No-KYC P2P Marketplace to Buy and Sell Monero, Bitcoin and more https://morphit.io
  • TypeScript 80.5%
  • Svelte 15.7%
  • Shell 2.1%
  • JavaScript 0.8%
  • Python 0.4%
  • Other 0.4%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Morphit Team 9f2a2b7396
All checks were successful
morphit-ci / TypeScript typecheck (sweep all workspaces) (push) Successful in 47s
morphit-ci / apps/web svelte-check (svelte-kit sync + svelte-aware tsc) (push) Successful in 40s
morphit-ci / Integration tests (real Postgres 16) (push) Successful in 39s
morphit-ci / ansible-lint (playbook quality gate) (push) Successful in 16s
morphit-ci / Smoke suite (run-smokes.sh, triple-pulse) (push) Successful in 30m24s
morphit-release / Build + publish release tarball (push) Successful in 31m23s
npm-audit-gate: review + allowlist 5 newly-disclosed HIGH CVEs (undici/ip-address/fast-uri/brace-expansion/postcss)
2026-08-03 15:16:15 -07:00
.forgejo v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
apps npm-audit-gate: review + allowlist 5 newly-disclosed HIGH CVEs (undici/ip-address/fast-uri/brace-expansion/postcss) 2026-08-03 15:16:15 -07:00
docs Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
merchant-qr-kit v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
node_modules v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:07:35 -07:00
ops Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
packages Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
scripts Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
.gitignore v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
LICENSE v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
MORPHIT-BRAG-LIST.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
morphit-setup.sh v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
morphit.config.env.example v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
package-lock.json Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
package.json Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
README.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
release-info.json v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.1.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.2.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.3.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.4.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.5.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.6.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.7.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.8.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.9.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.10.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.11.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.12.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.13.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.14.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.15.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.16.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.17.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.18.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.19.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.20.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.21.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.22.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.23.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.24.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.25.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.26.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.27.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.28.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.29.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.30.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.31.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.32.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.33.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.34.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.35.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.36.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.37.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.38.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.39.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.40.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.41.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.42.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.43.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.44.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.45.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.46.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.47.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.48.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.49.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0-beta.50.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.0.1.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.1.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.1.1.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.1.2.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.1.5.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.2.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.3.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.3.5.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.5.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.7.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.8.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.9.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.10.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.11.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.4.12.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.5.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.5.5.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.5.6.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.5.7.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.7.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.7.5.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.7.7.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.1.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.2.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.3.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.4.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.5.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.6.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.7.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.8.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.9.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.10.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.11.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.12.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.13.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.14.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.8.15.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.0.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.1.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.2.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.3.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.4.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.6.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.7.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.8.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
RELEASE-NOTES-v1.9.9.md v1.9.9 — documentation accuracy pass + home-hosting setup guide improvements 2026-07-31 01:14:03 -07:00
RELEASE-NOTES-v1.9.10.md v1.9.10 — resilient warrant canary + guided setup, ticker-compact order titles, Farsi/RTL rendering fix 2026-07-31 15:49:21 -07:00
RELEASE-NOTES-v1.9.11.md v1.9.11 — warrant canary survives upgrades, Farsi/RTL card layout, wider order titles 2026-07-31 22:04:18 -07:00
RELEASE-NOTES-v1.9.12.md Morphit v1.9.12 — warrant canary hands-off: fresh-server setup auto-chown, same-box auto-restore on upgrade, health stale-canary warning 2026-08-01 01:05:12 -07:00
RELEASE-NOTES-v1.9.13.md Morphit v1.9.13 — canary-ownership fix for root-owned installs (read owner from the previous install) + remove the chat debug tracer 2026-08-01 13:13:50 -07:00
RELEASE-NOTES-v1.9.14.md Morphit v1.9.14 — canary refresh self-heals a re-rooted served folder (hands-off across upgrades) 2026-08-01 15:50:12 -07:00
RELEASE-NOTES-v1.9.15.md Morphit v1.9.15 — RTL username fix (@handle always prefix), empty Featured card hidden, footer cleanup + 5-column reorg, run-a-node button → download 2026-08-01 20:10:12 -07:00
RELEASE-NOTES-v1.9.16.md v1.9.16 — guided-install completeness (Tor/I2P/canary/PGP summary checks, cross-mode register, optional Matrix contact) + RTL @handle + instances-card pill fixes 2026-08-02 14:35:59 -07:00
RELEASE-NOTES-v1.9.17.md v1.9.17 — hotfix: local install no longer crashes at the connection-safety check ('ansible_user' undefined); the harmless Python-interpreter warning is silenced 2026-08-02 19:02:20 -07:00
RELEASE-NOTES-v1.9.18.md v1.9.18 — hotfix: create the morphit-mcp system group before its user (local install no longer stops at 'Group morphit-mcp does not exist') 2026-08-02 23:59:45 -07:00
RELEASE-NOTES-v1.9.19.md Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
RELEASE-NOTES-v1.9.20.md Full-coverage install summary (verifies + shows every subsystem's health) + Matrix room contact option 2026-08-03 14:47:34 -07:00
SECURITY.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
TARBALL.md npm-audit-gate: review + allowlist 5 newly-disclosed HIGH CVEs (undici/ip-address/fast-uri/brace-expansion/postcss) 2026-08-03 15:16:15 -07:00
THIRD-PARTY-LICENSES.md v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
tsconfig.smoke-typecheck.json v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00
tsconfig.smoke.json v1.9.8: BLURT/USD source of truth (api.blurt.blog primary) + guided node setup 2026-07-30 14:09:09 -07:00

