Veilid for transport. Monero for settlement. No operator in between.
There is no DUCAT server anywhere — contacts, messages, bills and receipts are DHT records and end-to-end sealed payloads, and every phone runs a full Veilid node, giving back the routing and storage it takes.
Debug-signed, stagenet only. Not for real money — yet.
A ducat was a gold coin accepted from Venice to Vienna to the Levant for six centuries — no issuer relationship, no account behind it, no permission attached. DUCAT is that, for standing in front of someone and doing business.
Contacts, bills, payments and receipts travel as end-to-end sealed payloads over Veilid's DHT. There is nothing to subpoena, rate-limit, de-platform or shut down, because there is nothing running. Every phone is a full node, giving back the routing and storage it takes.
Made on the phone. No email, no phone number, nobody to register with — which is also why nobody can restore it for you, and the app says that out loud instead of burying it.
You hand someone a card — QR, ducat: link, or an NFC tap — and it
is good for one person. Once claimed it stops working, so a
screenshot that ends up somewhere else is not a way in.
X3DH-shaped encryption with one-time prekeys and forward secrecy. When the app has to fall back to the signed prekey, it shows you an open lock rather than hiding it.
Mailbox-based threads that work while either side is offline — carrying itemised bills whose lines must sum to their total or the message is refused, payments, and receipts issued by the payee pointing at the transaction they acknowledge. Small groups fan out into the same pairwise threads: no group key, no shared record, every thread property unchanged.
Every screenshot on this page is the app running on a phone, not a mockup. Nothing here asks you to sign up, because there is nobody to sign up with.
Your identity is a keypair made on the device — no email, no phone number, nobody to register with, which is also why nobody can restore it for you. The last step is the backup, because a wallet you cannot restore is the one way a person actually loses money here.
A self-custodial Monero wallet with fiat conversion throughout, scanned and spent by an embedded monero-oxide engine — no wallet daemon on the phone.
Paying shows the amount, the estimated network fee, the total, what you have left afterwards, how many notes it spends and roughly how long it will take — and lets you pick a speed. History is rebuilt from the chain: sends identified by key image, change never shown as income, every row carrying the running balance, and the whole statement exportable as CSV.
Monero spends discrete notes rather than a balance, so a wallet holding one big note can be unable to pay twice in a row. The app counts the notes it can spend and tells you to break one before you are standing at a counter, rather than failing there.
A contact is a keypair, not an identifier. One scan opens a mailbox-based conversation that works while either side is offline — and those threads carry commerce, not just text.
You hand someone a card — by QR, ducat: link, or an NFC tap — and it
is good for one person: once claimed it stops working, so a
screenshot that ends up somewhere else is not a way in.
A group is a roster that only grows, and its words ride one shared board record per generation (§16.24): every member writes its own pages under a group key the roster carries, so a message to five people is one write instead of five, and the record cannot be told apart from any other by the network. Nobody can forge as anyone else, and leaving is local. A group can split a bill — one total becomes a pairwise request to each person plus a sentence everyone can check the arithmetic against, and each request flips to paid as its reference lands.
Pick one of nine modes and the entire app hands over — its own tabs, nothing of the wallet's. Almost none of it needed a new wire object, which is the spec's proudest sentence.
A point of sale rings up items or takes a typed total, computes the sales tax for its region, and shows one code; the bill arrives on the customer's phone the moment they scan it, and a receipt goes back when they pay. A bar tab pings every drink to the customer and closes with one bill. A kiosk hands the phone to the customer entirely, with a staff panel behind a PIN. A donation box offers both rails — a DUCAT code that opens a conversation and sends a receipt once the money arrives, and a standing address any Monero wallet can give to, with its linkability cost stated on the screen rather than in a policy.
Type where you are going. Your phone turns a GPS fix into a geocell — a public bulletin board whose address is the place itself — and posts a hail: a claim-once card, a coarse area, and an offer priced from the real driving route. No name goes on the board — not on the card, not in the record behind it. Drivers watch their cell and its neighbours and claim it; the DHT referees the race, and no matchmaker exists.
The green line is the point: DUCAT's rates sit about 15% under a rideshare's rider-side rates, and the driver keeps all of it — the absent platform cut, handed to both of them. Acceptance arrives with a face on it: name, car, colour, plate, ETA — sealed to the rider, never shown to the board. Your own name and the doorway you are standing at go the other way at the same moment, to the one driver who claimed.
One trade, stated plainly on screen: address search, routing and map tiles query OpenStreetMap — the single place DUCAT sends location off-device. The boards themselves never carry better than ~1.2 km.
The same board machinery carries more than rides. A marketplace listing, a rental, or an hour of skilled help all post to a bulletin board addressed by the neighbourhood, and a stranger nearby reads it without either of you touching a platform.
Listings sit on coarser boards than hails — about five kilometres across, because people will travel to collect a set of keys. Searching reads your board and the ring around it, drawing results as each one answers, so something parked near you is on screen in under six seconds while "nothing listed around here" takes about forty and counts the areas off as it goes.
The listing form is split in two and the app tells you which half is which: everything in the first part goes on a public board anyone nearby can read, and the address, where the keys are, and the plate go in the second, which never leaves your phone until a booking is real.
