Features
A complete stablecoin payment stack for mobile money markets. Every feature accessible via USSD — no app required.
P2P USDC Transfers
Send stablecoins to any phone number. Transactions settle on Stellar in seconds. Fee-bumped so users never need to hold or acquire XLM.
- •Recipient identified by phone number
- •Idempotency keys prevent double-sends
- •Fee payer covers all Stellar transaction fees
- •Activity logged asynchronously (never blocks USSD)
Bill Payments
Pay utility bills, buy airtime and data — all from a USSD menu. USDC is debited, fiat is delivered to the provider via Airbills API.
- •Airtime, data, electricity, cable TV, internet, betting
- •Auto-refund on provider API failure
- •Fiat conversion via real-time CoinGecko rates
- •Daily spend limits enforced per KYC tier
Fiat On/Off Ramp (SEP-24)
Deposit local currency to get USDC. Withdraw USDC to receive local currency. Uses any Stellar SEP-24 compliant anchor.
- •SEP-10 authentication with anchor
- •Deposit: fiat → mobile money → anchor → USDC to wallet
- •Withdrawal: USDC → anchor → mobile money → fiat
- •Atomic order lifecycle: pending → processing → completed
Merchant Payments
Merchants register with a code. Users enter the merchant code and amount to pay instantly in USDC.
- •Merchant lookup by short code
- •Instant USDC settlement to merchant wallet
- •Transaction receipts via SMS
- •Merchant table in Postgres with public key mapping
Token Swaps
Swap between USDC and XLM using Stellar's built-in DEX. Path payments find the best route automatically.
- •path_payment_strict_send for predictable input amounts
- •Real-time XLM/USD pricing from CoinGecko
- •Automatic path finding on Stellar DEX
- •Fee-bumped like all other transactions
Custodial Wallet System
Deterministic key derivation from a master seed. Each phone number maps to exactly one Stellar keypair. No seed phrases, no key backup needed by users.
- •HKDF-SHA256 key derivation
- •AES-256-GCM encryption at rest
- •Argon2id PIN hashing
- •Same seed + phone = same wallet, always
Multi-Country Support
Deploy to any African country by changing two environment variables: FIAT_CURRENCY and FIAT_COUNTRY.
- •RWF, NGN, KES, GHS, and any CoinGecko-supported currency
- •Configurable USSD shortcode
- •Swappable SEP-24 anchor via config
- •Localized bill payment categories
Security-First Design
Built with Rust's memory safety, constant-time comparisons, and defense-in-depth security model.
- •IP allowlist for Africa's Talking callbacks
- •Redis-backed rate limiting
- •Constant-time webhook secret verification
- •Idempotency keys on all money movements