Morphit

A federated, non-custodial, no-KYC peer-to-peer marketplace for trading fiat against Bitcoin, Monero, BLURT, USDT, USDC, DAI, Bitcoin Cash, Litecoin, Dash, Dogecoin, Zcash, Pirate Chain, Decred, Solana, Ethereum, and Ripple.

You hold your own keys. There are no deposits to make and no withdrawals to wait for; trades settle directly between counterparty wallets. There is no central server to subpoena and no central database to leak — the orderbook lives on a public blockchain, and any operator running a Morphit indexer sees the same data. If one operator goes dark, another's URL still works and the federation continues.

This repository carries the full source for the indexer, relay, frontend, operator CLI, Matrix incident bot, and MCP server, plus the ops material (Ansible role, systemd units, env templates, runbooks) to stand up an instance on a fresh Ubuntu 24.04 VPS in roughly 30 minutes.

Status

Pre-launch, currently in the v1.0.0-beta release series. The canonical public instance is morphit.io; community operators are welcome to launch their own nodes alongside. There are no production deployments yet — the codebase has been through an intensive multi-month pre-launch hardening campaign documented in docs/AUDIT-2026-05.md.

New here? Start here 👇

If you want to run a Morphit node (or upgrade one, or fix something), don't read this whole file — go straight to the plain-language navigation hub, which tells you exactly which guide to open for what you want to do:

👉 docs/start-here/

The two commands you'll use most, from your install directory: npx morphit-ops (opens a menu of everything) and npx morphit-ops upgrade (updates to the latest version). The rest of this README is a technical overview for people evaluating or building the software.

What this is, concretely

  • Federated orderbook. Orders are signed by the user's posting key and broadcast as custom-JSON ops on the underlying chain. Every Morphit indexer in the federation reads the same chain and surfaces the same orderbook.
  • Barter, too. A listing isn't limited to cryptocurrency — it can offer goods or services ("barter"), priced in the seller's local currency and settled in a cryptocurrency the seller chooses to accept. The goods change hands off-platform; Morphit never touches them or the payment.
  • Non-custodial. Trade settlement is wallet-to-wallet. There is no on-platform balance for an operator to mismanage. Listing fees are paid on-chain; the split is asymmetric and disclosed upfront: BLURT-paid listing fees split 90/10 — 90% to the operator running the instance the order was posted through, 10% to the project treasury (@morphit-fees). BTC- and XMR-paid listing fees go 100% to the project treasury (the canonical morphit.io devs' wallets) — not to individual operators. This asymmetry is deliberate (BLURT splits atomically on-chain; BTC/XMR would require off-chain custodial bookkeeping that breaks the non-custodial design), and it's why operators earn from BLURT-paid fees only. Users pay 50% less when paying in BLURT, so BLURT-paid is where most volume — and operator revenue — naturally lands. Full mechanics: docs/FEES-AND-REWARDS.md.
  • No KYC. Signup is a cryptographic public key and a username. The system has no place to store an ID even if a regulator demanded one.
  • Privacy first. No cookies, no analytics, no IP logging. XMR support hardens with subaddresses and per-payment view-key proofs (the operator's private view key never reaches the network). On every chain Morphit trades (BTC, BCH, LTC, DASH, DOGE, ZEC, ARRR, DCR, SOL, ETH, XRP, BLURT, XMR), the address-share modal offers default-ON amount randomization and address-reuse warnings; BTC also gets optional PayJoin (BIP-78) endpoint propagation; DASH gets a wallet-side PrivateSend pre-mix workflow explained in the per-asset guide. Stablecoin trades (USDT, USDC, DAI) get the same amount-randomization defense at 6-decimal precision (cp30 reversal of the cp26 USDT pass-through decision — Circle/Tether freeze power is a separate, independently-real threat documented in each per-asset privacy guide). Per-asset privacy guides live at /[lang]/privacy/{asset}.
  • Encrypted chat. Per-message ECIES (X25519 + ChaCha20-Poly1305-IETF) with sender ephemerals, stored on-chain as ciphertext — see docs/adr/0015-chat-crypto.md.
  • Reach. Public hostname, Tor .onion, I2P .b32, Lokinet, and Nostr-relay channels are all first-class operator-config surfaces.

