How GitPaid works
Anyone can launch a Pump token for a public GitHub repository. GitPaid analyzes the repository's accepted history, freezes an immutable contributor snapshot, and the launcher's wallet creates the token with 100% of its Pump creator fees routed to GitPaid through a per-mint fee sharing config. Every lamport GitPaid actually receives from that token is split: 80% to the snapshot's contributors, 20% to $GITPAID buyback and burn. Nothing is projected or pre-allocated from expected volume.
A repository can have many independent tokens. Each token references exactly one snapshot for its whole life; re-analysis creates new snapshots for future tokens and never rewrites an existing token's allocation.
Contributor policy v1
Each contributor's weight is computed with exact rational arithmetic:
w_i = 0.60 × I_i/ΣI + 0.30 × M_i/ΣM + 0.10 × C_i/ΣC
- I (impact): accepted authorship. Merged pull requests and direct default-branch commits are work units; each unit (or group of units that form one outcome) has one budget of tier points (1 small, 3 substantial, 8 foundational), split equally among its human authors, including co-authors named in trailers.
- M (maintenance): substantive review and maintenance. Each merged unit gives the same tier budget to at most three distinct non-author, non-bot reviewers, shared equally. Releases and maintainer work credit their authors here.
- C (continuity): distinct UTC months with qualifying activity.
- Tier 8 needs corroboration beyond the author's own description; otherwise it is capped at 3. Bots, self-reviews, merge commits, cherry-picks of already-credited patches, empty and bulk-imported changes earn no independent credit.
- If a category is empty, its coefficient is redistributed proportionally over the others. If all are empty the repository is ineligible; GitPaid never invents an equal split.
- A language model may propose a category and tier for a work unit, with evidence references. Code validates every proposal (known actors, real evidence, allowed tiers) and rejects the rest; scoring is deterministic. Without a model key the deterministic heuristic classifier is used and never assigns tier 8.
Commit email addresses are only used, hashed, to link commits to GitHub accounts; they are never published. Authors that cannot be matched to a GitHub account appear as unresolved identities; their share is recorded and held, never redistributed to others. Full rules: docs/contributor-policy-v1.md in the source repository.
Fee routing
A GitPaid launch uses Pump's create_v2 and the pump-fees program. The token's creator is set to a sharing config PDA for that mint; the config has exactly one shareholder, GitPaid's fee destination, at 10,000 basis points, and its admin is revoked so the split can no longer be changed by the launcher.
In atomic mode (when the deployment has a frozen address lookup table) creation, sharing config and fee shares happen in one transaction: no fee can accrue to anyone else. In two-step mode the token is created with its sharing config first and fee shares are updated in a second transaction; creator fees earned in between go to the launcher, are disclosed before approval, and are never counted as GitPaid receipts. Attribution starts at the finalized slot of the routing transaction.
Receipts are Pump's own DistributeCreatorFeesEvent records naming the mint, cross-checked against the fee destination's balance change in the same transaction. Deposits that cannot be attributed to a mint are recorded as unclassified and allocated to no one.
Accounting and rounding
All amounts are integer lamports. For each token, cumulatively over its received gross G:
C = floor(4G / 5) contributors P = G − C buyback E_i = floor(C · w_i / W) contributor i (W = weight denominator) R = C − Σ E_i rounding reserve (still owed to contributors)
Allocation is computed on cumulative totals, so rounding never drifts and the order receipts are processed in does not matter. Every receipt, reservation, payout and return is a balanced double-entry journal; the public pages show the conservation checks that the ledger passes (Analytics, Capital flow).
Payouts
Contributors sign in with GitHub (no repository or email scopes) and bind a Solana wallet by signing a message bound to that GitHub session. Payouts settle in SOL from the fee destination; network fees are paid by a separate operations wallet so contributor balances are never reduced by gas. Payouts are limited per contributor and overall per day, and pause automatically if received fees surge far above their recent average, until an operator reviews the surge.
