AVAlgoVoi
UK · KYC + KYB · 7 chains live

Verifiable, provable agent payments. Self-hosted.

Compliance as an enabler, not a cost. You can deploy autonomous agents because the compliance is already solved.

Compliance stack
KYCKYBMLROAMLSanctions screeningFernet at-restAudit logSAR pipeline
Algorand
Voi
Hedera
Stellar
Base
Solana
Tempo
x402MPPAP2A2A
Drop-in for
🟣WooCommerce🔵OpenCart🩷PrestaShop🟢ShopwareBigCommerce🟠Magento🔷Xero🗓️Calendly
Scroll to explore
For merchants

Accept crypto on your storefront, API, or AI agent

One platform, seven chains, four payment protocols. Drop-in storefront plugins, hosted x402, MPP subscriptions, recurring pull payments, and webhook-grade notifications — no chain nodes, no indexer, no infrastructure.

Live — eCommerce Payment Adapters

Accept crypto on any platform
Algorand · Voi · Hedera · Stellar · Base · Solana · Tempo

Drop-in payment plugins for WooCommerce, OpenCart, PrestaShop, Shopware and more. Hosted checkout supports all seven chains — Algorand, Voi, Hedera, Stellar, Base, Solana & Tempo. Browser extension payments now available on six chains: Algorand, Voi, Hedera, Base, Arc & Tempo (x402, MPP, AP2 all wired).

🌐
Hosted Checkout
Redirect to AlgoVoi

Customer is redirected to a secure AlgoVoi-hosted payment page. Works with any wallet on seven chains — Pera, Defly, Lute, HashPack, Freighter, LOBSTR, MetaMask, Phantom, Trust. Payment confirmed via webhook + API status check.

AlgorandVOIHederaStellarBaseSolanaTempo
Extension Payment
Pay in-page via AlgoVoi wallet

Customer pays directly on the store page using the AlgoVoi browser extension. No redirect, instant on-chain settlement via algosdk.

AlgorandVOI
Payment flow
1
Customer selects chain
Algorand · VOI · Hedera · Stellar · Base · Solana · Tempo
2
Plugin creates payment link
POST /v1/payment-links
3
Hosted: redirect to checkout
Extension: pay in-page via wallet
4
On-chain verification
Webhook or API status check
5
Order confirmed
Status updated automatically
🟣
WooCommerce
HostedExtension

WordPress + WooCommerce plugin with hosted checkout redirect and in-page browser extension payment.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Visit demo store →
🔵
OpenCart
HostedExtension

OpenCart 4 extension with AJAX-powered checkout, chain selector, and dark-themed storefront.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Visit demo store →
🩷
PrestaShop
HostedExtension

PrestaShop 8 module with custom payment options, cookie-secured sessions, and full dark theme.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Visit demo store →
🟢
Shopware
HostedExtension

Shopware 6 plugin with Symfony payment handlers, Twig chain selector, and webhook verification.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Visit demo store →
🐘
Native PHP
HostedExtension

Framework-free PHP adapter. Single-file drop-in for any custom PHP application — no dependencies, no composer required.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Drop-in adapter — no platform required
🐍
Native Python
HostedExtension

Zero-dependency Python adapter using only the standard library. Works with Flask, Django, FastAPI, or plain WSGI.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Drop-in adapter — no platform required
🔷
Native Go
HostedExtension

Idiomatic Go package using only the standard library. Includes http.HandlerFunc helpers for webhooks and chain selectors.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Drop-in adapter — no platform required
🦀
Native Rust
HostedExtension

Zero-crate Rust library with pure-stdlib SHA-256, HMAC, and base64. Pluggable HttpClient trait for any TLS backend.

Hosted chains
AlgorandVOIHederaStellarBaseSolanaTempo
Extension chains
AlgorandVOI
Drop-in adapter — no platform required
🤖
MPP Server
Agent Protocol

Machine Payments Protocol middleware including MPP Subscriptions (recurring agent-billable resources). Gate your APIs behind WWW-Authenticate: Payment challenges. Flask, Django, WSGI.

Supported chains
AlgorandVOI
Drop-in adapter — no platform required
🤝
AP2 / A2A Server
Agent Protocol

Agent payment middleware supporting AP2 (ed25519 mandates) and Google A2A v0.3 skills (verify-payment, create-checkout, check-status). AI-to-AI payment orchestration out of the box.

Supported chains
AlgorandVOIHederaStellarBaseSolanaTempo
Drop-in adapter — no platform required
𝕏
X Bot
Cloud

Multi-tenant X (Twitter) bot. Tweet "pay £X" in a reply and the bot generates a live checkout link. Preferred chain per tenant.

