Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Payments

Payment providers move the money. Glimpr carries signed evidence of payment so that membership rights can be checked independently of a provider’s dashboard.

The funds flow is member → payment provider → creator. The protocol holds no member balance, creator payout balance or payment instrument.

The provider list

The creator signs an ordered list of authorised providers. The first is preferred; the remainder define fallback order. A host has no authority to insert itself, reorder the list or treat a receipt from an unauthorised provider as valid payment evidence.

Replacing a provider changes the creator’s authorisation for subsequent payment processing. It does not transfer captured funds, disputes or payment mandates out of the previous provider.

From payment to membership

  1. A charge is attempted through an authorised provider under the creator’s ordering and retry policy.
  2. The provider confirms the outcome and signs a receipt. An unconfirmed charge remains pending.
  3. The host validates the provider’s authority and the receipt’s relationship to the creator, member, offering and billing period.
  4. The host issues or extends the membership within its delegation and records the event in the creator’s history.
  5. The resulting evidence is made available with the history needed to verify it.

A receipt records what was actually paid, including amount and currency. Where a payment rail uses a different currency from the advertised offering, conversion and charging belong to the provider’s payment process; the receipt must not describe a payment that did not occur.

Payment confirmation, membership recording and witness acknowledgement can fail at different stages. Reliable operation requires reconciliation of uncertain outcomes and protection against duplicate charges. A retry is not evidence that the first attempt failed.

Failover

The reason for failure determines the next action.

ConditionIntended response
Provider refuses the creator or freezes further processingConsider the next authorised provider.
Temporary provider failureRetry within a bounded policy, then consider fallback.
Member’s payment instrument is declinedStop that charge attempt; another provider cannot be assumed to resolve the decline.
Payment is awaiting confirmationRetain the pending outcome and reconcile it before treating the charge as complete.

Fallback requires another usable provider and a valid way to pay through it. A card authorisation is not automatically portable between providers. Seamless switching is an integration requirement, not something the ordering of provider keys alone guarantees.

The design includes an alternative payment rail through Mel for cases where conventional providers are unavailable. Live provider integrations and that fallback rail remain outside the prototype’s established deployment claims.

Renewal and refunds

A renewal combines fresh payment evidence with a membership extension for the same member and creator. The extension advances paid coverage and continues the existing history.

A refund has two effects in different systems: the provider returns money, and a revocation changes membership standing. Neither action performs the other. Once a verifier has accepted history containing the revocation, the membership reads as revoked. See Memberships.

What payment independence means

Providers retain authority over settlement, fees, disputes and funds they hold. A replacement may serve future payments; it cannot release money frozen by its predecessor.

Glimpr’s contribution is to keep the membership relationship and provider choice under creator authority. It cannot compel any provider to serve a creator or guarantee that an alternative exists.