Private payroll is live.

See how

How it works

Private payroll

Upload a list, pay everyone at once, and nobody sees who got what. Not even your wallet shows up, because Gloam sends each payment for you.

Networks
Robinhood Chain, Tempo
Pay in
USDG, PathUSD, ETH
People per run
Up to 200
Status
Live on testnet

Why payroll needs privacy

On a public chain, payday is public. Anyone with an explorer can see what each person on your team earns, who your contractors are, and how much you spend each month. Your team can see each other's pay too. Gloam payroll pays everyone from your private balance, so the chain shows private transfers with no names and no amounts.

A payroll run
Step 1Add your teamUpload a CSV: name, Gloam address, amount. No address means that person gets a claim link.
Step 2Check who sees whatFlip the list to The public sees: every row becomes a private transfer with no name and no amount.
Step 3Pay everyoneGloam pays each person in turn from your private balance and shows each one as it lands.
Step 4Share and keep recordsDownload your results. Send claim links to the people who need them.

Run your first payroll

  1. Get test money. On Robinhood Chain, claim test USDG from the Paxos faucet. On Tempo, use the faucet button in the app for PathUSD. See the testnet guide.
  2. Add it privately. In Vault, Shield, move the total you want to pay into your private balance. One deposit that covers the whole run is simplest.
  3. Upload your list. In Payroll, pick the currency and drop in your CSV. Lines with problems are flagged and skipped until you fix them.
  4. Keep Hide my wallet on and press Pay. Keep the tab open while it runs, about 8 seconds per person.
  5. Download the results. They include each claim link and a record of every payment for your books.

List format

One person per line. A header row is optional.

name,gloam_address,amount
Duke,gloamr1.7fQk...x9Wd,6000
Yomi,,4800
Robin,gloamr1.3mPz...c4Ta,4200
  • Gloam address (starts with gloamr1.): they are paid directly and the payment shows up in their app.
  • Blank: they get a claim link after the run. Anyone with the link can claim it, so send each link only to its person.
  • A public 0x address is rejected on purpose: paying it would show the amount on the explorer.
  • Amounts are in the currency you pick, up to 6 decimals for USDG and PathUSD.

Who sees what

  • The public sees private transfers, sent by Gloam. No names, no amounts, and no link to your wallet.
  • Each person sees only their own pay.
  • You keep the full record in your results file.

What is still public: the amount you add to your private balance at the start, and any amount a person later cashes out to a public wallet. Paying out of a balance you built up over time hides your payroll total too. More detail in What stays private.

Scheduled payroll

Pay the same team every month without rebuilding the list. Save a pay list as a schedule, from New schedule, Save as a schedule under the Pay button, or Repeat this run on a finished run.

  • When: monthly on a day you pick, every two weeks, weekly on a weekday, or one time on a date. Add an end date if the schedule should stop.
  • Cap per run: the most one run may pay out. If the list grows past it, Pay stays off and says why, so a typo cannot send ten times the payroll.
  • Payroll due: when payday comes, the Payroll page shows a reminder with Run now. It loads the list into the normal run, with the same progress, resume and receipt.
  • Pause, edit or delete a schedule at any time. Each payday is run once, oldest first, so a missed month stays visible.

Why it does not pay on its own. Gloam never holds your keys, so no server can pay for you. The schedule reminds you and runs in one click, from your browser. Schedules are stored encrypted in this browser, like your runs.

If something goes wrong

  • Closed the tab mid-run? Open Payroll again and press Resume. Before continuing, Gloam checks the chain for the payment that was in flight, so nobody is paid twice and no money is lost.
  • Not enough private balance? The run pauses with an Add money privately button. Top up, then resume.
  • Your runs and claim links are stored encrypted in this browser, like your private balance. Back up from Settings before clearing browser data.

The Gloam relay

Normally the wallet that sends a transaction is public. With Hide my wallet on, Gloam submits your private sends, cash outs and payment notices from its own account, so your wallet never appears next to them. It is on by default in Payroll and in Vault, and free on testnet.

The relay cannot take or redirect money. Each payment is authorized by a proof made in your browser, and for a cash out the destination address is locked inside that proof. The relay checks the payment against the vault before sending it, then either submits it exactly as you made it or refuses. If the relay is ever offline, the app falls back to sending from your wallet and tells you first.

For developers

Apps and agents can use the same relay through the SDK (from @gloamtrade/sdk 0.0.5):

import { relayIntent } from "@gloamtrade/sdk";

// payment = await buildGloamPayment({ ... })
const hash = await relayIntent(payment.intent); // your wallet stays off the record

The MCP server settles agent payments through the relay with GLOAM_USE_RELAY=1. See Agents.

No middlemen

The vaults on both networks were redeployed so that nobody, including the Gloam team, can move your money or quietly change the rules. There is no admin withdraw, and any change to how proofs or prices are checked has to be announced on-chain three days before it can take effect. Pool addresses are on Networks.