How it works
Private payroll
Upload a list, pay everyone at once, and nobody sees who got what. Not even your wallet shows up, because Gloam sends each payment for you.
- Networks
- Robinhood Chain, Tempo
- Pay in
- USDG, PathUSD, ETH
- People per run
- Up to 200
- Status
- Live on testnet
Why payroll needs privacy
On a public chain, payday is public. Anyone with an explorer can see what each person on your team earns, who your contractors are, and how much you spend each month. Your team can see each other's pay too. Gloam payroll pays everyone from your private balance, so the chain shows private transfers with no names and no amounts.
Run your first payroll
- Get test money. On Robinhood Chain, claim test USDG from the Paxos faucet. On Tempo, use the faucet button in the app for PathUSD. See the testnet guide.
- Add it privately. In Vault, Shield, move the total you want to pay into your private balance. One deposit that covers the whole run is simplest.
- Upload your list. In Payroll, pick the currency and drop in your CSV. Lines with problems are flagged and skipped until you fix them.
- Keep Hide my wallet on and press Pay. Keep the tab open while it runs, about 8 seconds per person.
- Download the results. They include each claim link and a record of every payment for your books.
List format
One person per line. A header row is optional.
name,gloam_address,amount
Duke,gloamr1.7fQk...x9Wd,6000
Yomi,,4800
Robin,gloamr1.3mPz...c4Ta,4200- Gloam address (starts with
gloamr1.): they are paid directly and the payment shows up in their app. - Blank: they get a claim link after the run. Anyone with the link can claim it, so send each link only to its person.
- A public 0x address is rejected on purpose: paying it would show the amount on the explorer.
- Amounts are in the currency you pick, up to 6 decimals for USDG and PathUSD.
Who sees what
- The public sees private transfers, sent by Gloam. No names, no amounts, and no link to your wallet.
- Each person sees only their own pay.
- You keep the full record in your results file.
What is still public: the amount you add to your private balance at the start, and any amount a person later cashes out to a public wallet. Paying out of a balance you built up over time hides your payroll total too. More detail in What stays private.
Scheduled payroll
Pay the same team every month without rebuilding the list. Save a pay list as a schedule, from New schedule, Save as a schedule under the Pay button, or Repeat this run on a finished run.
- When: monthly on a day you pick, every two weeks, weekly on a weekday, or one time on a date. Add an end date if the schedule should stop.
- Cap per run: the most one run may pay out. If the list grows past it, Pay stays off and says why, so a typo cannot send ten times the payroll.
- Payroll due: when payday comes, the Payroll page shows a reminder with Run now. It loads the list into the normal run, with the same progress, resume and receipt.
- Pause, edit or delete a schedule at any time. Each payday is run once, oldest first, so a missed month stays visible.
Why it does not pay on its own. Gloam never holds your keys, so no server can pay for you. The schedule reminds you and runs in one click, from your browser. Schedules are stored encrypted in this browser, like your runs.
If something goes wrong
- Closed the tab mid-run? Open Payroll again and press Resume. Before continuing, Gloam checks the chain for the payment that was in flight, so nobody is paid twice and no money is lost.
- Not enough private balance? The run pauses with an Add money privately button. Top up, then resume.
- Your runs and claim links are stored encrypted in this browser, like your private balance. Back up from Settings before clearing browser data.
The Gloam relay
Normally the wallet that sends a transaction is public. With Hide my wallet on, Gloam submits your private sends, cash outs and payment notices from its own account, so your wallet never appears next to them. It is on by default in Payroll and in Vault, and free on testnet.
The relay cannot take or redirect money. Each payment is authorized by a proof made in your browser, and for a cash out the destination address is locked inside that proof. The relay checks the payment against the vault before sending it, then either submits it exactly as you made it or refuses. If the relay is ever offline, the app falls back to sending from your wallet and tells you first.
For developers
Apps and agents can use the same relay through the SDK (from @gloamtrade/sdk 0.0.5):
import { relayIntent } from "@gloamtrade/sdk";
// payment = await buildGloamPayment({ ... })
const hash = await relayIntent(payment.intent); // your wallet stays off the recordThe MCP server settles agent payments through the relay with GLOAM_USE_RELAY=1. See Agents.
No middlemen
The vaults on both networks were redeployed so that nobody, including the Gloam team, can move your money or quietly change the rules. There is no admin withdraw, and any change to how proofs or prices are checked has to be announced on-chain three days before it can take effect. Pool addresses are on Networks.