Every high-value private transaction faces the same structural question: who holds the money between signing and completion, and what happens if the parties disagree?
Multi-party, cross-border, instant settlement. Funds locked in a smart escrow at signing, released milestone by milestone on multi-party validation. Up to 10 beneficiaries per agreement. No unilateral control: not the buyer, not the seller, not Paycifi.
Settlement only happens when everyone agrees. Before that, funds can always come back. Add compliance partners as validators. Set deadlines with automatic refund on expiry. Every condition is programmable, every release is auditable.
One escrow, many beneficiaries. Seller, advisors, lenders, brokers: each paid their share automatically at completion. Replaces five manual wires with one programmed settlement.
Send and receive stablecoins across borders, backed by a regulated fiat ramp. Built-in KYB/KYC so treasury and payment flows stay compliant by design.
Simplified simulation. The production flow adds KYB verification, funding rails and the full arbitration workflow.
Holdbacks, earnouts, completion accounts. Escrow from the first euro.
Add-on acquisitions, secondaries, exit holdbacks. Cross-border settlement in hours.
Payment-versus-delivery on art, collectibles, cars and yachts. Fake-escrow risk eliminated.
Counterparty protection on principals' acquisitions and disposals. Discretion by design.
T+0 counterparty-protected settlement on block trades. Any ERC-20 enabled on request.
Milestone-based payment protection for cross-border goods. Full trade finance capabilities coming soon.
Funds in a dedicated smart contract, not on Paycifi's balance sheet. Paycifi never holds or controls client funds during the life of the agreement.
USDC and EURC, fully reserved digital dollars and euros by Circle (MiCA-approved EMT Issuer). Any ERC-20 stablecoin enabled on request for specific corridors.
Paycifi is an official Circle Alliance partner, building on the leading regulated stablecoin infrastructure.
Compliance verification on all parties before funds move. B2B only. Fiat ramp via regulated PSP partner.
Ethereum Layer 2 by Coinbase. Enterprise-grade infrastructure. ERC-4337 smart accounts.
The agreement between the parties always prevails. Where it is silent, our terms and conditions apply as a fallback, backed by ICC arbitration.
One fee on the escrowed amount. No setup fees, no monthly custody, no per-wire charges.
Escrow from the first euro. Accessible directly, no commitment.
Priority-based distribution to multiple stakeholders. For PE exits, structured finance, trade receivables.
Earn on escrowed capital via regulated DeFi integrations while funds wait.
External data feeds (Chainlink) trigger conditional releases. Delivery confirmed? Payment moves.
Add any compliance partner as a required validator on any agreement.
Above the threshold, Representations & Warranties insurance dominates (85-95% penetration). Below it, where most transactions happen, the options are a bank escrow (minimum too high), a lawyer trust account (single-party risk, no dispute mechanism), or nothing. SRS Acquiom reports that 91% of the deals it handles include an escrow holdback at a median of 10% of deal value. The infrastructure exists at the top. The mid-market deserves the same protection.
Funds locked at signing, released at the end of the survival period or upon claim resolution. Available from the first euro, no institutional minimum.
Milestone-based release tied to agreed performance metrics. Each tranche validates independently.
Post-closing adjustment mechanisms with escrowed amounts released on agreed final accounts.
Up to 10 beneficiaries paid from a single escrow: seller, advisors, lenders, broker. One programmed settlement replaces five manual wires.
Secure exclusivity deposits before full due diligence. Funds returned automatically if conditions are not met by deadline.
| Vector | Traditional banks | Legacy digital escrow | Crypto-native escrow | Paycifi |
|---|---|---|---|---|
| Custody risk | Wire freezes — High exposure to arbitrary compliance holds. | Counterparty risk — Funds tied to a single intermediary and manual approvals. | Key loss — Permanent loss via private-key mismanagement. | Non-custodial MPC — Funds never under our control; seamless wallet recovery. |
| Setup velocity | Weeks — Bureaucratic friction, manual compliance & paperwork. | Slow wires — Bottlenecked by legacy international rails. | Complexity — Cognitive barrier, zero business logic, raw UX. | Minutes — Fast deployment via seamless Web2 onboarding. |
| Workflow flexibility | Rigid & manual — Struggles with multi-party distributions across jurisdictions. | Bilateral only — Built for simple buyer-to-seller retail flows, not corporate deals. | Highly flexible — Requires custom smart contracts and Web3 expertise. | Dynamic & ready — Enterprise multi-party flows out-of-the-box, no Web3 knowledge required. |
| Dispute resolution | Years — Slow, cost-prohibitive multi-jurisdictional courts. | Opaque — Centralized, slow, subjective internal mediation. | Unpredictable — Community voting rejected by corporate legal teams. | ICC Standard — Built-in arbitration & lawyer network across 170 countries. |
In a private asset sale, one of two things happens: the buyer wires first and hopes the asset arrives, or the seller ships first and hopes the payment follows. Counterfeit escrow schemes are a documented and growing fraud vector. Nearly 700 fraud reports were logged between 2021 and 2023 by the Better Business Bureau in the hypercar segment alone, including explicit fake-escrow schemes. The art world found it necessary to create a dedicated arbitration court (CAfA, 2018) because ordinary courts were ill-equipped for provenance and condition disputes. No player has ever coupled that resolution capability with the funds themselves.
Provenance disputes, condition at delivery, chain of title. The arbitrator resolves, the smart escrow executes.
Payment on confirmed delivery and inspection. Broker commissions included. Fake-escrow risk eliminated.
Brokerage commission disputes, vessel condition at handover, multi-jurisdiction closings.
T+0 counterparty-protected settlement on block trades. Any ERC-20 stablecoin enabled on request for specific corridors.
This overview summarises Paycifi's regulatory self-assessment across the frameworks most relevant to its activity. It does not constitute a legal opinion. A more detailed internal memorandum, and formal legal confirmation of the points noted below, are available on request as part of due diligence.
As part of building its infrastructure, Paycifi has proactively assessed its regulatory position under the European and MENA frameworks most relevant to programmable escrow and stablecoin-based payment infrastructure: MiCA, the UAE's VARA and ADGM regimes, and PSD2. This assessment is grounded in the platform's technical architecture, which is designed so that Paycifi's operating entity, BE Blockchain SRL, never holds or controls user funds at any point.
| Framework | Status | Basis |
|---|---|---|
| MiCA (EU) | Outside CASP scope | Formalised in BE Blockchain SRL's Terms of Service, based on the platform's non-custodial architecture. |
| VARA (Dubai) | Outside custody-licence scope | Same control-based test as MiCA; consistent with the platform's architecture. |
| ADGM (Abu Dhabi) | Likely outside scope | Recent framework (January 2026) on fiat-referenced tokens; application to non-custodial models under review. |
| PSD2 (EU) | Not yet confirmed | Team's working position is non-applicability, based on absence of control over funds. This has not been confirmed by external counsel. |
Across custody-based regimes (MiCA, VARA, ADGM), the platform's non-custodial architecture supports a position of being outside licensing scope. PSD2 applies a different test, based on the substance of the commercial relationship rather than custody alone; formal confirmation of this point is in progress with specialised counsel.
