Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Glimpr: an experimental confederal creator-commerce protocol

Glimpr is a protocol for paid memberships in which the creator controls their identity, the member holds their membership, and a host serves the relationship under a limited grant of authority.

A creator’s name, membership history and payment arrangements should remain theirs when a service changes. Glimpr gives each of those claims a mechanism: signed routing information, witnessed history, bounded hosting authority and an ordered choice of payment providers.

Confederal describes how those mechanisms fit together:

  • Creator sovereignty. The creator’s signing identity is the root of authority. It authorises the host, the membership offering and changes of service. Clients check those authorisations independently.
  • No host-to-host federation. A client contacts the host serving the creator it needs. Hosts share a protocol for recognising creator authority; they do not have to establish a federation with one another.

Status. Glimpr is an experimental design with a private prototype. This book describes the protocol and its trust assumptions. It does not announce a released product, a public implementation or a stable integration contract. Deployment boundaries are stated in Limits.

Design principles

  • Bounded hosting authority. A creator authorises a host for one chapter of history and a fixed range of positions. An action outside that grant fails verification even when the host’s signature is genuine.
  • Portable membership history. Issuance, renewal and revocation belong to a per-creator append-only log. Witnessed checkpoints let a replacement host verify the history it receives.
  • Verifiable discovery. A name lookup carries evidence of inclusion or absence against a directory state the client can independently establish.
  • History-relative verification. Freshness and membership standing use witnessed progress and recorded billing periods. The verification decision does not consult a local clock.
  • Content sealed before upload. Member content is encrypted for the creator’s audience. Storage and the authority to decrypt it are separate responsibilities.
  • Money as facts, not custody. Providers handle funds. Signed payment evidence supports membership issuance and renewal; Glimpr holds no payout balance.
  • Separate member identities. Each creator relationship uses a distinct identity, reducing correlation through a shared account identifier.

Hosting is a job you can fire. The test is whether the name, history and existing memberships still work after the host changes. Signatures establish authority; available data and independent checks make the move usable.

Reading the design

Start with the Protocol overview, then Directory, Log and epochs, and Delegation and switching.

For the paid relationship, read Memberships, Payments, and Content sealing. Verification explains the evidence behind an access decision.

Signatures and encoding and Signed records describe the technical foundations without requiring implementation details. Privacy, Misbehaviour, and Limits state the boundaries.