Contributors whose GitHub profile links an X account are paid there through X Money by default, with no sign-up. GitPaid checks, in order, the profile's X field, its social accounts, its website, and x.com links in the bio. @mentions in a bio are GitHub mentions and are ignored, and a source naming two X accounts is skipped. Payments go to the permanent X account id, and the profile is re-read before every payment. A handle that now belongs to a different account, or an X account created after the profile was last edited, is held and not paid. X Money has no payout API, so a GitPaid operator sends each payment from GitPaid's X Money account, with a note linking here. X Money only pays 18+ US residents. Anyone it cannot pay, or who prefers a wallet, signs in with GitHub and binds a Solana wallet, which overrides the default. Deployments show whether X Money is on.
Claim window
Tokens launched under claim-window terms (default 365 days, shown in each launch plan and on the token page) give each contributor that long from their first earnings on the token to claim (bind a destination themselves) or be paid at least once. A contributor who claims or is paid in time never loses anything. An X account found on a GitHub profile is not a claim by itself: if X Money cannot pay it, the window keeps running. Unclaimed amounts past the window go to that token's $GITPAID buyback, recorded publicly in the ledger. Expiry is final. Tokens launched before these terms never expire. Your contributor page shows the date by which you need to claim.
Maintainer consent
Anyone can launch a token for a public repository, and its contributors did not ask for that. A repository's maintainers (admin, maintain or owner on GitHub) can sign in and stop new launches and registrations at any time from the repository page. Existing tokens keep paying contributors, because their fee routes are permanent on chain. Each repository also accepts only a few launches per day.
$GITPAID buyback and burn
The 20% share accrues as buyback obligations. Swaps and burns run only when a $GITPAID mint is configured and settlement is enabled; each swap is simulated and verified before signing, and purchased tokens are burned in a separate verified transaction. Until then obligations remain pending and visible. GitPaid does not create $GITPAID or assume any supply.
Verify it yourself
sharing_config = PDA(["sharing-config", mint], pfeeUxB6jkeY1Hxd7CsFCAjcbHA9rWtchMGdZ6VojVZ)
bonding_curve = PDA(["bonding-curve", mint], 6EF8rrecthR5Dkzon8Nwu78hRvfCKubJ14M5uBEwF6P)
1. bonding_curve.creator == sharing_config
2. sharing_config.shareholders == [{ address: <fee destination>, share_bps: 10000 }]
3. sharing_config.admin_revoked == true
4. sha256(manifest.json bytes) == the snapshot hash in the token metadata markerEach token page links a machine-readable proof at /api/proofs/token/<mint>; each snapshot links its manifest and evidence index and can be recomputed from stored evidence.
Interrupted launches
Every transaction is built by the API, verified independently by the API and again in your browser, signed by your wallet, and persisted before it is broadcast. A timeout is treated as unknown, never as failure: GitPaid will not build another transaction for that step until the first is confirmed, fails, or its blockhash is proven expired. If creation lands but routing does not, the token page and My launches show exactly which step remains; nothing is created twice.
Risks and limits
- Tokens are speculative and can go to zero. Creator fees depend entirely on trading that may never happen. GitPaid promises no returns and no minimum payout.
- Contributors did not ask for these tokens and do not endorse them. A token for a repository is not an offering by its maintainers.
- Pump retains protocol authorities (including an admin path on fee sharing configs). GitPaid monitors every route and pauses allocation from a token whose route changes, but cannot prevent protocol-level changes.
- The analysis measures accepted, visible GitHub activity. It cannot see private work, design discussions outside GitHub, or quality that the history does not show. Disputes can be filed; frozen snapshots are never edited, corrections apply to future snapshots.
- Unclaimed balances on tokens with claim-window terms expire to the buyback. If you contributed, check your contributor page.
- Custody: received fees sit in GitPaid's fee destination until paid. The optional X Money rail also holds a dollar float in GitPaid's X Money account. Backing is published on Capital flow.