Private keys are fragmented via Circle's MPC (Multi-Party Computation) infrastructure and held exclusively by the user's device, Circle's servers, and a backup mechanism. BE Blockchain SRL holds no key fragment at any point. Funds are released either by the parties' own cryptographic signatures, or, in the event of a dispute, by an independent arbitrator holding a separate signature key. BE Blockchain SRL's own wallet is used solely for the automated, hard-coded collection of service fees, and confers no power to modify, suspend, or redirect transactions.
This architecture is formalised in Paycifi's Terms of Service, which state that BE Blockchain SRL "does not qualify as a Crypto-Asset Service Provider (CASP) within the meaning of Article 3(1)(13) of MiCA and does not hold a CASP authorisation."
PSD2 is the one framework where the applicable test is not purely custody-based, and where formal confirmation of Paycifi's position remains outstanding. The team's working assessment is that PSD2 does not apply, given the platform never possesses or controls user funds. This assessment will be formalised through a dedicated legal opinion with specialised counsel, and this note will be updated once that opinion is obtained.
The current architecture already routes disputed funds to an independent, professionally liable arbitrator rather than to Paycifi. BE Blockchain SRL is developing a next-generation, fully non-custodial arbitration mechanism that will remove this step entirely, holding disputed funds in a dedicated escrow smart contract with pre-programmed allocation rules. This reflects an ongoing design commitment to minimising custody exposure across every part of the platform, not only the base transaction flow.
Further detail, including jurisdiction-specific analysis and the full internal legal memorandum, is available on request.
End of Regulatory Position Overview.
Last updated: February 2, 2026
BE Blockchain SRL (“Paycifi”, “we”, “us”, or “our”) operates the Paycifi platform, a software-as-a-service (SaaS) infrastructure designed for professional users to execute conditional payments and programmable escrow mechanisms based on blockchain technology. We are committed to protecting the privacy and personal data of our professional users and their representatives, in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). Note: Paycifi is a B2B platform and is not intended for consumers.
BE Blockchain SRL, registration number 0736.494.076, 49 rue du Centre, 5003 Saint-Marc, Belgium.
Email: privacy@paycifi.com · Website: beblockchain.be
3.1 Categories of data collected: identification data (first name, last name, professional email); company data (name, registration/VAT number, registered office address, business sector); technical and usage data (authentication tokens, IP addresses, technical logs and security events).
3.2 Purposes: account creation and authentication; execution and operation of Paycifi services; platform security, fraud prevention and abuse detection; compliance with legal and regulatory obligations (including AML/KYB); service communications and technical notifications.
Under GDPR Article 6: performance of a contract (account creation and service execution); compliance with legal obligations (AML, KYB, accounting); legitimate interests (platform security, fraud prevention, service integrity and improvement); consent (optional communications such as newsletters, withdrawable at any time).
Paycifi implements a Zero-Storage policy for sensitive financial and identity documentation. Certain services are provided by independent third parties: KYB & identity verification (Aiprise.com), fiat on/off-ramp (Getjoin.io), integrated digital wallet infrastructure (Circle). Paycifi does not store sensitive identity documents (passports, ID cards, incorporation certificates) on its own servers — only a technical unique identifier (UID) enabling secure interaction with these providers' APIs. Users should consult these providers' own privacy policies.
6.1 Privacy by design: no personal or sensitive data (names, emails, identity documents) is stored on-chain. 6.2 Pseudonymity: transactions are pseudonymised through public wallet addresses; blockchain data is publicly accessible and traceable by design. 6.3 Paycifi is exploring privacy-enhancing technologies (privacy-preserving stablecoins, zero-knowledge proofs), not guaranteed and subject to technical, regulatory and third-party constraints. 6.4 Immutability: blockchain transactions are permanent and irreversible; the right to erasure cannot apply to on-chain data, which users expressly acknowledge upon initiating a transaction.
The application layer (website and interface) is hosted by OVHcloud on servers located within the European Union. Where third-party providers process data outside the EU, Paycifi ensures appropriate safeguards (European Commission adequacy decisions or Standard Contractual Clauses).
Paycifi uses secure authentication tokens strictly necessary for session management, and may use analytics tools (including Google Analytics) for aggregated, anonymised usage statistics, deployed in accordance with applicable cookie consent requirements. Users may configure or withdraw consent via the platform's cookie settings.
Account creation implies agreement to receive essential service communications (security alerts, system updates, service disruptions). Newsletters or non-essential communications are opt-in and may be withdrawn at any time via the unsubscribe link.
In accordance with Belgian legal, accounting and tax obligations, Paycifi retains basic account and contractual data for ten (10) years following the end of the business relationship. Technical logs are retained only as long as necessary for security and compliance.
Under GDPR, users may access, rectify, or request erasure of their personal data; restrict or object to certain processing; request data portability; and withdraw consent at any time. Some rights may be limited by legal, contractual or technical constraints, particularly for blockchain-related data. Requests: privacy@paycifi.com (response within 30 days). Users may also lodge a complaint with the Belgian Data Protection Authority (APD-GBA).
This Privacy Policy may be updated to reflect legal, technical or operational changes. The latest version is always available on the Paycifi website.
End of Privacy Policy.
Last updated: July 2026
PLEASE READ THESE GENERAL TERMS AND CONDITIONS CAREFULLY PRIOR TO ANY USE.
By accessing the Paycifi platform and utilizing our conditional payment infrastructure services, you hereby acknowledge that you have read and accepted, without reservation, the entirety of these General Terms and Conditions, as well as all terms incorporated herein by reference (including, without limitation, the policies of our third-party service providers).
Your attention is specifically directed to the following:
Paycifi is a software platform for conditional payments and programmable escrow, based on Smart Contracts deployed on public blockchains. It is designed to enable professional parties to secure the financial execution of their contractual relationships, without substituting for the underlying contracts or existing legal mechanisms.
Paycifi acts exclusively as a provider of technical infrastructure and a software execution layer. The platform does not provide any legal, financial, banking, asset custody, or advisory services, and does not intervene in the contractual relationship between the utilizing parties.
The use of Paycifi implies full and unreserved acceptance of these Terms, which exclusively govern the relationship between the user and the platform editor, without prejudice to any contracts that may be entered into between the users themselves.
Paycifi's functionalities are based on:
These third-party providers deliver their services under their own liability and according to their own contractual terms. BE Blockchain SRL acts neither as a financial intermediary, nor as a custodian of funds, nor as a provider of regulated services within the meaning of banking or financial law.
