Codeproof · Fluxus ForgeVault · Ledger · Reveal
Sealing000%

Every code carries proof

Prepaid brand codes · one API · India-first

Brand vouchers sourced from global suppliers and sold through one API — every code envelope-encrypted, revealed exactly once, and reconciled to the paisa on a double-entry ledger.

[ Single reveal ][ Double-entry ][ Idempotent ]

Sealed, then shown once

Envelope-encrypted per code · reserve-then-commit wallet · a supplier timeout is held, never retried blind.

1Reveal per code
0Blind retries
₹0.01Reconciliation grain
100%Codes sealed at rest

One core, three channels

Built by Fluxus Forge

API partners · TapProof merchants · VIKAM consumers

Three ways to sell a code, one vault and one ledger behind all of them. The API is in build today; TapProof and VIKAM come next.

Request access
01 · The product

Distribution, not a marketplace.

Closed-loop brand codes — app stores, gaming, streaming, retail — bought by businesses from a prepaid B2B wallet, delivered sealed, and accounted for journal by journal.

Codeproof is

Infrastructure for selling codes safely.

  • B2B-first distribution of closed-loop brand codes
  • A prepaid B2B wallet per partner, topped up by bank transfer
  • An API with quotes, idempotent orders, single reveal and signed webhooks
  • A ledger where every balance is a sum of postings
Codeproof is not

A wallet, a PPI or a listing site.

  • No stored value for individuals, no consumer wallet
  • Not a marketplace — we are the principal
  • Codes never sit in plaintext — not in logs, events or our console
  • Not live at scale — in build, onboarding by invitation
Product facts · not traction

What is built today.

Counted from the codebase, not from a pitch deck. The sandbox runs the whole flow against a simulated supplier that also misbehaves on purpose.

8Sandbox SKUsincl. partial, timeout, out-of-stock, wrong-region
7Order statesevery change recorded
6Webhook event typessigned, sequenced
5KYC tiersT0 → T4
42Automated testsagainst real Postgres
1Reveal per codeenforced by the database
Catalogue · sandbox

Closed-loop brand codes.

The sandbox catalogue mirrors the categories we are contracting for: app stores, gaming, streaming. Each SKU carries its region, denomination, expiry rule, resale flag and terms.

Google Play

App-store credit · ₹100, ₹500, ₹1,000

PlayStation

Store wallet · ₹1,000, ₹2,000

Xbox

Gift card · ₹1,000

Steam

Wallet code · ₹800

Netflix

Gift card · ₹500

More brands

Via the supplier network after go-live, with India-region rights in writing.

Text monograms only — brand names are trademarks of their owners and imply no endorsement.

Every outcome, as an event.

Delivered, partly delivered, quarantined, held for the supplier — each one a signed, sequenced event your webhook receives. Illustrative data, real contract.

POST your-app.example/webhooks/codeproof200 OK
partner YOURORGseq 1040–1044signature verified
1
wallet.creditedfinal09:28:39
amountMinor5000000utrUTR2026092900421
2
order.fulfilledfinal09:29:17
orderIdord_7Q2KclientReferencetxn-8841codes3 × ****-****-…
3
order.partialfinal09:29:55
requested10delivered7refundedMinor147000
4
code.quarantinedclaim09:29:56
codeIdcod_M4XDreasonREGION_MISMATCH
5
order.ambiguousheld09:30:50
orderIdord_A91Pmoneyheld, not refundednextresolver asks supplier
HMAC
SHA-256 signed
ORDER
per-partner seq
DELIVERY
never dropped
REPLAY
GET /v1/events
Who it is for

Businesses that sell codes.

01

Recharge & bill-pay apps

Add gaming and app-store credit next to mobile recharge without holding supplier float yourself.

02

Kirana networks

Sell codes at the counter through TapProof, reveal behind the merchant PIN, earn a commission. Coming.

03

Rewards & loyalty

Turn points into brand codes delivered by API, with one reveal per code and a full audit trail.

04

Fintech cashback & benefits

Pay cashback or employee perks in brand codes, reconciled to the paisa against your own ledger.

Channels · roadmap, no dates

One core, three channels.

