Skip to content

Blind credits / from your wallet

Blind credits,
kept on your device.

Pay from your own wallet and end up holding blind credits in this browser. No account and no long-lived key: a one-time key is made here, receives your payment, buys the credits and is wiped. Below is a plain account of what stays linkable to you and what does not.
Preview · the credit issuer is not liveThe flow below is the design. No payment can be made on this page yet.
  1. 1

    One-time key

  2. 2

    Pay

  3. 3

    Credit

  4. 4

    Mint credits

  5. 5

    Keep them

  6. 6

    Wipe the key

1 · Make a one-time key and choose how to pay

The key is made in this tab, needs no account and never leaves it. It receives your payment, the page turns the credit into blind credits, and then the key is switched off and wiped.

USDG

USDG on Robinhood Chain is credited one for one, with no haircut, then turned into credits of the same value.

$Verify

Paying in $Verify is considered for after the token launch. Not available.

Your credits

None yet. Credits bought here stay in this browser and can be saved to a file you keep.

What is linkable, and what is not

Can be linked to you

  • The payment. Sending USDG is a public transfer on Robinhood Chain. Anyone, the router included, can see that your wallet paid, how much, and to which one-time key.
  • The purchase. The router records that the one-time key bought credits: how many and in which sizes. Put together, “this wallet bought N credits” is on record.
  • Your network address and timing. Buying over the open internet shows the router your IP address, and spending right after buying links the two by time. Waiting and using an onion route both help.

Cannot be linked to you

  • Which prompts the credits paid for. The router signs each credit blind: it never sees the credit it signs. When one is spent, the router can tell it is genuine and unspent, but not which purchase or wallet it came from. The call is logged against a hash of the credit, with no key, account or wallet, and its receipt says the same.

What credits do not hide

  • The text of a request. On every lane the router reads a request in memory to route it, and that includes calls paid with credits. Credits hide who pays, not what is sent.
  • Your address while spending, unless you use Tor. Spend credits through an onion address to keep your network address from the router. Calls on one circuit can be linked to each other.
  • Unused value. A credit pays for one call up to its value; the rest is not returned. Credits expire on the date shown with them, and a lost credit cannot be replaced, because nobody keeps a record of who holds them.

Spending them

The unlinkable lane is not served yet, so credits cannot be spent anywhere today. When it opens, a credit goes in the Authorization header as BlindCredit credit=<credit>, with the lane named in X-VR-Lane: unlinkable.

Read the credits spec