For any questions relating to the platform or these Terms, BE Blockchain SRL can be contacted at: contact@paycifi.com or via our official websites: https://beblockchain.be and https://paycifi.com.
Paycifi is a platform published and operated by BE Blockchain SRL (hereinafter "BE Blockchain" or "the Publisher"), a Belgian law private limited company specialising in the design, development, and operation of software solutions based on blockchain and Web3 technologies.
BE Blockchain SRL is a private limited company (SRL/BV) under Belgian law, with a share capital of 15,000 euros, whose registered office is located at 49, rue du Centre, 5003 Saint-Marc, Belgium, registered with the Crossroads Bank for Enterprises under number 0736.494.076, and subject to VAT under number BE0736.494.076.
BE Blockchain SRL designs and operates technical infrastructures intended for professional use, particularly in the fields of programmable payments, Smart Contracts, tokenisation, and blockchain interoperability. Paycifi is one of the platforms developed and operated by BE Blockchain SRL.
The Paycifi platform exclusively uses USDC (USD Coin) and EURC (Euro Coin) as settlement currencies. Both assets are issued by Circle Internet Financial, Ltd., an entity that has obtained the necessary authorisations to issue Electronic Money Tokens (EMTs) within the meaning of Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on Markets in Crypto-Assets ("MiCA"), which entered into full application on 30 December 2024.
BE Blockchain SRL operates Paycifi as a technology infrastructure provider and software execution layer. BE Blockchain SRL does not, in the context of the services described in these Terms:
Accordingly, BE Blockchain SRL does not qualify as a Crypto-Asset Service Provider (CASP) within the meaning of Article 3(1)(13) of MiCA and does not hold a CASP authorisation. The Publisher reserves the right to update this assessment at any time in the event of a change in applicable law, regulatory guidance, or the scope of services offered by the platform.
The User acknowledges and accepts that:
The Paycifi platform is published and operated by BE Blockchain SRL, a Belgian law private limited company, registered with the BCE under number 0736.494.076, whose registered office is located at 49, rue du Centre, 5003 Saint-Marc, Belgium (hereinafter "Paycifi" or "the Publisher"). Contact: contact@paycifi.com.
These Terms govern access to Paycifi as a software solution (SaaS). Paycifi acts exclusively as a provider of technical services offering an intermediation infrastructure for the execution of conditional payments.
The User expressly acknowledges and accepts the following principles, inherent in the technical architecture and functioning of the Paycifi platform:
To ensure the operation of the Platform and the compliance of the services, Paycifi relies on various specialised providers (notably for identity verification, risk analysis, wallet infrastructure, or hosting).
The platform is strictly reserved for professional use (B2B).
The User freely chooses their mode of interaction with the platform, which determines their liability regime.
The User may choose to connect their own third-party Wallet (e.g., MetaMask, Ledger). In this case:
By opting for a standard registration method via email and password, the User benefits from the integrated Wallet solution provided by Circle (Programmable Wallets). This choice entails the User's express adhesion to Circle's terms of use, including full understanding and acceptance of the following:
The User declares and warrants that they are not targeted, directly or indirectly, by international sanctions (notably OFAC, European Union, UN) and that they are not using the platform on behalf of persons subject to such measures.
BE Blockchain SRL implements risk-based compliance measures proportionate to its role as a technology infrastructure provider. The platform applies Know-Your-Business (KYB) verification procedures for all Users prior to accessing its services, through its third-party compliance provider. Notwithstanding the foregoing, BE Blockchain SRL reserves the right, at its sole discretion, to:
The User acknowledges that, by virtue of Paycifi's non-custodial architecture, BE Blockchain SRL does not have the technical ability to reverse, cancel, or intercept transactions that have been validated on the blockchain. Suspension of access to the platform interface does not affect the autonomous execution of Smart Contracts already deployed on the blockchain.
The payment infrastructure uses USDC and EURC stablecoins issued by Circle Internet Financial, Ltd. The User is expressly informed that the token issuer has technical functions enabling it to freeze assets in a Wallet in case of suspicion of illicit activity or violation of its own compliance rules. Paycifi cannot be held responsible for the impossibility of executing a Contract, a loss of access, or the inability to recover funds resulting from such a freeze measure applied by Circle.
Paycifi reserves the right to suspend or restrict access to its interface (web, API, fiat ramp) in case of:
The User acknowledges that the suspension of the Paycifi interface does not affect the existence or autonomous execution of the Smart Contract on the blockchain.
Paycifi does not guarantee the continuous operation of blockchain networks and disclaims all liability in case of:
Neither Party shall be held responsible for a total or partial failure to fulfil any of its obligations under these Terms when such failure results from a force majeure event within the meaning of Belgian law, as interpreted by the case law of the Belgian courts.
The following are notably considered force majeure events, without this list being exhaustive:
In the event of such an occurrence, Paycifi may suspend all or part of the access to the platform or its functionalities, without affecting the existence or the autonomous execution of the Smart Contracts deployed on the blockchain, which remain subject to the technical rules of the network concerned.
No compensation may be claimed from Paycifi on account of a force majeure event, the User expressly acknowledging the systemic, regulatory, and technological risks inherent in the use of blockchain technologies and digital assets.
In consideration for the development of the Smart Contracts, the provision of the application interface (front-end), and the continuous evolution of access services, Paycifi collects service fees.
Access to certain functionalities of the platform requires professional identity verification (KYB).
The User acknowledges that interaction with the blockchain generates network fees:
Fees related to the Fiat Ramp (fiat currency/crypto conversion) are billed directly by the conversion provider. Paycifi does not intervene in this financial flow and does not receive any commission on this operation, unless otherwise stated in a specific commercial agreement.
For large volumes or personalised Smart Contract needs, adapted fee structures may be negotiated via a separate service contract derogating from these standard fees. Enterprise agreements may provide for bespoke commission rates, custom Smart Contract deployments, and volume-based discounts, all of which are governed by the terms of the applicable separate contract.
The Arbitrator's fees are set by the latter independently. The User acknowledges that Paycifi does not receive any retro-commission on arbitration fees and does not intervene in their negotiation.
The Contract generated via Paycifi constitutes the technical and cryptographic translation of the financial commitments between the Partners. This technical agreement is autonomous and distinct from any commercial or civil contract concluded elsewhere between the Partners. Paycifi is a third party to the contractual relations of the Partners and assumes, as such, no obligation or responsibility regarding the Payer's solvency, or the conformity or quality of the Beneficiary's services.
