Repository navigation
Home
Over a decade after the creation of Bitcoin there are still very few places accepting cryptocurrencies.
Nobody accepts crypto, because nobody pays with crypto. Nobody pays with crypto, because nobody accepts crypto.
This is known as the chicken and egg problem.
The few places that accept cryptocurrencies often don't offer a very user-friendly experience.
Bitrequest's goal is to take the egg out of the equation, by making the process of accepting cryptocurrencies as easy and user-friendly as possible.
Bitrequest is an application for accepting cryptocurrencies.
It is a payment observer, not a payment processor: payments go straight from the payer's wallet to yours, and the app only verifies on-chain that they arrived. Bitrequest is never in the money flow — nothing to custody, nothing to freeze, no one to ask permission.
The application generates payment requests which can be used as:
- Point of Sale
- Shared with WhatsApp, SMS, email, etc.
- E-commerce checkouts
| Currency | Address Formats | Special Features |
|---|---|---|
| Bitcoin | Legacy (1...), SegWit (bc1q...) | xpub/zpub derivation |
| Lightning | BOLT11 invoices | LND, Core Lightning, LNbits, Spark, NWC, LNURL, Boltcard/NFC |
| Litecoin | Legacy (L...), SegWit (ltc1q...) | Ltub derivation |
| Ethereum | EIP-55 checksum (0x...) | ERC-20 tokens |
| Ethereum L2 | Same as ETH | Base, Arbitrum One, Polygon PoS, BSC |
| Monero | Standard & subaddresses | View key scanning, stealth addresses |
| Kaspa | kaspa:q... (40-bit bech32) | kpub derivation |
| Bitcoin Cash | CashAddr (bitcoincash:q...) | — |
| Dogecoin | Legacy (D...) | dgub derivation |
| Dash | Legacy (X...) | InstantSend support |
| Nano | nano_... | Instant, feeless |
| Nimiq | NQ... | Browser-native |
Bitrequest was built as a non-profit project by XpressZo with the goal of wider crypto adoption.
Donations are welcome.
- Wider crypto adoption
- Improving and maintaining Bitrequest
Payment requests (bitrequests) consist of:
- Cryptocurrency address input
- Amount input (in fiat or crypto)
- URI (Uniform Resource Identifier)
- QR-code (encoded URI)
Amounts in fiat are converted to the equivalent in crypto in real-time.
The QR-code is an encoded URI consisting of app-protocol, address, and amount and can be scanned by most crypto wallet apps. Opening the URI or scanning the QR-code with a crypto wallet will autofill the wallet's send dialog with the corresponding address and amount (if supported).
| Currency | URI Scheme | Example |
|---|---|---|
| Bitcoin | bitcoin: |
bitcoin:bc1q...?amount=0.001 |
| Lightning | lightning: |
lightning:lnbc... |
| Ethereum | ethereum: |
ethereum:0x...?value=1e18 |
| Monero | monero: |
monero:4...?tx_amount=0.1 |
| Kaspa | kaspa: |
kaspa:qp...?amount=100 |
| Litecoin | litecoin: |
litecoin:ltc1q...?amount=0.5 |
Supports Lightning invoices (BOLT11/LNURL) and NFC/Boltcard taps.
ERC-20 requests on Ethereum and the L2s use the token's actual decimals for that chain (for example USDT is 6 on Ethereum, Arbitrum, Base and Polygon but 18 on BSC), looked up before the QR is shown.
When the QR-code is visible, a WebSocket connection is opened in the background that listens for incoming transactions on the request address. When incoming transactions are detected, the request status changes to 'paid' or 'pending', depending on the number of selected confirmations.
This is the payment-observer machinery at work: Bitrequest watches the settlement layer and reports what it sees — it never touches the transaction itself.
| Method | Used For | Providers |
|---|---|---|
| WebSocket | Real-time notifications | BlockCypher, mempool.space, Alchemy (Ethereum and L2), Nano nodes |
| Polling | Fallback monitoring, and primary method for Kaspa and Nimiq | Various block explorers |
| Node RPC | Direct scanning | Electrum, personal nodes |
| View key scanning | Monero privacy | Remote nodes, LWS |
Supports zero-conf and InstantSend for instant feedback on small payments.
Each request has a unique URL which can be shared with WhatsApp, SMS, email, etc.
Bitrequest has a built-in share function which opens your device's share dialog and automatically shortens the URL (optional).
Requests include metadata:
- Title and description (BIP21)
- Fiat amount and currency
- Timestamp for rate locking
Addresses can be added:
- Manually — With QR scanning support
- BIP39 seed phrase — 12 word mnemonics
- Extended public keys — xpub, zpub, Ltub, dgub, kpub
| Currency | Path | Extended Key |
|---|---|---|
| Bitcoin SegWit | m/84'/0'/0'/0/ | zpub |
| Bitcoin Legacy | m/44'/0'/0'/0/ | xpub |
| Litecoin SegWit | m/84'/2'/0'/0/ | zpub |
| Litecoin Legacy | m/44'/2'/0'/0/ | Ltub |
| Ethereum | m/44'/60'/0'/0/ | xpub |
| Kaspa | m/44'/111111'/0'/0/ | kpub |
| Dogecoin | m/44'/3'/0'/0/ | dgub |
| Dash | m/44'/5'/0'/0/ | xpub |
| Bitcoin Cash | m/44'/145'/0'/0/ | xpub |
Multiple addresses can be added per cryptocurrency.
