Orochia
Creator video platform
Stream in 4K, sell access, pay creators — with the rigour of financial infrastructure. Open source, Apache-2.0.
70 API endpoints, extracted from the code
Payments & trust
The client never says it paid.
Every unlock starts as a payment intent and ends only when the gateway's signed webhook arrives — verified in constant time, settled exactly once, written to a double-entry ledger.
The usual shortcut
- The browser reports “payment OK” and gets the video
- A replayed webhook credits twice
- Balances drift from what was really paid
Orochia's guarantee
- Access granted only by the signed gateway webhook
- Idempotent settlement: one intent, one credit
- Balances computed from the ledger, never a counter
Compliance
Obligations become invariants.
18+ certification at sign-up, creator verification (18 U.S.C. § 2257) before any upload, content reports persisted and triaged — enforced on the server, reviewed in the admin console.
Verified before upload
Upload sessions open only for creators whose records an operator approved.
Reports are data
Suspected minors, non-consensual content and DMCA claims are stored before being acknowledged.
See it run
Watch the real product, then follow a request.
Screen recordings of the latest build, and an animated walk through playback, paid unlock and upload.
Animated architecture
Step through each journey; every endpoint is checked against the code.
Follow a requestQuick start
- 01Install
npm installNode 20 or later, Docker running.
- 02Set everything up
npm run setupWrites .env, starts PostgreSQL 16 + Redis 7, migrates and seeds — idempotent.
- 03Run it
npm run devhttp://localhost:3000 · db:status, db:reset, db:studio for the database.
Architecture modules
packages/mediaTus resumable upload sessions · HMAC-signed HLS URLs (300 s) · Signed Bunny webhooks
packages/paymentsPayment intents recorded before checkout · CCBill · Segpay · NowPayments · Stripe adapters · Constant-time webhook signatures, no lenient mode
packages/db23 tables
apps/web/app/api/legal/report18+ certification at registration · Creator verification before upload · Persisted content reports
Documentation
Design principles
Zero-trust playback
No raw media URL reaches a client: every play is authorised, then signed for 300 seconds.
Direct-to-CDN media
Uploads and segments go straight to Bunny Stream; the web servers never carry video.
Fail-closed configuration
Missing secrets refuse to run in production; demo mode does not exist there.