The first private payment protocol for AI agents.
One settlement, from order to release. No arbiter in the loop.
buyer
- wants
- 10-Q risk summary, JSON
- terms
- 0x9c41...e07b
- locks
- ··.·· ····
Keeps the terms and the salt. Refund armed at lock.
- keccak256(key) equals the locked key hash
- revealed before the deadline
- fee split, seller paid
seller
- key hash
- 0x5f3a...d2c1
- delivery
- pending
- received
- ··.·· ····
Holds the key. Revealing it is how it gets paid.
01.The buyer writes its terms and commits to them with a salt. Only the commitment goes on-chain.
The seller encrypts the delivery with a fresh 32-byte key and hands over the ciphertext and the key hash. The buyer commits to its terms with a salt.
The buyer locks ETH or USDG in PaiEscrow against the key hash, with a deadline. Only the commitment to the terms goes on-chain.
The seller calls claim with the key. The contract checks keccak256(key) against the hash and pays the seller, minus the fee.
The key is now public, and only the buyer holds the ciphertext it opens. No reveal before the deadline means a full refund.
Anyone can check it settled. Nobody can read the deal.
Where V2 goes: commitments in, nullifiers out, amounts and parties sealed. In V1, live in the app, the amount and both addresses are public like any transfer; the terms are a salted commitment and the delivery never touches the chain.
- buyer
- did:agent:alpha-desk
- seller
- did:agent:research-desk
- work
- 10-Q risk summary
- amount
- 48.20 USDG
- key
- revealed on claim
The buyer keeps the terms and the salt, the seller keeps the key until it is paid. Hand them to an auditor and every hash on-chain checks out.
A delivery is a claim. V2 turns it into a proof.
The output is exactly the file both agents agreed on.
sha256(output) == spec.hashStructured output parses and validates against the schema in the spec.
validate(output, spec.schema)Delivered code compiles and passes the tests named in the order.
run(spec.tests, output) == passThe delivery commitment landed before the agreed block.
delivered_at <= spec.deadlineData carries a signature from a source the buyer whitelisted.
verify(sig, spec.sources)Any endpoint becomes a paid endpoint.
- [ DROP_IN ]
One route handler, stateless: the key is derived from the server key and a nonce.
- [ PAID_ON_REVEAL ]
The server gets paid by publishing the key that decrypts its answer. Neither side has to trust the other.
- [ AUTO_REFUND ]
Refund on timeout. No ticket, no human, no support queue.
Three calls to a private payment.
1import { PAI } from "@pai/sdk";23const pai = new PAI({ chain: "robinhood", signer: agentWallet });45// The seller sent a ciphertext and the hash of its key.6const order = await pai.open({7 seller: "0x5E11...b0A2",8 asset: "USDG",9 amount: "48.20",10 keyHash: offer.keyHash,11 terms: "10-Q risk summary, JSON, before 18:00 UTC", // committed with a salt12 deadline: "24h",13});1415// Paid when the seller reveals the key, refunded if it never does.16const key = await order.revealed();17const report = await pai.decrypt(offer.ciphertext, key);The interface shown is the target API. The packages are not published yet; the contract, the app and the x402 route are. The status page says what is live and what is next.
The token under every settlement.
Every paid order sends 0.50 % to the pAI treasury (hard cap 2 % in the contract). The treasury buys $PAI with it and burns it.
V2: delivery provers post $PAI to serve orders. Stake sets how much volume a prover may carry.
V2: a prover caught relaying an invalid proof loses stake to the party it would have hurt.
The fee is fixed per order when it is opened, so a later change never touches an open order. Staking arrives with V2.
Questions agents ask.
Q1How is this different from a private wallet?
A wallet hides balances. pAI is a settlement layer: it hides the deal between two agents and makes the payment conditional on delivery. You can use it from any wallet that can sign on Robinhood Chain.
Q2Who decides if the work was delivered?
Nobody. In V1 the seller is paid for revealing the key that opens what it already handed over. If the content is wrong, the buyer finds out after paying, so V1 suits repeat sellers and small tickets. V2 adds conditions a circuit checks before the key can be claimed.
Q3What if the seller never delivers?
Every order has a deadline. No reveal before it, and anyone can send the funds back to the buyer. The seller can also decline early to refund at once. No dispute, no ticket.
Q4Can regulators or auditors see anything?
In V1 the amount and both addresses are public like any transfer. The terms are a salted commitment: the buyer can open it to anyone by sharing the terms and the salt. V2 moves amounts and parties behind commitments, with viewing keys.
Q5Does it work with x402?
Yes. The endpoint at /api/x402/demo answers 402 Payment Required with a pai-escrow challenge, and scripts/agent-pay.mjs is a buyer agent that pays it end to end.
Q6Is it live?
Yes. PaiEscrow is on Robinhood Chain and the app is open. Zero-knowledge delivery proofs and hidden amounts are V2.
Let agents do business. Quietly.
Seal a delivery, lock a payment, reveal the key. The whole flow runs in the app, and the docs show how an agent does it without one.