The vault, the ledger and the order engine are shared. Each channel only changes where the code is revealed and who is allowed to reveal it.

Now · sandbox

API partners

The /v1 API and the partner portal. Prepaid B2B wallet, quotes, idempotent orders, single reveal, signed webhooks.

Next

TapProof merchants

A “Sell vouchers” tab inside TapProof. The counter reveal sits behind the app PIN; the merchant commission gets its own ledger account.

After

VIKAM consumers

A UPI-only catalogue inside VIKAM, device-bound reveal, velocity limits and a consumer dispute flow.

03 · How an order works

Reserve first. Settle what arrives.

01 · Quote

Price fixed

Landed cost from supplier cost and FX; your price from face value minus your discount — held until the quote expires.

02 · Reserve

Money held

Under a lock on your wallet: status, tier caps and balance checked, the amount moved from available to reserved. Never negative.

03 · Supplier

Bought once

Our order id is the supplier reference, so the supplier itself dedupes. A timeout is never retried as a new purchase.

04 · Sealed code

Validated, encrypted

Region, denomination, expiry and duplicates checked. Good codes sealed; bad ones quarantined and claimed back.

05 · One reveal

Shown once

Plaintext only on an explicit reveal, once per code, audited with the device id. A second attempt returns the original timestamp.

06 · Ledger

Settled to the paisa

Delivered units settle reserved → supplier float + margin; undelivered units release to available in the same transaction.

Order lifecycle · 7 states

Where your money is, always.

Every order walks the same state machine. Each transition is validated, recorded with a reason, and emitted as an event.

  1. CREATED

    Order accepted

    Checked against your status, tier caps and balance. Nothing has moved yet.

  2. WALLET_RESERVED

    Money reserved

    The total moves from available to reserved under a lock on your wallet.

  3. SUPPLIER_PENDING

    With the supplier

    Bought once, with our order id as the supplier reference. Money stays reserved.

  • FULFILLED

    Delivered

    Reserved settles to supplier float and margin. Every code sealed.

  • PARTIALLY_FULFILLED

    Partly delivered

    You pay for delivered units only; the rest is released to available.

  • FAILED

    Failed — refunded

    The full amount is released back to available. No codes, no charge.

SUPPLIER_AMBIGUOUS

Confirming with supplier

The supplier timed out or answered unclearly after we sent the order. Money stays held — never refunded blind, never re-bought. A resolver asks the supplier about our reference and settles to one of the three finals; if the supplier never received it, the order fails and releases after a grace period.

Pricing · worked to the paisa

One ₹1,000 code, priced.

The same arithmetic the pricing code runs, in integer paise. Foreign cost is converted with a decimal library and always rounded up, so we never under-cost a code.

Quote · GPLAY-IN-1000 × 1Illustrative FX
Face value₹1,000.00
Partner discount · 2%− ₹20.00
Your price₹980.00
Supplier cost · $11.00 × ₹84.10₹925.10
Bank charge 0.25% + 18% GST, rounded up₹2.78
Landed cost₹927.88
Margin₹52.12 · 5.32%
Margin floor 1% — quotes below it are refusedQuote held 60 s
FX

Stale rates refuse to quote.

A rate older than the configured age makes the SKU unquotable rather than guessing.

Floor

No loss-leading by accident.

If price minus landed cost falls under the floor, the SKU is shown as unavailable.

Expiry

Sixty days or it is not sold.

SKUs whose codes would expire within 60 days are not quotable.

Hold

The price you saw is the price.

A quote fixes the unit price until it expires; an expired quote returns a fresh one.

The ledger, shown

One ₹980 order, journalled.

Double-entry and append-only. Balances are sums of postings; the database rejects a journal that does not balance and any attempt to edit one.

JournalAccountDr ₹Cr ₹
Reservepartner:available980.00
partner:reserved980.00
Settlepartner:reserved980.00
supplier:float927.88
revenue:voucher_margin52.12
Release · on failurepartner:reserved980.00
partner:available980.00

Top-ups: Dr bank clearing / Cr partner available, idempotent on the bank UTR. Bad codes: Dr supplier claims / Cr supplier float.

04 · Security and money

Built for the day it goes wrong.

