory, storefront, Studio, buyer access center, promo inventory, bounded free trials, demo checkout, member controls, and fail-closed adapters.
Privy browser/server auth, an enforced Privy-compatible browser CSP, exact-origin cookie mutation guards, owner-only step-up team roles/data exports, verified subject privacy intake, PostgreSQL migrations, creator tenancy, guarded product editing/publishing, a normalized Attention Room, member operations, queues, bans, refund records, and audit storage are implemented.
ChangeNOW exchange creation, immutable offer snapshots, concurrent-open deduplication, four live provider rails, durably leased reconciliation, versioned provider-expiry late-settlement coverage, renewal notices, and atomic provider-refund convergence are implemented; partner proof is still required.
Signed one-current-link group setup, rate-limited capability proof, privacy-minimized creator inventory, disconnect/product lock convergence, crash-recoverable webhooks, account-bound join requests, revocation, bans, renewal DMs, and drift repair are implemented. Operator configure/probe commands remain dry-run by default.
Durable heartbeats, private metrics, a secret-free read-only operator summary, four-eyes launch evidence, public prelaunch status, versioned terminal-session minimization, server-owned commerce correlation with hashed audience lookup, redacted exception groups, and signed alert delivery are implemented. Real delivered paging, controlled operator-use evidence, and the broader legal retention program remain deployment gates.
Discord roles, X communities, email, gated downloads, creator APIs, agent observability, then owner-controlled AI agent storefronts.
Only after jurisdictional analysis: public parameters, mint authorities, vesting contracts, governance scopes, and treasury attestations.
10 / PURCHASE SUPPORT
Buyers can open a case inside Access; PAYMF attaches the owned entitlement or payment context through a 30-minute account-bound capability rather than exposing its database ID. The complete combined purchase inventory continues through a separate member-bound encrypted keyset, and the drawer deduplicates it with scoped CONTEXT-… labels. Creator Owner, Admin, and Support roles answer in the Support desk. Queue rows contain no message body; an authorized drawer lazily loads a bounded thread, while actor/case-bound encrypted keysets continue older cases and messages. Every HTTP page is its own repeatable-read snapshot. Never send a seed phrase, private key, or bot token.
Confirm the exact asset, network, amount, deposit address, and memo in the buyer checkout—not in a support message. PAYMF waits for authenticated ChangeNOW status; a wallet screenshot cannot unlock access.
Open Access, confirm the correct Telegram identity, and use redelivery when PAYMF marks it available. “Queued” is not “delivered”; if recovery is refused, quote only the scoped receipt, entitlement, or case reference shown by PAYMF, never a provider address or raw database ID.
A request is not a completed refund. Ordinary creator intake must snapshot the deployed named/versioned elapsed-day policy under the money lock; legacy requests without it cannot be approved. Owner/Admin review uses an actor-bound 30-minute capability on one constant route; Support is read-only and no refund row ID enters the browser. That operating window is not a statutory-right decision. Completion still requires matched provider/on-chain evidence and commits atomically with access and revenue reversal.
Do not post sensitive evidence in a group. Use the operator-configured private support URL and rotate exposed credentials immediately.
11 / LINKS + SOURCE MATERIAL
READ ENOUGH?