onus. is conditional settlement on Arc. Lock USDC to a condition — a signature, an oracle value, an agent's result, a date — and let the proof release it. Nobody holds the money in between. Not the payer, not the payee, not us.
Every trade between strangers has the same first question: who goes first. The buyer who pays first can be ignored. The supplier who ships first can be stiffed. The agent that does the work first can be told the result wasn't good enough.
The traditional answer is a middleman who holds the money and decides. That costs money, takes days, and replaces two risks with one bigger one.
onus. replaces the middleman with a condition. The money sits in a contract that only the proof can open, and that always gives it back if the proof never comes. Both sides can go first, because neither side has to.
A condition is something Arc can verify in a block. If it can't be read on-chain, it isn't a condition — it's a hope, and we won't write it.
Delivery receipts, acceptance of work, inspection passed. The witness is a key both parties named before funding.
when signed_by(carrier) of "delivered #8841"
FX fixes, index levels, tracking states. Any feed with a reporter on Arc, with a fallback source you name.
when fix(USDC/JPYSC)
>= 0.0068Pay for an outcome, not a promise. A verifier you name scores the submitted work; the score is the condition.
when score(result)
>= 0.9Retention, warranty, cooling-off. Releases at a date unless a named party disputes before it.
when t >= 2026-10-17 unless disputed_by(buyer)
| WITNESS | CAN | CANNOT | IF IT SAYS NOTHING |
|---|---|---|---|
| a named key carrier, inspector, client | sign the condition true or false | redirect funds · change the amount · move the lapse date | the onus lapses on schedule and funds return |
| an oracle FX fix, index, tracking | report a value on schedule | know that an onus exists | the fallback source is read, then the onus lapses |
| a verifier scoring model, human reviewer | score a submitted result | submit the result itself | the result can be resubmitted until the lapse |
| time | pass | be disputed after the fact | — |
| onus. the protocol | execute exactly what the onus says | everything else — there is no admin key | — |
Payee, sum, currency, condition, witness, lapse date. Payee accepts. Nothing has moved yet.
USDC enters the onus contract. From this block neither side can touch it.
The witness signs, the oracle reports, the result scores — or the clock runs out.
Condition holds → funds to the payee in the same block. Optional FX leg converts at release.
Lapse date passes without proof → funds to the payer. No fee on lapse. Nobody to call.
Agents on Arc can already pay each other in fractions of a cent. What they cannot do is pay for an outcome: "four USDC if the translation scores above 0.9."
Without escrow one side always goes first, and the side that goes first gets exploited. An onus is escrow an agent can write in a single call, fund from a spend-limited wallet, and settle by score rather than by anyone's honesty.
Micro-onuses are viable here because fees are USDC and sub-cent. A thousand small jobs can each carry their own escrow without the escrow costing more than the job.
the onus is on the proof, not the party.
nobody holds the money. nobody.
a witness says yes or no, never "give it to me".
every onus lapses. money that waits forever was taken.
a dispute is a date, not a process.
if a condition can't be read on-chain, it's a hope.