01
The invoice leaves
It goes out of your billing system with a number on it, and from that moment the number and the money are in two different places.
Payvol
The open payment layer for Canton.
Built on
The problem
An invoice leaves by email. A payment lands on chain minutes later. Then a person opens a statement, hunts for the amount, guesses which invoice it belongs to, and marks it closed by hand.
01
It goes out of your billing system with a number on it, and from that moment the number and the money are in two different places.
02
Later, in a different system, from a wallet you do not control. Sometimes partially. Sometimes twice. Rarely with anything on it that says which invoice it answers.
03
Export a statement, sort by amount and date, decide which payment is which. The work is not the payment. It is the matching, and it happens after the fact, every month.
Modules
One asks, one checks, one chooses how it settles, one watches it arrive, one matches it to the invoice, and one carries it to the systems you already run. Connect is not built yet; the other five install from npm.
How it moves
Four steps, and no point where somebody has to guess what a payment was for.
Ask
One artifact carrying the payee, the instrument, the amount and a reference. It is a link, a QR and an NFC tap from the same bytes.
Pay
Any wallet that reads the profile can pay it. Nothing is installed on the payer side, and the wallet shows what it will move before it asks for a signature.
Observe
The settlement lands on your participant with a digest of the request in its metadata. You read it from your own view, and you ask nobody.
Match
Amount, timing, instrument, receiver and policy answered separately, so the right amount to the wrong account does not read like a payment that is merely late.
Built on Canton
Canton brings the accounts, the assets, the privacy model and atomic settlement. The Token Standard defines how value moves. Payvol adds the layer above and consumes the rest rather than competing with it.
The transfer runs through the instrument registry under the Token Standard. Payvol references those entry points and does not replace them.
The payer, the payee and the instrument registry can read the identifier. A party that took no part reads nothing. The registry is a signatory of the template, so this is structural rather than a choice of ours.
No custody and no key. A request can only propose. The payer signature is the only thing that moves value, and it is made in their wallet.
No index to scan, no relay to trust, no account to open. Every module runs on infrastructure you already have.
Get started
The format, the SDK and the conformance suite are open source. Build your own implementation and run it against the same vectors we run, in your own browser.
import { encode } from '@payvol/core';
const uri = encode({
version: '0.1',
type: 'transfer',
recipient: 'payvol-demo-recipient',
instrument: 'DSO::1220be58c29e65de40bf273be1dc2b266d43a9a002ea5b18955aeef7aac881bb471a/Amulet',
amount: '1.5000000000',
reference: 'PAYVOL-DEMO-2026-08-01',
}); Returns
canton:payvol-demo-recipient?instrument=DSO%3A%3A1220be58c29e65de40bf273be1dc2b266d43a9a002ea5b18955aeef7aac881bb471a%2FAmulet&amount=1.5000000000&reference=PAYVOL-DEMO-2026-08-01