Docs

Spend rails

The account is built so day-to-day spend can settle from notes you control — without publishing every merchant.

Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.

A private account that cannot pay for coffee is a vault with extra steps. Spend is specified to settle from shielded balance, with per-device limits, freeze, and a kill switch you control.

No unshield-to-spend as the happy path

Forcing an unshield before every purchase would republish the user at the worst moment. The intended path is pool-level settlement to a rail. The chain sees the pool act, not which account paid which merchant.

What is not on this page

No Visa, Mastercard, Apple Pay, or bank partner is listed as live. When underwriting and issuance are real, the partner names will appear here with the same status note as everything else. Until then, treat “card” copy on the wider web as unofficial.

Controls

Limits, freeze, and kill switch are account features, not issuer afterthoughts. A lost device should be stoppable without waiting on a call centre that can also see your history.