Supported chains
AlgorandVOIHederaStellarBaseSolanaTempo
Drop-in adapter — no platform required
✈️
Telegram Bot
Cloud

Cloud-hosted Telegram bot. Send a payment request in any chat and receive an instant AlgoVoi checkout link. Multi-tenant, webhook-driven.

Supported chains
AlgorandVOIHederaStellarBaseSolanaTempo
Drop-in adapter — no platform required
💬
Viber Bot
Cloud

Cloud-hosted Viber bot. Request a payment inside any Viber conversation and get a checkout link delivered in seconds.

Supported chains
AlgorandVOIHederaStellarBaseSolanaTempo
Drop-in adapter — no platform required
🎮
Discord Bot
Cloud

Shared multi-tenant Discord bot. Invite once, type "pay £X" in any claimed guild and AlgoVoi replies with a live checkout link. Per-guild preferred network, auto-refreshed guild map.

Supported chains
AlgorandVOIHederaStellarBaseSolanaTempo
Drop-in adapter — no platform required
60 days testnet · KYC unlocks $1,000 free mainnet · 0.50% after

Start accepting crypto payments today

Sign up with your wallet — testnet is live instantly. Pass our quick ID check (individuals auto-approved in minutes; companies typically within 1 business day) and your first $1,000 of mainnet payments are free across all 7 chains. After that, just 0.50% per payment.

✓ 60 days free testnet✓ $1,000 free mainnet after KYC✓ All 7 chains✓ 0.50% after trial✓ UK-regulated · MLRs 2017

Security-first architecture

Every adapter is hardened against real-world payment attack vectors.

🔐
HMAC webhook verification
Signed webhooks with hash_equals — empty secrets rejected before HMAC check.
🛡️
SSRF protection
Checkout URL host validated against configured API base before any server-side fetch.
⏱️
Timing-safe comparisons
hash_equals for all secret comparisons — order keys, HMAC signatures, tokens.
Cancel-bypass prevention
Hosted checkout returns verified via API before marking orders complete. No blind trust.
👤
Order ownership checks
Customer ID cross-referenced on verify endpoints — prevents cookie-swap attacks.
🔒
TLS enforced
SSL verification enabled on all outbound HTTP calls across every platform.
xChain v2 · MetaMask → Algorand & Solana & Stellar

Let MetaMask users pay your Algorand, Solana, or Stellar checkout — no destination wallet

EVM USDC bridged via Circle CCTP V2 (Solana destinations — native USDC, ~50s, zero slippage) or Allbridge Core (Algorand and Stellar destinations). Per-tenant routing, picked at attempt creation. No bridge UI, no swap, no destination-chain credentials in the customer’s wallet.

AlgorandLive
USDCa (ASA 31566704)
Allbridge Core · ~5s direct / ~2–4 min bridged
Settled via deterministic LogicSig — EIP-712 sign in MetaMask authorises the final ASA transfer to the merchant.
SolanaLive
Circle USDC
Circle CCTP V2 Fast Transfer · ~50–90s end-to-end
Burn-and-mint native Circle USDC. Zero pool slippage, ~14 bps Fast Transfer fee absorbed by AlgoVoi’s slippage tolerance. AlgoVoi runs the relayer wallet.
StellarLive
USDC (canonical Circle issuer)
Allbridge Core today, CCTP V2 when Circle ships mainnet · ~60–120s
Allbridge Core delivers classic Stellar USDC at Circle’s canonical issuer GA5ZSEJY… directly to the merchant’s Stellar address. Any Stellar wallet supports the asset — no Soroban-aware wallet required. Circle CCTP V2 Stellar mainnet is on Circle’s 2026 roadmap and will be added as a second protocol once contracts ship.
1
Customer clicks "xChain"
On any Algorand or Solana mainnet hosted checkout, the xChain tab sits next to the standard QR and wallet buttons — no merchant action needed.
2
MetaMask connects
Customer signs in with their existing EVM wallet — MetaMask, Coinbase Wallet, Rabby, or any injected provider. No destination-chain wallet to install.
3
Bridge USDC
Solana → Circle CCTP V2 Fast Transfer (~50s, native USDC, zero slippage). Algorand → Allbridge Core (~2-4 min). Per-tenant routing, picked at attempt creation.
4
Settled on-chain
For Algorand: EIP-712 LogicSig signs the final ASA transfer. For Solana: AlgoVoi’s relayer claims via CCTP receive_message, USDC mints natively to the merchant ATA. Webhook fires, customer redirects to the order-received page.
Bridge sources
7 EVM chains · Circle CCTP V2 + Allbridge Core
CCTP V2 routes Solana (zero slippage, ~50s); Allbridge handles Algorand and Stellar
Ethereumeip155:1🔷Baseeip155:8453🟦Arbitrumeip155:42161🔴Optimismeip155:10🟣Polygoneip155:137🟡BNB Chaineip155:56🔺Avalancheeip155:43114
🦊
No new wallet
Your customers already have MetaMask. They never learn what an ASA or SPL token is, never install a destination-chain wallet, never see a seed phrase.
~5s to ~4 min
Algorand direct path settles in one block. Solana bridge typically completes in 90–120 seconds. The checkout page holds the customer through it.
🤖
Per-tenant destination
Each tenant picks Algorand or Solana via the xchain_destination_chain flag. Both can run concurrently across a fleet of merchants on the same gateway.
🛠️
No bridges to manage
Solana via CCTP V2 — zero pool slippage, only Circle’s ~14 bps Fast Transfer fee. Algorand via Allbridge — ~0.3% combined pool fee. Both absorbed by AlgoVoi’s slippage tolerance; the merchant receives the checkout total.
🔐
EIP-712 + LogicSig
For Algorand destinations: AVM v11 LogicSig recovers the secp256k1 signer and asserts the EVM address matches. The customer signs typed-data, never raw bytes.
💸
Source-tx revert detection
If the bridge transaction reverts on the source chain (insufficient gas, allowance issue), the checkout detects it within seconds and surfaces a "Try bridge again" prompt. No funds move; no spinning indefinitely.
Live on Algorand, Solana & Stellar mainnet

