Skip to content

Repository files navigation

Commerce Payments Protocol

A permissionless protocol for onchain payments that mimics traditional "authorize and capture" payment flows.

Quick Start

The Commerce Payments Protocol facilitates secure escrow-based payments with flexible authorization and capture patterns. Operators drive payment flows using modular token collectors while the protocol ensures payer and merchant protections.

📖 Read the Full Documentation

Key Features

  • Two-Phase Payments: Separate authorization and capture for guaranteed merchant payments and management of real-world complexity
  • Flexible Fee Structure: Configurable fee rates and recipients within predefined ranges
  • Modular Token Collection: Support for multiple authorization methods (ERC-3009, Permit2, allowances, spend permissions)
  • Built-in Protections: Time-based expiries, amount limits, and reclaim mechanisms
  • Operator Model: Permissionless operators manage payment flows while remaining trust-minimized

Deployment Addresses

Deployed via CREATE2, so each contract has the same address on Base Mainnet and Base Sepolia.

v1.1.0 (latest)

Contract Address
AuthCaptureEscrow 0xf96815976523E00e65Be8f34cA5e64b4f41EB19c
ERC3009PaymentCollector 0x8612dfdc421f80336cd14E8EF9cb1E765dB5ab88
Permit2PaymentCollector 0xD69831Aed5bfe262067ec4c751f4F830EcdD446e
PreApprovalPaymentCollector 0xF1F9C408C787B2bC6CAEB91e5BbEc434a5c8d2Ea
SpendPermissionPaymentCollector 0xB508c1C0a13849693DC175307667653C5977a408
OperatorRefundCollector 0x7a03443724d14798c4AB4622F1DAAcA761Fea486

v1.0.0

Contract Address
AuthCaptureEscrow 0xBdEA0D1bcC5966192B070Fdf62aB4EF5b4420cff
ERC3009PaymentCollector 0x0E3dF9510de65469C4518D7843919c0b8C7A7757
Permit2PaymentCollector 0x992476B9Ee81d52a5BdA0622C333938D0Af0aB26
PreApprovalPaymentCollector 0x1b77ABd71FCD21fbe2398AE821Aa27D1E6B94bC6
SpendPermissionPaymentCollector 0x8d9F34934dc9619e5DC3Df27D0A40b4A744E7eAa
OperatorRefundCollector 0x934907bffd0901b6A21e398B9C53A4A38F02fa5d

Documentation

  • Protocol Overview - Architecture, components, and payment lifecycle
  • Security Analysis - Security features, risk assessment, and mitigation strategies
  • Token Collectors Guide - Modular payment authorization methods
  • Fee System - Comprehensive fee mechanics and examples
  • Core Operations:
    • Authorize - Reserve funds for future capture
    • Capture - Transfer authorized funds to merchants
    • Charge - Immediate authorization and capture
    • Void - Cancel authorizations (operator)
    • Reclaim - Recover expired authorizations (payer)
    • Refund - Return captured funds to payers

Development

# Install dependencies
forge install

# Run tests
forge test

# Deploy (example)
forge script script/Deploy.s.sol --rpc-url $RPC_URL --broadcast

License

MIT License - see LICENSE file for details.

Security Audits

Audited by Spearbit and Coinbase Protocol Security.

Audit Date Report
Coinbase Protocol Security audit 1 03/19/2025 Report
Coinbase Protocol Security audit 2 03/26/2025 Report
Spearbit audit 1 04/01/2025 Report
Coinbase Protocol Security audit 3 04/15/2025 Report
Spearbit audit 2 04/22/2025 Report
Spearbit audit 3 (rounding and billing change, v1.1.0, #90) 07/22/2026 Report

About

Onchain authorization and capture for trust-minimized commerce.

Resources

Contributing

Security policy

Stars

135 stars

Watchers

8 watching

Forks

Releases

Used by

Contributors

Languages