The funds are locked in a Smart Contract whose code is public, auditable, and verifiable on the block explorers of the blockchain used. This Smart Contract acts as an automated and neutral execution layer, whose operation is strictly limited to the programmed instructions validated by the Partners' cryptographic signatures. BE Blockchain SRL has no technical ability to modify, pause, redirect, or intervene in the execution of any Smart Contract once deployed, regardless of the circumstances, including in cases of fraud, regulatory action, or force majeure. The Partners expressly acknowledge and accept this architecture as a defining feature of the platform.
The User acknowledges that this mechanism operates as follows:
The Partners acknowledge that the exclusive remedies available to them in respect of any locked funds are those described in this Article and in Article 22. No other mechanism of intervention, recovery, or redirection exists within the platform architecture.
The Partners are free to pre-designate an arbitrator of their choice at the time of Contract creation, either from the list of Referenced Arbitrators available on the platform or as an External Arbitrator invited directly via email address or Wallet. By pre-designating an arbitrator, the Partners expressly agree that such person shall conduct the arbitration in accordance with the ICC Rules of Arbitration on an ad hoc basis. For the avoidance of doubt, arbitration conducted pursuant to these Terms is not administered by the ICC International Court of Arbitration. The ICC International Court of Arbitration shall only intervene to appoint the arbitrator if the pre-designated arbitrator is unable or unwilling to serve, or if no arbitrator was designated by the Partners at the time of Contract creation.
Referenced Arbitrators listed on the platform are independent professionals selected by Paycifi on the basis of professional qualifications and relevant expertise. They are not appointed by or affiliated with the ICC International Court of Arbitration. Paycifi guarantees neither the neutrality nor the competence of External Arbitrators.
Failing an amicable settlement within thirty (30) days, the dispute shall be finally settled under the Rules of Arbitration of the International Chamber of Commerce (ICC). The parties expressly opt into the ICC Expedited Procedure Provisions pursuant to Article 30(3) of the ICC Rules of Arbitration (2021), regardless of the amount in dispute. The arbitration shall be conducted before a sole arbitrator appointed in accordance with Article 22.1.
The seat of arbitration shall be Geneva, Switzerland. The language of the arbitration shall be English, unless otherwise agreed in writing by the Partners prior to the initiation of arbitration proceedings.
In the current version of the platform (V1), upon initiation of a formal Dispute Notification by a Partner, the Smart Contract enables the technical release of escrowed funds to the pre-designated Arbitrator's Wallet address, as recorded in the Smart Contract at the time of its creation. This transfer is executed autonomously by the Smart Contract upon the cryptographic instruction of the initiating Partner, without any discretionary intervention by BE Blockchain SRL. BE Blockchain SRL does not hold, control, or direct these funds at any point in this process. From the moment of transfer, the Arbitrator assumes sole custody of the funds as an independent fiduciary, acting under their own professional responsibility and subject to the ICC Rules of Arbitration. BE Blockchain SRL's technical mission in respect of the concerned Contract is concluded upon execution of this transfer.
This mechanism is transitional. BE Blockchain SRL is actively developing a V2 non-custodial arbitration architecture in which disputed funds will be held in a new independent escrow Smart Contract with pre-programmed allocation rules, eliminating the requirement for funds to transit through the Arbitrator's personal wallet. Users will be notified of the migration to V2 in accordance with Article 30 of these Terms.
For disputes between the Partners themselves, arbitration pursuant to Article 22.2 shall be the exclusive method of resolution. For any dispute between a Partner and BE Blockchain SRL (as Publisher and operator of the Paycifi platform), and for any urgent, conservatory, or provisional measures required before the constitution of the arbitral tribunal, the courts of Belgium shall have exclusive jurisdiction. This provision does not affect the exclusive competence of Swiss courts to support the arbitration proceedings pursuant to the Swiss Private International Law Act (PILA) at the seat of arbitration in Geneva. Users established outside the European Union acknowledge that this forum selection constitutes a valid and binding clause under applicable international private law rules, without prejudice to their right to seek urgent or conservatory relief before any court of competent jurisdiction in their country of establishment.
Referenced Arbitrators listed on the platform have been subject to a due diligence review by Paycifi covering professional qualifications and relevant expertise. Notwithstanding such review, Referenced Arbitrators act as fully independent professionals. Prior to engaging with any Arbitrator (Referenced or External), the Partners are solely responsible for verifying that the Arbitrator holds adequate professional indemnity insurance commensurate with the value of the transaction. The Partners are invited to request confirmation of insurance coverage directly from the Arbitrator as a condition precedent to the designation. Paycifi does not provide professional liability insurance for any Arbitrator and disclaims all liability for any fault, negligence, or misconduct of the Arbitrator once the funds have been transferred from the Smart Contract to the Arbitrator's Wallet.
The transfer of funds to the Arbitrator is only technically possible if:
The parties may, at any stage of the arbitration procedure and prior to the issuance of a final award, reach an amicable settlement of their dispute. In such event, the parties may jointly request the arbitrator to record the settlement in the form of a consent award (also referred to as an "award on agreed terms") pursuant to Article 32 of the ICC Rules of Arbitration (2021).
A consent award has the same legal force and effect as a final award on the merits and is enforceable in the same manner, including under the New York Convention on the Recognition and Enforcement of Foreign Arbitral Awards of 1958, in all signatory states.
Upon notification of an amicable settlement prior to the issuance of a final award, the ICC Court shall fix the fees of the arbitrator and the ICC administrative expenses taking into account the stage reached in the proceedings. Any balance remaining from the advance on costs paid by the parties shall be reimbursed in accordance with the ICC Rules.
Paycifi provides its Services on a best-efforts basis (an obligation of means) and "as is." BE Blockchain SRL disclaims all liability regarding:
To the extent permitted by applicable law:
The User undertakes to warrant, indemnify, and hold harmless BE Blockchain SRL (as well as its directors and employees) from any claim, legal action, damage, loss, or sanction (including attorney's fees) resulting from:
All intellectual property rights in and to the Paycifi platform, including but not limited to the Smart Contract source code, front-end interfaces, application programming interfaces (APIs), algorithms, documentation, trademarks, and visual identity, are and remain the exclusive property of BE Blockchain SRL or its licensors.
The Smart Contract source code underlying the Paycifi platform is made publicly available ("Source Available") to enable independent security audits, academic research, and transparency verification. The publication of the source code does not constitute an open-source licence within the meaning of the Open Source Initiative (OSI) definition.
Subject to the terms and conditions of this Article, BE Blockchain SRL grants to any person who accesses the published source code a limited, non-exclusive, non-transferable, non-sublicensable, royalty-free licence to:
The following uses are expressly prohibited without prior written authorisation from BE Blockchain SRL:
This licence shall automatically convert to the Apache Licence, Version 2.0 (Apache 2.0) on the date that is four (4) years after the initial public release of the relevant version of the Smart Contract source code (the "Change Date"), at which point the source code will be freely usable under the terms of the Apache 2.0 Licence, available at https://www.apache.org/licenses/LICENSE-2.0.
