Introduction
Recurring payments for onchain businesses. Bill subscribers on a schedule and run payroll in one transaction, without ever holding your customers' funds.
Building with an AI agent? Give it these rules:
- Token amounts are integers in raw units at the token's precision. USDC on Stellar has 7 decimals, so
29 USDCis290000000. Never send floats to the contract. - Build on Stellar Testnet first. The contract ID is
CAZBZBUWBSQYK2RZ6WHMXVDLIQHSU5WD7ANZYL6HLNSCRUOTNYCDYQNGand the network passphrase isTest SDF Network ; September 2015. - A subscription needs two signed calls from the subscriber:
approveon the token (spender = Orbit contract), thencreate_vaulton Orbit. There is no single "create subscription" call on-chain. - A confirmed ledger transaction is the source of truth for a payment. Never trust a client-side success callback or redirect on its own.
- Durations are in seconds and use ledger time (
env.ledger().timestamp()). Addresses are Stellar strkeys (G...accounts,C...contracts).
Orbit is a pull-payment protocol built on Stellar Soroban. A subscriber signs once, keeps their USDC in their own wallet, and the merchant pulls a fixed amount each billing interval. The same contract pays a whole payroll in one atomic transaction.
Stablecoins settle in seconds. What's been missing is a way to charge them every month without asking the customer to sign every month, or making them lock funds in an escrow.
What is Orbit?
Orbit separates authorization from custody. The subscriber sets a spending ceiling on the token itself, and the Orbit contract decides when the merchant may use it. Funds go straight from the subscriber's wallet to the merchant's. Orbit never holds a balance.
Orbit is live on Stellar Testnet. The contract is not audited yet, and mainnet is on the roadmap.
What Orbit handles
Allowance vaults store the terms (token, amount per interval, interval length) for each subscriber and merchant pair. The contract rejects a pull until the interval has passed on the ledger, and the token allowance caps the total the merchant can ever take.
Pay tens of contributors in one transaction with batch_disburse. If a single transfer fails, the whole batch reverts, so nobody ends up paid twice or not at all.
Send customers to a hosted checkout page at /pay/[id], or embed the <OrbitCheckout /> widget in your own React app. Both connect the Freighter wallet.
Manage plans, subscribers, payment links and payroll from the dashboard, or script them against the Merchant API.
Who is Orbit for?
Orbit is for teams that already get paid in stablecoins and want billing that runs itself.
You're a great fit if you're building
SaaS and memberships
Monthly or yearly USDC plans. Customers stay in control of their funds, and you bill on schedule.
AI tools and APIs
Charge a fixed amount per cycle from a keeper or your backend, with no manual approval each month.
DAOs and remote teams
Upload a CSV and pay every contributor in one ledger transaction for a fraction of a cent.
Creators and communities
Share a payment link. Fans subscribe with Freighter in a couple of clicks.
Why Orbit is different
Funds stay with the subscriber
Orbit is only the spender on the token. Every transfer goes straight from the subscriber to the merchant, and the contract never holds a balance.
Cancel on the token itself
Setting the allowance to 0 stops billing right away. No support ticket, and no merchant cooperation needed.
Quickstart
Install the Stellar CLI and fund an identity
stellar keys generate merchant --network testnet --fund
stellar keys generate subscriber --network testnet --fundSubscriber approves Orbit and opens a vault
stellar contract invoke --id $TOKEN --source subscriber --network testnet -- \
approve --from $SUBSCRIBER --spender $ORBIT --amount 3480000000 --live_until_ledger 5000000
stellar contract invoke --id $ORBIT --source subscriber --network testnet -- \
create_vault --user $SUBSCRIBER --merchant $MERCHANT --token $TOKEN \
--amount_per_interval 290000000 --interval_seconds 2592000Merchant pulls the first cycle
stellar contract invoke --id $ORBIT --source merchant --network testnet -- \
pull_funds --user $SUBSCRIBER --merchant $MERCHANTFor the full walkthrough with environment variables and checks, see the Quickstart.