Orochia
Documentation
GitHub

Orochia

Creator video platform

Stream in 4K, sell access, pay creators — with the rigour of financial infrastructure. Open source, Apache-2.0.

Next.js 16 App Router Drizzle ORM PostgreSQL 16 Bunny.net Stream

70 API endpoints, extracted from the code

Payments & trust

The client never says it paid.

Every unlock starts as a payment intent and ends only when the gateway's signed webhook arrives — verified in constant time, settled exactly once, written to a double-entry ledger.

The usual shortcut

  • The browser reports “payment OK” and gets the video
  • A replayed webhook credits twice
  • Balances drift from what was really paid

Orochia's guarantee

  • Access granted only by the signed gateway webhook
  • Idempotent settlement: one intent, one credit
  • Balances computed from the ledger, never a counter

Compliance

Obligations become invariants.

18+ certification at sign-up, creator verification (18 U.S.C. § 2257) before any upload, content reports persisted and triaged — enforced on the server, reviewed in the admin console.

Verified before upload

Upload sessions open only for creators whose records an operator approved.

Reports are data

Suspected minors, non-consensual content and DMCA claims are stored before being acknowledged.

See it run

Watch the real product, then follow a request.

Screen recordings of the latest build, and an animated walk through playback, paid unlock and upload.

Video tour

Feed, tipping, creator studio and admin console, recorded on the real app.

Watch the tour

Animated architecture

Step through each journey; every endpoint is checked against the code.

Follow a request

Quick start

  1. 01
    Installnpm install

    Node 20 or later, Docker running.

  2. 02
    Set everything upnpm run setup

    Writes .env, starts PostgreSQL 16 + Redis 7, migrates and seeds — idempotent.

  3. 03
    Run itnpm run dev

    http://localhost:3000 · db:status, db:reset, db:studio for the database.

Architecture modules

Media ingest & deliverypackages/media

Tus resumable upload sessions · HMAC-signed HLS URLs (300 s) · Signed Bunny webhooks

Payments & ledgerpackages/payments

Payment intents recorded before checkout · CCBill · Segpay · NowPayments · Stripe adapters · Constant-time webhook signatures, no lenient mode

Data persistencepackages/db

23 tables

Complianceapps/web/app/api/legal/report

18+ certification at registration · Creator verification before upload · Persisted content reports

Documentation

Design principles

Zero-trust playback

No raw media URL reaches a client: every play is authorised, then signed for 300 seconds.

Direct-to-CDN media

Uploads and segments go straight to Bunny Stream; the web servers never carry video.

Fail-closed configuration

Missing secrets refuse to run in production; demo mode does not exist there.