Single-reveal vault

Plaintext exists twice: in transit, and in your one reveal.

Per-code envelope encryption bound to its context, masked everywhere else. The reveal flips the code, decrypts and audits in one transaction.

Double-entry ledger

Balances are sums, never stored numbers.

Append-only journals, balanced by the database. Top-ups are idempotent on the bank UTR. Corrections are new journals, never edits.

Ambiguous orders

Unknown means held, not guessed.

When a supplier times out, money stays reserved while a resolver asks the supplier about that exact reference — then delivers or releases.

Idempotent orders

Retry without fear.

The same Idempotency-Key returns the original result. A different body under the same key is rejected.

Partial fulfilment

Pay for what arrives.

Asked for 10, got 7: you get 7, pay for 7, and 3 are released to your balance in the same transaction.

Tier caps

Limits inside the lock.

Daily and monthly caps are enforced at order time, inside the same lock that reserves the money.

Security · how the vault works

A code is a sealed envelope.

Envelope encryption

One data key per code.

Each code is encrypted with its own random AES-256-GCM data key; that key is wrapped by a key-encryption key. The ciphertext is bound to its order and code, so it cannot be moved to another record.

Single reveal

Once, audited, per device.

Revealing flips the code, decrypts and writes the audit row in one transaction, with the device id. A second attempt returns the original timestamp, and is audited too.

Masked everywhere else

Plaintext never rests.

Orders, events, webhooks and our own console show ****-****-1234. Plaintext is never logged, never put in events, and never stored unsealed.

Key rotation

Dual-key reads.

New codes seal under the active key; older codes still open under the key that sealed them, so rotation needs no downtime or re-encryption window.

Sign-in

Magic links bound to the browser.

No passwords. A sign-in link works once, expires quickly, and only in the browser that requested it — a forwarded link is useless.

Staff

Fluxus Forge staff only.

The console accepts @fluxusforge.in accounts with roles: owner, operations, finance, read-only support. Staff never see plaintext codes.

Compliance posture

Said plainly, pending marked.

What Codeproof is and is not, and which pieces are still in progress before partners go live.

AreaPositionStatus
ProductClosed-loop brand codes sold to businesses. Not a PPI, no consumer wallet, no stored value for individuals.By design
GSTVoucher treatment per CBIC Circular 243/37/2024, with a separate taxable fee line. Invoice template awaiting CA sign-off.Pending
TDS194Q tracking on purchases, matched to 26AS quarterly.Pending
DPDPConsent and retention: sealed codes purged 90 days after reveal; the hash and audit trail are kept.Pending
GrievanceA named grievance officer and published SLA before partner go-live.Pending
KYCTiered onboarding T0–T4 with caps enforced at order time; KYC flows run through the Fluxus Forge onboarding team.Caps live · KYC manual
Integrate in four calls

Catalogue, quote, order, reveal.

Bearer-key REST with money as integer paise. Webhooks cover everything else — delivered, partly delivered, failed, held, quarantined, wallet credited.

01 · CatalogueGET /v1/catalog
GET /v1/catalog
curl -s https://codeproof.fluxusforge.in/v1/catalog?brand=Google%20Play \
  -H "Authorization: Bearer $KEY"
# → items[]: sku, faceValueMinor, unitPriceMinor, available
02 · QuotePOST /v1/quotes
POST /v1/quotes
curl -s https://codeproof.fluxusforge.in/v1/quotes \
  -H "Authorization: Bearer $KEY" -H "Content-Type: application/json" \
  -d '{"sku":"GPLAY-IN-1000","qty":1}'
# → quoteId, totalMinor "98000", expiresAt (+60 s)
03 · OrderPOST /v1/orders
POST /v1/orders
curl -s https://codeproof.fluxusforge.in/v1/orders \
  -H "Authorization: Bearer $KEY" -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{"quoteId":"…","clientReference":"txn-8841"}'
# → 201 FULFILLED · 202 SUPPLIER_AMBIGUOUS — retry with the same key
04 · RevealPOST …/codes/{codeId}/reveal
POST …/codes/{codeId}/reveal
curl -s -X POST \
  https://codeproof.fluxusforge.in/v1/orders/$ORDER/codes/$CODE/reveal \
  -H "Authorization: Bearer $KEY" -H "X-Device-Id: pos-12"
# → { code, revealedAt } — once. Again → 409 ALREADY_REVEALED
Compared

Versus a typical voucher API.

