The world's first offline-first payment protocol

Pay anyone. Anywhere.
Even with zero internet.

NexPay is the world's first offline transaction software — a secure payment ecosystem that lets two phones exchange cryptographically-signed value directly via BLE, NFC, QR and Wi-Fi Direct, then auto-reconciles with the cloud the moment connectivity returns.

Created by Jitesh — connect at jiteshprakash.com.np

Hybrid Payment Engine
Online Offline
NexPay
Online path
  • Server balance validation
  • Risk analysis in real time
  • Immediate settlement
Offline path
  • Offline Reserve (max 50%)
  • Peer cryptographic verification
  • Local two-phase commit
Synchronization
Server Reconciliation & Settlement
BLE NFC QR Wi-Fi Direct ECDSA · SHA-256 AES-256-GCM
🔒
Signed & hashedECDSA + SHA-256
50% reserve capcontrolled offline exposure
0
Local transaction confirmation
0
Offline transport channels
0
Offline reserve cap
0
Concurrent reconciliation capacity

Design targets from the NexPay specification — not production benchmarks.

The Problem

Digital money stops working when the network dies

Every payment app assumes constant internet, immediate bank authorization, and centralized approval for every transfer. That assumption breaks the moment connectivity does.

📺

Poor Network Coverage

Rural towns, remote villages and basements where the signal bar never fills — and payments silently fail.

🌍

Outages & Disasters

When storms, floods or blackouts take down towers, cash becomes the only option — even between two smartphones.

📱

Mobile Data Exhaustion

Users who run out of prepaid data mid-day lose access to their own money at the worst possible moment.

🎉

Congested Events

Stadiums, festivals and markets overload towers — thousands of phones, zero bandwidth for payments.

🏫

Offline Merchant Terminals

Shops and kiosks that can't afford connectivity or lose POS connectivity daily revert to cash registers.

NexPay is the bridge.

Digital trust that doesn't depend on connectivity — bringing the reliability of cash to the modern wallet.

Solve it →
Core Innovation

Not just offline. Offline-first by design.

NexPay transfers ownership of money using cryptographic proof — enabling trusted peer-to-peer value exchange with no server approval required at the moment of payment.

💰

Hybrid Wallet

One wallet, two logical balances. An online balance for internet payments and a cryptographically pre-approved offline reserve for disconnected transfers.

  • Online balance fully server-synced
  • Offline reserve works with no signal
  • Clear status for every rupee
🛡

Offline Reserve Allocation

Up to 50% of your balance can be locked into a pre-approved, cryptographically protected offline reserve — refreshable anytime you reconnect.

  • Safety cap prevents over-exposure
  • Signed authorization from server
  • Auto-refreshes when online
📦

Secure Transaction Package

Every transfer travels as an STP — an atomic, signed payload containing IDs, amount, timestamp, previous hash and an ECDSA signature.

  • Tamper-evident by construction
  • Replay-resistant nonces
  • Canonical SHA-256 digest

Two-Phase Commit

Offline payments use a local prepare → verify → commit handshake so both devices agree before value moves — even with no network.

  • Receiver verifies signature locally
  • Commit + ACK exchange
  • Local ledger persistence both sides
🔗

Chain of Custody

Each offline transfer links to the previous transaction's hash, forming a micro-block chain that captures full ownership history.

  • Immutable ownership trail
  • Divergence detection on sync
  • Auditable end to end

Cloud Reconciliation

When connectivity returns, pending STPs upload automatically. The server rebuilds the graph, validates every signature, scores risk and settles.

  • Automatic batch upload
  • Graph reconstruction + fraud scoring
  • PENDING_SYNC → SETTLED visibility
How It Works

Money moves device to device — then syncs when it can

No internet? No problem. The payment completes locally between two nearby devices and reconciles with the network the moment you're connected again.

01

Create & Sign

You enter the amount. NexPay builds a Secure Transaction Package and signs it with your hardware-backed TEE key.

