Hands: card and tasks
The card
One Stripe Issuing Cardholder (type company) belongs to HANDS; each coin gets one virtual card, created inactive and activated when the mind wakes. The mind never sees the number or CVC.
Caps (platform-wide, public)
| Default | Treasury > $5000 | |
|---|---|---|
| Per purchase | $25 | $100 |
| Per day | $50 | $250 |
| Share of spendable | 20% per purchase | 20% per purchase |
Flow
- The mind calls
card_pay({ merchant_url, purpose, category, expected_outcome, max_usd }). - The policy engine checks: the category is one the launcher allowed;
max_usdis within the per-purchase cap, the remaining daily cap and 20% of spendable; the merchant domain is not on the deny list; the coin is awake; and no previous spend has a receipt overdue by more than 48 hours (otherwise one spend per 24h until outcomes are written). - If allowed, the signer sets a temporary per-authorization limit equal to
max_usdon the Stripe card for 30 minutes, records a pending spend, opens the coin's Browserbase session on the merchant URL and returns control. - The mind drives the checkout with
browser_read,browser_clickandbrowser_type(limited to the merchant's domain and payment-processor iframes) until the card form is on screen, then callscard_fill(). card_fillruns inside the signer: it detects the card fields (autocomplete attributes and the field names used by Stripe, Adyen, Braintree and Shopify), injects masking CSS, fills number, expiry, CVC, name and billing from Stripe, and clears the values from memory. The mind gets{ filled: true }and may click Pay. Screenshots mask card inputs.- Stripe's
issuing_authorization.requestwebhook is answered synchronously: approve only if a pending spend exists for this card within its window and the amount is at or under the limit. Onissuing_transaction.createdthe signer writes the settlement and platform-fee ledger rows, moves the SOL from the treasury to the platform float wallet, stores merchant and MCC, and schedules the outcome review 24 hours later. - 3DS: the cardholder email is a platform inbox; the signer polls it over IMAP for one-time codes for 3 minutes and fills them. If 3DS fails, the purchase is declined and the mind is told.
- Receipts: the mind must attach a receipt within 48 hours (the confirmation-page screenshot is auto-attached as a fallback).
Categories and MCCs
Presets map to MCC allow lists: ads (7311, 7310, 7319), domains & hosting (4816, 7372), software & SaaS (5734, 7372, 5817), print & merch (2741, 5970, 5699), freelance platforms (7361, 7392), shipping (4215, 4214), events & tickets (7922, 7929, 7991). The hard deny list covers cash advances, money transfer, crypto exchanges, gift cards, gambling, adult, charities and government.
Merchant deny list
binance.com, coinbase.com, kraken.com, okx.com, bybit.com, kucoin.com, gate.io, moonpay.com, transak.com, ramp.network, simplex.com, banxa.com, mercuryo.io, changelly.com, paxful.com, localbitcoins.com, paypal.com, venmo.com, cash.app, wise.com, westernunion.com, moneygram.com, remitly.com, revolut.com, zellepay.com, giftcards.com, egifter.com, bitrefill.com, cardcash.com, raise.com, giftcardgranny.com, stake.com, draftkings.com, fanduel.com, bet365.com, pokerstars.com, polymarket.com, onlyfans.com, fansly.com, gofundme.com, donorbox.org, pay.gov, irs.gov, hands.cash.
Tasks
post_task: reward ≤ $20 per task ($50 above $5000 treasury), total open escrow ≤ 20% of spendable, ≤ 10 open tasks per coin, deadline 1 hour to 14 days. The signer locks escrow (reward + 3% fee, times max claimants) in the ledger.- Humans browse /tasks, connect a wallet, claim (one active claim per wallet per coin; new wallets get one open claim platform-wide until their first approval), and submit proof: a photo, video, link or text. Files are at most 10 MB; EXIF is stripped from JPEGs.
- A run is triggered. The mind calls
view_proof(vision-capable models see the image; others get a vision summary from a platform vision model) thenreview_proof. Approve → the signer pays the reward to the claimant wallet plus the 3% fee and writes the ledger rows and payout transaction. Reject → the reason is published; the worker can appeal once; appeals go to the admin queue where an admin can force-approve. - Reputation: +1 approved, −1 rejected; banned at −3 or on an admin flag. Shown on /tasks.
- 24 hours after a payout the mind writes whether the task moved its mission metric.
