[ DOCUMENTATION_MENU ]
[ OVERVIEW ]

Status and roadmap

What exists today, what ships next, in order. No dates we cannot keep.

This page is the single source of truth about what is real.

Live on Robinhood Chain mainnet

  • PaiEscrowV2, every order opened against a zero-knowledge proof of delivery: 0x6FdD0A840f29bA1F4b67b2328343D949dc4764A0. ETH and USDG, refund after the deadline, release by the buyer, decline by the seller, fee 0.50 % snapshotted per order and capped at 2 % in the contract.
  • DeliveryVerifier, the Groth16 verifier for the delivery circuit: 0x8E3D0C497CCbB0cc44663A2D5Df00Fd131C29f06.
  • PoseidonT2, the circomlib-compatible Poseidon the claim checks the key with: 0xd4De205c325cAFBc11a1FebdB061bF00cA48Cc4b.
  • All three verified on Sourcify (exact match). 17 Foundry tests on V2 run against real snarkjs proofs, including tampered and swapped proofs.
  • The app at /app: prepare a delivery and prove it in the browser, check a package and lock against it, claim, refund, release, decline, decrypt, and an explorer that reads every order from the contract.
  • A live x402 route at /api/x402/demo that proves its answer server side, and a buyer agent, scripts/agent-pay.mjs, that verifies the proof before paying. See x402 integration.
  • PaiEscrow V1, the hash-lock escrow without proofs, stays readable at 0x0b5aacaB93ee0Ce06da9aF3F151b2671F69b4805. New orders go to V2.

Not live yet

  • $PAI launches on Pons, on Robinhood Chain. Until the address is posted on this site, there is no official token.
  • The animations on the home page are simulations and say so.
  • The phase 2 trusted setup has a single contribution. See zk delivery proofs.

What pAI hides, and what it does not

Today Next
What was ordered salted commitment salted commitment
The delivery never on-chain, encrypted, proven in zero knowledge same
Delivery checked before payment yes, Groth16 proof verified by the buyer and by the contract plus content conditions
Amount and asset public inside a commitment
Buyer and seller public shielded

Roadmap, in order

  1. Multi-party phase 2 ceremony for the delivery circuit, then a new verifier.
  2. SDK alpha. @pai/sdk wrapping prove, verify, open, claim and decrypt, the same calls the app makes.
  3. x402 middleware. @pai/x402, the demo route packaged for any server.
  4. Content conditions. Schema and signed-source circuits on top of the delivery proof.
  5. Larger deliveries. Chunked proofs and a prover network for files beyond one proof, with provers staking $PAI.
  6. Shielded escrow. Commitments, nullifiers and viewing keys, so amounts and parties leave the public record.

Each step is announced here when it ships, with addresses linked.