The names "Paycifi" and "BE Blockchain," as well as all associated logos, trade names, and visual identities, are the exclusive property of BE Blockchain SRL. No use of these marks is permitted without prior written consent.
Any feedback, suggestions, or improvements communicated to BE Blockchain SRL by a User in connection with the platform shall be deemed non-confidential and may be freely used by BE Blockchain SRL without any obligation of compensation to the User.
The service is provided "as is" and "as available." Paycifi reserves the right to suspend the user interface for maintenance without prior notice, which does not affect the persistence of Contracts on the blockchain.
These Terms are governed by Belgian law. Any dispute between a User and BE Blockchain SRL relating to the use of the platform or the Publisher's liability (as opposed to disputes between Partners, which are governed by Article 22) shall be subject to the exclusive jurisdiction of the courts of Liège, Namur division, Belgium, without prejudice to any mandatory provisions of applicable law and to the provisions of Article 22.5 regarding the support jurisdiction of the Swiss courts at the seat of arbitration.
If any provision of these Terms is deemed invalid or unenforceable by a court, the other provisions shall remain in full force and effect. The invalid clause shall be replaced by a valid provision that most closely approximates the original economic intent.
Preliminary notice: To provide its infrastructure services, Paycifi integrates solutions from independent third-party providers. By accepting the Paycifi Terms and Conditions, the User expressly acknowledges and agrees to be bound by the respective terms and conditions of the following providers, which govern the specific services they deliver.
End of Terms and Conditions.
Onboard payers and partners, authenticate them with externally owned wallets, and operate the programmable escrow lifecycle — directly through the Paycifi REST API and the on-chain DShare contract.
Welcome to the Paycifi public API. These endpoints let you onboard payers and partners, authenticate them with externally owned wallets, interface with already-provisioned programmable wallets, and manage their business profile — without relying on the Paycifi frontend.
GET /auth/nonce then POST /auth/nonce to issue access/refresh tokens for the connected wallet.POST /users/register once you collect the role-specific metadata required for agreements or arbitrators.GET /auth/nonce + POST /auth/nonce for signature-based authentication using wallets fully controlled by the integrator.POST /users/register with accountType set to arbitrator plus the additional fields listed in the Profile completion guide.Wallet (externally provisioned)
│
▼
GET /auth/nonce + POST /auth/nonce
│
▼
POST /users/register (if profile data required)
│
▼
Ready for Paycifi agreement & escrow endpoints
After completing wallet setup, authentication, and any required profile updates, the account is ready to create escrow agreements and operate through the rest of the Paycifi platform.
Authentication endpoints issue access and refresh tokens for users authenticating with externally owned wallets. Wallet creation and custody remain entirely under your control.
Use when users own a wallet and prefer signing challenges instead of creating credentials. Wallets are fully provisioned and controlled externally by you or your users; Paycifi does not manage wallet creation in this flow. Required for wallets that skipped the email/password signup path. If the wallet address is not yet known, Paycifi automatically creates a new user record associated with that wallet during authentication.
Authenticate owned-wallet users via nonce signing without using email/password credentials.
no-wallet.wallet-connection-error.GET /auth/nonce to retrieve { nonce, backSig }.POST /auth/nonce with { userAddress, frontSig, nonce, backSig }.{ user, accessToken, refreshToken }./auth/noncePOST /auth/nonce
Content-Type: application/json
{
"userAddress": "0x92c5...bc10",
"frontSig": "0x7c9c5b...",
"nonce": "Please connect your wallet by signing the following message:\nnonce:5a84c3e98d9c",
"backSig": "f8f1337dc5b5d5703f7d7a8b9814d9ebfca4d0f7f2bb1d3a39c2b1c4ab3d8e90"
}
{
"user": {
"userId": "6ce832d9-64a8-40f7-a8c9-61f8d7d00101",
"walletAddress": "0x92c5...bc10",
"walletType": "owned_wallet",
"firstname": "Lena",
"lastname": "Signer",
"accountType": "standard"
},
"accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"refreshToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}
errorCode to guide user messaging (e.g., wallet missing, signature failure). Disconnect the wallet if instructed.no-wallet — wallet provider not detected.wallet-connection-error — wallet could not connect or disconnected mid-flow.signature-error / invalid-signature — user declined or wallet returned an invalid signature.missing-data — nonce verification payload incomplete.invalid-nonce — integrity check failed for nonce/backSig.user-check-error, user-creation-error, refresh-token-update-error — backend persistence issues.GET /auth/noncePOST /auth/nonceRun immediately after the user authenticates via wallet signature (nonce login) and before granting access to any agreement workflow. Use for every wallet-authenticated user whenever you must capture legal/business details (name, address, arbitrator info) to participate in Paycifi agreements.
Attach off-chain identity (email, name, business metadata) to the wallet that was already authenticated so Paycifi can route invitations, identify participants, and register arbitrators. POST /users/register completes or updates the authenticated user profile. The email captured here is required for agreement invitations, notifications, and participant identification — not for authentication.
firstname, lastname, email) plus any optional business metadata.Authorization header with the current accessToken.website) before submitting.accountType to arbitrator only when the user meets the extra data requirements listed below.GET /auth/check-email-available/:email. Abort if available: false.POST /users/register (requires Authorization header). Payload must include firstname, lastname, normalized email, phone/address fields as collected, and accountType. Arbitrators must also provide website.accountType to arbitrator.website (mandatory) and phone if available.additionalInfo with context that will be shown to agreement participants./users/registerPOST /users/register
Authorization: Bearer <accessToken>
Content-Type: application/json
{
"firstname": "Paula",
"lastname": "Integrator",
"email": "ops@partner.com",
"phone": "+32470001122",
"country": "BE",
"region": "Brussels",
"city": "Brussels",
"address1": "123 Rue Royale",
"postalCode": "1000",
"accountType": "arbitrator",
"website": "https://arbitrators.paycifi.com"
}
{
"userId": "f3f4d6f2-8f1e-4a08-9b90-2ec2d0b6f001",
"firstname": "Paula",
"lastname": "Integrator",
"email": "ops@partner.com",
"accountType": "standard",
"walletAddress": "0x1234...abcd",
"additionalInfo": null
}
The accountType field returned by /users/register dictates post-login routing: arbitrator accounts should be redirected to arbitrator dashboards / agreement-review flows; all other accounts should be routed to the standard agreement workspace. Persist this value so subsequent logins can immediately direct users to the correct feature set.
wrong-user-id — Authorization missing or userId absent from token.missing-data — firstname, lastname, email, or walletAddress not supplied.email-already-exists — result from /auth/check-email-available.user-insert-error — database failure while inserting user profile.wallet-insert-error — internal data inconsistency while ensuring wallet linkage.register-arbitrator-error — arbitrator-specific persistence failure.registration-tx-error — generic transaction failure (rolled back).GET /auth/check-email-available/:emailPOST /users/registerAfter the user has authenticated, completed wallet linking, and finished profile completion, when a payer is ready to formalize scope, participants, fees, and deadlines for a programmable escrow. Run this before any funding challenges or participant acceptance workflows, because those steps depend on the agreement ID generated here.
