Non-custodial recurring payments on Base. Authorize once. Pay forever.
AuthOnce is an on-chain subscription protocol built on Base Network. Merchants create subscription products. Subscribers authorize once using an EIP-2612 gasless permit signature and are billed automatically — in USDC, USDT, or EURC — without ever giving up custody of their funds.
- Merchant registers and creates a subscription product with a price, interval, and accepted token.
- Subscriber signs a single EIP-2612 permit off-chain — no gas required, no on-chain approval transaction.
- Keeper bot executes pulls automatically on each billing date using the stored permit.
- Protocol collects 0.5% atomically on every payment. Merchant receives the rest instantly.
No funds are ever held by the protocol. The subscriber's wallet is never drained beyond the exact subscription amount per cycle.
- EIP-2612 gasless authorization — Subscribers sign once off-chain. No approval transaction, no gas cost at signup.
- Multi-token — USDC, USDT, EURC. Admin-controlled whitelist.
- EIP-712 + ERC-1271 — Standard wallet-native authorization. Compatible with MetaMask, Ledger, Coinbase Wallet, Gnosis Safe, and AI agent wallets.
- Programmable grace period — 1–30 day configurable dunning window. Keeper retries daily before expiring.
- Intro pricing — Up to 12 pulls at a reduced introductory rate before switching to full price.
- Free trials — Up to 90-day trial periods before first payment.
- 30-day price change notice — Enforced on-chain. Merchants cannot change prices without minimum notice.
- Non-custodial — Protocol never holds funds. No VASP/CASP licence required.
- AI agent payments — Smart contract wallets authorize pulls via EIP-712 structured signatures with per-pull deadlines. Currently requires a signature every billing cycle — full autonomous operation is planned via on-chain session keys, not yet built.
- DataOnce ready —
dataVaultIdfield on every subscription for Phase 2 encrypted data vaults.
SubscriptionVault.sol — Core protocol. Subscriptions, pulls, grace periods.
MerchantRegistry.sol — Merchant whitelist. Invite-only with self-serve toggle.
scripts/keeper.js — Keeper bot. Polls due subscriptions, executes pulls.
scripts/notifier.js — Event listener. Sends webhooks and emails on all events.
scripts/api.js — REST API. Merchant dashboard, Google OAuth, JWT wallet auth.
scripts/db.js — PostgreSQL schema and queries.
scripts/webhook.js — HMAC-SHA256 webhook dispatcher with exponential backoff.
frontend/ — React + Vite merchant and subscriber portal.
| Contract | Address |
|---|---|
| SubscriptionVault | 0xd6377Fa4809C4b745F5F1801193e5a90cD4AAE26 |
| MerchantRegistry | 0x393BA721aB45f4d4DaAC1B914e7F6377508C0299 |
| USDC (test) | 0x036CbD53842c5426634e7929541eC2318f3dCF7e |
| Contract | Address |
|---|---|
| SubscriptionVault | [deploy pending — Q3 2026] |
| MerchantRegistry | [deploy pending — Q3 2026] |
| USDC | 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Protocol Treasury | 0x737D4EeAEF67f776724482a29367615703A2DEB1 |
- Vault funded at exactly 1× subscription amount per billing cycle — no over-funding, no balance, no refund UX.
- Keeper bot is the only caller of
executePull()andexpireSubscription(). - Protocol fee: 0.5% — global constant, same for all merchants and tokens. Hard ceiling 2%, never raiseable above it.
- Payment token at signup = all future pulls — token is immutable per subscription.
- Cancellation: subscriber or guardian only — merchant cannot block or delay.
- Price changes:
setProductExpiry()enforces 30-day minimum notice on-chain. - Grace period: default 7 days, configurable 1–30 days per subscription.
EOA subscribers (MetaMask, Ledger, Coinbase Wallet) authorize via EIP-2612 permit — a gasless off-chain signature that grants the vault a one-time pull allowance per billing cycle. No on-chain approval transaction required at signup.
The permit is signed once and stored. The keeper bot presents it on each billing date. If the permit is expired or revoked, the pull fails gracefully and the grace period begins.
