Skip to main content
GIWA Sepolia is the only public GIWA network today, and the only network any Tokscale claim links an explorer to. Local Anvil fixtures borrow its chain ID but are a different network; see Network Separation.
The application is hosted at giwa.tokscale.ai, with its public gateway at https://api.giwa.tokscale.ai. Payment and worker services remain private. Hosted exact top-ups settle on GIWA Sepolia, while a complete hosted upto request ending in delivery and a verified receipt is still pending. Live Evidence records the boundary.

Network facts

Two GIWA-documented faucets supply gas ETH:
  • https://faucet.giwa.io: 0.005 ETH per 24 hours.
  • Nodit faucet at https://faucet.lambda256.io/giwa-sepolia: 0.01 ETH per 24 hours.

Tokscale deployments

GIWA does not officially support x402, so Tokscale ported the stack itself. These contracts were deployed by Tokscale, each with a public deployment record pinning its runtime code hash. Source and manifests live in junhoyeo/tokscale-giwa-contracts; the explorer reports every row below as source-verified. Deployment details:
Scope, quoted from the deployment records: tUSD is test-only ERC-3009 exact evidence, not a stablecoin, and not an authorization for production use. The Upto proxy deployment is deterministic test infrastructure. The hosted route now issues body-bound upto challenges whose challenge-issued expiry the Keychain harness signs, but deployment of the proxy alone does not prove payment verification, admission, terminal settlement, model delivery, or receipt verification.

Preinstalls and predeploys

These already existed on GIWA Sepolia. Tokscale verified their bytecode and builds against them rather than deploying them. Dojang (도장, the seal) is GIWA’s verified-identity attestation system. Tokscale reads it, and gating Passport eligibility on it is a Phase 2 mechanism. See Dojang: On-Chain Attestations.

Proven transactions

The original three transactions anchor the contract-level payment claims. Hosted Stage A adds real top-up settlements from the dedicated Keychain payer.
  1. ERC-3009 exact settlement: transaction 0xad1a2f7b5aff4033e7779437ec487e8b51eb8170ba1c6c8cc971f6de37fcb9f8 moved 1.0 tUSD (1,000,000 base units) from payer 0x02cdd4a6f1308d310d624292a731c2d276310dc5 to 0x016af5632b7d2d3bbd2a6e589b65e828d1a5b125 at block 31,331,118, through facilitator 0xab5805032f0fd80e56c4d2a0fd72d961500c2cf8. The deployment record pins the consumed authorization nonce, which is what makes the authorization single-use, and a retry of the same authorization was replay-rejected with the ERC-3009 authorization-used selector.
  2. Facilitator smoke test: settlement transaction 0x890c08920ae4672b27204fc2b0a2073264148d48f85792db7b6e5424ff9e265a passed against the pinned facilitator image ghcr.io/x402-rs/x402-facilitator@sha256:89ab5c03… after the prerequisite contracts above were deployed. This answered the open question of whether x402 works on GIWA at all.
  3. Permit2 upto settlement: transaction 0x93bf1e60ce1fa0559603111f96cfcdd081eab17b71fb406a32f88ca1562cd274 settled at block 31,917,698 with status 0x1, moving the ACTUAL 1,000,000 base units against a signed MAXIMUM of 1,500,000. That disagreement is the upto scheme: /verify carried the maximum and /settle carried the actual. x402-rs routed to settle (selector ff11e7b4, 14 words), not settleWithPermit. It cost 85,723 gas, with the L1 fee at 16.9% of the total. Replaying the same authorization reverted on Permit2 InvalidNonce() during gas estimation and was never broadcast; the consumed Permit2 nonce bit, not the error string, is what proves replay protection.
Representative hosted exact top-up settlements from payer 0x02cdd4a6f1308d310d624292a731c2d276310dc5: 0xf6093345…, 0xfe84d874…, and 0xca7b2b8d…. These prove hosted Stage A settlement. They are not presented as hosted Stage B upto delivery evidence. No Usage Root is anchored here yet, so receipt and attestation evidence remains local-only. Live Evidence is the authoritative split.

Evidence

The Tokscale-authored contracts rebuild from public source under Solidity 0.8.30, optimizer at 200 runs, evmVersion = prague. Compare the result against runtimeCodeHash in the matching manifest under deployments/, and against the explorer’s own bytecode:
Three further read-only targets check this state directly and need no secrets beyond RPC access. Unlike the rebuild above, these run inside the maintainers’ product repository:

Next steps