Payment authorization & evidence layer · built on ORBIS.ID

One tap.
Proves who you are,
pays, and keeps the receipt.

One signature.
Identity, age and payment
proof your disputes have never had.

Scan one code at any checkout. Everything happens on your own phone: you see the shop's real legal name and the exact amount, you choose how to pay, and one fingerprint or face signs it. Your card, your key and your biometrics never leave the device. You keep a receipt no one can alter.

A card authorization proves a card was presented. It never proves a specific person agreed to specific terms — which is why merchants lose most disputes they contest. ORBPAY replaces the argument with a signature: identity, entitlement and the exact amount, signed once on the customer's device, delivered to your backend, charged through the PSP you already use.

1signature per purchase
0card numbers on the web page
$0held or moved by ORBPAY, ever
Freeverification, offline, forever
ORBLINK app: scanning a merchant ORBPAY code ORBLINK app: verified offer from Demo Bistro, $84.20, age over 21 will be proved, pay with Chase ••4291 ORBLINK app: system biometric prompt — Confirm payment $84.20 to Demo Bistro ORBLINK app: Signed — one signature over identity, amount and merchant ORBLINK app: sealed receipt with verification checklist
Merchant checkoutShows a QR: reference + channel key. No amount, no URL.
ORBPAY registry · read-onlyPhone confirms “Demo Bistro” is a verified, permissioned merchant.
Merchant backendSigns the offer. Later receives the signed mandate.
Merchant’s own PSPCharges exactly $84.20 and returns an auth code.
ORBPAYNever in the funds path. Holds no card, no key, no biometric, no data.
1 · Scan — the code carries a reference and a channel key, nothing to open
Never holds funds. The merchant charges through its own PSP.
The key is born in your phone. Non-exportable, biometric-gated.
Renders only signed data. What you see is what you sign.
A receipt nobody can edit. Held by both sides, verifiable offline.
Merchants can only request. Never charge.

How a purchase actually happens

Thirteen messages. One signature. ORBPAY appears in exactly one of them — and it is a read.

Step through the ceremony. Watch what crosses each boundary, and what never does. The red zone is the regulated funds path: money moves there, between the merchant and the merchant’s own processor. ORBPAY is never inside it.

Custody, made visible

Pick anything sensitive. See who holds it. Notice the empty column.

The question every payments company gets asked is “what happens if you are breached?” Our answer is structural: there is nothing to take. Money, card details, biometrics and personal data each live with exactly one party — and it is never ORBPAY.

The money

ORBPAY: never

Moves once, from your bank to the merchant, through the processor the merchant already has a contract with. ORBPAY has no PSP keys, no gateway calls and no account — the build fails if any ORBPAY code path can reach a payment endpoint.

Your phone
Merchant
Merchant’s PSP
ORBPAY
Enforced in the build, not in a policy: no-unported-network — the phone may only talk to three host classes: the static registry (read), the merchant’s channel endpoint, and the merchant’s PSP. Nothing else compiles.

Inside ORBLINK · Wallet › ORBPAY

Every screen renders only what was signed.

These are the actual ORBPAY screens from the ORBLINK app. The offer sheet cannot display a value from a web page — its inputs are typed so that only a verified, merchant-signed offer can reach it. What you see is, literally, what you sign.

At the counter

Age check and payment in one scan. No card. No ID out of the wallet.

A bottle of wine at a corner shop today means two rituals: show an ID, then tap a card. With ORBPAY the terminal shows one code. Your phone proves “over 21” — not your birthdate, not your name — and pays, in the same signature. Press play.

HARBOR MARKET · LANE 2ORBPAY READY
Harbor Market
Pinot Noir 750 ml 21+$24.00
Sparkling water ×2$3.60
Sales tax$2.28
Total$29.88
SCAN WITH ORBPAY · EXPIRES 04:59
Approved
RECORD SEALED · rec_9K2…
Age over 21 — proved by DIDit-issued passport
$29.88 authorised · auth A1B2C3
Customer signature verified · non-repudiable
No card data touched this terminal

What happened, in order

  1. 1Terminal shows the codeReference + channel key. Under five minutes to live. Nothing to open, nothing to type.
  2. 2Phone checks the shopReads the signed registry: Harbor Market is a real, permissioned merchant, in good standing right now.
  3. 3Phone pulls the signed order$29.88, three lines, one item flagged 21+. The terminal’s screen is never trusted — only the signature.
  4. 4You approve, once“Pay $29.88 to Harbor Market · age over 21 will be shared.” Face or finger. One signature covers the proof and the payment.
  5. 5Merchant charges its own processorExactly $29.88. Not a cent more can ever be taken under this signature.
  6. 6Record sealed, both sides keep itOffer + your acceptance + auth code, hash-chained. The clerk sees “Approved · 21+”. You keep the receipt forever.
What did not happen
  • No driver’s licence was shown — the clerk never saw a name or a birthdate
  • No card was inserted, tapped or typed — the terminal holds no PAN
  • No fake QR could redirect the phone — the code contains no URL to open
  • Nothing about this purchase reached ORBPAY except a hashed “it happened”

Why people use it

Why businesses adopt it

Your key. Your phone. Your receipt. Nothing of yours on anyone’s server.

