Codeproof · Fluxus ForgeVault · Ledger · Reveal
Sealing000%

Every code carries proof

Prepaid brand codes · one API · India-first

Brand vouchers sourced from global suppliers and sold through one API — every code envelope-encrypted, revealed exactly once, and reconciled to the paisa on a double-entry ledger.

[ Single reveal ][ Double-entry ][ Idempotent ]

Sealed, then shown once

Envelope-encrypted per code · reserve-then-commit wallet · a supplier timeout is held, never retried blind.

1Reveal per code
0Blind retries
₹0.01Reconciliation grain
100%Codes sealed at rest

Built by Fluxus Forge

Sealed, then shown once

In build · partner access by invitation.

The same ledger discipline and signed-event contract as Fieldproof — for prepaid codes.

Request access
01 · The product

Distribution, not a marketplace.

Closed-loop brand codes — app stores, gaming, streaming, retail — bought by businesses from a prepaid B2B wallet, delivered sealed, and accounted for journal by journal.

Codeproof is

Infrastructure for selling codes safely.

  • B2B-first distribution of closed-loop brand codes
  • A prepaid B2B wallet per partner, topped up by bank transfer
  • An API with quotes, idempotent orders, single reveal and signed webhooks
  • A ledger where every balance is a sum of postings
Codeproof is not

A wallet, a PPI or a listing site.

  • No stored value for individuals, no consumer wallet
  • Not a marketplace — we are the principal
  • Codes never sit in plaintext — not in logs, events or our console
  • Not live at scale — in build, onboarding by invitation

Every outcome, as an event.

Delivered, partly delivered, quarantined, held for the supplier — each one a signed, sequenced event your webhook receives. Illustrative data, real contract.

POST your-app.example/webhooks/codeproof200 OK
partner YOURORGseq 1040–1044signature verified
1
wallet.creditedfinal09:28:39
amountMinor5000000utrUTR2026092900421
2
order.fulfilledfinal09:29:17
orderIdord_7Q2KclientReferencetxn-8841codes3 × ****-****-…
3
order.partialfinal09:29:55
requested10delivered7refundedMinor147000
4
code.quarantinedclaim09:29:56
codeIdcod_M4XDreasonREGION_MISMATCH
5
order.ambiguousheld09:30:50
orderIdord_A91Pmoneyheld, not refundednextresolver asks supplier
HMAC
SHA-256 signed
ORDER
per-partner seq
DELIVERY
never dropped
REPLAY
GET /v1/events
02 · Three channels, one core

One vault behind every counter.

Channel 1 · in build

API partners

Recharge apps, kirana aggregators and reward platforms buy through the /v1 API or the partner portal. The volume channel, and the first one.

Channel 2 · coming

TapProof merchants

A “Sell vouchers” tab for TapProof merchants: kiranas sell codes at the counter and earn a commission, with the reveal behind the app PIN.

Channel 3 · coming

VIKAM consumers

A catalogue inside the VIKAM app, UPI-only, with device-bound reveal and velocity limits.

03 · How an order works

Reserve first. Settle what arrives.

01 · Quote

Price fixed

Landed cost from supplier cost and FX; your price from face value minus your discount — held until the quote expires.

02 · Reserve

Money held

Under a lock on your wallet: status, tier caps and balance checked, the amount moved from available to reserved. Never negative.

03 · Supplier

Bought once

Our order id is the supplier reference, so the supplier itself dedupes. A timeout is never retried as a new purchase.

04 · Sealed code

Validated, encrypted

Region, denomination, expiry and duplicates checked. Good codes sealed; bad ones quarantined and claimed back.

05 · One reveal

Shown once

Plaintext only on an explicit reveal, once per code, audited with the device id. A second attempt returns the original timestamp.

06 · Ledger

Settled to the paisa

Delivered units settle reserved → supplier float + margin; undelivered units release to available in the same transaction.

04 · Security and money

Built for the day it goes wrong.

Single-reveal vault

Plaintext exists twice: in transit, and in your one reveal.

Per-code envelope encryption bound to its context, masked everywhere else. The reveal flips the code, decrypts and audits in one transaction.

Double-entry ledger

Balances are sums, never stored numbers.

Append-only journals, balanced by the database. Top-ups are idempotent on the bank UTR. Corrections are new journals, never edits.

Ambiguous orders

Unknown means held, not guessed.

When a supplier times out, money stays reserved while a resolver asks the supplier about that exact reference — then delivers or releases.

Idempotent orders

Retry without fear.

The same Idempotency-Key returns the original result. A different body under the same key is rejected.

