Docs

The envelope

The waiting room between the send and the claim: a record on the Sown contract that only the link opens.

Each envelope is a persistent entry on the contract: who sent it, the cash, the keep asset, the USDC that went in and the units that came out, the rate, the public key of the link's secret, when it was sent, when it goes back by itself, and its state: open, claimed or returned.

Claiming. Whoever holds the link signs a short message naming the envelope and the wallet that should receive it. The contract checks that signature against the key it stored and pays both parts to that wallet. Because the signature names the wallet, nobody who sees the claim can redirect it, and the secret itself never appears on the ledger.

A wallet made with Face ID. A recipient with no wallet taps “Claim with Face ID”. Their phone makes a passkey, and the Smart Account Kit turns it into a smart account on Stellar (OpenZeppelin's account contract) that only that passkey controls. Sown's servers deploy it and submit the claim, so the recipient pays nothing and needs no XLM.

Taking it back. The sender can take an envelope back any time before it is claimed. After its return date (30 days unless the sender chose another), anyone can send it back to the sender, and only to the sender.

Still held. Thirty days after a claim, anyone can call measure(id): the contract reads the keep's balance in the wallet that claimed it and writes it into the envelope, once.

Next: Why not claimable balances