Brand vouchers sourced from global suppliers and sold through one API — every code envelope-encrypted, revealed exactly once, and reconciled to the paisa on a double-entry ledger.
Closed-loop brand codes — app stores, gaming, streaming, retail — bought by businesses from a prepaid B2B wallet, delivered sealed, and accounted for journal by journal.
Codeproof is
Infrastructure for selling codes safely.
B2B-first distribution of closed-loop brand codes
A prepaid B2B wallet per partner, topped up by bank transfer
An API with quotes, idempotent orders, single reveal and signed webhooks
A ledger where every balance is a sum of postings
Codeproof is not
A wallet, a PPI or a listing site.
No stored value for individuals, no consumer wallet
Not a marketplace — we are the principal
Codes never sit in plaintext — not in logs, events or our console
Not live at scale — in build, onboarding by invitation
Product facts · not traction
What is built today.
Counted from the codebase, not from a pitch deck. The sandbox runs the whole flow against a simulated supplier that also misbehaves on purpose.
The sandbox catalogue mirrors the categories we are contracting for: app stores, gaming, streaming. Each SKU carries its region, denomination, expiry rule, resale flag and terms.
GP
Google Play
App-store credit · ₹100, ₹500, ₹1,000
PS
PlayStation
Store wallet · ₹1,000, ₹2,000
XB
Xbox
Gift card · ₹1,000
ST
Steam
Wallet code · ₹800
NF
Netflix
Gift card · ₹500
+
More brands
Via the supplier network after go-live, with India-region rights in writing.
Text monograms only — brand names are trademarks of their owners and imply no endorsement.
Every outcome, as an event.
Delivered, partly delivered, quarantined, held for the supplier — each one a signed, sequenced event your webhook receives. Illustrative data, real contract.
orderIdord_A91Pmoneyheld, not refundednextresolver asks supplier
HMAC
SHA-256 signed
ORDER
per-partner seq
DELIVERY
never dropped
REPLAY
GET /v1/events
Who it is for
Businesses that sell codes.
01
Recharge & bill-pay apps
Add gaming and app-store credit next to mobile recharge without holding supplier float yourself.
02
Kirana networks
Sell codes at the counter through TapProof, reveal behind the merchant PIN, earn a commission. Coming.
03
Rewards & loyalty
Turn points into brand codes delivered by API, with one reveal per code and a full audit trail.
04
Fintech cashback & benefits
Pay cashback or employee perks in brand codes, reconciled to the paisa against your own ledger.
Channels · roadmap, no dates
One core, three channels.
The vault, the ledger and the order engine are shared. Each channel only changes where the code is revealed and who is allowed to reveal it.
Now · sandbox
API partners
The /v1 API and the partner portal. Prepaid B2B wallet, quotes, idempotent orders, single reveal, signed webhooks.
Next
TapProof merchants
A “Sell vouchers” tab inside TapProof. The counter reveal sits behind the app PIN; the merchant commission gets its own ledger account.
After
VIKAM consumers
A UPI-only catalogue inside VIKAM, device-bound reveal, velocity limits and a consumer dispute flow.
03 · How an order works
Reserve first. Settle what arrives.
01 · Quote
Price fixed
Landed cost from supplier cost and FX; your price from face value minus your discount — held until the quote expires.
02 · Reserve
Money held
Under a lock on your wallet: status, tier caps and balance checked, the amount moved from available to reserved. Never negative.
03 · Supplier
Bought once
Our order id is the supplier reference, so the supplier itself dedupes. A timeout is never retried as a new purchase.
04 · Sealed code
Validated, encrypted
Region, denomination, expiry and duplicates checked. Good codes sealed; bad ones quarantined and claimed back.
05 · One reveal
Shown once
Plaintext only on an explicit reveal, once per code, audited with the device id. A second attempt returns the original timestamp.
06 · Ledger
Settled to the paisa
Delivered units settle reserved → supplier float + margin; undelivered units release to available in the same transaction.
Order lifecycle · 7 states
Where your money is, always.
Every order walks the same state machine. Each transition is validated, recorded with a reason, and emitted as an event.
CREATED
Order accepted
Checked against your status, tier caps and balance. Nothing has moved yet.
WALLET_RESERVED
Money reserved
The total moves from available to reserved under a lock on your wallet.
SUPPLIER_PENDING
With the supplier
Bought once, with our order id as the supplier reference. Money stays reserved.
then exactly one of
FULFILLED
Delivered
Reserved settles to supplier float and margin. Every code sealed.
