Sean-Claude Van Damme's General Store • Oak City

The Trade Counter

Try it now, no account

Why a marketplace would

How it works

  1. The sandbox, first. Before any conversation, sign against the sandbox account with the secret printed on this page. Real signatures, real goods, marked test, booked nowhere. POST /api/trade/sandbox/check tells you which of the four checks your signer fails and why, without delivering anything. Check it yourself: The sandbox's secret, dialect and daily cap are on its account row at /api/trade/contract; its deliveries appear on /api/trade/ledger as test, never billed.
  2. The account. The keeper opens an account by hand: your platform, your signing dialect, the items you may order, a daily cap, a credit ceiling. You issue us one signing secret (and a provider key if your scheme sends one). We hold them as Worker secrets; nothing of ours is ever asked of you. Check it yourself: Your account's row — items, share, cap, ceiling, mode — is printed at /api/trade/contract the moment it exists, and its receivable is on /api/trade/ledger.
  3. The sale, on your side. Your customer buys the item from you at your price, in your currency, on your terms. We are not in that transaction and never see it. Check it yourself: Nothing to check with us — which is the point. Our trade price per item is public; what you charge above it is yours.
  4. The instruction. Your backend POSTs one JSON body to /api/trade/{account}/{item_id}, signed HMAC-SHA256 over timestamp, nonce and the exact bytes of the body. We check the signature, the five-minute window, and that the nonce has never been seen — on a store that answers the same from every edge. Check it yourself: The reference signer is published in this repository (src/lib/trade-auth.ts, signTradeRequest); sign a body with it and compare bytes with your own before any account is live.
  5. The delivery. The goods are made exactly as the front door makes them — the probe runs, the record is written, the certificate is minted — and come back in one JSON object inside thirty seconds. A delivery that fails books nothing: no statement line, no receivable. Check it yourself: The certificate says settled_via: trade_account, names your account and the trade price, and binds the sha256 of your signed instruction. It carries no chain fields, because no chain was involved, and it verifies free forever at /api/verify/{cert_id}.
  6. The statement. Each delivery on a live account adds one line to your statement: item, trade price, your share, our net. Outstanding net is the receivable, published per account. You pay on your cadence; the keeper records each payout by hand and the two sides are reconciled against each other. Check it yourself: /api/trade/ledger prints every account's delivered count, billed and outstanding figures, with the truncation flag any bounded read here carries. Your own rows, both sides, are yours to read at GET /api/trade/{account}/statement, signed like any order.

The shelf at the counter

ItemRetailTrade priceStore netsFields
Certificate of Patronage$20$25.27$24.00order_ref, agent_name, purpose
Context Anchor$1$1.27$1.20summary, order_ref, agent_name, purpose
A Bitcoin Anchor$1$1.27$1.20digest, label, order_ref, agent_name, purpose
The Calling Card$0.99$1.26$1.19url, order_ref, agent_name, purpose
The Shop Window$3$3.79$3.60url, order_ref, agent_name, purpose
The Once-Over$5$6.32$6.00url, order_ref, agent_name, purpose
The Refresh$1$1.27$1.20url, order_ref, agent_name, purpose
The Good Buyer$0.99$1.26$1.19url, max_usd, no_spend_controls, order_ref, agent_name, purpose
The Company an Address Keeps$5$6.32$6.00address, order_ref, agent_name, purpose

The call

Every refusal, by name

What the receipt says

Accounts open

Questions people ask

What this is not

What you can do with this

Back to the front of the store. Agents: /llms.txt, /skill.md, or /menu.json.