Superteam Vietnam · Bounty submission

ProofPort — portable, issuer-signed work receipts

Turn one public merged GitHub pull request into a credential that keeps artifact facts, issuer assurance, and Solana lifecycle state separate—and independently inspectable.

Working MVPGitHub OAuth, Phantom signing, SAS issuance, public verification

Live on Solana devnetBrowser receipt + two finalized sponsored issuance transactions

Honest stagePre-revenue; no users, partnerships, or regulatory approval claimed

Don't trust the pitch

Run the proof.

This page downloads the real browser-issued credential and runs all six portable integrity checks locally. No account, wallet, or server-side verdict is involved. One opt-in judge-mode audit then asks GitHub for six stable artifact bindings, asks Solana RPC for eight SAS bindings, and attacks three fresh in-memory copies. The detailed transcripts remain open below so every pass, failure, and unavailable source can be inspected or retried separately.

Browser verification transcript

Public bundle · computed locally

Checking…
Downloading the public credential…

The cryptographic checks run inside this browser after the bundle arrives.

Working product

From merged PR to portable proof.

This reproducible walkthrough uses no staged wallet secrets or private repository data. Captions are burned in.

Watch on YouTubeDownload MP4 fallbackRead the two-page deck

The business today

Work evidence exists. Trust context does not travel.

Independent engineers already have public merged pull requests, but a link shows only the artifact. Generic references are vague, platform reviews are trapped inside one marketplace, and recruiters still spend time reconstructing who confirmed what.

1

Artifact without assurance

A GitHub PR can prove code was merged, but not the scope of a maintainer's claim about the contributor's work.

2

References without portability

Testimonials and marketplace ratings lose provenance or disappear when a developer changes platform.

3

Verification without a shared state

Each employer repeats manual checks and depends on the issuer's or ProofPort's database remaining available.

Why onchain

Use the chain for shared authority and lifecycle—not storage theater.

Plain signed JSON already makes a claim portable. SAS adds the part unrelated issuers and verifiers otherwise cannot share cleanly: a neutral credential authority, schema, authorized signer, expiry, and closable lifecycle state.

Solana proves registry and signer state. It does not prove an issuer is honest. The full work claim stays offchain, issuer-signed, and downloadable; only an integrity reference and lifecycle state need to be onchain.
How it works in practice

One narrow claim, six inspectable steps.

  1. Developer signs in with GitHub and imports one public merged PR.
  2. ProofPort re-fetches server-derived merge and commit facts.
  3. A request freezes the canonical claim and its content hash.
  4. An identified issuer signs that exact hash with Ed25519.
  5. A separate sponsor may pay gas, but the issuer wallet must still authorize the SAS transaction.
  6. Anyone verifies the public page or portable JSON without an account.
Production-shaped onboarding

Users keep authority. ProofPort can remove the SOL hurdle.

Each issuer deterministically owns an isolated SAS credential and schema. A bounded sponsor pays fees and account rent, while the issuer's wallet remains the required authority and signer. ProofPort cannot manufacture an issuer receipt with the sponsor key.

Live devnet evidence used two separate keys: the issuer stayed at 0 SOL while the sponsor paid. The first transaction created the issuer's credential, schema, and attestation; the second reused the same credential/schema for a lower marginal cost.
What happens next

Convert technical proof into independent trust.

With a team and resources tomorrow, the priority is not another chain feature. It is evidence that real maintainers and hiring teams value this workflow.

1

First external issuer

Complete one receipt signed by the actual maintainer of a merged contribution and document where the flow creates friction.

2

Five buyer interviews

Test verification value with Vietnamese outsourcing firms, developer platforms, and remote hiring teams before pricing.

3

Pilot-grade operations

Add a GitHub App, managed PostgreSQL, durable hosting, issuer recovery, and Vietnam-focused legal review for a narrow pilot.

Founder fit

Built from lived developer-workflow experience.

Tang Minh Vu is a Vietnam-based full-stack engineer and independent SaaS/developer-tools builder with 3+ years of experience shipping end-to-end products. He operates 10+ production systems, built ContribAI (244 GitHub stars), has 10+ upstream pull requests merged, and won a Standouts award at the Agora Agents Hackathon 2026.

Evidence boundary: the live browser receipt is a self-issued technical validation, not independent maintainer confirmation. The lifecycle-close transaction belongs to a separate test attestation. The two-key sponsor trace validates the production transaction builder, not the authenticated browser route with that test issuer. ProofPort is pre-revenue, and commercial operation in Vietnam still requires legal review.