PARTIALLY_FULFILLED
Partly delivered
You pay for delivered units only; the rest is released to available.
FAILED
Failed — refunded
The full amount is released back to available. No codes, no charge.
SUPPLIER_AMBIGUOUS
Confirming with supplier
The supplier timed out or answered unclearly after we sent the order. Money stays held — never refunded blind, never re-bought. A resolver asks the supplier about our reference and settles to one of the three finals; if the supplier never received it, the order fails and releases after a grace period.
Pricing · worked to the paisa
One ₹1,000 code, priced.
The same arithmetic the pricing code runs, in integer paise. Foreign cost is converted with a decimal library and always rounded up, so we never under-cost a code.
Quote · GPLAY-IN-1000 × 1Illustrative FX
Face value₹1,000.00
Partner discount · 2%− ₹20.00
Your price₹980.00
Supplier cost · $11.00 × ₹84.10₹925.10
Bank charge 0.25% + 18% GST, rounded up₹2.78
Landed cost₹927.88
Margin₹52.12 · 5.32%
Margin floor 1% — quotes below it are refusedQuote held 60 s
FX
Stale rates refuse to quote.
A rate older than the configured age makes the SKU unquotable rather than guessing.
Floor
No loss-leading by accident.
If price minus landed cost falls under the floor, the SKU is shown as unavailable.
Expiry
Sixty days or it is not sold.
SKUs whose codes would expire within 60 days are not quotable.
Hold
The price you saw is the price.
A quote fixes the unit price until it expires; an expired quote returns a fresh one.
The ledger, shown
One ₹980 order, journalled.
Double-entry and append-only. Balances are sums of postings; the database rejects a journal that does not balance and any attempt to edit one.
Journal
Account
Dr ₹
Cr ₹
Reserve
partner:available
980.00
partner:reserved
980.00
Settle
partner:reserved
980.00
supplier:float
927.88
revenue:voucher_margin
52.12
Release · on failure
partner:reserved
980.00
partner:available
980.00
Top-ups: Dr bank clearing / Cr partner available, idempotent on the bank UTR. Bad codes: Dr supplier claims / Cr supplier float.
04 · Security and money
Built for the day it goes wrong.
Single-reveal vault
Plaintext exists twice: in transit, and in your one reveal.
Per-code envelope encryption bound to its context, masked everywhere else. The reveal flips the code, decrypts and audits in one transaction.
Double-entry ledger
Balances are sums, never stored numbers.
Append-only journals, balanced by the database. Top-ups are idempotent on the bank UTR. Corrections are new journals, never edits.
Ambiguous orders
Unknown means held, not guessed.
When a supplier times out, money stays reserved while a resolver asks the supplier about that exact reference — then delivers or releases.
Idempotent orders
Retry without fear.
The same Idempotency-Key returns the original result. A different body under the same key is rejected.
Partial fulfilment
Pay for what arrives.
Asked for 10, got 7: you get 7, pay for 7, and 3 are released to your balance in the same transaction.
Tier caps
Limits inside the lock.
Daily and monthly caps are enforced at order time, inside the same lock that reserves the money.
Security · how the vault works
A code is a sealed envelope.
Envelope encryption
One data key per code.
Each code is encrypted with its own random AES-256-GCM data key; that key is wrapped by a key-encryption key. The ciphertext is bound to its order and code, so it cannot be moved to another record.
Single reveal
Once, audited, per device.
Revealing flips the code, decrypts and writes the audit row in one transaction, with the device id. A second attempt returns the original timestamp, and is audited too.
Masked everywhere else
Plaintext never rests.
Orders, events, webhooks and our own console show ****-****-1234. Plaintext is never logged, never put in events, and never stored unsealed.
Key rotation
Dual-key reads.
New codes seal under the active key; older codes still open under the key that sealed them, so rotation needs no downtime or re-encryption window.
Sign-in
Magic links bound to the browser.
No passwords. A sign-in link works once, expires quickly, and only in the browser that requested it — a forwarded link is useless.
Staff
Fluxus Forge staff only.
The console accepts @fluxusforge.in accounts with roles: owner, operations, finance, read-only support. Staff never see plaintext codes.
Compliance posture
Said plainly, pending marked.
What Codeproof is and is not, and which pieces are still in progress before partners go live.
Area
Position
Status
Product
Closed-loop brand codes sold to businesses. Not a PPI, no consumer wallet, no stored value for individuals.
By design
GST
Voucher treatment per CBIC Circular 243/37/2024, with a separate taxable fee line. Invoice template awaiting CA sign-off.