Create a programmable deal that binds the payer, service providers, and an optional arbitrator around defined tasks, amounts, and deadlines. The backend stores the agreement, provisions invitations, and mirrors the payload on-chain; from that point, acceptance, validation, funding, arbitration, and payouts are enforced directly by the DShare smart contract while the backend supplies orchestration utilities and status reads.
Authorization: Bearer <accessToken> header. Only Paycifi-issued tokens are accepted; unauthenticated external wallets cannot invoke this endpoint.POST /users/register done) and wallet setup finished so payer funding can occur later.owner: true, and agreementInfo.ownerUserId MUST match that participant’s userId and the authenticated user. The owner can be either the payer or a provider.name, email, walletAddress, and optionally phone/additionalInfo. If the email already exists on a non-arbitrator user, the backend aborts with agreement-creation-service-error; otherwise it reuses or auto-registers the arbitrator and sends an invitation.agreementInfo.ownerUserId equals both the authenticated user ID and the participant flagged with owner: true.acceptanceDeadline and completionDeadline as UNIX timestamps in seconds.agreementInfo.currency).agreementItems entry references an existing participant ID and includes the required pricing fields.Use the dedicated arbitrator endpoint to fetch curated (Paycifi-approved) or non-curated arbitrators before calling POST /agreements.
/arbitrators?isCurated=true|falseAuthorization: Bearer <accessToken> header.isCurated is mandatory. true lists curated arbitrators Paycifi already validated; false lists all non-curated arbitrators in your workspace.{ id, name, email, isAvailable } to pre-fill arbitrationSettings.GET /arbitrators/availability?email=<email>; it returns { success, available, arbitrator }.GET /arbitrators?isCurated=true
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
[
{ "id": "23c44f2e-865e-4c2f-8f85-2d3c5d2a9e11", "name": "DShare Arbitration Desk", "email": "panel@paycifi.com", "isAvailable": true },
{ "id": "6a89e5fd-9342-4dbe-8b39-2064c3914ea4", "name": "Global Escrow Partners", "email": "team@global-escrow.io", "isAvailable": false }
]
acceptanceDeadline must be greater than the current block timestamp.completionDeadline must be strictly greater than acceptanceDeadline.completionDeadline cannot exceed the current timestamp by more than ~100 years./agreementsPOST /agreements
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
Content-Type: application/json
{
"participants": [
{
"id": "payer-temp",
"userId": "3f6f6b4f-9c7d-4b9b-9f5a-43b0d4c2f101",
"participantType": "payer",
"name": "Acme Corp",
"email": "payer@acme.com",
"owner": true,
"additionalInfo": "Main funding entity"
},
{
"id": "provider-temp",
"userId": "92a4b2b6-45f5-4501-8e71-0d371cbb9011",
"participantType": "provider",
"name": "Studio Nova",
"email": "studio@nova.io",
"additionalInfo": "Creative agency"
}
],
"agreementInfo": {
"title": "Website Localization Sprint",
"description": "Localize the main marketing site in FR/DE",
"currency": "USDC",
"totalAmount": 1800,
"feePayerStrategy": "payer",
"acceptanceDeadline": 1735603200,
"completionDeadline": 1738281600,
"ownerUserId": "3f6f6b4f-9c7d-4b9b-9f5a-43b0d4c2f101",
"network": "base"
},
"agreementItems": [
{ "id": "item-1", "participantId": "provider-temp", "description": "Landing page localization", "quantity": 1, "unitPrice": 900, "fees": 45 },
{ "id": "item-2", "participantId": "provider-temp", "description": "Product tour localization", "quantity": 1, "unitPrice": 900, "fees": 45 }
],
"arbitrationSettings": {
"name": "DShare Panel",
"email": "arbitration@paycifi.com",
"phone": "+33180000000",
"additionalInfo": "Escrow arbitration panel",
"walletAddress": "0x0000000000000000000000000000000000000000"
}
}
{
"success": true,
"agreementId": "a55f1c3c-7de1-4ed3-8c90-9cf52a4b1d1a",
"agreementInfo": {
"id": "a55f1c3c-7de1-4ed3-8c90-9cf52a4b1d1a",
"title": "Website Localization Sprint",
"status": "pending",
"currency": "USDC",
"acceptanceDeadline": "2024-12-31T00:00:00.000Z",
"completionDeadline": "2025-01-31T00:00:00.000Z",
"payerTotalAmountWithFees": 1889.1
},
"participants": [
{ "id": "e0d1b4c5-0b80-4c08-8a58-90a8e4481f10", "participantType": "payer", "owner": true, "agreementStatus": "pending" },
{ "id": "17ce72bf-9b1a-4b70-8618-2afcce9f5f80", "participantType": "provider", "agreementStatus": "pending" },
{ "id": "db5a9fef-29ce-4cde-bc41-1881c5f5b24c", "participantType": "arbitrator", "agreementStatus": "pending" }
],
"blockchainAgreement": {
"agreementId": "0x613535f163332d6465312d34...",
"contractAddress": "0xabc123...",
"tokenAddress": "0xdef456...",
"rpcUrl": "https://base-mainnet.g.alchemy.com/v2/...",
"acceptanceDeadline": 1735603200,
"completionDeadline": 1738281600
}
}
agreementId, participants, and blockchainAgreement. Use participant IDs to drive acceptance and funding flows.errorCode/missingData to fix payload issues (e.g., missing-data, missing-acceptance-deadline, bad-completion-deadline).unknown currency indicates an unsupported code; deadline-too-far indicates completion is beyond the allowed horizon.fees-calculation-error, agreement-creation-error, agreement-creation-service-error, or agreement-creation-controller-error require retry after verifying payload and backend health.missing-datafees-calculation-errormissing-currencymissing-acceptance-deadlinemissing-completion-deadlinebad-acceptance-deadlinebad-completion-deadlinedeadline-too-faragreement-creation-erroragreement-creation-service-erroragreement-creation-controller-errorPOST /agreements — create the agreement and deploy it on-chain.PATCH /agreements/participants/:participantId/status — collect accept/decline responses from each participant.POST /agreements/:agreementId/recalculate-status — recompute the overall state after participant updates (optional helper).agreement_status = pending.{
"agreementId": "d9b6da1a-432c-47d8-8b0d-9ac01aa4f1ce",
"network": "polygon",
"contractAddress": "0xabc123...789",
"role": "provider",
"email": "studio@nova.io"
}
This payload is informational. It does not include or reserve any wallet address.