Fewer disputes to lose, no identity vendor to pay, and the PSP you already have.

The key that spends is born in your phone

Generated inside the Secure Enclave or StrongBox, never exportable — not by you, not by us, not by a court order served on ORBPAY. A stolen, unlocked phone can’t sign: every signature needs a fresh face or finger.

You see the shop’s legal name — never a look-alike domain

The phone resolves the merchant from a signed public registry and displays “Demo Bistro”, its verified entity, not whatever a page or a sticker says. First-time merchants are flagged before the sensor is ever offered.

The amount you see is the amount that is signed

Nothing from the web page is ever displayed or signed — only the merchant-signed offer pulled over an encrypted channel. A hacked checkout showing $47.30 while charging $4,730 simply cannot happen.

Merchants can ask. They can never charge.

A tip, a minibar, a renewal at a new price — each arrives as a request you approve or decline. Silent charges and surprise renewals are impossible by construction, not by policy.

Prove “over 21” without handing over your birthday

Your KYC passport is issued once by DIDit and lives in your wallet. Merchants receive a single yes/no fact, never the document. No more uploading your ID to every shop that sells wine or vapes.

A receipt that is proof, not a claim

Three signatures sealed together — the shop’s offer, your acceptance, the processor’s authorisation. You can verify it on your phone in airplane mode, years later. Nobody, including ORBPAY, can edit it.

75%of card-not-present disputes at digital merchants are first-party fraud — real customers who bought, then disputed.Datos Insights / Mastercard · Jun 2026
8.1%net share of disputes merchants actually win when they contest — because the evidence is reconstructed, not recorded.Industry dispute data · 2024
$4.61true cost to a US merchant per $1 of fraud loss, once fees, goods, labour and chargebacks are counted.LexisNexis · Apr 2025

Non-repudiable consent, captured before the money moves

A hardware-bound, biometric-gated signature over the exact terms is the strongest dispute evidence that exists. “I didn’t recognise it” meets a record of who agreed, to what, when.

Age verification and payment in one signature

Stop paying an identity vendor per check and storing the results. The mandate carries age_over_21: true from a DIDit-issued credential, cryptographically inseparable from the payment authorisation.

Take payment data off your page entirely

No card number, name or ID ever passes through your checkout. Web-skimming has nothing to skim, and PCI DSS 4.0.1 §6.4.3 / §11.6.1 script monitoring stops being your problem on that page.

PCI DSS 4.0.1 mandatory since 31 Mar 2025

Keep your PSP, your acquirer, your rates

The phone tokenises the customer’s card directly with your processor using your publishable key. Your backend charges as it does today. No migration, no new money relationship, no re-plumbing.

Quishing-proof by design

Your ORBPAY code carries no URL. A counterfeit sticker or injected QR cannot make a phone contact anything the signed registry does not name. Your brand stops being a phishing vector.

Request tips, incidentals and renewals — and get approvals that can’t be charged back

Every follow-up produces its own signed record chained to the original. More signatures, never looser ones: each is a two-second push to a device you already paired.

Why the maths closes quickly

A merchant doing $1m/month in high-risk card-not-present volume carries roughly $62,800 a month across chargebacks and fraud, the high-risk processing premium, an age or identity vendor, and payment-page PCI obligations. ORBPAY costs on the order of $1,000. A ten percent reduction pays for it six times over — and verification of every record is free, forever.

See the integration

Anatomy of the evidence

One document, signed once. Then sealed with two more signatures.

Hover or tap any field. The composite mandate binds identity, merchant, amount, order and instrument so they cannot be separated. The sealed record adds the merchant’s offer and the processor’s authorisation — three independent signatures, one immutable artifact, held by both parties.

JWS · alg ES256 · typ orbpay-mandate+jwt · kid did:jwk:… · signed in the Secure Enclave / StrongBox
"mandate_id": "md_7Qx…",REPLAY KEY "iat": 1757900045, "exp": 1757900165,120 S "claims": [ { "format": "sd-jwt-vc", age_over_21 → true } ],232 "merchant": { "did": "did:web:id.demobistro.example", "legal_name": "Demo Bistro" },234 "amount": { "minor": 8420, "currency": "USD" },236 · FINAL "offer_digest": "sha256:c1f0…",238 "instrument": { "rail": "card", "token_ref": "sha256:9a…", "display": "Visa ••4291" },240 "options_chosen": [],BEFORE SIGNING "nonce": "n_Qp…", "session": "sha256:…",242 "dev": { "assurance": "secure_enclave" }INFO
⟡ ONE SIGNATURE (244) · ES256 · key never leaves the device · biometric-gated per use

This is how ledgers have worked for five hundred years: an invoice is never amended, a credit note is issued. Auditors and ERP systems understand it instantly — and every link is verifiable without ORBPAY.

