PROVEIT Test a coin

Docs

What PROVEIT does

Paste a pump.fun coin. PROVEIT reads the website listed in that coin's metadata, opens it in a fresh headless browser, gets past "Connect wallet" with a sandbox wallet that was never funded, tries the site's main action and stamps what it saw: WORKS, PARTIAL or NO PRODUCT. The run streams live in the observation monitor, is recorded unedited and keeps a permanent result page.

The tested URL always comes from the coin's metadata on pump.fun. Nobody can make the agent open a URL they typed. A paid instruction is goal text only.

A house pick runs every 5 minutes: the most traded coin of the last 60 minutes with a testable website (at least 15 SOL of volume and 25 trades, not tested in the last 24 hours), weighted by free suggestions.

Planner tier right now: rules. In the rules tier the agent's decisions come from a fixed rule set (find the main button, connect, type a goal, wait for output). The model tier hands the same browser to a vision model with the same evidence rules.

Verdict criteria

WORKS

The hero action produced visible output, or the post-connect app rendered and reacted to input. Example: Voxelforge rendered fox.glb after "Generate".

PARTIAL

Reached the product but was stopped only by a required signature ("needs a signature: stopped there"), or the output was still pending, or the site timed out. The recording shows how far it got. PARTIAL never means "no product". Example: Tidalpost asked for signMessage; Merlo stayed on "Generating…".

NO PRODUCT

No interactive product reachable: a dead button, a placeholder, a 404 or "coming soon". Example: Glintmaps' "Launch app" opens a 404; Halocode is a "coming soon" page.

NO PRODUCT needs positive evidence: an HTTP 404, "coming soon" text with nothing to use, no interactive elements, or a button that changes nothing (no DOM change and no network request within 5 s, checked twice). Anything uncertain is PARTIAL.

The stamp judges the website's main action only, never a person, a wallet or a coin's safety.

The sandbox wallet

A fresh ed25519 keypair is made for every run. Only its public key enters the page; the secret key is zeroed and thrown away before the page loads and is never stored. The wallet answers Connect (Phantom, Solflare and Wallet Standard interfaces, named "Sandbox Wallet"). Every signMessage, signTransaction, signAndSendTransaction and signIn is refused with "User rejected the request." and the step log says "sign blocked".

We never sign or connect a real wallet on a tested site. We never send a transaction for you, never ask for a seed phrase and never hold your tokens.

Tiers and limits

House pick30 s cap, every 5 minutes, no badge
Deep test90 s cap, your instruction (max 140 characters), a badge, jumps the queue
Prioritydispute = paid = re-test = badge refresh, then holder tests, then house picks
Dispute1 free deep re-test per coin, ever, signed by the coin's creator wallet

Burn to test

A deep test, a re-test or a badge refresh burns $5.00 of $PRVIT. The quote reads the $PRVIT price from our own RPC read of the pump.fun bonding curve (or the PumpSwap pool after graduation) and SOL/USD, then rounds the amount up to whole tokens.

  • The quote holds for 10 minutes.
  • Memo format: PRVIT:<target CA>:<nonce>, 12-character nonce.
  • We verify at finalized commitment: the transaction succeeded, a burn of $PRVIT of at least the quote by the transaction's fee payer, the exact memo, landed inside the quote window. One signature unlocks one test, once.
  • What you sign, exactly: Compute budget (60,000 units, 10,000 micro-lamports) · BurnChecked of the quoted $PRVIT from your own token account · Memo. No transfer to anyone. Your wallet simulates it before you sign.
  • Three ways: scan the Solana Pay QR (or "Open in wallet" on mobile), sign with a browser wallet for that one transaction, or burn any other way and paste the signature.

Holder tier

Hold 250,000 $PRVIT and get 1 free deep test a day per wallet (UTC day). You sign a short message (no transaction, no connect kept): "PROVEIT holder test", the target CA, your wallet, a nonce and a 10-minute expiry. We verify the ed25519 signature and read the balance live across all your token accounts (Token and Token-2022). Global cap: 48 holder tests a day.

Accepted residual risk: tokens passed between wallets can unlock several claims in one day. The global daily cap bounds it.

Badges

Every deep test sets the coin's badge: "PROVEN WORKS · tested 2 d ago" in WORKS ink, or a neutral PARTIAL / NO PRODUCT variant. The badge greys out 7 days after the last test. A refresh burns $5.00, re-tests the site, then re-dates the badge with the new result.