Pending
TDS
194Q tracking on purchases, matched to 26AS quarterly.
Pending
DPDP
Consent and retention: sealed codes purged 90 days after reveal; the hash and audit trail are kept.
Pending
Grievance
A named grievance officer and published SLA before partner go-live.
Pending
KYC
Tiered onboarding T0–T4 with caps enforced at order time; KYC flows run through the Fluxus Forge onboarding team.
Caps live · KYC manual
Integrate in four calls
Catalogue, quote, order, reveal.
Bearer-key REST with money as integer paise. Webhooks cover everything else — delivered, partly delivered, failed, held, quarantined, wallet credited.
Masked codes; plaintext through one audited reveal
Supplier timeout
Retry the purchase and hope
Ambiguous state, money held, settled by a status check
Balances
A balance column updated in place
Double-entry journals; balances are sums
Callbacks
Unsigned, unordered, best-effort
HMAC-signed, sequenced per partner, replayable
Onboarding
Manual KYC, one limit for everyone
Tiered limits T0–T4 enforced at order time
06 · Onboarding tiers
Caps follow your KYC.
Every partner is one legal entity with one wallet. Tier and caps are set at onboarding and enforced on every order.
Tier
Who
KYC
Monthly cap
Channels
T0
Consumer — individual, own use
Mobile OTP + PAN + device binding
₹25K / month, ₹10K / day, 3 codes / day
VIKAM / web
T1
Reseller — proprietor or freelancer
Aadhaar eKYC with liveness + PAN + penny-drop + selfie
₹2L / month
App + portal
T2
Proprietorship, partnership or LLP
Udyam or GST + firm PAN + partner KYC + bank in firm name + premises proof
₹25L / month (₹5L without GST)
Portal + API
T3
Private limited company
CIN + MCA directors + board resolution + GST + company PAN + bank in company name + UBO ≥ 10%
₹5Cr / month, raised on history
API + portal
T4
Enterprise — aggregators, fintechs, corporates
T3 + your AML policy + site or video visit + addendum
Custom, optional credit line
API
07 · Questions
Straight answers.
Codeproof is in build. The core — catalogue, pricing, orders, the single-reveal vault, the double-entry ledger and the partner API — runs today against a simulated supplier. Partner access is by invitation while we complete supplier contracts and go-live checks.
No. Codeproof sells closed-loop brand codes to businesses. Partners hold a prepaid B2B balance with us to buy codes; there is no stored value for individuals and no consumer wallet.
By bank transfer (UPI, NEFT, RTGS or IMPS) to your own virtual account, whose details you receive during onboarding. Every credit is matched to its bank UTR and can never be applied twice. Cards and net-banking are not accepted.
The order becomes “Confirming with supplier”. Your money is held — not spent and not refunded blind — while our resolver asks the supplier what happened to that exact order reference. It then settles to delivered or refunded. We never re-buy, so you are never charged twice.
Codes are envelope-encrypted per code the moment they arrive and are masked everywhere, including in our own console. Plaintext exists only in the one reveal response you request, and every reveal attempt is audited.
No. Each code is revealed exactly once; a second reveal returns 409 ALREADY_REVEALED with the original time. Hand the code to your customer from that one response — we cannot show it again, and neither can our staff.
You prepay your own B2B wallet with Fluxus Forge by bank transfer. An order reserves the amount, settles only for codes actually delivered, and releases the rest. Your balance is always the sum of your ledger entries, which you can read at any time.
Undelivered units are released to your available balance in the same transaction that finalises the order — automatically for failed and partly delivered orders. Withdrawals from the wallet go only to your registered, verified bank account.
The sandbox runs the real order engine, vault and ledger against a simulated supplier. Codes are fake and no money moves. Some SKUs misbehave on purpose — partial delivery, timeout, out of stock, wrong-region codes — so you can build against every outcome before go-live.
Every code is validated before it is sealed — region, denomination, expiry of at least 60 days, duplicates. A code that fails is quarantined, you are not charged for it, and we raise a claim against the supplier.
Service targets · not yet measured in production
What we will hold ourselves to.
These are the objectives the system is built against. They are targets, not achievements — there is no production traffic yet.
< 3 sOrder p95API call to sealed code
< 0.1%Ambiguous rateorders needing a status check
< 0.05%Disputesof codes delivered
< 24 hRecon exceptionsclosed after detection
08 · Request access
Access is by invitation.
Tell us who you are and how you would distribute codes. We review every request and reply by email.