Private commerce on Solana

The Private
Commerce Layer

Build it. Launch it. Monetize it. Privately.
95% Of every sale
goes straight
to the creator
0 Funds held
by the platform
How it works

Live · Solana mainnet · no custody

The checkout, verified by the chain.

A purchase in front of you: the buyer signs one transaction carrying two transfers and a reference key. The server reads the balances that changed and only then releases the key. Same arithmetic as production — 95 / 5, nothing parked in between.

purchase · demonstrationrunning
Launch a product
Settlement · always sums to the price
1.000SOL
creator 0.950fee 0.050
Balance delta · creator
+0.000
Balance delta · treasury
+0.000
Reference key in tx
—
Held by platform
0.000 SOL
Key released
locked

§01 — The mechanism

Four steps, and the platform never touches the money.

A marketplace normally holds the payment and the goods, and then has to be trusted with both. Here the goods are encrypted before they leave the creator's device and the payment goes wallet to wallet. What is left for the platform is bookkeeping: did the chain move what the order says it should?

01

Launch

A creator lists a file, a secret, or access to a repository, with a price in SOL. No approval queue: the listing is live the moment it is published.

02

Encrypt

The browser generates a key and encrypts the content before upload. Storage only ever sees ciphertext; a leaked URL is useless.

03

Pay

One transaction, two transfers: 95% to the creator, 5% to the treasury, plus a reference key unique to this order. Either both land or neither does.

04

Unlock

The server reads the confirmed transaction, checks every balance that changed, and releases the key. Decryption happens on the buyer's device.

§02 — What you can sell

Anything that fits in a file, a secret, or a door.

Datasets, research, source code, API keys, private community links, repository access — and apps you host yourself, gated by a single ownership check. Pick what the buyer receives; the checkout is the same every time.

The buyer receives

The exact bytes you uploaded, decrypted on their device.

Encrypted in your browser with a fresh AES-256-GCM key, then uploaded straight to blob storage — it never passes through the API. After payment the buyer fetches the ciphertext and unlocks it locally; the download starts in their browser.

dataset.zip.enc 142.6 MB ciphertext key 32 bytes released after payment decrypt local AES-GCM · WebCrypto download dataset.zip
  • Executables and installers are refused by name
  • Only ciphertext ever reaches storage
  • Re-downloadable from Purchases at any time

§03 — The encryption

Where the plaintext exists, and where it never does.

Three parties, one key. The creator's browser makes it, the buyer's browser uses it, and the platform holds it wrapped so that a purchase at 3 a.m. can be delivered without the creator being awake. Follow the packets.

Creator plaintext · key Storage ciphertext EVERYNTH key, wrapped Buyer plaintext ciphertext key (TLS) ciphertext key, after payment paid SOL · wallet → wallet · chain verifies
KEYGenerated per product by the creator's browser (WebCrypto, AES-256-GCM). Never derived from anything guessable.
CTCiphertext = 12-byte IV + AES-GCM output. Files go straight to blob storage; secrets sit inline in the database.
WRAPEVERYNTH stores the key wrapped with a master key that lives only in the server environment. Losing it makes every product undecryptable — so it is backed up like money.
OPENAfter the chain confirms payment, the buyer's browser fetches ciphertext + key and decrypts locally. The plaintext is never assembled on a server.
Honest limit. In v1 the platform can technically unwrap a key. That is what lets a purchase be delivered while the creator is offline, and what lets a reported product be inspected. Full end-to-end keys arrive with private chat on the roadmap.

§04 — Lifecycle

From listing to unlocked. Five moments.

Two are signatures from the creator, two from the buyer, and one is the chain doing what it does. The invariant across all five: nothing is released until a confirmed transaction moves exactly what the order froze.

0 1
launch()
Creator

Content encrypted in the browser, ciphertext uploaded, key wrapped and stored. Price in lamports, minimum 0.02 SOL so the fee clears rent.

0 2
order()
Buyer

The server freezes the payout terms — creator, amounts, treasury — and mints a reference key unique to this order. Pressing Buy again reuses it.

0 3
pay
Wallet · chain

Two SystemProgram transfers in one transaction, reference attached. Confirmed at "confirmed" commitment by the buyer's own RPC.