Contract wallet subscribers (AI agents, Gnosis Safe, smart wallets) authorize pulls via EIP-712 structured signatures.
Domain:
name: "AuthOnce"
version: "7"
chainId: <runtime>
verifyingContract: <SubscriptionVault address>
PullAuthorisation type:
PullAuthorisation(
uint256 subscriptionId,
address token,
uint256 amount,
uint256 pullCount,
uint256 deadline
)
pullCount acts as a nonce — each pull has a unique hash. deadline enforces a tight 24-hour TTL per pull signature.
On-chain protocol fee: 0.5% on every payment. Same for all merchants, all tokens.
Merchant tiers determine platform features only — not the on-chain fee.
| Tier | Price | What you get |
|---|---|---|
| Starter | Free | Full protocol access, all tokens, webhooks, basic notifications |
| Growth | €49/month | Branded subscriber emails, priority support |
| Business | €199/month | Custom sender domain, advanced analytics |
| Enterprise | Custom | Custom integrations, SLA, white-label options |
Tier enforcement is off-chain (API). The contract is tier-agnostic.
| Layer | Technology |
|---|---|
| Smart contracts | Solidity 0.8.24, Hardhat, Base Network |
| Keeper + Notifier | Node.js, Railway |
| Backend API | Express.js, PostgreSQL, Railway |
| Frontend | React, Vite, Cloudflare Pages |
| Subscriber auth | Google OAuth (Passport.js) or wallet-signature login |
| Merchant auth | Wallet-signature login (MetaMask / RainbowKit) + JWT |
| Notifications | Resend + HMAC-signed webhooks |
| DNS + CDN | Cloudflare |
AuthOnce is fully crypto-native — no fiat payment processor anywhere in the stack. All payments settle directly on-chain, wallet to wallet.
- Node.js 18+
- PostgreSQL
- A funded Base Sepolia wallet
git clone https://github.com/Vascodiogo/the-opportunity
cd the-opportunity
npm install
cp .env.example .env
# Fill in .env values
DEPLOYER_PRIVATE_KEY= # Deployer wallet private key (deploy only)
KEEPER_PRIVATE_KEY= # Keeper bot wallet private key
VAULT_ADDRESS= # SubscriptionVault contract address
BASE_SEPOLIA_RPC_URL= # Base Sepolia RPC endpoint
DATABASE_URL= # PostgreSQL connection string
RESEND_API_KEY= # Resend email API key
GOOGLE_CLIENT_ID= # Google OAuth client ID
GOOGLE_CLIENT_SECRET= # Google OAuth client secret
JWT_SECRET= # Admin JWT secret
ENCRYPTION_KEY= # AES-256 key used for at-rest encryption of sensitive off-chain data
PROTOCOL_TREASURY_ADDRESS= # Safe multisig treasury address
# Base Sepolia
npx hardhat run scripts/deploy.js --network base-sepolia
# Base Mainnet
npx hardhat run scripts/deploy.js --network base-mainnet
node scripts/api.js # Backend API
node scripts/keeper.js # Keeper bot
node scripts/notifier.js # Notification backend
cd frontend && npm run dev # Frontend
AuthOnce sends HMAC-SHA256 signed webhooks to registered merchant endpoints on all subscription lifecycle events.
| Event | Trigger |
|---|---|
subscription.created |
New subscription authorized |
payment.success |
Pull executed successfully |
payment.failed |
Insufficient funds or allowance |
payment.upcoming |
3 days before next payment |
subscription.paused |
Subscription entered grace period |
subscription.resumed |
Subscription resumed after grace |
subscription.cancelled |
Subscriber cancelled |
subscription.expired |
Grace period ended, no recovery |
subscription.expiring |
Price change notice (30 days) |
Business Source License 1.1 (BUSL-1.1)
© 2026 Vasco Humberto dos Reis Diogo. All Rights Reserved.
Production use requires a commercial licence. Contact: vasco@authonce.io
- Website: authonce.io
- App: app.authonce.io
- X: @AuthOnce
- X: @VascoBuilds
- Farcaster: @authonce
- Contact: vasco@authonce.io