portofel
all your money, from every bank you use, on one screen — this page is also the git repo.
Clone
This site serves the repository over git's dumb-HTTP protocol as plain static files (plain files — there is no git server here, or any server at all):
git clone https://git.ardegazu.ro/portofel.git
cd portofel
What it is
portofel is the suite's wallet: one card per bank you use, the balance big, the issuer visible, and a send button that pays any friend who holds an account there. A balance is a fold over that bank's encrypted log — this app holds your bank links, replicates each log as an ordinary banca member, and computes every number locally. There is deliberately no total across banks: different issuers are different currencies, and the wallet never pretends otherwise. Installable PWA — works saved to an iOS home screen, safe-area aware.
How it works
- No server, no room of its own. Browsers are libp2p peers: they meet through a circuit-relay-v2 node, discover each other via gossipsub, and upgrade to direct WebRTC. Each bank is its own encrypted room, keyed by the capability link you hold — the link never leaves the browser, and this wallet opens one headless bank session per link.
- Everything is end-to-end encrypted. Every peer pair is noise-encrypted end-to-end (even while frames still cross the relay), and bank membership is proved with a sealed hello derived from the link — an undecryptable hello means you're not in the bank. A sealed offline mailbox carries entries between members who are never online together.
- A payment is banca's payment. portofel signs the same wallet-kit order banca signs, appends it to the bank's log, and shows it with the same honest words: provisional until the banker acknowledges it, final after — never anything dressed up as done that is not.
- Hosting without an origin server. The client is a static build served as plain files — there is no backend anywhere. This page you're reading works the same way.
What's in the repo
client/src/portofel/app/ — the wallet
ClojureScript, no framework: the bank directory (banks.cljs),
the headless bank session (bankroom.cljs — banca's fold,
compiled from the sha-pinned banca sources, never a transcription), the
store, and the one-column card UI with its send sheet.
the kits — compiled from source, off the classpath
The shared rooms core (ardegazu-rooms-kit), the suite
identity (ardegazu-id-kit), friends and presence
(ardegazu-social-kit), the money artifacts
(ardegazu-wallet-kit) and banca's pure namespaces — all
sha-pinned npm git deps whose ClojureScript compiles into this build.
deploy/ — the publish pipeline
publish-repo.sh builds this very site: landing page + bare
mirror exploded to loose objects (static file servers and git's dumb-HTTP protocol
agree on "every path must exist"), with an anonymity gate that refuses to
publish identity-bearing bytes.
Run it yourself
cd client && npm install && npm run dev # :5173
Deploy: npm run build, then publish client/dist/ as
static files anywhere — IPFS, a CDN, a folder behind nginx. It needs nothing but
a libp2p circuit relay it's allowed to talk to (see
src/portofel/config.cljs).
Guarantees & limits, honestly
- The relay operator sees connection metadata, opaque room ids, and frame sizes/timing. Not content, not names, not amounts.
- A bank link is the whole capability, and it is irreversible: anyone who holds it reads every payment between every member of that bank, forever. Forgetting a bank here removes it from your devices — it un-discloses nothing.
- A payment is provisional until the banker acknowledges it, and the screen says so; the banker of each bank is who you are trusting, exactly as in banca.
- MIT licensed. Built on WebRTC and WebCrypto.