oc · me
§ status

Operational, with the caveats.

Every subsystem the product depends on, with the operator name and the current state. Honest about which parts we run vs. which parts run on federation infrastructure vs. which parts run on external public goods.

loading slo…

running probes…

§ live probes · client-side
probing… · auto-refresh 60s
  • me.ochk.io · /api/health
    liveness — running app + cookie parsing
    pending
  • auth · /api/auth/me
    401 with no cookie is correct; 5xx is not
    pending
  • ochk.io · /.well-known/jwks.json
    public Ed25519 JWK every consumer verifies against
    pending
  • envelope · /api/envelope/[id]
    404 for unknown id is correct; 5xx is not
    pending
  • fee policy · /api/platform-fee-policy
    PLATFORM_FEE_POLICY canonical record
    pending
  • integrator config · /api/integrator-config
    sample IntegratorPriceConfig list
    pending
subsystemoperatorrolestate
me.ochk.io · web
orangecheckconsumer marketing surface and authenticated app
operational
auth host · ochk.io
auth host jwks · 1/1 reachable
orangecheckoc_session JWT issuance and JWKS publication
operational
federation custody
A federation is bound, but no payout rail is enabled, so nothing settles through it yet. BIP-322 self-custody is the live path today. See /custody for the derived posture.
guardian set (see /custody)threshold-signing wallet for non-graduated users
forming
oc envelope signing
orangecheckevent envelope co-signature for billing reconciliation
operational
opentimestamps anchor
opentimestamps calendars · 2/2 reachable
opentimestamps calendar federationaggregated event-root anchoring to Bitcoin headers
operational
nostr relay set
nostr relay set · 3/4 reachable (1 expected-unreachable from this runtime: relay.damus.io)
relay.ochk.io, damus, nos.lol, snort.socialpublic envelope republication
operational
lightning settlement
A federation is bound, but no payout rail is enabled, so no sats move yet. Earnings accrue as a verifiable ledger credit and stay claimable. See /custody.
federation lightning gatewaycashback payouts
forming

what "degraded" means here

We treat any externally-observable signal that contradicts the user promise as either "degraded" or "incident" — never "operational with caveats." If sat-earning events are published with delay, that's degraded. If they're not published at all, that's an incident.

Anchored events on Bitcoin headers and Nostr-published envelopes do not depend on this status page being up. Even during a full me.ochk.io outage, prior /me/earn entries continue to verify offline against the OC public JWK and Bitcoin block headers.

Subscribe to incident updates by following github.com/orangecheck/oc-me-web/issues for the "incident" label. Public post-mortems land in /changelog.