Reach 100M+ MetaMask users without onboarding them to Algorand, Solana, or Stellar

xChain is automatically enabled on every tenant configured for algorand_mainnet or solana_mainnet or stellar_mainnet. Solana defaults to Circle CCTP V2 for ~50s native USDC settlement; Algorand and Stellar use Allbridge Core (Algorand via the deterministic LogicSig pattern, Stellar via canonical Circle USDC delivered through a Soroban swap pool — any Stellar wallet works). CCTP V2 will be added to Stellar once Circle ships mainnet contracts.

Hosted x402 Facilitator

x402 as a service —
monetise any API in minutes

Gate any HTTP endpoint behind a crypto micropayment. AlgoVoi hosts the x402 facilitator, verifies on-chain settlement, and fires your webhook — you just add middleware. No chain nodes. No indexer. No infrastructure.

1
Register your resource
Sign up with your wallet — 60 days free on testnet. Pass our quick KYC to unlock $1,000 of free mainnet payments, then configure your resource URL, price, and payout address.
2
Gate your API endpoint
Add a single middleware call. On unpaid requests, return the PAYMENT-REQUIRED header — we build it for you.
3
AlgoVoi pays automatically
The browser extension intercepts the 402, signs an on-chain transaction, and retries the request — invisible to the user.
4
Settlement confirmed
Our hosted facilitator verifies the on-chain txId and calls your /settle webhook. Funds land in your wallet.
x402_example.py10 lines
# Python — gate any Flask route with x402
from algovoi import require_payment

@app.route("/api/data")
@require_payment(
    price="1000000",   # 1 VOI in microunits
    asset="0",         # native coin
    network="voi-mainnet",
    pay_to="YOUR_VOI_ADDRESS",
)
def premium_data():
    return jsonify({"data": "..."})
🌐
Hosted facilitator
No chain nodes, no indexer — we verify on-chain settlement and call your webhook.
Sub-second settlement
Transaction confirmed on Algorand or Voi, indexed, and webhook fired in under 5 seconds.
🔑
API key auth
Manage resources and check payment status with your tenant API key. KYB-gated, no shared secrets.
🛡️
Spending cap enforcement
Per-user caps enforced client-side by AlgoVoi. Users can never be overcharged.
📦
Drop-in middleware
Python, Go, PHP, Rust, and Node.js helpers. Add to any framework in under 10 lines.
💸
Any price, any asset
Charge fractions of a cent for AI inference, $1 for articles, or $100 for data exports.
🔁
Recurring & subscriptions
Recurr Tier 2 pull executor charges authorised wallets on cycle, and MPP subscription resources gate agent-billable streams.
🤖
Agentic mandates (in dev)
Fiat-backed signed JWT spending authority. Agents will pay autonomously, AlgoVoi settles on-chain, the human is billed in GBP. Backend live, onboarding flow in development.
Use cases
🤖 AI inference APIs📰 Premium content📊 Data exports🗺️ Geocoding & maps🔍 Search APIs💬 LLM completions📈 Market data feeds🎮 Game asset APIs
60 days testnet · KYC unlocks $1,000 free mainnet · 0.50% after

Start charging for your API today

Sign up with your wallet, drop in the middleware, and you're live on testnet instantly. Pass our quick ID check and your first $1,000 of mainnet payments are on us — AlgoVoi users pay automatically.