Try to break it

Six attacks that end payment products. Run each one against the phone.

Every attack below is a switch in our reference test merchant, and each must be rejected for the build to pass. Choose one to see how the phone responds — the rejection reasons are the real enumerated codes, not marketing.

orblink › orbpay › ceremony.log

        
Rejected before the sensor was offeredThe phone renders only from the merchant-signed offer. The page is never trusted, so it is never in the signature.

Where ORBPAY sits

Every serious system binds one axis well. The join is unoccupied.

Apple has the key but splits identity and payment into separate APIs. Google’s AP2 has the signed mandate but no identity binding and a coalition gate. W3C SPC binds the amount but trusts the page and stops at Chromium. BankID has the signature but stops at the border. Each holds at most two cells.

SystemIdentity in
same signature
Renders only
signed data
Works outside
the browser
No scheme
gate
Portable
receipt
Request-only
charging
No licence
needed
Any
rail
ORBPAY
W3C Secure Payment Confirmation
Apple Pay + Verify with Wallet
Google Pay + Wallet ID
Google AP2 (agentic mandates)
EMV 3DS + delegated authentication
Pix · UPI · Swish · BLIK · Wero
BankID · itsme · MitID
Yoti · Persona · Incode · Jumio
holds it partly, gated, or by exception does notORBPAY marks are specified architecture, build phase-gated · competitor marks from published documentation, Sept 2026

For businesses · integration

Drop in a widget. Sign your offer. Keep your PSP.

Your web page becomes a display surface — it shows a code and, later, “paid”. Your backend does three things it is already good at: sign an order, accept a document, call the processor it has a contract with. No customer data ever touches your front end.

Onboard as a permissioned merchant

An organisation account is opened by a real, KYC’d person holding an ORBLINK key. Your legal name and offer-signing key go into the signed public registry. That is what the phone displays.

Sign the offer server-side

Items, tax, shipping, options, the final amount, your PSP’s publishable key — signed with a key in your HSM. The checkout widget renders the engagement token as a QR, NFC or deep link.

Accept the mandate at your channel endpoint

Our SDK verifies every check: your offer digest, the recomputed amount, nonce and session, the customer’s credential binding, replay. Any failure is a signed decline — no gateway call is made.

Charge your own PSP. Seal the record.

Create the PaymentIntent for exactly the mandated amount with the single-use token the phone minted at your PSP. On authorisation, seal the record and return it. Verification is free for everyone, forever.

// checkout page · display only · nothing sensitive ever renders here
const session = await fetch("/orbpay/session", { method: "POST", body: cart }).then(r => r.json());
orbpay.widget("#pay", { token: session.engagement_token });   // ORBPAY1.<ref + channel key> — no amount, no URL

// backend · your HSM signs; your PSP charges; ORBPAY receives nothing but a hashed metering event
const offer   = signer.signOffer({ mid, ref, amount: { minor: 8420, currency: "USD" }, lines, required_claims: ["age_over_21"], psp: { provider: "stripe", publishable_key } });
channel.onMandate(async ({ mandate, instrument_payload }) => {
  const ok = orbpay.verifyMandate(mandate, { offer, registrySnapshot });          // offline-capable; every check enumerated
  if (!ok.pass) return channel.decline(ok.reason);
  const pi = await stripe.paymentIntents.create({ amount: 8420, currency: "usd", payment_method: instrument_payload.psp_token, confirm: true });
  return channel.seal(signer.sealRecord({ offer, mandate, authorization: pi }));     // three signatures, one immutable record
});

Any rail

Card first (Stripe, then Adyen). Bank transfer, Pix, UPI, stablecoin — the mandate is identical; rail is configuration. ORBPAY competes with no rail and can authorise onto all of them.

Any surface

Web checkout, in-app, POS terminal, kiosk, invoice, agent-to-merchant. The engagement token is modality-agnostic: QR, NFC, BLE or deep link carry the same payload.

Free verification, forever

Anyone — an auditor, a bank, a regulator, the customer — verifies a record against static signed files on a CDN. A total ORBPAY outage does not stop a single verification.

What’s real, stated the way the app states it

ORBPAY’s architecture is complete and its artifact formats are defined; the build is phase-gated on ORBIS.ID and ORBLINK, which are close to release. Capabilities on this page are described as specified, not as shipped. The screens above are the ORBLINK shell running in sandbox mode; the same “What’s real” register that labels each capability inside the app labels every claim here. External figures are dated and sourced. ORBPAY is a technical service provider by design — it never initiates a payment or holds funds — a reading we consider favourable, not adjudicated, and one we will confirm with formal opinions before scale. Structure: ORBPAY is a separate company with strategic relationships to ORBIS.ID and ORBLINK. Nothing here is investment, legal or financial advice.