Priority can be set by dragging addresses or selecting randomly for enhanced privacy.
- Monero — View keys for scanning incoming transactions without spend capability
- Lightning — LND / Core Lightning / LNbits / Spark / NWC node connections with invoice generation
- Kaspa — Native kpub support with 40-bit bech32 checksum addresses
Bitrequest saves all shared and received requests and monitors their status by scanning the blockchain.
Features include:
- Transaction history with confirmations
- Receipts (PDF/shareable)
- Archive/unarchive functionality
- Filtering by address, status, or date range
- CSV export for accounting
Set your name or company name. Recipients will see this name on their request.
When Bitrequest is integrated in a webshop, this form can be used to provide billing/shipping information.
Set your country's local currency or one of 170+ world currencies.
Choose from English, Dutch, French, Spanish, German, Chinese, Hindi and Japanese. New translations are welcome; see docs/translate_prompt.md in the repo.
Choose where Bitrequest gets its crypto exchange rates from:
- CoinMarketCap (default)
- CoinPaprika
- CoinGecko
Automatic fallback between providers if one fails.
Choose where Bitrequest gets its fiat exchange rates from:
- Fixer (default)
- CoinGecko
- ExchangeRatesAPI
- Currencylayer
When sharing a request, URLs can be shortened:
- Bitly
- Bitrequest's built-in URL shortener
- Or disable URL shortening
See Bitrequest's Privacy Policy.
Bitrequest saves all data on your device. Clearing device storage will lose all data.
Backups are always encrypted (with your seed phrase if you have one, otherwise with a key derived from your PIN). The seed phrase itself is never included in a backup.
Backup options:
- JSON file download — Manual backup
- Google Drive sync — Automatic backup on every change
See Bitrequest's Privacy Policy.
Restore data from a previous backup or import from a different device. Device-local settings (the encrypted seed, PIN and lock state) are never overwritten by an imported file.
| Mode | Access Level |
|---|---|
| Admin | Full access with PIN |
| Cashier | View-only, create requests only |
PIN protection prevents unauthorized address changes or viewing sensitive request details.
Enter your own API keys for dedicated quotas. By default, Bitrequest's shared API keys are used, which may reach limits under heavy usage.
Set up a team member's device (a cashier, a second till, a colleague) in one step, without sharing your seed phrase or any way to spend your funds.
An invite installs Bitrequest on the team member's device with:
- Your selected receiving addresses
- If you use a seed phrase: extended public keys (xpub, zpub, etc.) derived from it, so the device can generate fresh receiving addresses on its own
- Your settings, with security mode set to Cashier (create requests only, no changes to addresses or settings)
It never contains your seed phrase, your PIN, or your request history. Team members can receive payments to your addresses, but cannot access funds or change anything.
Sending an invite
- Open Settings → Team invite (requires your PIN; if you use a seed phrase it must be verified first).
- Share the invite link (WhatsApp, SMS, email, etc.) or show the QR code for the team member to scan.
- The team member opens the link or scans the QR code and taps Install.
The invite is stored encrypted on the payment proxy and deleted after one week. The install dialog shows how long the invitation is still valid. Anyone holding the link can install the invite, so treat it like the file itself and send it only to the person it is for.
Updating a team member Send a new invite from the same account. The team member's device recognizes it and offers Update instead of Install, replacing the old public keys with your latest ones.
Good to know
- An invite can't be installed on the device that created it.
- If a device already has a team installed from a different account, Bitrequest shows a warning before replacing its keys. The account name in an invite is chosen by the sender and can't be verified, so only install invites you expect.
- Device-local settings on the receiving device, such as an existing PIN-encrypted seed, are never overwritten by an invite.
Bitrequest is a Progressive Web Application (PWA).
~92% of the code runs client-side in the browser.
Programming language: JavaScript (vanilla JS, minimal jQuery).
The source code is 100% open-source: GitHub.