AI adapters · 7 providers live

Gate your AI API callsbehind on-chain payment

Drop-in wrappers for every major LLM provider. Charge per token, per request, per call — settle to your wallet on Algorand, VOI, Hedera, Stellar, Base, Solana, or Tempo. Every adapter speaks x402, MPP, and AP2 out of the box.

OpenAI
GPT-4o + compatibles
101/101
Claude
Anthropic Sonnet 4.5
76/76
Gemini
Google 2.0 Flash
75/75
Bedrock
AWS Nova / Llama
57/57
Cohere
Command-R family
Live
xAI
Grok 4 / 3 / 2
70/70
Mistral
Large / Codestral
70/70
+ more
Via base_url on OpenAI adapter
Mistral, Together, Groq, Perplexity, DeepSeek…
All seven adapters live at github.com/chopmob-cloud/AlgoVoi-Platform-Adapters · Comet-validated · on-chain Phase 2 verified
Agent payment protocol comparison
ProtocolTriggerOn-chain txnBest for
x402HTTP 402 responseYes — AVM pay txnWeb content / APIs
MPPWWW-Authenticate: PaymentYes — AVM charge txnMachine-to-machine APIs
AP2window.algorand.ap2.request()No — ed25519 mandateAI agent commerce
WCalgo_signTxn via WalletConnectYes — any AVM txnAI agent arbitrary signing
Live — Stripe-grade outbound webhooks

Get notified the moment
a payment confirms

Wire AlgoVoi to wherever your team already is — Slack, Teams, Discord, Telegram, or your own backend. Auto-retry for 32 hours, HMAC-signed payloads, full audit log, manual retry. Same reliability stack behind every destination.

💼
Slack
Block Kit message
📣
Discord
Embed in any channel
🟪
Microsoft Teams
Adaptive Card
🟣
Mattermost
Slack-compatible
🚀
Rocket.Chat
Self-hosted
💭
Google Chat
Cards v2
🟢
Zulip
Topic-threaded
📨
Telegram
Bot sendMessage
🪝
Generic webhook
Your own backend
🔁
Auto-retry up to 32 hours
Slack down? Receiver flaky? Failed deliveries automatically re-fire with exponential backoff (30s → 2m → 10m → 1h → 6h → dead-letter). Six attempts over ~32 hours before we stop trying.
🔐
HMAC-SHA256 signed payloads
Every outbound POST carries an X-AlgoVoi-Signature header in Stripe-style format (t=<unix>,v1=<hex>). Per-destination algvw_* secret you can rotate from the dashboard. Verify before trusting the data.
📋
Per-tenant audit log
Every dispatch attempt is recorded — status, attempts, last HTTP code, last error, payload preview. Filterable by provider and status, paginated, no SQL access required.
Manual retry, one click
Receiver fixed an outage? Hit Retry on a failed delivery. Same path as the worker — same idempotency, same signature, same payload. No replay attack surface.
🌐
One pipeline, nine destinations
Same retry queue, same signing, same audit log behind every destination. No drift between channels. Adding a tenth destination is a one-file change for us — the existing nine just keep working.
Real-time, fail-soft
First delivery attempt fires inline at payment confirmation — typical end-to-end latency is sub-second. Notifier failures NEVER block the on-chain confirmation; you always get paid even if Slack is down.
Generic webhook event
POST your-backend.example.com · X-AlgoVoi-Signature: t=1777200000,v1=…
{
  "id":          "evt_a3f7c192-d8e1-4b6c-9f0a-7b1e2c4d8e3f",
  "type":        "payment.confirmed",
  "created":     1777200000,
  "api_version": "1",
  "data": {
    "tenant_label":      "Acme Payments Ltd",
    "resource_id":       "premium-content",
    "chain":             "algorand:mainnet",
    "asset":             { "id": "31566704", "label": "USDC", "decimals": 6 },
    "amount_microunits": "5000000",
    "amount_pretty":     "5 USDC",
    "tx_id":             "ABCD1234EFGH5678ABCD1234EFGH5678ABCD1234EFGH5678ABCD",
    "payer_address":     "GHSRL2SAY247…MWI"
  }
}

# Verify in Python
expected = hmac.new(SECRET.encode(), f"{ts}.".encode() + raw_body, hashlib.sha256).hexdigest()
if not hmac.compare_digest(expected, v1):
    abort(401)
Same offer · 60 days testnet · KYC unlocks $1,000 free mainnet · 0.50% after

Wire your stack in two minutes

Paste a Slack incoming-webhook URL, a Discord channel webhook, a Teams workflow URL — or point AlgoVoi at your own backend. Every destination shares the same retry queue, same signing layer, same audit page. No infrastructure to run.

