Cova powers USDG payments for services with uncertain final prices: reserve an approved budget, settle a signed rate for session time, and release unused funds on Arbitrum.


Cova brings authorization and capture to USDG payments on Arbitrum. It helps service providers secure a customer-approved payment budget before a service begins, then collect only the amount actually owed when the session ends.
An invoice issued after usage does not reserve the customer's funds. Charging the full maximum upfront creates a refund and reconciliation workflow. This matters when providers incur costs before the final bill is known, while customers want a clear spending limit. Our initial focus is developer platforms offering digital services billed by session duration to users who already hold stablecoins.
CovaVault separates customer funds into available and reserved balances. Customers approve and deposit USDG, authorize a merchant and an expiry, and retain access to their unreserved balance. The authorized merchant can capture the final charge, while unused funds return to the customer's available Cova balance and can be withdrawn. Expired reservations can be recovered permissionlessly.
Our timed checkout adds enforceable billing terms to this primitive. A provider signs a quote containing the customer, service, rate, maximum budget, duration limit and expiry. The customer signs an authorization bound to that quote. A relayer submits the start transaction, and the provider adapter waits for confirmed active Router state before beginning work. On stop, CovaSessionRouter calculates the charge from onchain session duration at the signed rate, transfers that amount to the provider, and releases the remainder in the same transaction.
For example, a 20 USDG budget at 0.50 USDG per minute covers up to 40 minutes. A 28-minute session costs 14 USDG and releases 6 USDG back to the customer's available balance. This is an explanatory example; the payment receipt records the actual onchain duration and amounts.
The MVP includes immutable Solidity contracts, EIP-712 authorizations, a typed TypeScript SDK, wallet-based funding, relayed session controls, transaction receipts and recovery for expired, pending or reverted operations. Contracts use OpenZeppelin protections, merchant permissions, nonces, expiry validation and explicit accounting. Arbitrum supports the repeated EVM payment transitions, and official Paxos USDG is the settlement asset.
The contracts are deployed and source-verified on Arbitrum Sepolia, and the frontend and session APIs are live on Vercel. The full local payment lifecycle and browser flows have been validated. Cova is a testnet MVP: its onchain clock verifies billing terms and payment state, while service delivery and quality remain the provider's responsibility. Our next step is to validate the integration with external service providers and funded public pilot sessions.
During the hackathon, we built and deployed the Cova payment MVP:
- Implemented CovaVault v2 with USDG deposits and withdrawals, available/reserved accounting, merchant-scoped holds, partial captures, remainder release and permissionless expiry recovery.
- Added EIP-712 customer authorizations with nonces, replay prevention and contract-wallet signature support.
- Built a typed SDK with live contract reads, transaction handling and hold/session discovery.
- Implemented CovaSessionRouter with provider-signed billing quotes, quote-bound customer consent, deterministic duration-based charges, atomic capture/release and session cleanup.
- Shipped the Next.js checkout and direct-hold playground, injected-wallet support, chain switching, exact approvals, relayed session start/stop, receipts and recovery after refresh, pending confirmation or transaction revert.
- Added a reference provider adapter that starts an illustrative local workload only after confirmed Router activation and stops/finalizes at the signed duration cap.
- Passed 107 Foundry tests, 48 unit tests and the complete 11-test browser suite. Three opt-in fork tests were skipped in the no-RPC test run. Production builds and merged-main CI passed.
- Deployed and source-verified the Vault and Router on Arbitrum Sepolia using official Paxos USDG, published the application on Vercel, and merged the implementation into the public GitHub repository.
An actual local API/SDK/Anvil run reserved 20 MockUSDG from a 100-token deposit. After 122 seconds at 0.50 per minute, the provider received 1.016666 and 18.983334 was released, leaving 98.983334 available. MockUSDG is a local testing fixture; the public deployment uses official USDG. A funded public settlement recording remains a separate demo step.