Here is a real test order from start to finish. The buyer ordered 1,000 milliseconds of robot-arm time at 0.00001 USDC per millisecond, and the device actually ran for 618 milliseconds. Step through it. The sequence diagram on the left lights up what happens at each step, and the ledger on the right shows where the money is at that moment.
Run the numbers yourself
The settlement rules live in the contract, and anyone can check the math. The charge is the unit price times the amount actually delivered. The platform fee comes out of the seller's revenue. The rest is split among the payees by the shares in the terms. Everything not delivered goes back to the buyer. Drag the sliders below and see.
When the buyer disputes the delivery
Signed device metering is evidence, yet the real world has surprises. A robot arm jams, the meter reads normally, and the job is still unfinished. So every metered order gets a dispute window once delivery is proposed. The buyer can write a reason, sign it and raise a dispute. The money stays in the contract, and the arbiter named in advance in the service terms decides how much was really delivered. If the arbiter does not rule in time, the buyer gets a full refund.
More details that make machines trustworthy
Claiming is identity. The first time a device is claimed, it signs a one-time challenge with a key generated inside the device. From then on only that organization can run it and sell it. Anyone else who gets hold of the device still can't pass as it.
Encryption reaches the chip. The device connects to the gateway over a TLS-encrypted WebSocket. In the "module + host" design, the UART or SPI link between the module and your MCU is also encrypted frame by frame with the Noise protocol.
Anyone can verify the evidence. The platform batches device-signed records into a Merkle tree and anchors only the root hash on-chain. Every record comes with a full inclusion proof: the record, the Merkle path, the on-chain root and the transaction.
Firmware updates leave nothing to luck. A device installs only firmware signed by the publisher key. New versions roll out in batches and pause automatically when the failure rate passes a threshold. If new firmware fails to boot, the device rolls back to the previous version on its own.
Devices that fail security can't trade. Each product can set a security policy covering secure boot, flash encryption and how keys are stored. Devices that fall short get flagged, and the policy can block them from buying and selling outright.
Payee keys stay with the seller. When a seller uses its own payee address, no order takes effect until the seller's key signs its terms. The seller can sign with a wallet in the app, or run a signing tool next to the key that signs automatically under rules the seller sets.