Live on Starknet mainnet · private payroll on STRK20

Pay your team.
No one sees who got what.

Shield STRK into the STRK20 pool, pay with private note to note transfers, then your team unshields to any address. Deposits and withdrawals are public and screened. Amounts and recipients inside the pool stay private.

Pool verified on Starknet mainnet
SN_MAIN 0x534e5f4d41494eSTRK 0x0471…38dPool 0x0403…12a
Vault balance · shielded notes
Private until you unshield
Wallet holds viewing keys. Nothing leaves your device.
Shielded
Pool
0x0403…12a
STRK20 · 10 block finality
Token
STRK
0x0471…38d · screened deposits
Privacy
note → note
Amount plus parties hidden
payroll.cairo · privacy_invoke
let pool = 0x040337b1af3c663e…;
shield(pool, STRK, 5000);
transfer(pool, team[0], 1200); // OPEN placeholder
transfer(pool, team[1], 900);
unshield(pool, STRK, myAddr, 1200);
Payroll run
Payroll run confirmed in one invoke per person

Sequential private transfers. Each tx is relayed, so the on chain sender is the relayer, not you.

TIP-403 clear · OPEN resolved by wallet
Viewing keys
Your keys stay in your wallet
hashKeccak -> sign -> Poseidon
strk20.starknet.io/app
PrivateRegistry never persisted
ContractDiscoveryProvider(pool)

All authority lives on chain. Verify it here.

Same pattern as remlo: every contract address is listed so judges can check without trusting this frontend.

ContractAddressExplorer
STRK20 pool0x040337b1af3c663e86e333bab5a4b28da8d4652a15a69beee2b677776ffe812aStarkScan
STRK token0x04718f5a0fc34cc1af16a1cdee98ffb20c31f5cd61d6ab07201858f4287c938dStarkScan
Echo helper (3 action bundle)0x78ae662e0cc6d1ab2cfeaf2a51ba8783d88e31886f88a794d142f95a6f8735bStarkScan
Chain SN_MAIN · 10 block proof validity · deposits and withdrawals are public and screened by the compliance signer.

Shield, pay privately, then unshield

Remlo has payroll, escrow and reputation. ShadowPay has shield, private transfer and unshield. Same table first thinking.

01 · SHIELD

Fund the vault

Public deposit into the STRK20 pool. Your STRK becomes shielded notes. Wait 10 blocks before the next private move.

shield(pool, STRK, 5000)
// public, screened
// viewing keys in wallet
02 · PAY

Pay privately

Private note to note to your team. Amount and recipients are hidden by the STARK proof. Relayer is the on chain sender.

transfer(pool, team[0], 1200)
transfer(pool, team[1], 900)
// OPEN placeholder resolved
// by wallet
03 · UNSHIELD

They cash out

Employee discovers notes with viewing keys, then withdraws to any Starknet address. Public exit, private history.

unshield(pool, STRK, addr, 900)
// public withdrawal
// private link hidden

What is private and what is not

Private

  • Who paid whom in note to note transfers
  • Amount of each private transfer
  • Link between your shielded notes

Public by design

  • Deposits and withdrawals, screened for compliance
  • DeFi via shared anonymizer pool address visible, amounts and timing visible
  • Relayer is the on chain sender for private txs
shield→private notes→unshield10 block wait between private moves · stay shielded longer for stronger privacy

Run it on mainnet. Three txs touching the pool is the submission.

Connect a STRK20 wallet, shield a small amount, do one private transfer, then unshield. Or use the batch panels below for the org and employee flow.

ShadowPay payroll

SN_MAIN · Pool 0x040337…812a
You're shielding
STRKSTRK
Deposit into the privacy pool-
NetworkMAINNET
Org · batch pay (private)
Sequential private note→note transfers. Each tx is relayed; amount + parties stay private.
STRK
Connect a wallet to pay. Self-address prefill works for a dry run. Paste a teammate address above.
Honest: deposits/withdrawals are public + screened; note→note hides who + how much. Stay shielded longer for stronger privacy.
Employee · claim privately
Discover shielded notes, then unshield to any Starknet address.
Uses wallet viewing keys · nothing leaves your device.
STRK →