✓ 9 destinations✓ HMAC-SHA256 signed✓ Auto-retry 32h✓ Manual retry✓ Per-tenant audit log
Live — Multi-Tenant Payment Platform

Hosted payment infrastructure
for businesses

AlgoVoi-Hand is a managed, compliance-ready crypto payment gateway. Register as a tenant, pass a compliance review, and accept payments on seven chains — without running nodes, facilitators, or verification servers.

Tenant onboarding
1
Wallet signup
Instant testnet · 60 days free
2
KYC / KYB
Individuals: auto-approved · Companies: ~1 business day
3
$1,000 free mainnet
All 7 chains · keep every penny
4
Standard plan
0.50% per payment · auto-deducted
🔑
One tenant API key
Register once, get an API key. Point the AlgoVoi gateway at your resource definitions — no chain nodes or facilitator servers to run.
🏗️
Hard tenant isolation
Every tenant is fully isolated at the database level using row-level security. Your payments, receipts, and API keys never touch another tenant.
⛓️
Seven chains supported
Accept payments on Algorand, VOI, Hedera, Stellar, Base, Solana, or Tempo mainnet. Multi-chain checkout with chain picker — customers choose their preferred network.
🤖
Browser, agent & A2A ready
Human users pay via the AlgoVoi extension. AI agents use x402/MPP/AP2 or Google A2A v0.3 skills (verify-payment, create-checkout, check-status) — identical backend, same flow.
🛡️
Security-first, fail-closed
Kill switch, amount caps, test/live network separation, and a 10-layer security model — enforced at the gateway, not just documented.
📊
Full audit trail
Every challenge, verification, limit change, and key event is logged per tenant with typed event codes and no PII in log lines.
🪪
KYC auto-approval for individuals
Individual and sole-trader accounts are verified and approved automatically on document upload — no MLRO wait. Company KYB follows the standard compliance review.
Register your tenant — control plane API
# Control plane — create tenant (after KYB application approved)
POST https://cp.algovoi.co.uk/tenants
Authorization: Bearer <admin-key>

{
  "display_name": "Acme Payments Ltd",
  "networks": ["algorand_mainnet", "voi_mainnet"],
  "payout_addresses": {
    "algorand_mainnet": "AAAA…ZZZZ",
    "voi_mainnet":      "BBBB…YYYY"
  },
  # Simplified CDD — required before first mainnet payment
  "legal_entity_name": "Acme Payments Ltd",
  "jurisdiction":       "GB",
  "contact_name":       "Jane Smith"
}

# → 201  { "id": "uuid", "short_id": "acme-x4f2",
#           "mode": "test", "kyb_status": "pending" }

# Issue a tenant API key (shown once only)
POST /tenants/{id}/apikeys
# → { "key": "ak_live_…" }
🧪
60 days free on testnet
Full testnet access on day one — no review, no fees, no card. Identical API surface to mainnet, zero code change when you go live.
KYC unlocks $1,000 free mainnet
Individuals & sole traders are auto-approved in minutes. Companies typically approved within 1 business day. UK-regulated under MLRs 2017 and SAMLA 2018.
Instant settlement
Payments land directly at your payout address on-chain. No platform float, no settlement delay — what clears is yours immediately.

Start free, settle real money

Sign up with your wallet — testnet access is instant, no review needed. Pass our quick ID check and get $1,000 of real USDC payments across Solana, Base, Algorand, Hedera, Stellar, VOI, and Tempo with zero platform fees. After that, just 0.50% per payment.

✓ 60 days free testnet✓ $1,000 free mainnet after KYC✓ All 7 chains✓ 0.50% after trial✓ UK-regulated · MLRs 2017

10-Layer
Security Stack

Every request passes through multiple independent security layers. Defence-in-depth from the network edge to on-chain verification.

