Ring-signature checkout

A buyer, a facilitator, and a proof that the facilitator is one the buyer already decided to trust — without revealing which one. This page is served from an nsite (Nostr blobs + a manifest event); there is no server behind it.

Try it — the two-actor view (one window, both panes)

Both actors, one take

Buyer on the left, facilitator on the right. This is the surface used in the recorded demo. Recommended for a first look.

Open the two-pane flow

Separate tabs

The same two pages as independent clients. Open both in this browser so they share an origin — the token hand-off rides a BroadcastChannel.

Buyer Facilitator

What to do, in order

  1. Fill the basket: two pizzas, 27,900 sats.
  2. Choose a facilitator — take Food Runners Berlin (in the roster).
  3. Press the proof button on the facilitator pane. The buyer's verdict card appears: a member of your trust set signed this order, anonymity set = 4.
  4. Try the attack button: replay the same proof for a different order → refused, LSAG signature verification failed.
  5. Continue to payment: a real invoice is issued by the mint, but only because the proof verified. No proof, no invoice.
  6. Watch the paid leg run by itself: mint reports PAID, the buyer mints the ecash, the token crosses, the facilitator redeems, and the mint confirms the buyer's proofs are SPENT before the order is released to the kitchen.
Honest notes before you draw conclusions.

Source: mcp-cashu-exchange/apps/worker/public (branch pr/trust-ring-paid-leg) — the nsite is a copy of those static pages, nothing else. Electrum-side code: felixfelix-bot/electrum, branch pr/trust-vendor-plugin.