kinlock-registry
Data, not code. One public JSON file per verified payee, schema-validated, bound to the on-chain record by a hash so the registry can't quietly drift from what the contract says.
Payee fields (public only)
payees/<country>/*.json, validated against
schemas/payee.schema.json:
slugdisplay_namecategory(School or Rent)country(ISO 3166-1 alpha-2)local_currency(ISO 4217)citypayout_addressattesterverified_at
No personal data, no identity documents, no phone numbers, no evidence. If it isn't on this list, it doesn't go in the registry.
What CI enforces
- A payee's
countrymust be insupported-countries.json. - Its
attestermust be authorized for that country inattesters/<handle>.json. - Its directory must match its declared country.
- Its
slugmust be globally unique. meta_hash(SHA-256 of sorted-key compact JSON) must match the on-chain record, checked on a schedule against the deployed contract.
Who adds a payee
Never the registry maintainers acting alone, and never an agent on its own initiative. Payee additions come from a named attester, through a reviewed pull request, after the attester completes an onboarding checklist (trustline, XLM float, a real test release).