0 4
settle()
Server

Fetches the transaction, checks the reference, then the lamport delta of every recipient. One signature can settle one purchase, ever.

0 5
unlock()
Buyer

Key and ciphertext handed to the buyer only. Decrypt, download, or be invited to the repository. Re-openable from Purchases.

§05 — The surface

Nine routes. The whole external surface.

Nothing is admin-only except takedowns. There is no upgrade switch on the payment path because there is no program to upgrade: the transaction is two transfers anyone can inspect on Solscan.

RouteEffectCaller
POST /api/sessionSign in with a wallet signature; sets an HMAC session cookieanyone
POST /api/uploadShort-lived token for a direct encrypted upload to storagesigned in
POST /api/productsLaunch a file, secret or GitHub productcreator
PATCH /api/products/:idEdit listing details and cover; content is immutablecreator
POST /api/ordersFreeze payout terms and mint a reference keybuyer
POST /api/orders/:id/confirmAsk the server to verify the chain; never trusted, only checkedbuyer
GET /api/purchases/:id/contentKey + ciphertext (or its URL) for a paid purchasebuyer
POST /api/purchases/:id/githubInvite the buyer's GitHub account read-onlybuyer
GET /api/verifyDoes this wallet own this product? Public, CORS-openanyone
// gate your own app with one request
const res = await fetch(
  "https://everynth.org/api/verify?product="
  + PRODUCT_ID + "&wallet=" + wallet
);
const { owned, since } = await res.json();
if (!owned) location.href =
  "https://everynth.org/p/" + PRODUCT_ID;

// prove wallet control first — a signed message,
// exactly as EVERYNTH does at sign-in.

§06 — Deployment

Nobody holds the money, so nobody can lose it.

The payment path has no program of ours and therefore no admin key, no pause, no upgrade. What can go wrong is bounded to the one order in front of you — and a paid order that failed to verify recovers itself from the chain on the next click.

Status
LIVE
Network
SOLANA MAINNET
Payment
NATIVE SOL · 2 TRANSFERS · 1 TX
Program
NONE · SYSTEMPROGRAM ONLY
Custody
NONE · WALLET → WALLET
Fee
5% FLAT · FROM CREATOR SHARE
Minimum price
0.02 SOL · FEE CLEARS RENT
Content
AES-256-GCM · BROWSER SIDE
Files
≤ 200 MB · CIPHERTEXT IN BLOB
Key custody
PLATFORM-WRAPPED · V1
Refunds
NONE · DELIVERY IS INSTANT
Settlement · drag the price
1.000=0.950+0.050SOL
Creator receives0.950 SOL
Treasury receives0.050 SOL
Buyer pays1.000 SOL + network fee
Platform balance after0.000 SOL

Fee = floor(price × 500 / 10 000) lamports; creator share = price − fee. The two always sum to the price exactly, there is no rounding residue for anyone to keep.

Built for  Commerce

Every part of the checkout is engineered so the platform never
holds money or readable goods, giving creators a rail they can
launch on, sell through and deliver from in production.

Creator Share
Wallet-to-Wallet Payout

%

Of every sale,
straight to the creator

Encrypted Delivery
Sealed in the Browser

MB

Per file, ciphertext only
ever reaches storage

Ownership Check
Cross-App Access

req

One request gates
your own app or agent

§08 — The design

Three places. Each sees only what it must.

There is no smart contract to audit, because two transfers do not need one. What there is instead is a strict split of who knows what: your device, our server, and the chain. Hover a layer to see its view of a purchase.

01

Your device

plaintext lives here, and only here
  • plaintext file or secret
  • the content key it generated
  • your wallet's private key
  • AES-256-GCM in the browser
  • signs the login and the payment
  • decrypts after unlock
02

EVERYNTH

bookkeeping, never custody
  • ciphertext, never plaintext
  • content key, wrapped by the master key
  • orders, references, session cookies
  • freezes payout terms per order
  • reads confirmed balance deltas
  • releases the key, invites on GitHub
03

Solana

public by nature
  • wallet addresses and amounts
  • the order's reference key
  • nothing about the goods
  • two SystemProgram transfers, one tx
  • confirms in seconds
  • no program of ours to upgrade or pause