Payment Flow Security Trace

Token validated
Link from DB
Kill switch check
HTML escaped
Amount from DB
Memo on-chain
HMAC signed
Indexer verified
Ledger idempotent
Redirect
🔒

TLS & Edge Protection

Nginx + Cloudflare

  • TLS 1.3 enforced at Cloudflare edge; nginx accepts only TLS 1.3 + 1.2 with strong ciphers
  • HSTS enforced (1 year, includeSubDomains)
  • Cloudflare-only origin enforcement (iptables drops direct-IP probes)
  • Rate limiting: 5 req/min auth, 60 req/min API
  • Admin API restricted to localhost
🛡️

API Authentication

Gateway

  • Argon2id-hashed API keys (64 MiB memory cost)
  • Timing-safe comparison prevents oracle attacks
  • Per-tenant rate limiting + RLS context isolation
  • 64 KB body size limit on all requests
  • CSP headers: default-src none on API routes
💳

Hosted Checkout

Payment pages

  • All display values HTML-escaped (XSS prevention)
  • Amount & receiver always from database (never client)
  • Memo binding verified on-chain (replay prevention)
  • Payment link tokens: 192-bit cryptographic random
  • Kill switch check before rendering
🔗

On-Chain Verification

Facilitator

  • HMAC-SHA256 signed internal requests
  • 60-second replay protection window
  • Direct indexer/Mirror Node verification
  • Supports Algorand, VOI, Hedera, Stellar, Base, Solana, and Tempo
  • Integer-only arithmetic (no float rounding)
🏛️

Admin & Control Plane

Operator API

  • Three-path auth: static key / JWT / DB-backed keys
  • IP allowlist checked before key verification
  • Granular scope enforcement (14 permission atoms)
  • Full audit trail on every admin action
  • CORS whitelist with wildcard guard at startup
🗄️

Database Security

PostgreSQL 16/17

  • TLS 1.3 enforced (ssl_min_protocol_version=TLSv1.3, AES-256-GCM cipher)
  • hostssl required for any non-bridge source; hostnossl reject as belt rule
  • Row-Level Security policies per tenant
  • Internal Docker network only (no host port published)
  • Self-signed CA (10y root, 825d server cert), private key kept offline
🔗

Inter-VM Network

Vultr private VPC

  • All control-plane / facilitator / KYB / bot traffic on a private VPC
  • Sub-1ms RTT between production hosts
  • No inter-VM control traffic crosses the public internet
  • VPC-only firewall on facilitator-2 (port 8001) and KYB (port 8022)
  • SSH key-only on every host (PasswordAuthentication no)
🔐

Encryption at Rest

Cryptography

  • Two-key separation: KYB documents and tenant secrets use different Fernet keys
  • Production startup refuses to launch if keys equal or unset
  • AVK1 magic-prefix scheme on KYB files (forward-compat for AVK2/AVK3 rotation)
  • MultiFernet for zero-downtime key rotation on either layer
  • API keys: Argon2id one-way hash (never stored)
📊

Price Oracle

Fiat conversion

  • CoinGecko response capped at 64 KB (OOM prevention)
  • Plausibility bounds: $0.001 - $100K per unit
  • Pure integer arithmetic (zero float precision loss)
  • 30-minute staleness check with error fallback
  • Background loop independent of request traffic
🐳

Infrastructure

Docker & Containers

  • All services run as non-root (appuser)
  • Network segregation: public + internal networks
  • Only nginx exposes ports 80/443
  • Minimal base images (python:slim, nginx:alpine)
  • Log rotation: 50 MB max, 5 files
⚙️

Configuration Safety

Startup validation

  • All secrets enforced at minimum 32 characters
  • Production mode blocks dev-only features
  • Fernet key format validated at startup
  • Localhost DB URL rejected in production
  • Secret values never logged (only length)

All security controls are code-verified against the production codebase. Full technical audit available at docs/SECURITY_OVERVIEW.md

Substrate authorship · IETF · cross-implementation evidence

We author the IETFreceipt-format substrate

Six sole-AlgoVoi-authored IETF Internet-Drafts on datatracker. 512 byte-for-byte cross-validation agreements across eight implementations and seven vector sets. A production platform that runs the substrate in production across eight chain families, plus a public adopters registry recording downstream parties anchoring to the same canonicalisation discipline. Substrate work = open standards; APM = production implementation; one acquirer story across both surfaces. The standards we author become the production stack we ship — see below.

IETF substrate

Six sole-AlgoVoi IETF Internet-Drafts

POSTED on IETF datatracker · Independent Submission, Informational

AlgoVoi authors the IETF receipt-format substrate for agentic payments under sole authorship: canonicalisation discipline + compliance + settlement + cancellation + refund + composite-trust-query. All six I-Ds POSTED on datatracker with -01 cross-reference revisions live. Anchors to urn:x402:canonicalisation:jcs-rfc8785-v1.

View on IETF datatracker →
Cross-validation

Nine-implementation cross-validation

512/512 byte-for-byte agreements · 7 vector sets

Cumulative 512 byte-for-byte agreements across two attestation runs (2026-05-24: 192/192; 2026-05-25: 320/320) covering 7 distinct vector sets under 9 independent JCS implementations across 9 languages. PHP runner uses ~50 lines of pure-stdlib inline JCS, proving the discipline reproduces in any runtime with native JSON + SHA-256.

