The P&L took revenue from AdminPaid events and holdings from eth_getBalance, so anything else moving through a receiver was invisible. Receiver A has earned 10,871.89 POL and holds 4,561.19; nothing explained the difference, and the gap would have widened every time Marty drew from it. "Why would I ever keep a receiver wallet that I never take anything out of? That's stupid, so I need to be able to account for it." Three kinds, because three different things move through that wallet and only one is profit. Revenue is outside income, a ClickBaitPays withdrawal paid in POL, and counts toward profit. A draw is house profit spent on something, such as funding RM Circle #139's Culmen to Apex upgrade; it leaves the wallet but is not a cost of running InstantAdPay. A transfer is Marty's own capital parked in the Tangem receiver for safekeeping, and moves the balance only: counting it as revenue would report his savings as earnings. The pane now states earned, plus revenue, less draws, against what is actually held, and names any unexplained drift rather than hiding it in a balance. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
InstantAdPay — site
Membership advertising with immutable on-chain settlement. Zero-dependency Node server (RM Circle pattern): static pages + JSON API + SSE ledger.
Architecture
server.js— http server: pages,/api/*,/join/<id>sponsor links, SSE feedchain.js— contract reader + persistent event indexer (free public RPCs)auth.js— SIWE wallet sign-in (EIP-4361), sessions in the volumeaccounts.js— site-side records only (free members, last-touch sponsor attribution, handles). The CHAIN is the source of truth for money/credits.public/— landing, live ledger, member area; no client libraries
Chain flip (rehearsal → mainnet)
Everything chain-specific lives in data/config.json (volume):
{contract, chainId, chainName, explorer, rpcs, deployBlock}.
Defaults point at the Amoy rehearsal deployment. Launch = deploy the
mainnet contract, wipe accounts.json/sessions.json/chain-index.json,
PATCH /api/admin/chain with the mainnet values, set rehearsal:false via
/api/admin/site. Same code, different config.
Run
PORT=3100 node server.js # DATA_DIR defaults to ./data
Admin API auth: Authorization: Bearer $ADMIN_PASSWORD.
Spec: ../CONTRACT-SPEC.md (v1.0.3-frozen). Contracts: ../contracts/.
Chatbot knowledge is part of every change
chatbot.js answers members two ways: CANNED regex answers and systemPrompt() for the AI. Any
change that a member could ask about (a new pane, a rule, a price, a limit, a fix they noticed) is not
done until both are updated in the same commit, and KNOWLEDGE_DATE in chatbot.js is bumped. The QA
runner (bash qa/run.sh public) fails when a release note on the live site is newer than that date.