A verifiable verdict for every dispute.
A randomly selected jury runs distributed key generation, votes under commit/reveal, and produces a threshold Schnorr attestation over the final verdict — verifiable by anyone against the Court's group public key.
No trusted verifier. No committee to take on faith. No custody of anyone's money.
Threshold Schnorr · Commit / Reveal · Authority layer only
Every dispute runs the same six phases. Each phase is cryptographic, and the final attestation is verifiable by any third party — forever, without asking us.
Jury picked
A jury is selected at random for the session. Selection binds identities to the case before anyone votes.
Setup — DKG
Jurors run distributed key generation together. The group key is born without any dealer and no single juror holds it.
Vote — commit
Each juror commits to a salted hash of their outcome. Nobody can copy anyone else's vote.
Count — reveal
Reveals publish the outcome and salt; each must match the juror's earlier commit or it is rejected.
Sign
The jury produces a threshold Schnorr signature over the final verdict — no single juror, and no minority, can forge it.
Verdict
The attestation is published. Anyone can verify it against the Court's group public key.
Never holds funds
The Court never holds, receives, redirects, or intermediates user funds. It contains no settlement logic — it authorizes, others settle.
Verifiable by anyone
The verdict is a threshold Schnorr attestation over a group public key. Verification needs no access to the Court, its jurors, or its operators.
No single point of trust
Key generation is distributed, votes are secret until counted, and the verdict requires a threshold of jurors — not an admin key.
Jurors are randomly selected from registered candidates. Honest participation is backed by a bond; a juror who withholds or defects cannot carry a verdict alone.
Register
Opt in with your Nostr identity and choose the categories you can judge.
Get selected
Sessions pick juries at random — no applications, no favoritism, no insider seat.
Vote in secret
Commit first, reveal later. Your reasoning never has to become public; your vote is bound cryptographically.
Sign and earn
Jurors who complete the ceremony sign the verdict and earn from the session.
A randomly selected jury runs distributed key generation, votes under commit/reveal, and produces a threshold Schnorr attestation over the final verdict that any third party can verify. — BAO Court protocol paper
The protocol ships as platform-neutral TypeScript with normative testvectors — math and state machines only, no networking, no storage, no secrets.
Support the Court
Jury verification, session signaling and public attestations are paid for by the community. Zaps go straight to the Court's Lightning address.
Suggested amounts in sats — click an amount to copy the zap request, then paste it into your Lightning wallet. No custody, no invoices held by us.
The Court is one chamber of the ₿AO Network
Chat in the Troll₿ox, fund milestones in the Fund, and let the Court rule when honest people disagree.
Decide. Verify. Never custody.