- Merchant
- Example Store
- Operation
- Product purchase
- Total
- 24.00 IPI
IPI Independent Protocol Infrastructure
Tap it. Approve it. Prove it.
IPI connects physical product identity, checkout, wallet approval and chain-backed ownership in one connected system.
Pay in a physical store with IPI Card, approve the complete operation in IPI Wallet and receive the merchant-provided receipt, warranty context, authenticity and ownership records in the same flow.
Built in public. The IPI Terminal and secure product authentication are currently in active development.
Card introduces the wallet-bound authorization factor. It carries no independent balance or recovery seed.
- 01Receipt / invoiceMerchant and payment trail✓
- 02Warranty contextTerms selected by the issuer✓
- 03Authenticity recordIdentity and disclosed provenance✓
- 04Ownership recordAccepted by the customer✓
Automatic for the customerExplicitly approvedIndependently verifiable
From the store counter to a Wallet that remembers.
Most checkout systems stop after the payment succeeds.
IPI can deliver the product relationship with it.
-
01
Identify the product
IPI Terminal reads the product identity and assembles the merchant, item, amount and operation.
-
02
Tap IPI Card
The customer presents a wallet-bound authorization factor at the physical checkout.
-
03
Approve in Wallet
IPI Wallet shows the product, merchant, amount and resulting records before confirmation.
-
04
Receive the proof bundle
After approval, the integrated merchant can deliver the receipt, warranty context, authenticity and ownership records to the Wallet.
A secure tap is a role—not a rectangle.
IPI is designed for cards, chips, stickers and embedded inlays that can live with a person or inside a product.
Choose the trust profile, physical format and purpose the operation actually needs.
IPI Card
A wallet-bound authorization factor for payment and high-value operations. It is not a second wallet: it holds no independent balance and no recovery seed.
- Tap to introduce the authorization factor
- Review the complete operation in IPI Wallet
- Freeze or replace the factor without moving the assets
IPI Product Chip
A physical identity and authentication layer embedded in an item, package or asset. It can identify the product and prove chip-level evidence, but cannot change ownership by itself.
- Connect an item to its durable product record
- Carry identity through production, sale and service
- Separate product proof from human authorization
Symmetric verification
Efficient authentication using protected shared key material and a verifier-controlled lifecycle. The current physical development evidence uses NTAG 424 DNA with dynamic SDM/SUN proofs.
Asymmetric verification
A future profile where the chip proves possession of a private key that does not leave the secure hardware, enabling verification through the corresponding public key.
One protocol. Multiple physical forms.
Cards, chips, adhesive labels and embedded inlays are being prepared for future availability. Physical format does not decide the role: where the verified security profile and lifecycle permit it, a form can identify a product or act as an authorization factor. Final supported operations and sale dates will be published only after production verification.
One account. Replaceable hardware keys.
IPI combines tamper-resistant secure elements with account abstraction. Each physical card or device holds its own non-exportable private key, while the user keeps one permanent smart-account address. Authorized cards can be added, removed or replaced without moving assets or changing the account.
- Private keys are generated and protected inside the secure element.
- Multiple independent hardware cards can authorize one IPI smart account.
- A lost or stolen card can be revoked and replaced.
- The account address, assets and history remain unchanged.
- Configurable authorization policies can support one-of-many or multi-factor approval.
- No single manufacturer or individual card permanently controls the account.
ONE ADDRESS
Assets + history remain here
Watch an in-store IPI purchase reach the Wallet.
Follow a controlled interface simulation from the merchant’s counter to the customer’s proof bundle. It does not sign, broadcast or record a real transaction.
- Product identified and checkout createdWaiting to start1
- Customer taps IPI Card at the TerminalWaiting for checkout2
- Customer reviews and approves in IPI WalletWaiting for card factor3
- Receipt, warranty, authenticity and ownership deliveredWaiting for approval4
The payment is the start of the product relationship.
When a merchant or platform integrates the complete IPI flow, the Wallet can become the customer’s verifiable place for the records created around a purchase—not another disconnected loyalty app.
One approval. The relevant records arrive with the completed purchase.
