glidepay is live on Arc mainnetLaunch note
Mainnet

Architecture

glidepay is a Next.js application running on Arc mainnet. Accounts are Circle developer-controlled wallets: Circle holds the keys, and glidepay's server requests signatures through Circle's API. Here's the stack and the responsibility split.

The pieces

  • Next.js 16 (App Router). UI and server routes. Deployed on Vercel.
  • Clerk. Authentication. Email and Google sign-in. We never touch passwords.
  • Circle Developer-Controlled Wallets. A smart account on Arc for each user, plus a separate wallet for Savings. Server-side signing via Circle's API. No keys or secrets ever land in the client.
  • Circle App Kit. Swap and bridge primitives. USDC ↔ EURC ↔ cirBTC on Arc, plus CCTP V2 cross-chain.
  • Supabase Postgres + Prisma. User metadata, contacts, payment requests, scheduled sends, automation rules, activity records, chat history, and a hash of your PIN. Source of truth for off-chain state.
  • Groq. The language model behind Billy. It returns structured JSON intents, and every money move still shows a confirm card before anything happens.
  • Web Push (VAPID). Push alerts on the installed app when USDC or EURC arrives, alongside the in-app notification feed.

The flow when you send

  1. You tap Send → type the amount → pick the recipient → confirm with your 6-digit PIN
  2. Client POSTs /api/send with { walletId, destinationAddress, amount, token, note }
  3. Server checks your PIN, resolves the recipient (0x / @paytag / contact), validates ownership of the source wallet, asserts sufficient balance, and checks for a duplicate send in the last 10s (idempotency)
  4. Server calls Circle createTransactionwith the wallet's server-side signing credential
  5. The transaction settles on Arc with sub-second finality; we record a Transaction row and push-notify the recipient

The flow when someone sends to you cross-chain

Rolling out, not live yet. See Universal Receive for the full version. Short: Circle webhook fires on inbound USDC at your receive address → handler atomically claims the event → gas refill if needed → CCTP V2 burn-on-source + mint-on-Arc → push.

Why developer-controlled wallets

Browser-side wallet management means extension pop-ups, seed phrases, and users who lose access permanently. Developer-controlled wallets (via Circle) mean email-and-Google sign-in, an account you can sign back into from any device, and a UX that looks like Venmo. The trade-off is trust. You trust glidepay and Circle to operate your wallet honestly, and on mainnet that trust covers real money. See Security model for the longer version.