After receiving an invitation, the discovery step is to fetch the off-chain agreement snapshot:
/api/v1/agreements/:agreementIdThis provides the participants and their emails, the participant’s partnerId (participants[].id) required for on-chain acceptance, and the expected role plus current agreement_status. It is a discovery/synchronization utility — the escrow protocol itself does not require this call if the participant already knows their partnerId through another trusted channel.
Accepting an agreement is not an API call. Acceptance happens only when the participant’s wallet submits acceptAgreement(agreementId, partnerId) on the DShare smart contract. Both agreementId and partnerId are bytes32-encoded UUIDs.
acceptAgreement(bytes32(agreementIdUuid), bytes32(partnerIdUuid))
At creation and invitation time, partner wallet addresses are not known on-chain. The contract binds the wallet address only when the participant accepts: the first successful acceptAgreement call records msg.sender as the wallet address for that partnerId. This binding is permanent and cannot be changed afterward.
The contract verifies the agreement is still Pending, the participant has not already accepted, the referenced partnerId exists, and no wallet is yet set for that partnerId. If valid, it marks the participant accepted, emits PartnerAccepted, and updates acceptance counters.
The partnerId is the participant UUID that identifies the partner entry in the agreement. Fetch the agreement details and match the invitation email to the returned participants list.
{
"participants": [
{ "id": "17ce72bf-9b1a-4b70-8618-2afcce9f5f80", "participantType": "provider", "email": "studio@nova.io", "agreement_status": "pending" },
{ "id": "e0d1b4c5-0b80-4c08-8a58-90a8e4481f10", "participantType": "payer", "email": "payer@acme.com", "agreement_status": "pending" }
]
}
Here the invitation email studio@nova.io maps to partnerId = 17ce72bf-9b1a-4b70-8618-2afcce9f5f80.
Participants do not need to authenticate with Paycifi to accept an agreement. Any wallet can accept directly on-chain as long as it controls the address that will be recorded for that participant and knows the agreementId and partnerId. This lets external or unauthenticated wallets fully participate after receiving an invitation.
After a participant accepts on-chain, integrators may optionally call PATCH /agreements/participants/:participantId/status to synchronize off-chain status for dashboards. This is not required for on-chain acceptance and does not grant or revoke on-chain permissions. Declining off-chain does not perform any on-chain action; the DShare contract has no on-chain “decline invitation” operation.
The Paycifi backend is not an authority for acceptance. The DShare smart contract is the single source of truth for acceptance state, role permissions, and lifecycle transitions. Use events such as PartnerAccepted and AgreementApproved as the authoritative feed; REST updates are optional synchronization helpers only.
Invitation received
↓
GET /api/v1/agreements/:agreementId
↓
Resolve partnerId by matching invitation email to participants[].email
↓
acceptAgreement(agreementId, partnerId) (on-chain)
↓
PartnerAccepted event
↓
AgreementApproved event (once all required participants accept and conditions are met)
Whenever a signed-in user needs a consolidated list of agreements they created or joined: dashboards, recent-activity views, or any post-login screen that must show ongoing deals, pending actions, or archived work.
Expose the agreements visible to the authenticated user so clients can build list views, highlight pending obligations, and deep-link into details without duplicating backend filtering. The endpoint returns Paycifi’s indexed agreement summaries and participant metadata; on-chain funding, validation, arbitration, and payout events settle independently on DShare and are reconciled asynchronously.
Authorization: Bearer <accessToken> via the populateUser middleware). Malformed or expired tokens are rejected.userId path parameter MUST belong to the authenticated user; the backend rejects attempts to read another user’s agreements.GET /api/v1/agreements/user/:userId?status=<optional> with an Authorization header. The optional status must match an agreement_statuses.label value (e.g., pending, funded, completed).userId appears in any role are returned. Agreements the user archived (is_archived = true) are excluded regardless of status.acceptance_deadline ascending and returned as summary objects with agreement metadata, role context (isOwner, selfParticipantType, userStatus, providersEmails), a nested payer snapshot, and the arbitrator name when present./api/v1/agreements/user/:userId?status=pendingGET /api/v1/agreements/user/3f6f6b4f-9c7d-4b9b-9f5a-43b0d4c2f101?status=pending
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
[
{
"id": "d9b6da1a-432c-47d8-8b0d-9ac01aa4f1ce",
"creationDate": "2025-01-04T11:22:03.145Z",
"title": "Design Sprint Retainer",
"description": "4-week design sprint with Nova Studio",
"network": "polygon",
"currency": "USDC",
"totalAmount": 12000,
"status": "pending",
"arbitrationStatus": null,
"acceptanceDeadline": 1736371200,
"completionDeadline": 1738972800,
"ownerUserId": "3f6f6b4f-9c7d-4b9b-9f5a-43b0d4c2f101",
"isOwner": true,
"selfParticipantType": "payer",
"userStatus": "pending",
"arbitratorName": null,
"providersEmails": ["studio@nova.io"],
"payer": {
"id": "f0629825-ea62-4a79-83e0-020b4b3f07c1",
"userId": "3f6f6b4f-9c7d-4b9b-9f5a-43b0d4c2f101",
"name": "Acme Corp",
"email": "payer@acme.com",
"participantType": "payer",
"owner": true,
"status": "pending"
}
}
]
isOwner and selfParticipantType to tailor actions. The API never exposes agreements where the user is not a participant.id to fetch full details via GET /api/v1/agreements/:agreementId.| HTTP | Error code | When it occurs |
|---|---|---|
| 400 | missing-userId | userId path parameter is absent. |
| 500 | agreements-retrieval-controller-error | Unexpected failure inside the controller when fetching agreements. |
| 500 | agreementIds-retrieval-service-error | Database failure while assembling the agreement summary. |
Immediately after a user selects an agreement from the list to render a full detail view, confirm readiness before funding, drive participant acceptance, or review arbitration activity. It is the prerequisite for any lifecycle action that depends on the latest snapshot of the agreement.
