CatiPay

CatiPay · On-chain payment inspection

The cat checks
before you pay.

  • 01Inspect the destination.
  • 02Read the token.
  • 03Check the allowance.
  • 04Prepare the transaction.
  • 05Then sign.

No custody. / No private keys. / No blind signatures.

CatiPay mascot

Position

A payment should not begin with a signature.
It should begin with a read.

CatiPay behaves like a careful cat inspecting a payment before it leaves the desk. Every value on the receipt comes from your wallet, an RPC read, a contract call or a dry run. Nothing is invented.

CatiPay reads

  1. 01
    RecipientAddress or ENS, resolved and checksummed.
  2. 02
    ChainEthereum, Base, Arbitrum, OP Mainnet, Polygon.
  3. 03
    Tokenname(), symbol(), decimals(), totalSupply() via multicall.
  4. 04
    AmountparseUnits only. No floating point, ever.
  5. 05
    Wallet balanceNative and token balance from the RPC.
  6. 06
    Allowanceallowance(owner, spender) with honest thresholds.
  7. 07
    Gas requirementestimateGas plus current fee market.
  8. 08
    Contract statusBytecode present or externally owned account.
  9. 09
    Transaction calldataEncoded, decoded and shown before the wallet opens.

The desk

Six instruments.
One reading order.

Every instrument reads live data through viem with RPC fallbacks. Configure your own keys or use the public endpoints.

Primary flow

From connection to receipt, in the order the cat reads it.

  1. 01Connect wallet
  2. 02Enter payment
  3. 03Read destination
  4. 04Read token
  5. 05Check balance
  6. 06Check allowance
  7. 07Estimate gas
  8. 08Simulate
  9. 09Review calldata
  10. 10Sign in wallet
  11. 11Wait for receipt
  12. 12CatiPay receipt

Security model

01

No custody.

CatiPay never holds funds. It prepares a transaction object and hands it to your wallet.

02

No private keys.

Keys, seed phrases and wallet exports are never requested, read or stored. There is no field for them.

03

No blind signatures.

Target, value, method, calldata, gas and a dry run are on the receipt before the wallet opens.

Verdicts are cautious by design. BLOCKED is used only for technically impossible actions such as an invalid address, an insufficient balance or a failed simulation. Anything uncertain is marked CHECK. CatiPay never calls a transaction safe.

CatiPay mascot, ears back