02

Transmit Offline

The STP travels to the receiver's phone over BLE, NFC tap, QR scan or Wi-Fi Direct — no internet required.

03

Verify & Commit

The receiver verifies the signature, hash and chain continuity, then both ledgers commit — done in under 100ms.

04

Sync & Settle

Back online, pending STPs upload, the server reconstructs the transaction graph, validates and marks them SETTLED.

Prototype demo

Offline payment flow

Walk through the two-phase commit sequence described in the NexPay specification.

Online
Go offline to unlock the true power of NexPay.

Illustrative prototype simulation — the generated STP and log are example data, not a real transaction.

STP — Secure Transaction Package IDLE
1Prepare
2Verify
3Commit
4Sync
// Awaiting transaction…
{
  "status": "READY",
  "note": "Choose an amount and hit Send"
}
Transport Layer

Four channels. One protocol.

The same signed STP travels over whichever local connection is available — the protocol never changes, only the medium.

📡

Bluetooth Low Energy

GATT-based packet exchange between nearby phones. Best for markets, queues and person-to-person transfers up to ~10m.

~10m range
📱

NFC Tap-to-Pay

ISO-DEP tap between devices or merchant terminals. The fastest physical gesture in payments — instant, offline, secure.

<4cm tap

QR Codes

Encrypted STP encoded as compact payloads. Scan-to-pay works with any camera — no pairing, no setup, universal reach.

Any camera
📡

Wi-Fi Direct

Local HTTP handshake between peers for larger batches and merchant checkout flows without any internet uplink.

High throughput
Security Architecture

Bank-grade crypto, on-device and off

NexPay treats offline payments as first-class transactions. Every STP is signed, hashed, chained and audited — from creation to settlement.

🔒

Hardware-Backed Keys

Identity keys are generated and stored in the Trusted Execution Environment (TEE) when available, with secure software fallback on older devices.

ECDSA + SHA-256

Every STP payload is signed with ECDSA over SHA-256 and verified by the receiver offline and by the server during reconciliation.

🔐

AES-256-GCM at Rest

Local ledgers and wallet databases are encrypted with AES-256-GCM. A compromised phone doesn't expose readable records.

🔗

Micro-Block Hash Chains

Each offline transfer references the previous hash, creating tamper-evident chain of custody across disconnected transfers.

Replay & Double-Spend Protection

Unique transaction IDs, timestamps and nonces block replay. Local reserve decrement and server graph checks block double-spend.

📈

Graph Fraud Detection

The server reconstructs the full transaction graph on sync, detects divergent chains and scores risk before settling any balance.

📱 Device Encrypted STP
📡 Peer Signature verify
🗃 Sync Queue PENDING_SYNC
🗺 NexPay Server Graph rebuild
SETTLED Audit trail
PCI-DSS aligned GDPR / CCPA aware KYC & AML ready Full audit trails
Who It Serves

Built for the last mile — and beyond

From market stalls to emergency tents, NexPay keeps money moving when the network can't.

🛒

Rural Merchants

Accept digital payments with weak or no cellular signal. Instant settlement notifications and minimal setup keep small shops selling.

  • Soundbox merchant alerts
  • Offline queue mode
  • Auto-reconciliation
👥

Consumers

Send money to friends, family and vendors without internet, data balance or signal — and see payment status every step of the way.

  • P2P & P2M offline
  • Split payments
  • Status visibility
🩹

Emergency Response

When infrastructure is damaged, relief teams still need to move value. NexPay works device-to-device with later secure reconciliation.

  • Works post-disaster
  • Offline donor transfers
  • Auditable distribution
🏦

Banks & Institutions

Accurate settlement records, complete audit trails, risk scoring and regulatory compliance — a resilient rail for partner ecosystems.

  • API integration
  • Risk & fraud engine
  • Regulator-ready exports
🏠

Governments

Cash-transfer programs and subsidy distribution reach citizens in low-connectivity regions without excluding anyone.

  • Program disbursement
  • Offline verification
  • Compliance reporting
💻

Developers

A modular architecture with pluggable transports, a documented protocol and open APIs for building resilient payment products.

