Practices
Short rules that keep tills and merchants honest.
Discovery
- Newest by author +
d, then readp - Never subscribe by
#palone - Discard
v1whole — no half-migration
Vouchers
- Verify against the announcement's
p - Rebuild canonical fields before
verifyEventif you mutate objects (nostr-toolsmemos survive spreads) - Optional keys are omitted, never
null
Mint & claim
- Benefit freezes at mint — edit definitions for future issuances only
- Nonce is a bearer token — redact query strings in proxy logs
- Claim before invoice
- Already-claimed is
200, not an error - Create/mint have no idempotency key — reconcile, don't blind-retry
Auth
- Add a random
noncetag on every NIP-98 event - Re-mint Bearer on any
401 - Owner is never a row on their own minters list
Scope
- Absent
productDs/capmeans all products / no ceiling - Never send
nullfor those semantics