A match is not escrow.
The verifier observes public fields. It cannot freeze, release, reverse or recover anyone’s funds.
Put one buyer-funded settlement under the lamp. CAT checks the exact seller amount and the declared JudgeCat service fee under one transaction signature. It never holds funds or tells the seller to ship.
The verifier observes public fields. It cannot freeze, release, reverse or recover anyone’s funds.
The seller independently decides what to do next. CAT records evidence; it does not control performance.
Delivery and tracking details remain private. Only a digest may prove that an unchanged private record existed.
Choose a transfer scenario. The same strict checks run every time; seller proceeds and the disclosed service fee must match together before simulated dispatch.
This button cannot move money or collect a fee. It sends only the chosen scenario name to the public simulator.
Exact-match sample is ready for examination.
Loading sample…Loading sample…Loading sample…
Signed term · simulated only
CATX:loading
No real transfer is inspected in this demonstration.
The simulator proves the state rules are understandable. It does not prove the production payment parser is safe.
Buyer and seller countersign the identical devnet order using the existing CAT Authority message-signature boundary.
Test seller and service-fee instructions under one signature, exact lamports, memo placement, stale blocks, reorg handling and signature reuse.
A transaction signature may satisfy one docket only. Failed and reused evidence must remain blocked across restarts.
Only after the gates pass would a wallet be asked to construct a direct devnet payment. Mainnet remains a separate decision.