Merge a PR.
Get paid
in USDC

MergePay puts USDC on GitHub issues and pays whoever merges the fix. It takes seconds and runs on Arc. GitHub signs the proof of the merge, and the contract checks that signature itself. There's no bot, no backend and no key to trust.

● live on arc mainnet

Every payout is
on the chain.

Funding, awards and payouts are all contract events on Arc. This feed is read straight from the chain, not from a database we could edit.

Escrowed
Paid out
Bounties
activity.feed

The faster it merges,
the faster you're paid.

01-fund.app
01

Fund an issue

Anyone can put USDC on any public GitHub issue. The money sits in the contract, and if nothing merges by the deadline, funders take their share back.

02-merge.app
02

Claim it, merge it

A contributor comments /claim, so nobody else can take their payout, then opens a PR that says “Fixes #42”. When a maintainer merges it, a pinned GitHub workflow asks GitHub to sign a proof.

03-paid.app
03

Get paid in USDC

Arc checks GitHub's signature on-chain and sends the USDC to the author. The PR gets a comment with the receipt. No invoice, no waiting.

merge.log
  1. PR #128 mergedacme/widgets · closes #42
  2. GitHub signs an OIDC JWTaud = mergepay:0x…:42:1001
  3. Arc verifies RS256 on-chainmodexp precompile · ~770k gas ≈ $0.016
  4. 50 USDC → @alicetx link posted on the PR ✔

4.5 seconds,
merge to money.

Every GitHub Actions job can ask GitHub for a signed identity token. MergePay's contract checks the RSA signature on that token directly on Arc, reads who merged what, and pays. The relayer that submits the proof only covers gas. It can't change who gets paid.

payout-rules.md

Payout rules

This is what a paid merge looks like. Every line is enforced by the contract, or by the pinned workflow whose GitHub-signed proof the contract checks.

  • Claim it first

    Comment /claim on the funded issue. You're assigned, and only your PR can be paid. One claim at a time per repo, and 7 days with no activity releases it.

  • The PR closes it and gets merged

    Write “Fixes #N” in the PR body. Only merged PRs count: a maintainer's merge is the bar, and closed-without-merge pays nothing.

  • You wrote it, or your agent did

    The recipient's GitHub ID is inside the signed token. If a coding agent opened the PR from a bot account, the human it's assigned to gets paid, not the bot.

  • The workflow is the pinned one

    Each bounty stores the exact workflow version allowed to award it. Forks and edited copies are rejected.

  • Link a wallet within 180 days

    Before or after the merge. Awards wait in the contract under your GitHub ID. If nobody claims one for 180 days, it goes back to the funders.

  • Before the deadline

    Unclaimed bounties become refundable after their expiry, and each funder takes back exactly what they put in.

Open the app →

Pick up a funded issue.

Each of these has USDC waiting in the contract. Ship the fix and it's yours.

bounties.db

Why this only works on Arc.

gas.txt

USDC

is the gas token

Bounty, relayer fee and payout are one asset. A first-time contributor with a zero balance gets paid and never needs another token.

finality.txt

<1s

deterministic finality

The payout is final the moment its block lands, so the “paid” comment on the PR is a receipt, not a promise.

cost.txt

$0.016

to verify RSA on-chain

Checking GitHub's 2048-bit signature costs about 770k gas, priced in dollars. Sponsors set a flat relayer fee and never think about gas.

get-started.app

for maintainers & sponsors

Put USDC on your repo.

  1. Fund an issue from the app with any wallet on Arc.
  2. Add one workflow file to the repo. The app pre-fills it.
  3. Merge PRs like you always do. Payouts happen on their own.
Fund an issue →

for contributors

Get paid for your PRs.

  1. Comment /claim on a funded issue and ship the fix.
  2. Run the one-time link workflow in a repo you own.
  3. USDC lands in your wallet when the PR merges. No gas needed.
Link my wallet →

Questions, answered.

Who holds the money?

The MergePay contract on Arc. We never custody funds. It pays out only on a valid GitHub-signed merge proof, or refunds funders after the deadline.

Can someone fake a merge?

They'd need GitHub's private signing key. The contract checks the RS256 signature, the repo ID, the event, the pinned workflow and the recipient before paying a cent.

Do contributors need crypto?

Only a wallet address. Gas is paid by the relayer and reimbursed from the bounty, so a contributor never needs a balance.

What if nobody fixes it?

After the expiry you chose, every funder can reclaim exactly what they put in, straight from the contract.

Can two people race for one bounty?

No. The first person to comment /claim gets the issue, and only their merged PR is paid. Other PRs get an automatic heads-up that they won't be paid. If the claimant goes quiet for 7 days (no PR, commits or comments), the claim is released for someone else.

My coding agent opens the PRs. Who gets paid?

You do. If the agent opens the PR under your account, you're the author. If it opens the PR from its own bot account (Copilot, Claude and others can), the payout goes to the human the PR is assigned to, as long as that's the person who claimed the issue. MergePay never takes a wallet address from PR text an agent wrote, so a prompt injection can't redirect the money.

What if the winner never claims?

The award waits 180 days for them to link a wallet. After that, anyone can send it back to the funders, split by what each put in. Winners who link in time are never affected.

What does it cost?

No platform fee. Each award costs about $0.016 in gas on Arc, covered by a small relayer fee the funder sets. The default is $0.03.

What do I have to trust?

GitHub's signing keys (registered on-chain and checkable against GitHub's public JWKS), and the maintainers' merge decisions. Everything else is code you can read.