bitcoin++ Berlin 2026 · KaleidoPay
Pay with what you have.
Receive what you want.
One reusable BOLT12 QR says which layers the receiver accepts, in order: Bark, Arkade, Lightning, on-chain. The payer's wallet reads it and quotes every route it can pay, directly or through a swap provider found on Nostr. Any other BOLT12 wallet still sees a normal offer.
Demo
See it in the app
Recorded from Rate, KaleidoSwap's mobile wallet, on the iOS simulator with live mainnet quotes. Nothing was paid in these recordings.
Pay with what you have (40 s). Scan, see the receiver's order, compare Bark direct, Lightning, on-chain and four Electrum swap providers.
The receiver decides (35 s). A receiver who prefers on-chain: their choice and the best price are marked separately.
Screens
Receiver and payer in Rate
How it works
One code, every route
RECEIVER
Say where you want the money
- In Rate, open Receive → Reusable payment QR and connect your own LDK node over Nostr Wallet Connect.
- Pick the layers you accept and put them in order. Bark and Arkade addresses come from your wallets. The order is saved.
- Your node issues one reusable BOLT12 offer carrying that order. An on-chain address travels next to it in a BIP321 link.
PAYER
Pay with what you have
- Scan. KaleidoPay decodes the offer and shows They accept, in order.
- It quotes every route your wallet can pay, every fee included: Bark to their Bark address (no swap), the offer over Lightning, Bark's on-chain send, or an Electrum swap provider found on Nostr.
- Their choice and Best price are marked. You pick; nothing moves until you confirm.
RECEIVERRate
→ NWC →
LDK FORKissues the offer
→
BOLT12 OFFERssps_rails inside
→ scan →
PAYERRate · Bark
→
ROUTEBark · Lightning · on-chain · swap
The record
ssps_rails is an experimental offer field (type 1000000385) from the open SSPS spec §5.3: the receiver's rails, most preferred first. Bark and Arkade entries carry the receiver's address and the server's key. Lightning is always accepted.
Why the node issues it
LDK recognises its own offers with an HMAC over every record, so rails can't be added afterwards. We patched rust-lightning, ldk-node and ldk-server to issue offers with the record, including amountless reusable ones.
Swaps on an open market
Electrum's swap providers advertise on Nostr. KaleidoPay talks to them with Electrum's own protocol: the wallet pays a hold invoice and a prepayment, the provider locks on-chain, the wallet claims to the receiver's address and checks every script itself.
Beyond Bark
Nostr Lightning Swap Providers
KaleidoPay is not tied to Bark. The payer's wallet only needs to read the receiver's rails and pay Lightning. A Nostr Lightning Swap Provider announces on Nostr which rails it delivers to, quotes a swap from Lightning, and locks the receiver's asset on the receiver's rail for the same payment hash as the payer's Lightning payment: both settle, or neither.
PAYER · ANY WALLETpays sats over Lightning
→
NOSTR LIGHTNING SWAP PROVIDERquotes, then locks for the same hash
→
RECEIVERBTC · L-BTC · USDT on Liquid · Ark · RGB
LIVE TODAY
Electrum's providers
The first ones: Lightning → on-chain bitcoin, discovered on Nostr and quoted live on mainnet in Rate. KaleidoPay speaks their protocol and checks every lock itself.
NEXT · STABLECOINS
The receiver wants USDT on Liquid
They list liquid:mainnet/<USDt>. The payer pays sats over Lightning; a provider, for example a KaleidoSwap maker, locks USDt on Liquid for the hash; the claim pays the receiver's Liquid address. The payer never holds USDT.
NEXT · ANY RAIL, ANY WALLET
An open market
Rails: on-chain, Liquid BTC and assets, Arkade, RGB on Lightning. Payers: Bark today; Arkade, Spark or any Lightning node next. Every provider that can route a payment quotes it, and the wallet shows them side by side.
Direct routes appear whenever payer and receiver share a layer (Bark to Bark, Arkade to Arkade, Liquid to Liquid). Providers fill every gap in between. The locks and messages are specified in SSPS.
Status, honestly
What works today
Proven
- Scan → receiver's order → live quotes for every route, on mainnet in Rate (iOS simulator). Quotes only.
- Receiver flow: ordered layers saved; the LDK fork issues the offer with the rails over encrypted NWC (regtest, and signet with a real node); bytes checked after issuance.
- A wallet that doesn't know the record pays the offer (end-to-end test with real bitcoind and ldk-server).
- Electrum swaps over Nostr fully paid and claimed on Mutinynet in 24 s and 19 s, with our own provider.
- Bark pays Lightning and Arkade receives Lightning on mainnet (small amounts).
- SSPS spec published (CC0) with test vectors.
Not yet
- A complete payment from Bark through an enriched QR, end to end: receiver and payer have run on different networks so far.
- Arkade paying an Arkade address directly: the wallet library has no fee estimate to quote with yet.
- The receiver answering with a per-payment lock (
ssps_lock) instead of a static address.
The end-to-end demo video uses a real signet receiver node and live quotes; its final payment step is simulated and labelled as such on screen.
Built in Berlin, 1–3 October 2026
What existed, and what we built
Before EXISTING
- Rate, KaleidoSwap's mobile wallet: Spark, Arkade, RGB, Lightning over NWC, QR scanner.
- wallet-engine, the multi-protocol wallet library behind Rate.
- SSPS drafts (private), including the idea of rails in a BOLT12 offer.
- A regtest fixture with LDK nodes and an NWC bridge.
Built at the hackathon NEW
- Bark in wallet-engine and Rate, and Bark paying BOLT12 offers.
- LDK forks that issue offers carrying the receiver's rails, incl. Bark/Arkade addresses and amountless offers.
- NWC methods for reusable offers with ordered rails and receipt lookup.
- universal-code: the rails codec, BIP321 + offer, network detection, route planner.
- swap-market: a client for Electrum's swap providers over Nostr, plus our own providers on signet and Mutinynet.
- KaleidoPay in Rate: receiver layers and reusable QR; payer review with every route, provider comparison, recovery.
- SSPS published, with a Bark rail.
What's next
Where this goes
One QR for any wallet
Bark, Arkade, Lightning, on-chain today; Liquid and RGB Lightning assets next. The receiver states a preference, the payer's wallet finds a route.
Providers compete per payment
An open market on Nostr: Electrum's providers today, SSPS makers next, each payment quoted by whoever can route it.
Per-payment locks
ssps_lock in the invoice, so a payer can pay on-chain or on Ark without Lightning in between.
Upstream
A bLIP for the offer record, the LDK changes, and Bark BOLT12 support in wallet-engine.
Mainnet receiver
A mainnet receiver node behind NWC, then real payments end to end.