Partial fulfilment

Pay for what arrives.

Asked for 10, got 7: you get 7, pay for 7, and 3 are released to your balance in the same transaction.

Tier caps

Limits inside the lock.

Daily and monthly caps are enforced at order time, inside the same lock that reserves the money.

05 · For developers

Three calls to a sealed code.

Bearer-key REST, quotes with a TTL, idempotent orders, and sequenced, HMAC-signed webhooks you can replay from any sequence number.

Partner API · /v1
# 1 · Quote — the price is fixed until expiresAt
curl -s https://codeproof.fluxusforge.in/v1/quotes \
  -H "Authorization: Bearer $CODEPROOF_KEY" \
  -H "Content-Type: application/json" \
  -d '{"sku":"GPLAY-IN-500","qty":2}'

# 2 · Order — the Idempotency-Key makes a retry safe
curl -s https://codeproof.fluxusforge.in/v1/orders \
  -H "Authorization: Bearer $CODEPROOF_KEY" \
  -H "Idempotency-Key: 0b9e6c1e-…" \
  -d '{"quoteId":"q_…","clientReference":"txn-8841"}'
# → 201 FULFILLED · 202 SUPPLIER_AMBIGUOUS (money held)

# 3 · Reveal — plaintext once, audited per device
curl -s -X POST https://codeproof.fluxusforge.in/v1/orders/$ORDER/codes/$CODE/reveal \
  -H "Authorization: Bearer $CODEPROOF_KEY" \
  -H "X-Device-Id: pos-terminal-12"
Webhook delivery
POST https://your-app.example/codeproof
X-Codeproof-Event: order.partial
X-Codeproof-Seq: 1042
X-Codeproof-Signature: t=1767000000,v1=5f2c…e9

{
  "seq": "1042",
  "type": "order.partial",
  "createdAt": "…",
  "data": {
    "orderId": "…", "clientReference": "txn-8841",
    "requested": 10, "delivered": 7, "refundedMinor": "147000",
    "codes": [{ "codeId": "…", "masked": "****-****-7Q2K", "expiresAt": "…" }]
  }
}
// Signed: HMAC-SHA256(secret, t + "." + body)
// Ordered per partner by seq · retried with backoff · never dropped
Full API reference
06 · Onboarding tiers

Caps follow your KYC.

Every partner is one legal entity with one wallet. Tier and caps are set at onboarding and enforced on every order.

TierWhoKYCMonthly capChannels
T0Consumer — individual, own useMobile OTP + PAN + device binding₹25K / month, ₹10K / day, 3 codes / dayVIKAM / web
T1Reseller — proprietor or freelancerAadhaar eKYC with liveness + PAN + penny-drop + selfie₹2L / monthApp + portal
T2Proprietorship, partnership or LLPUdyam or GST + firm PAN + partner KYC + bank in firm name + premises proof₹25L / month (₹5L without GST)Portal + API
T3Private limited companyCIN + MCA directors + board resolution + GST + company PAN + bank in company name + UBO ≥ 10%₹5Cr / month, raised on historyAPI + portal
T4Enterprise — aggregators, fintechs, corporatesT3 + your AML policy + site or video visit + addendumCustom, optional credit lineAPI
07 · Questions

Straight answers.

Codeproof is in build. The core — catalogue, pricing, orders, the single-reveal vault, the double-entry ledger and the partner API — runs today against a simulated supplier. Partner access is by invitation while we complete supplier contracts and go-live checks.

No. Codeproof sells closed-loop brand codes to businesses. Partners hold a prepaid B2B balance with us to buy codes; there is no stored value for individuals and no consumer wallet.

By bank transfer (UPI, NEFT, RTGS or IMPS) to your own virtual account, whose details you receive during onboarding. Every credit is matched to its bank UTR and can never be applied twice. Cards and net-banking are not accepted.

The order becomes “Confirming with supplier”. Your money is held — not spent and not refunded blind — while our resolver asks the supplier what happened to that exact order reference. It then settles to delivered or refunded. We never re-buy, so you are never charged twice.

Codes are envelope-encrypted per code the moment they arrive and are masked everywhere, including in our own console. Plaintext exists only in the one reveal response you request, and every reveal attempt is audited.

Every code is validated before it is sealed — region, denomination, expiry of at least 60 days, duplicates. A code that fails is quarantined, you are not charged for it, and we raise a claim against the supplier.

08 · Request access

Access is by invitation.

Tell us who you are and how you would distribute codes. We review every request and reply by email.

Every code carries proof.

Read the API