See 8-impl matrix →
Adopter record

Substrate Adopters Registry

AlgoVoi + Supership + PEAC Protocol

A public registry of parties publishing artefacts under canon_version: jcs-rfc8785-v1. Three current entries including PEAC Protocol as the first organic downstream-adopter signal observed in the wild. Machine-readable JSON-LD mirror at /adopters.json for automated consumption by composite-trust-query verifiers and downstream tooling.

View Adopters Registry →
Production platform

AlgoVoi APM (Agent Payment Module)

Live rails + Recurr · 7 chains live + ARC testnet · non-custodial, instant finality

The production deployment of the substrate work, in three schemes. (1) Live rails — x402, MPP, AP2 and A2A across 7 live chains (Algorand, VOI, Hedera, Stellar, Base, Solana, Tempo) plus ARC testnet. Non-custodial, instant on-chain finality, no customer funds held. (2) Recurr — recurring and subscription payments the customer authorises and pays from their own wallet, settling in real time each cycle. Also non-custodial. (3) Agentic Payment Mandates — a fiat-funded (PayPal Orders v2) custodial spending-authority rail, in development, and subject to the EMR 2011 safeguarding and FCA authorisation requirements specified in our docs. It runs as a separate runtime from the live rails and Recurr and does not affect them. All five receipt formats emit under the JCS canonicalisation pin. Substrate = open standards; APM = production implementation; one acquirer story.

View APM landing →
Adversarial bench

Agent Trust Bench

193 profiles · 31 adversarial categories · 8 chains

A public, provider-neutral test suite for agentic payment security. 193 adversarial and benign x402 profiles across 31 threat categories, same profiles exposed on all 8 supported chains. RECEIVE-ONLY by invariant, $1 USDC cap per call, 30-day responsible-disclosure window, all proceeds donated. Machine-readable discovery at /.well-known/x402.json.

agent-trust-bench.algovoi.co.uk →
Verifier repo

Public audit-verifier repo

Stdlib + RFC 8785 JCS · auditor-runnable offline

External auditors verify AlgoVoi compliance retention without trusting our gateway. Reads bundle JSON offline, recomputes per-row content_hash under RFC 8785 JCS, checks chain continuity, validates HMAC envelope signature, and confirms the Object Lock COMPLIANCE manifest entry — all on an air-gapped machine.

View on GitHub →
Reference impl

16 packages on PyPI + npm · Apache 2.0

6 substrate I-D refs · rfc9421 verifier · 10 lite modules · cross-validated

Core I-D reference suite: algovoi-substrate (JCS canonicalisation + action_ref + compliance receipts), algovoi-settlement-attestation, algovoi-refund-receipt, algovoi-cancellation-receipt, algovoi-composite-trust-query, algovoi-rfc9421-verifier. Plus 10 open lite modules: agent-passport-lite, payment-mandate-lite, policy-binding, compliance-gate-lite, spend-guardrail-lite, cancellation-receipt-lite, refund-receipt-lite, composite-trust-query-lite, delegation-ref, substrate-guard. All 16 live on PyPI at 0.1.3+. Each core library matches the IETF I-D it implements.

View npm packages →
Agent identity

ARC Testnet · ERC-8004 agent registry

Agent ID 5938 · cross-protocol identity

AlgoVoi is registered as an ERC-8004 agent on ARC Testnet (agent ID 5938). Demonstrates cross-protocol identity for autonomous-payment agents — the same identity stack scales to ARC mainnet when the chain launches.

See privacy_class discussion →
Four protocols supported (x402 · MPP · AP2 · A2A) · Substrate authorship anchored across 25 independent public surfaces (IETF datatracker · npm · PyPI · GitHub · docs.algovoi.co.uk) · Independent verifiability built in — no part of the compliance posture requires trusting our gateway
Development · production product · on sale now

We ship what we standardise

The same substrate we author at the IETF — hardened, post-quantum, and on sale today. A cryptographic trust core, ten self-hosted OEM SDKs, and a self-serve store where you buy a licence in USDC and install in minutes. Standards we author; products we ship.

Cryptographic core

Substrate 2 — post-quantum trust core

Falcon-1024 + ML-DSA · Bulletproofs ZK reputation · cross-issuer federation

The cryptographic trust foundation, on-premise. Post-quantum signing by default (FIPS 204 / FN-DSA), zero-knowledge reputation — prove a score clears a threshold without revealing it, with offline-verifiable Bulletproofs range proofs — and cross-issuer federation that composes credentials with no shared trust root. Available in the Enterprise / On-premise plan.