Creator fees

The $PRVIT fee engine runs every 5 minutes. It reads the creator fee vault, collects when it holds at least 0.003 SOL, and splits it exactly: 60% compute, 20% ops, 20% buyback. The buyback wallet buys $PRVIT and burns it in the same transaction, every 5 minutes. Every round is a ledger row with its Solscan link.

Engine state: armed, waiting for mint.

payerB8YZ…4Gdy
computeFD6W…LwmT
ops5kbw…69NU
buyback2cdX…GakN
creator (option A only)9BF2…mbMm

The creator fee route (option A: the engine holds the creator key; option B: read-only, the operator claims) is set at launch.

Compute budget

One daily budget, shown publicly: the larger of $25.00 a day and 60% of the creator fees collected in the last 24 hours. Under 70% spent, house picks get the full model tier; from 70% to 100% the small model; above 100% the rules tier. The cadence never changes: a house pick every 5 minutes. Paid, holder and dispute tests always get the best enabled tier.

$0.00 of $25.00 compute today · tier rules

Isolation

The browser runs as its own system user inside its own network namespace. Egress is http and https to public addresses only: private, loopback, link-local and cloud-metadata ranges and every address of our server are dropped by the firewall, and IPv6 is off. DNS is pinned: we resolve the website ourselves, refuse private answers and map the host to that one address. Every run gets a throwaway browser profile, downloads are denied, camera, microphone, location and notifications are denied, and the browser is killed at the time cap. A self-test proves the isolation before any run (last check : passed).

The agent-only route check fetches the same URL without JavaScript from inside the same sandbox and compares the title and the visible text. If they differ, the result says "served differently to the agent". It never changes the verdict.

Retention

Recordings share 3 GB. House test recordings are kept while space allows. Paid tests keep theirs for 30 days or while the badge is live; dispute re-tests for 30 days. When a recording expires the result page keeps the step log, six frames and the final screenshot.

Calibration

Six tiny practice sites run through the real browser at every runner start and once a day. They are calibration specimens, not coins: never counted, never on the wall, the leaderboard or the ledger. If any verdict differs from the expected one, house picks pause and the page says "runner paused: calibration failed".

SpecimenExpectedObserved
voxelforge.appWORKSWORKS
tidalpost.xyzPARTIALPARTIAL
glintmaps.ioNO PRODUCTNO PRODUCT
orbyagent.aiWORKSWORKS
halocode.devNO PRODUCTNO PRODUCT
merlo.chatPARTIALPARTIAL

What a stamp is not

A stamp is an automated observation of a public website at one moment. It is not a judgement of a person, a wallet, a team or a coin's safety, and it is not financial advice. We never name wallets. We do not use words that accuse anyone; the stamp only says what the agent could and could not do.

FAQ

Do I need a wallet to watch?

No. Watching is free and needs no wallet. A wallet is used only when you sign your own burn or a holder or dev message, scoped to that one action.

Can I make it open any URL?

No. It only opens the website in the coin's pump.fun metadata. Instructions are goal text, never a URL.

Why PARTIAL and not WORKS?

The agent reached the product but a required signature, pending output or a timeout stopped it. The sandbox wallet never signs, so sites that gate everything behind a signature end there.

The verdict is wrong. What now?

The coin's creator wallet can sign a dev note shown on the result page, and gets one free dispute re-test per coin.

Where does the price on WORKS cards come from?

Our own read of the pump.fun curve or PumpSwap pool at test time and now. Price is never shown on PARTIAL or NO PRODUCT.

What happens to my burned $PRVIT?

It is burned: the supply goes down. Nobody receives it.

How often are house picks?

Every 5 minutes, from one period setting. Paid and holder tests jump ahead of them.

Can a site detect the agent?

Yes, a site can serve the agent something else. The route check compares a plain fetch with what the browser got and flags differences on the result page.

Risks

  • Automated observation can be wrong: a slow site may read PARTIAL, an unusual layout may confuse the rules tier. The recording is always attached so anyone can check.
  • Tested sites are third-party pages. The browser is isolated, but a browser exploit on a hostile site is a residual risk we accept and monitor; the operator has a kill switch and a host denylist.
  • $PRVIT price moves; quotes hold for 10 minutes and are re-read after that.
  • Holder claims can be repeated across wallets within the global daily cap.