Kaspa Deposit is non-custodial collateral for a rental, borrowed equipment or another clearly described obligation. The depositor locks KAS in an on-chain covenant. If the holder files no claim before the deadline, the deposit auto-returns to the depositor — no request, approval or custodial account required.
Two roles, neither with unilateral control
DepositorProvides the KAS collateral. Gets it back automatically when the term and claim window end without a claim, and may accept a full or partial settlement when a claim exists.
HolderReceives the protection, not custody of the money. May return the deposit early or file an evidence-backed claim for some or all of it before the deadline.
Kaspa ForgeNever holds the deposit or either party's signing key. The service relays public state and ciphertext, watches covenant clocks and coordinates disputes within the contract's fixed destinations.
The lifecycle: agreement → clock → return
Create. Either side opens the Deposit wizard, chooses their role, amount, term, claim window and describes exactly what the collateral secures. The invite shows every term before the other side joins.
Join. Each party receives a separate deal key generated locally in their browser. Keys and the service token are stored in the encrypted Desk profile, never as a custodial account.
Fund. The depositor funds the shown address with the deposit plus the visible fee reserve, then locks it into the covenant. From that transaction onward, neither party can redirect the KAS outside the allowed outcomes.
Run the term. The holder can return the collateral early, or file a claim at any point during the term and its final claim window. With no claim, the covenant's keyless path returns the deposit automatically.
Withdraw. A payout first lands under the receiving party's deal key. Open the Deposit panel and use Withdraw funds to send it to the Desk wallet or any Kaspa address.
The covenant: Escrow mechanics, reversed default
Kaspa Deposit uses the published escrow.sil covenant. The holder maps to the contract buyer; the depositor maps to the contract seller. That internal mapping makes the existing seller-directed automatic and emergency paths return collateral to the depositor while the public interface consistently speaks in deposit roles.
Early returnThe holder signs; the agreed deposit goes back to the depositor.
Accepted claimThe depositor signs an agreed payment to the holder. Both sides can instead sign any proportional split.
No claimAfter the term plus claim window, a keyless auto-return pays the depositor. The holder's permission is not required.
Arbitrated claimA human arbiter may return everything, award a proven amount to the holder or split it. No contract path pays the arbiter or any unrelated address.
Silent arbiterThe emergency timeout returns the full balance to the depositor without a service fee. An unavailable service cannot strand the collateral forever.
Terms, limits and fees
AmountFrom 50 KAS, with no product-level upper cap.
Term7 to 730 days, entered as a duration or end date.
Claim window3 / 7 / 14 / 30 days after the term; a claim may also be filed earlier during the term. The matching arbiter deadlines are 10 / 14 / 21 / 45 days.
Normal settlement0.5%, minimum 1.2 KAS: auto-return, early return or mutual settlement. This reserve is funded on top, so the agreed deposit itself can return in full, apart from the small network fee.
Human arbitration2%, minimum 5 KAS, only when a claim reaches the arbiter. Emergency timeout has no service fee.
Claims, evidence and authority
The holder files the claim. Filing freezes auto-return and states what happened, what amount is requested and why.
Evidence stays encrypted until a party reveals it. The deal chat and media are end-to-end encrypted and integrity-anchored. A chat key reveals the case material, but cannot move funds.
The AI mediator proposes. It can recommend full return, holder payment or a proportional split. It holds no signing key and its proposal is non-binding.
Parties sign agreement; otherwise a human rules. The burden of proof is on the holder: intake photos, inventory, receipts or repair estimates should support the requested amount. The arbiter's signature remains constrained to the two parties and a visible fee.
Keys, recovery and privacy
Keys remain in the browser inside the password-encrypted Desk profile. Keep an offline .age key-file backup and its password separately; support will never ask for either.
Forge Sync carries Deposit records as encrypted ciphertext. It is useful between devices, but it does not replace a key-file backup you control.
The public covenant outlives the interface. The contract source, browser code and hosted-independent dealctl recovery package are in the public repository. Build from source, verify its checksum manifest and use any Kaspa v2+ node with --utxoindex.
The server stores public deal parameters and encrypted traffic. Sensitive dispute material is removed after closure. See Escrow and Deposit privacy for the precise boundary.
Honest boundary. A covenant can constrain where funds may go; it cannot know whether a rented apartment or camera was damaged. Fair treatment of a contested real-world fact depends on evidence and a human arbiter. Use the encrypted deal chat for the condition report, photos and agreement before the term begins.