An on-device agent
Apple Speech and Foundation Models turn a voice request into a structured proposal. Mate checks the product, store, chain and amount. The model receives no card data or signing tool.
ETHOnline 2026 · Physical iPhone prototype
Ask for a beer. Prove your age privately. Pay on Arc.
An iPhone companion that helps you act while keeping your identity evidence on your phone.
Native iPhone app required for card reading and proving. Testnet only; no real money or delivery.

What actually works
The physical-card flow completed on a real iPhone. These supplied app captures show an order, a locally generated proof and its completed Arc payment.



How it works
Apple Speech and Foundation Models turn a voice request into a structured proposal. Mate checks the product, store, chain and amount. The model receives no card data or signing tool.
The physical My Number card provides a government-signed credential and signs this order's challenge. A Noir circuit checks the signatures, age of at least twenty and time limits.
The native prover creates an order-bound ZK proof locally. The shop receives the proof and public order inputs. Its Arc Age Gate contract verifies them through two RPC providers.
After user approval, Privy signs the exact x402 USDC authorization. The merchant sponsors gas on Arc Testnet. The app checks the receipt before showing success.
Card password, certificate, card signature, name, address, birth date and private proof witness.
Order-bound age proof, public order inputs, buyer address and exact payment. Wallet login and chain access use network services.
Age verification is a contract call enforced by the Worker, separate from the USDC transfer. Payments remain public and linkable.
Technology stack
SwiftUI · Foundation Models · Speech · DockKit · CoreNFC
JPKI / RSA · Age circuit · Native Rust bridge · Groth16 verifier
Workers · D1 · Durable Object · Persistent order recovery
Embedded buyer wallet · Exact USDC authorization · Sponsored gas
ProveKit is from World Foundation. This checkout uses My Number card identity; World ID authentication is not connected.
Explore the working build
A compatible iPhone with the native build is required for the purchase. The website is the connected store and project overview, not a browser replacement for the phone's NFC reader or prover.
Demonstrated: physical-card authentication, local age proof, Privy/x402 test payment, English checkout, explorer link and saved-order recovery. Checkout reliability and the hands-free experience are still being improved.
The prover uses a pinned experimental ProveKit Groth16 branch and a single-party test setup. Certificate revocation is not checked. Age verification relies on agreement between the two configured RPC providers. Smartphone My Number card, World ID, delegated payment permissions and a live Graph-driven decision are not integrated.
Public libraries and AI-assisted development are attributed in the repository. The cover is generated artwork; the purchase screens are actual user-supplied app captures.