hackquest logo

Nota

A receipt your agent can spend once. Nota binds an x402 payment to the line items the seller signed, and makes that receipt redeemable — exactly once, only by the wallet that paid.

ビデオ

プロジェクト画像 1
プロジェクト画像 2

テックスタック

Solidity
Web3
Node
Next
React

説明

The gap
x402 gave agents a way to pay. It gave them nothing to hold afterwards. A transfer tells you an amount and two addresses — not what was bought, not which agent was acting, not what it was owed.

What Nota does
The seller signs the line items, quantities, total and payee as EIP-712 typed data before payment. The buyer pays USDC. An on-chain receipt binds the payment to exactly what was signed.

That receipt is an entitlement. The buyer redeems it later, once, and only from the wallet that paid. Wrong wallet, or a second attempt from the right one: rejected, no transaction sent.

Two ways to bind a receipt to an x402 payment

Bound — through our EIP-3009 adapter. Payment and receipt land in one transaction. The commitment sits inside the quote the seller signed before delivery, so it commits to what was promised.

Attested — through any facilitator that has never heard of Nota. The seller attests afterwards to what it delivered. Weaker: the seller's own commitment, not a transfer the contract witnessed. But it is the only path that can speak to delivery, and it works with every facilitator in the ecosystem.

We ship both.

Repositories
notaxyz/contracts — receipt store, consume-once registry, attestReceipt
notaxyz/entitlements — EIP-3009 settlement adapter, entitlement redemption, verification runbook
notaxyz/x402-facilitator — Bazaar discovery extension and a DoS fix, forked from https://github.com/hummusonrails/x402-facilitator.
notaxyz/bazaar-seller — seller reference implementation and independent verifier

Zero protocol fee. Immutable. Neither new contract is a proxy, has an owner, or has an upgrade path

ハッカソンの進行状況

Pre-existing
Receipt primitive live on Arbitrum One since June 2026, Base since August. Entitlement layer on Base mainnet in September — a real 0.10 USDC purchase, redeemed on chain.

Built during the buildathon, all on Arbitrum. Four layers, each on top of the one before it.

1 — Discovery. Implemented the x402 Bazaar extension in a fork of an existing open-source Arbitrum facilitator: declaration, indexing, and a guard rejecting loopback and private resource URLs from discovery records.

While in there, closed an unauthenticated DoS in its schema validation. Attacker-supplied JSON Schema ran on the event loop — a 60-character payload blocked it for a measured 109 seconds. Now under 400 ms in a worker thread with a hard timeout. Not Nota-specific; going upstream.

2 — A seller that sells through it. notaxyz/bazaar-seller lists its resource in that discovery index and serves the 402, so an agent finds the listing and pays for it without ever being told the URL. Plus an independent verifier that recomputes the hash over the delivered bytes rather than trusting the seller's output.

3 — A receipt attached to that sale. attestReceipt, a settlement-free path in the receipt store, for when payment settles through a facilitator the store never sees — which is exactly what layer 1 is. The seller commits on chain to the bytes it returned. No funds move, and the purchase reference is still consumed once, globally. 54,826 gas, against 121,339 for the full signed-receipt path.

4 — The entitlement layer, brought to Arbitrum. The EIP-3009 settlement adapter and the redemption contract, so a receipt from either path becomes something the buyer can redeem later, once, only from the wallet that paid.

Deployed and exercised. Four contracts on Arbitrum Sepolia, all source-verified, with both payment paths run end to end against the live chain — not a fork.

  • Attested: discovery → 402 → payment → delivery → attestation → six independent verification checks, including recomputing the hash over the delivered bytes.

  • Bound: purchase through the adapter → redemption rejected for the wrong wallet → accepted once for the right one → rejected on replay.

A reproducible runbook (documentation/ARBITRUM_SEPOLIA_DEMO.md). A reviewer can verify every recorded transaction on chain without running anything, or reproduce the whole flow with their own keys.

資金調達の状況

Bootstrapped, solo founder. No external funding raised. Applying to this buildathon's grants pool.

チームリーダー
FFarzam
プロジェクトリンク
エコシステムをデプロイ
Arbitrum SepoliaArbitrum Sepolia
業界
InfraAIOther