  • TransportChannel interface
  • Full protocol docs
  • REST API contract
Protocol Spec

The anatomy of a Secure Transaction Package

One atomic object carries the entire offline payment — signed, hashed, chained and verifiable by anyone holding the sender's public key.

stp.json
// NexPay Secure Transaction Package (STP)
{
  "transactionId": "tx_9f2c81a4d",
  "senderId":      "user_7b3e91",
  "receiverId":    "user_5a02c8",
  "amount":        250.00,
  "currency":      "INR",
  "timestamp":     1716412800000,
  "previousHash": "d2f2a9e1c4…",
  "metadata":     {"note": "market"},
  "signature":    "MEUCIQD…",  // ECDSA/SHA-256
  "hash":          "a41d0f8b…"   // canonical digest
}
Chain of custody

Every STP extends a local micro-block chain via previousHash, capturing unbroken ownership history across disconnected hops.

Two-phase commit

Prepare → Verify → Commit → ACK. Both parties persist to encrypted local ledgers with state PENDING_SYNC in under 100ms.

Reconciliation

On reconnect, batches upload, the server rebuilds the graph, validates signatures & hashes, applies risk scoring, and settles to SETTLED.

State machine

CREATED → PREPARED → PENDING_SYNC → SYNCING → SETTLED, with explicit FAILED paths and conflict resolution.

Roadmap

Three phases to a resilient payment economy

Phase 1 · Now

Core Offline Protocol

  • Offline transfer protocol & STP
  • Hybrid wallet with offline reserve
  • Cloud reconciliation & audit trail
  • QR + BLE transport
Phase 2 · Next

Merchant Ecosystem

  • NFC tap + Wi-Fi Direct channels
  • Group splits & utility payments
  • Soundbox & voice alerts
  • Expanded fraud & risk engine
Phase 3 · Vision

Borderless Resilience

  • Cross-border offline settlement
  • Wearable & satellite-assisted sync
  • Offline CBDC research & pilots
  • Open ecosystem standards (ISO 20022)
FAQ

Questions, answered

How can a payment work with no internet?

Your wallet holds a pre-approved offline reserve (up to 50% of balance) signed by the server. Offline, your phone builds a Secure Transaction Package, signs it with your TEE key, and transmits it to the receiver over BLE, NFC, QR or Wi-Fi Direct. The receiver verifies the signature locally and both devices persist the transaction. No server is needed at the moment of payment.

What happens to offline transactions when I reconnect?

Pending transactions upload automatically. The server reconstructs the transaction graph, verifies every signature and hash link, applies fraud risk scoring, then settles balances and marks each transaction SETTLED. You can watch this happen live in the simulator above.

How do you prevent double-spending offline?

Three layers: the offline reserve is decremented locally on every commit, so you physically can't exceed it; every STP carries a unique transaction ID, timestamp and nonce to block replay; and on sync the server's graph reconstruction detects conflicting chains and duplicate spends, rejecting invalid transactions.

Which devices and channels are supported?

Consumer Android smartphones with BLE, camera, NFC and Wi-Fi. Keys live in the hardware TEE where available, with a secure software fallback on older devices (Android API 26+). The same STP format works across every transport channel.

Is NexPay compliant with regulations?

The architecture aligns with PCI-DSS for payment data, GDPR/CCPA-aware data handling, KYC & AML workflows, and full audit trails. Every settled transaction retains compliance metadata and can be exported for regulators on demand.

What if my device is lost or stolen?

Device revocation and remote disable mechanisms let you invalidate a device's keys. Local data is AES-256 encrypted, the wallet is protected by PIN or biometrics, and the offline reserve cap limits any possible exposure.

World's first offline transaction software

Your money should work even when the network doesn't.

Join the offline-first payment revolution. Get NexPay and pay anyone, anywhere — with or without a signal.

Free to download · Works on Android API 26+ · 4 offline channels

Built by Jitesh — questions, partnerships & feedback: jiteshprakash.com.np