Typical voucher APICodeproof
Code deliveryPlaintext codes in the order responseMasked codes; plaintext through one audited reveal
Supplier timeoutRetry the purchase and hopeAmbiguous state, money held, settled by a status check
BalancesA balance column updated in placeDouble-entry journals; balances are sums
CallbacksUnsigned, unordered, best-effortHMAC-signed, sequenced per partner, replayable
OnboardingManual KYC, one limit for everyoneTiered limits T0–T4 enforced at order time
06 · Onboarding tiers

Caps follow your KYC.

Every partner is one legal entity with one wallet. Tier and caps are set at onboarding and enforced on every order.

TierWhoKYCMonthly capChannels
T0Consumer — individual, own useMobile OTP + PAN + device binding₹25K / month, ₹10K / day, 3 codes / dayVIKAM / web
T1Reseller — proprietor or freelancerAadhaar eKYC with liveness + PAN + penny-drop + selfie₹2L / monthApp + portal
T2Proprietorship, partnership or LLPUdyam or GST + firm PAN + partner KYC + bank in firm name + premises proof₹25L / month (₹5L without GST)Portal + API
T3Private limited companyCIN + MCA directors + board resolution + GST + company PAN + bank in company name + UBO ≥ 10%₹5Cr / month, raised on historyAPI + portal
T4Enterprise — aggregators, fintechs, corporatesT3 + your AML policy + site or video visit + addendumCustom, optional credit lineAPI
07 · Questions

Straight answers.

Codeproof is in build. The core — catalogue, pricing, orders, the single-reveal vault, the double-entry ledger and the partner API — runs today against a simulated supplier. Partner access is by invitation while we complete supplier contracts and go-live checks.

No. Codeproof sells closed-loop brand codes to businesses. Partners hold a prepaid B2B balance with us to buy codes; there is no stored value for individuals and no consumer wallet.

By bank transfer (UPI, NEFT, RTGS or IMPS) to your own virtual account, whose details you receive during onboarding. Every credit is matched to its bank UTR and can never be applied twice. Cards and net-banking are not accepted.

The order becomes “Confirming with supplier”. Your money is held — not spent and not refunded blind — while our resolver asks the supplier what happened to that exact order reference. It then settles to delivered or refunded. We never re-buy, so you are never charged twice.

Codes are envelope-encrypted per code the moment they arrive and are masked everywhere, including in our own console. Plaintext exists only in the one reveal response you request, and every reveal attempt is audited.

No. Each code is revealed exactly once; a second reveal returns 409 ALREADY_REVEALED with the original time. Hand the code to your customer from that one response — we cannot show it again, and neither can our staff.

You prepay your own B2B wallet with Fluxus Forge by bank transfer. An order reserves the amount, settles only for codes actually delivered, and releases the rest. Your balance is always the sum of your ledger entries, which you can read at any time.

Undelivered units are released to your available balance in the same transaction that finalises the order — automatically for failed and partly delivered orders. Withdrawals from the wallet go only to your registered, verified bank account.

The sandbox runs the real order engine, vault and ledger against a simulated supplier. Codes are fake and no money moves. Some SKUs misbehave on purpose — partial delivery, timeout, out of stock, wrong-region codes — so you can build against every outcome before go-live.

Every code is validated before it is sealed — region, denomination, expiry of at least 60 days, duplicates. A code that fails is quarantined, you are not charged for it, and we raise a claim against the supplier.

Service targets · not yet measured in production

What we will hold ourselves to.

These are the objectives the system is built against. They are targets, not achievements — there is no production traffic yet.

< 3 sOrder p95API call to sealed code
< 0.1%Ambiguous rateorders needing a status check
< 0.05%Disputesof codes delivered
< 24 hRecon exceptionsclosed after detection
08 · Request access

Access is by invitation.

Tell us who you are and how you would distribute codes. We review every request and reply by email.

Every code carries proof.

Read the API