The USDC path is implemented behind an evidence gate and remains disabled until the live channel, denomination trace, relayer and transfer path are independently verified.
Illustrative integrated experience. Availability depends on the participating issuer, merchant and application.
Built as one system.
IPI Terminal
A clear checkout experience for products, payments, receipts and ownership operations.
Product Identity
NFC and cryptographic product identity connecting physical items with their digital records.
IPI Wallet
The human approval layer where the customer verifies exactly what is being signed.
IPI Chain
The independent network layer for verification, settlement and ownership events.
More than a network. A product stack with visible boundaries.
IPI is being developed across protocol, physical identity, consumer approval and merchant infrastructure.
Every capability is labeled by evidence—not ambition.
Infrastructure you can inspect today.
Public interfaces backed by the running IPI testnet.
- 01IPI ScanBlocks, transactions, accounts, validators and EVM lookup
- 02Dual executionNative IPI state with EVM and CosmWasm execution paths
- 03Open network interfacesRPC, REST, WebSocket and EVM JSON-RPC; gRPC tracked separately
- 04Test infrastructureWallet interface, faucet, status and public monitoring
Integrated source under real-world testing.
Implemented boundaries that are not being presented as production-ready.
- 01IPI Wallet applicationsWeb/PWA plus separate Android and iOS consumer shells
- 02IPI TerminalAndroid merchant shell for charge, products, Tap, sales and business
- 03IPI Tap v1QR, deep link, NFC/HCE and Nearby transport boundaries
- 04Commerce and identityProducts, acceptance, ownership, receipts and recoverable sale states
Explicitly blocked until evidence exists.
Controls stay unavailable instead of manufacturing a success state.
- 01Production wallet custodyTrusted account and signing adapters remain a release gate
- 02Merchant authenticationProtected Terminal operations require a real identity provider
- 03Secure card provisioningProduction keys, attestation and shared replay state are pending
- 04Live USDC over IBCDisabled until channel, trace, relayer and transfer evidence all pass
Proof, not promises.
The IPI public testnet is available now.
Latest finalized blocks
- Connecting to IPI Scan data…
One proof layer. Many products the ecosystem can build.
The goal is not for IPI to manufacture every application below. The goal is open infrastructure and a credible direction for builders, merchants, manufacturers and communities.
These are potential development paths—not claims that every product is available today.
Proofs that stay with the purchase.
- Receipt and invoice trailDurable proof of what was bought, from whom and when.
- Warranty and repair historyThe issuer decides which warranty terms and authorized service events are disclosed.
- Authenticity and ownershipOriginality evidence, possession proof and transferable ownership records.
- Verified reviewsProduct and service feedback backed by purchase or service evidence.
More context around every transaction.
- Discounts and loyaltyEligibility based on products, purchases or disclosed customer groups.
- E-commerce and P2P flowsConnect online checkout, wallet approval, acceptance and transfer.
- Auctions and marketplacesApplications can combine listing, payment, provenance and delivery evidence.
- Product and service exchangeTyped operations for sales, refunds, payouts and product-for-product exchange.
Turn operational events into evidence.
- Materials and origin trailsDisclosed provenance from raw materials through production and distribution.
- Fraud detection signalsFind mismatches across identity, custody, inventory and declared movement.
- Provable inventory and servicesAttest stock, custody or completed work without one shared private database.
- Customs, excise and tax proofsOptional evidence issued by authorized participants and verified later.
Give long-lived assets a verifiable memory.
- Digital Product PassportsRecords designed to outlive a manufacturer’s private application.
- Vehicles and equipmentOdometer, ownership and authorized service events with accountable issuers.
- Medical and industrial identificationNFC, RFID and embedded identities chosen for the risk profile.
- Commodities and goods marketsFuture applications can combine asset evidence, custody and settlement.
IPI provides verifiable primitives, not automatic truth. Every claim still needs an accountable issuer, appropriate hardware, a disclosure policy and evidence that can be checked. Private business or customer data should not be placed on a public chain by default.
Most chains begin with a transaction.
IPI begins with the complete operation.