Substrate 2 →
Commercial suite

Ten self-hosted OEM SDKs

Post-quantum-signed, offline-verifiable evidence

Settlement verification, agent passport, payment mandate, spend guardrail, privacy proofs, compliance gate, verifiable audit log, and a verifiable archive family — each a standalone Falcon-1024-signing SDK that runs in your own infrastructure. Every purchase mints a Substrate 2 receipt.

Explore the suite →
Buy today

Self-serve store — pay in USDC

7 mainnet chains · instant licence + install

Buy a Starter licence self-serve in USDC across seven mainnet chains. Settlement issues a post-quantum-signed licence key plus a one-command private-index install — on-screen and by email — so you install and run in minutes.

Open the store →
Licensing

Offline-verifiable OEM licensing

Post-quantum-signed keys · no phone-home

Every SDK verifies its own licence offline against a Falcon-1024 signature — no licence server, no callback, no telemetry. Buy once, deploy self-hosted, run air-gapped if you need to.

How licensing works →
Post-quantum signing by default (Falcon-1024 + ML-DSA) · zero-knowledge reputation (offline-verifiable Bulletproofs) · cross-issuer federation · self-hosted, no phone-home · paid in USDC across mainnet chains
Agent-to-agent settlement

Two agents settle directly.
One integration. Every chain, every protocol.

AlgoVoi Mesh lets two autonomous agents mutually authenticate with post-quantum Falcon-1024, negotiate a chain over signed offers, and settle one content-addressed reference on-chain that anyone can recompute offline. The same mesh settles the full agentic-payment suite, x402, AP2, A2A and MPP, not a single protocol. Proven on-chain across multiple chains and consensus families, including the first settlement on a UTXO chain (Bitcoin).

🔐
Mutual post-quantum auth
Each agent verifies the other with Falcon-1024 (FIPS 206) credentials before anything settles. No shared secret, no central issuer in the path.
🧩
Every protocol, one mesh
x402, AP2, A2A and MPP payment flows all settle through the same Mesh. You are never locked to a single rail or a single protocol.
⛓️
One primitive, every chain
The chain never verifies Falcon, it only carries a 32-byte anchor. One integration settles on account-model and UTXO chains alike, including Bitcoin.
🧾
Content-addressed settlement
Every settlement is one execution reference anyone can recompute from the raw fields with stock RFC 8785 and SHA-256.
🔎
Offline-verifiable
A relying party confirms the settlement offline against the bundled issuer key, with no call back to AlgoVoi.
🚫
Non-custodial by design
AlgoVoi never holds funds and is never a party. The two agents settle directly; we anchor the proof.

Post-quantum settlement at the agent boundary

The agent-to-agent trust stays post-quantum even on chains whose own signatures are not, because the chain only ever carries the anchor. AlgoVoi Mesh is a $299 perpetual licence, per enforcement boundary, self-hosted, with no metering.

Open core

Free to build on.
Paid where it counts.

Build the whole agentic trust chain with the open Keystone toolchain, then license the cores that carry value. Every core is self-hosted, offline-verifiable, and non-custodial.

L3 · agent-to-agent
AlgoVoi Mesh
$299
Two agents settle directly on any chain, mutually authenticated with post-quantum Falcon-1024. One content-addressed reference, verifiable offline.
View in the store →
L2 · prove the task
Keystone Journey
$99
Bind a whole multi-agent task into one content-addressed journey_ref and verify its continuity, scope and completeness offline. The free framework adapters call this engine.
View in the store →
L2 · kill switch
Keystone Revocation
$99
Offline-verifiable revocation references for agent credentials and keys. Revoke once, check from the bytes, no phone-home and no fail-open.
View in the store →

Run the whole estate yourself

When you need the operator platform, AlgoVoi Payment Rails and the Verifiable Compliance Suite are self-hosted, one-time perpetual licences from $15k. Your Keystone references are the evidence they consume.

See all bundles on the store →

Prefer to try it hands-on? The multi-chain wallet and the live x402 / MPP / agent demo run in your browser.

Try the live wallet and agent demo →

Ready to pay the web
with crypto?

AlgoVoi is free, open source, and built for on-chain micropayments and AI agent commerce. Swap tokens, connect agents, and pay the web — install in seconds.

Building on agents? Run your own rails.

Self-hosted x402 / MPP / AP2 / agent-to-agent rails with operator custody, where every settlement produces a post-quantum signed receipt an auditor verifies offline with stock open-source tools. One-time perpetual licence, from $15k. Verifiable Compliance Suite from $15k.