The records that carry a bill carry a page just as well. Your key is already an address, so what you write has somewhere to live without asking anyone for room.
A persona's home sits at the address its own key names, and the feed is the timeline of the people you keep — a post can carry a picture and a file, and hearts come back. Sites are served from disk by whoever published them and open in a sealed room, so reading one fetches nothing from anywhere else.
Publications — a newspaper, a serial, a piece of software — are sold worldwide on topic boards rather than by neighbourhood: a post lands on the topic's board and on its language's board both, and "Everything" reads all six shelves side by side. A listing fetches its bundle from the seller's own phone — up to 24 photographs at full size, a description, specs and attached files — refused whole on any key it does not name, so a bad document cannot hide good pictures.
There is no company in the middle to take sides, so DUCAT does something simpler. The money sits in an address only the two of you can open, and the release hands each side their own stake back by name. Nobody can take a stake — including us, because there is no us to pay.
Those numbers are argued rather than guessed — Bisq's 2-of-2 no-custodian model is the closest working precedent, and the dual-deposit literature proves the arrangement cheat-proof at equilibrium. Two bounds fall out: a stake worth less than the fee to return it becomes zero rather than decoration, and none exceeds half the price. The exposed side funds second, so their money never sits alone in a shared address.
When a deal wants more than a bond: rider, driver and a mutually trusted arbiter contact run a distributed key generation over the sealed thread — three devices derive one Monero address, each holding only a share, any two able to sign, no dealer anywhere. The happy path is two taps.
Anything else is a settlement: either side proposes a split, the other signs or counters. A stranded party asks the arbiter, whose co-signature is the ruling — a captured arbiter can at worst pick between the named parties, never pay itself. Chain-proven on stagenet in every shape, including a two-input FROST release.
Before there is any deal there is a stranger, and the question is what their name cost them. A persona may burn Monero — send it to an address nobody holds the keys to, derived from a hash anyone can recompute — and carry Monero's own payment proof for it. Your client checks that proof against its own node, asks a second node whether the transaction is in a block, and from then on shows the persona in words wherever you decide something: burned 0.01 XMR, since block N. Never a score. The rule that matters is the warning: when what you are about to risk is worth more than what they burned, the app says so, because a name that cost nothing has nothing to lose by vanishing.
After a settled deal either side may sign a rated receipt, and anyone you have met in person may sign a vouch. Both travel in a sealed thread and both are weighed by the reader alone — one voice per signer, counting only signers whose own burn you verified, and counting a vouch only from people already in your contacts. One hop, no graph, nothing published anywhere. Reputation that costs money instead of privacy.
A privacy tool that is unpleasant to use gets used once. This one names what things cost you, speaks twenty languages, and has a dark theme that isn't an afterthought.
Convenience has a price in a privacy system, and the app names it at the moment you choose rather than in a policy nobody reads. Letting contacts pay you directly means reusing one address — so it says that anyone watching the chain can tell the same person was paid each time, including people who only ever paid you once, and points at the alternative. The same habit runs through: a mempool sighting is shown as seen, never settled; a profile is always presented as the claim it is.
It speaks twenty languages — every screen reads from resources, plurals are composed rather than concatenated, and Arabic and Farsi prove the mirror. Receipts are records, not messages: every receipt lives in its own store, survives thread and contact deletion, and rides the encrypted backup — which carries the people as well as the money.
A native window over the same Rust the phone runs — so a shopkeeper's till, a kiosk, the press room, the market and the feed are one implementation, not a port.
It speaks the phone's twenty languages from the same resources, and is proven against the phone across every rite: chat, groups on boards, bills and receipts, a kiosk order paid from a phone that had never met the desk, files and sites served and fetched, and calls with real sound.
The README keeps a ledger of what has actually run end-to-end on the live network and live stagenet — and states the gaps rather than burying them.
core/Every build is debug-signed and settles on Monero's stagenet — coins with no value, by design. The spec is draft 1.1.0-dev13 and says of itself: nothing here is final, and §14 is the real agenda. Try it, break it, read it — just don't fund it.
ducat-protocol.md is the primary artifact — five parts,
a changelog first, and a conformance suite that a second implementation runs so the
document cannot drift from the code silently.
★ ducat-protocol.md the spec — draft 1.1.0-dev13, changelog first core/ reference implementation (Rust) vectors/ 406 conformance cases + schema conformance/ four checkers, run on every push harness/ end-to-end over real Veilid routes sim/ offline simulator, market scenarios applications/ android/ + desktop/ (same sources) mobile/ the Rust bridge: wallet · mailbox · node research/ evidence, not product
schema.jsonStewardship is normative, not aspirational: §18.7 makes Veilid's ethic a conformance requirement — no protocol fees, no node payment, ever. Build anything you like from this code, but a client that monetizes carriage is not DUCAT.
Nothing to install first — every build carries its own Rust library and JVM. Android on a phone, and the same application as a native window on Linux, Windows and macOS. There is no iOS build; it gets a folder when it earns one.
Phone browser, newest build, no release page to navigate. armeabi-v7a
only for phones older than about 2016; x86_64 is for emulators.
Apple Silicon and Intel builds. Unsigned — macOS will warn on first open.
Debug-signed, stagenet only — not for real money.