A payment alone cannot prove what changed in the physical world. IPI is being designed so product identity, participant intent, settlement, receipt and ownership can be reviewed and verified as one connected event.
Product-aware primitives
Native models for products, chips, checkout, receipts, acceptance and ownership—not only generic token transfers.
Typed IPI Tap operations
Twenty-two versioned operations across Wallet and Terminal, independent of QR, NFC, nearby or deep-link transport.
Human-readable authorization
The exact product, amount, parties and action are bound to the summary the customer reviews before approval.
Multiple execution paths
Native IPI settlement alongside public EVM and CosmWasm execution, exposed through standard network interfaces.
Hardware with separate roles
A card authorizes, a product chip identifies, the account owns. No seed or independent card balance is required.
Fail-closed engineering
Unverified cards, identities, exchange rates and USDC routes stay unavailable instead of producing a manufactured success state.
Portable execution. Message-first integration. Verification without gatekeepers.
Research directions include broader WebAssembly portability, language-neutral message schemas, parallel execution, modular protocol upgrades, wider validator participation and privacy-preserving proofs. These are not current testnet performance or consensus claims.
Progress is measured by evidence.
The IPI roadmap is a sequence of verification gates—not a promise of dates, token value or production readiness.
Read the complete roadmap ↗-
00
Current focus
Make the project legible
Public ownership, maturity labels, licensing, architecture and decision records.
-
01
Current focus
Reproducible protocol baseline
Builds, network identity, compatibility tests, release artifacts and independent verification.
-
02
Verification gate
Verifiable commerce primitives
Product passports, chips, checkout, receipts, wallet signing and public/private data boundaries.
-
03
Verification gate
Independent operation
Repeatable node, wallet, explorer, terminal, monitoring, recovery and degraded-mode operation.
-
04
Planned
Interoperability with explicit trust
IBC and anchoring only with published custody, accounting, failure and exit models.
-
05
Long-term
Community-operated releases
Independent reviewers, multiple operators, security reviews and durable public governance.
The physical and digital worlds should not be separate systems.
A product can be genuine while its receipt is lost.
A payment can be valid while the product information is incomplete.
A database can contain ownership records while remaining controlled by one company.
IPI is being built to connect these elements into one independently verifiable flow.
Build, test and verify.
Connect to the public IPI testnet and explore the infrastructure currently available.
Developer documentation and integration tools are being expanded as the product moves through public testing.
Make every product provable.
Tell us what you are building, what must be verified and where the physical and digital flow breaks today.
- 01Technical first responseIntegration, protocol and infrastructure conversations
- 02Contact is optionalPublic testnet access does not require commercial approval
- 03Privacy-aware intakeYour message is emailed to IPI and never written on-chain
Built in public.
Used with context.
Clear boundaries for an experimental public network, open-source software and the information submitted through this website.
Public testnet notice
IPI public testnet infrastructure and product components are experimental and remain under active development. Availability, interfaces, network state and features may change or be interrupted.
- Testnet IPI has no represented monetary value and is not offered for purchase.
- Nothing on this site is investment, financial, tax or legal advice.
- Use of testnet software is at your own risk and provided without warranties.
Open infrastructure
IPI does not take custody of user private keys or assets. Public-network records can be visible, persistent and difficult or impossible to reverse after submission.
- The current public testnet uses a limited, operator-run validator set.
- The protocol direction is independent verification without permanent control by one card, manufacturer or marketplace.
- Public repositories are available on GitHub under the licences stated in each repository. External services apply their own terms.
Website privacy summary
The landing does not use advertising or behavioural analytics cookies. If you use the contact form, it processes your name, email, optional organization, selected interest and message only to answer the enquiry and protect the form from abuse.
- Your network address is used in memory for a one-hour rate limit; form content is not stored in the landing database or written on-chain.
- The message is delivered to the IPI project mailbox and may be processed by hosting, edge-security and mail providers. It is not sold or used for automated decision-making.
- Enquiries are retained for up to 12 months after the conversation ends, unless a longer period is required to establish or defend legal claims.
- You may request access, correction, deletion, restriction or object to processing, and may complain to your competent data-protection authority.
Privacy and legal requests: [email protected]