┌──────────────────────────────────────────────────────────────┐
│ Client (Browser/PWA) │
├──────────────────────────────────────────────────────────────┤
│ UI Layer │ Crypto Layer │ Data Layer │
│ - Request forms │ - BIP39/BIP32 │ - localStorage │
│ - QR generation │ - Address gen │ - sessionStorage │
│ - Status display │ - Tx scanning │ - Google Drive │
└────────┬───────────┴─────────┬──────────┴──────────┬──────────┘
│ │ │
▼ ▼ ▼
┌─────────────────┐ ┌─────────────────┐ ┌──────────────┐
│ API Proxy │ │ Block Explorers │ │ Personal │
│ app.bitrequest │ │ WebSocket APIs │ │ Nodes │
└─────────────────┘ └─────────────────┘ └──────────────┘
Bitrequest implements complex cryptographic protocols in pure JavaScript to maintain a minimal footprint (~919KB zipped total):
| Implementation | Description | Replaces |
|---|---|---|
| BIP39/BIP32 | HD wallet derivation, mnemonic handling | bitcoinjs-lib (~200KB) |
| secp256k1 | Elliptic curve operations, key derivation | elliptic.js (~100KB) |
| Monero Crypto | Ed25519, view key scanning, stealth addresses | monero-javascript (~7MB) |
| Kaspa Bech32 | 40-bit checksum variant, kpub encoding | kaspa-wasm (~7MB) |
| Keccak256 | Ethereum address derivation | js-sha3 (~15KB) |
| CashAddr | Bitcoin Cash address encoding | — |
These implementations are available as standalone libraries for other projects:
| Library | Description | Link |
|---|---|---|
| bip39-utils-js | BIP39/BIP32 HD wallet utilities | GitHub |
| crypto-utils-js | Low-level crypto (secp256k1, hashing, encoding) | GitHub |
| xmr-utils-js | Monero cryptographic utilities | GitHub |
A small PHP proxy handles caching and API calls: proxy source.
API calls are proxied through app.bitrequest.io by default, enabling out-of-the-box usage without personal API keys.
For self-hosting:
- Configure host in global_queries.js
- Provide your own API keys in config.php
Proxy features:
- Multi-API fallbacks
- TOR support
- Response caching to reduce rate limits
All API keys in the GitHub repository are left blank to prevent misuse. Users can:
- Use Bitrequest's shared keys (default, may hit rate limits)
- Enter personal keys in app settings
Connect to remote or local nodes for direct transaction scanning and enhanced privacy.
| Currency | Node Type | Protocol |
|---|---|---|
| Bitcoin/Litecoin | Electrum | TCP/SSL |
| Ethereum | JSON-RPC | HTTP/WebSocket |
| Ethereum L2 | JSON-RPC | HTTP/WebSocket |
| Monero | Remote Node / LWS | HTTP |
| Lightning | LND | REST API |
| Lightning | LNbits | REST API |
| Lightning | Core Lightning | REST API (CLNRest) |
| Lightning | Spark | Identity key (no host required) |
| Lightning | NWC | Connection URI (no host required) |
| Feature | LND | LNbits | Core Lightning | Spark | NWC |
|---|---|---|---|---|---|
| Invoice generation | ✓ | ✓ | ✓ | ✓ | ✓ |
| Payment monitoring | ✓ | ✓ | ✓ | ✓ | ✓ |
| LNURL support | ✓ | ✓ | ✓ | ✓ | ✓ |
| Boltcard/NFC | ✓ | ✓ | — | — | — |
For Proof-of-Work coins, set minimum confirmations before status changes to 'paid':
| Risk Level | Confirmations | Use Case |
|---|---|---|
| High risk | 0 (zero-conf) | Coffee, small items |
| Medium | 1-2 | Standard purchases |
| Low risk | 3-6 | Large payments |
Dash InstantSend and Nano provide instant finality without confirmation wait.
Monero requires a private view key to scan for incoming transactions while maintaining sender privacy. Bitrequest scans:
- Standard addresses
- Subaddresses
- With view tag optimization for faster scanning
Kaspa uses a unique address format:
- Derivation path: m/44'/111111'/0'/0/
- Extended keys: kpub (0x038f332e) / kprv (0x038f2ef4)
- Address format: kaspa:q... (67 characters for Schnorr/P2SH, 69 for ECDSA)
- Checksum: 8-character (40-bit) vs Bitcoin's 6-character
Compatible with KasWare and Kaspium wallets.
When a request is sent in fiat currency, time passes between sending and payment. Due to crypto volatility, Bitrequest:
- Records the exchange rate at request creation
- Fetches the rate at payment time via CoinGecko/CoinPaprika historical APIs
- Compares received amount against original fiat value
- Displays any over/underpayment
Rates are cached client-side for efficiency.
Bitrequest can be used as a checkout for e-commerce websites.
- Documentation: Webshop Integration Wiki
- Demo: bitrequest.io/brewery
Features:
- Multi-chain support
- Lightning payments
- Real-time status callbacks
- Customizable UI
Bitrequest is available on:
- iOS: App Store
- Android: Google Play
These native apps are wrappers for the PWA bitrequest.github.io, providing:
- Consistent experience across browsers
- Native sharing
- App store discoverability
Interactive test suites for verifying crypto implementations:
- BIP39 Utils Tests — HD wallet derivation, xpub/kpub generation
- Crypto Utils Tests — Address generation, hashing, encoding
- XMR Utils Tests — Address generation, Monero related cryptography