Return the complete agreement payload — participants, items, deadlines, funding data, and blockchain references — so integrators can present accurate state and determine which follow-up actions (funding, acceptance, arbitration, unlock) are currently available.
populateUser middleware). Reading the DShare contract directly on-chain does not require Paycifi authentication, but this REST snapshot does.agreementId MUST be a valid UUID referencing an existing agreement with an on-chain contract address./api/v1/agreements/:agreementIdGET /api/v1/agreements/d9b6da1a-432c-47d8-8b0d-9ac01aa4f1ce
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
{
"agreementId": "d9b6da1a-432c-47d8-8b0d-9ac01aa4f1ce",
"agreementInfo": {
"title": "Design Sprint Retainer",
"ownerUserId": "3f6f6b4f-9c7d-4b9b-9f5a-43b0d4c2f101",
"acceptanceDeadline": 1736371200,
"completionDeadline": 1738972800,
"feesPct": 2.5,
"feePayerStrategy": "payer_covers_all",
"network": "polygon",
"contractAddress": "0xabc123...789",
"currency": "USDC",
"totalAmount": 12000,
"status": "pending",
"arbitratorStatus": null
},
"participants": [
{ "id": "f0629825-...", "fullname": "Acme Corp", "email": "payer@acme.com", "participantType": "payer", "agreement_status": "pending", "owner": true },
{ "id": "92a4b2b6-...", "fullname": "Studio Nova","email": "studio@nova.io","participantType": "provider", "agreement_status": "pending", "realisation_status": "not_started", "owner": false },
{ "id": "23c44f2e-...", "fullname": "DShare Arbitration Desk", "email": "panel@paycifi.com", "participantType": "arbitrator", "agreement_status": "pending", "owner": false }
],
"agreementItems": [
{ "id": "agreement-name", "description": "Design Sprint Retainer", "isAgreementName": true },
{ "id": "9c442ff5-...", "description": "Sprint fee", "quantity": 4, "unitPrice": 3000, "participantId": "92a4b2b6-...", "providerStatus": "pending", "payerStatus": "pending" }
],
"arbitrationSettings": { "id": "23c44f2e-...", "name": "DShare Arbitration Desk", "email": "panel@paycifi.com", "walletAddress": "0x5555...9999" },
"blockchain": { "rpcUrl": "https://polygon.rpc.paycifi.com", "contractAddress": "0xabc123...789", "tokenAddress": "0xdef456...321", "createdAtBlock": 53288123 },
"blockchainAgreement": { "agreementId": "0x646462...", "payer": "0x1111...", "provider": "0x2222...", "amount": "12000000000", "state": "Pending", "unlockFundsTxHash": null }
}
404 agreement-not-found indicates an invalid ID; 409 agreement-missing-contract-address means the record exists but lacks an on-chain contract, so blockchain data cannot be fetched.agreementInfo.status, item statuses, and participant agreement_status to determine whether to show funding, acceptance, realization, or arbitration actions.owner: true should see the “Fund” action, executed by calling the DShare contract from a wallet that signs transactions on-chain.| HTTP | Error code | When it occurs |
|---|---|---|
| 400 | missing-agreementId | Path parameter was omitted. |
| 404 | agreement-not-found | No agreement matches the provided ID. |
| 409 | agreement-missing-contract-address | Agreement exists but has no contract address. |
| 500 | agreement-detail-retrieval-controller-error | Failure while reading agreement data from the database. |
| 500 | blockchainAgreement-retrieval-controller-error | Failure while fetching the on-chain snapshot. |
validateService is the core lifecycle function: it records participant decisions and automatically routes funds to partners, funders, or the mediator depending on the outcome.createAgreement transaction (msg.sender). In the current architecture this is a backend-controlled signer acting on behalf of the initiating user, so creator-only actions such as cancelAgreement are authorized exclusively to the backend signer.fundAgreement. ONLY the funder can call unlockFunds or unlockAfterCompletionTimeout.acceptAgreement for their partnerId, and partners share validateService permissions with the funder.mediatorApprove. Any validator (partner or funder) can escalate via ServiceState.CalledMediator.Each partner calls acceptAgreement(agreementId, partnerId) once their wallet is ready. The contract emits PartnerAccepted for every acceptance. When all partners have accepted and the funder has already locked funds, DShare automatically emits AgreementApproved. No funds move during acceptance; balances remain locked in escrow.
validateService(agreementId, ServiceState state) can be called by any approved partner or the funder. ServiceState encoding:
0 = Pending
1 = Validated
2 = Declined
3 = CalledMediator
Every call updates the caller’s service state and the global counters. DShare moves funds inside this function as soon as the relevant condition is satisfied.
Validated (1) and numApprovedServices == validatorCount, the same transaction pays each approved partner via ERC-20 transfers, sets fundState = Distributed / serviceState = Validated, and emits AgreementValidated. unlockFunds is not involved.Declined (2) and numDeclinedServices == validatorCount, the same transaction refunds the funder in full (protocol fees remain collected), sets fundState = UnlockedFund / serviceState = Cancelled, and emits UnlockFunds.CalledMediator (3) provided a mediator was set. The transaction immediately transfers the entire net amount to the mediator, sets serviceState = Mediation, and emits AgreementMediated. This bypasses unlock logic and is irreversible.These functions do not run during the normal lifecycle. They exist for exceptional cases and always require a manual transaction from the funder.
unlockFunds — callable only by the funder while globalState == Pending, serviceState == Pending, and funds are still locked. Early exit before approval: refunds the funder immediately and emits UnlockFunds.unlockAfterCompletionTimeout — callable only by the funder after the completion deadline has passed, provided the agreement is not cancelled, not in mediation, and funds remain locked. Deadline-based manual refund; emits UnlockFundsAfterTimeout.cancelAgreement(agreementId) can be executed only by the creator while the agreement is pending. If escrow funds were locked, the same transaction refunds the funder and sets fundState = UnlockedFund before emitting AgreementCancelled. No automatic cancellation exists.
Integrators MUST subscribe to events to track the escrow without polling:
PartnerAccepted, AgreementApproved, AgreementValidated, AgreementMediated, UnlockFunds, FundsUnlocked (ERC-20 payout confirmation), UnlockFundsAfterTimeout.Events are emitted in the exact transaction that moved funds or changed state, making them the authoritative feed for dashboards, accounting, and alerts.
The DShare escrow protocol is wallet-agnostic. Any Ethereum-compatible wallet (EOA, smart wallet, MPC, custodial service) can interact with the contract, provided the wallet address matches the role stored on-chain (creator, funder, partner, or mediator). The protocol relies exclusively on msg.sender equality checks for authorization.
| Scenario | Function that moves funds | Triggering role | Automatic / explicit |
|---|---|---|---|
| All validators approve | validateService (final call, ServiceState.Validated) | Approving validator | Automatic (inside the call) |
| All validators decline | validateService (final call, ServiceState.Declined) | Declining validator | Automatic refund |
| Arbitration escalation | validateService (ServiceState.CalledMediator) | Any validator | Automatic mediator payout |
| Early exit before approval | unlockFunds | Funder only | Explicit transaction |
| Missed completion deadline | unlockAfterCompletionTimeout | Funder only | Explicit transaction |
| Creator cancels pending agreement | cancelAgreement | Creator only | Explicit transaction (refund if funded) |
Thanks — we've received your message and will reply within one business day. You can also reach us directly at contact@paycifi.com.