For the long version, every claim is enumerated and source-anchored in MORPHIT-BRAG-LIST.md.

Repo layout

Directory What's in it
apps/web/ SvelteKit frontend, fully prerendered per locale (10 locales × dozens of indexable routes; the canonical list of routes is whatever apps/web/src/routes/[lang]/**/+page.svelte enumerates at build time)
apps/indexer/ Reads Blurt blocks, materializes orderbook + chat + reputation, exposes /v1/* HTTP API
apps/relay/ Holds the operator's relay active key; signup broadcasts, welcome-bonus payouts, Web Push delivery
apps/ops-cli/ morphit-ops init / edit / upgrade — operator setup wizard and release apply tool
apps/matrix-bot/ Optional Matrix incident-pager bot for operators who want push-to-phone alerting
packages/ Shared TypeScript packages: asset-registry, indexer-client, relay-client, operator-config, release-schema, net-defense, rpc-pool
docs/ ADRs (docs/adr/0001-… through 0051-…), audit logs, operator runbooks
ops/ Ansible role, systemd units, env templates, nginx + BunkerWeb configs, postgres init
scripts/ Build, smoke, mediakit, sitemap, llms.txt, and ceremony helpers

Running an instance

The complete walkthrough is in docs/RUN-A-MORPHIT-NODE.md. The short version:

  1. Provision a $5/mo Ubuntu 24.04 VPS with Postgres reachable.
  2. git clone this repo (or extract a signed release tarball — see docs/UPGRADING.md).
  3. npm ci from the repo root (workspace install — must be run from the root).
  4. npm run build --workspaces --if-present to build the artifacts: the static web app nginx serves, plus the morphit-ops and morphit-mcp bundles. (The relay and indexer run from TypeScript source and have no build step; the web app must be built before nginx has anything to serve.)
  5. npx morphit-ops init to walk the setup wizard (~23 prompts; configures treasury addresses, fee targets, explorer URLs, operator tag, VAPID keys for Web Push).
  6. bash scripts/run-smokes.sh to confirm the self-checks (~358 runners, several thousand scenarios) pass against your environment.
  7. Follow docs/PRE-LAUNCH-CHECKLIST.md and docs/LAUNCH-DAY.md before opening to traffic.

For developers

  • Architecture overview: docs/ARCHITECTURE.md
  • API reference: docs/API.md
  • ADR index: docs/adr/0001-… through docs/adr/0051-…
  • Audit log: docs/AUDIT-2026-05.md
  • Per-language translation guide: docs/CONTRIBUTING-TRANSLATIONS.md
  • Adding a workspace (apps/* or packages/*): docs/ADDING-A-WORKSPACE.md
  • Adding a tradable coin: docs/ADDING-A-COIN.md
  • Locale graduation (PLANNED → SUPPORTED): docs/LOCALE-GRADUATION.md

The smoke suite is the source of truth for behavior:

bash scripts/run-smokes.sh

Triple-pulse it (run three times back-to-back) to filter flakes before submitting changes.

Reporting bugs

Use Forgejo's New Issue form — the bug-report template auto-loads and walks you through the fields we need. Security-sensitive issues (anything involving keys, funds, fee bypass, or leaked private data) go to the operator's Matrix DM channel listed in §16 of the form — do NOT post them as a public issue or in the community chat room.

Offline alternative: docs/NEW-ISSUE-FOUND.md (plain Markdown copy of the bug-report fields you can email).

Community

  • Matrix room (public): #agorise:matrix.org — for questions, announcements, "is this a known bug?"
  • Security disclosures (private): @agorise:matrix.org direct message (E2EE) — see docs/SECURITY.md.

License

AGPL-3.0-only. Every operator running a modified instance must make their source available to their users. See LICENSE.

Third-party dependencies are used under their own licenses (overwhelmingly permissive — MIT/ISC/Apache-2.0/BSD); see THIRD-PARTY-LICENSES. Note that the Blurt client @beblurt/dblurt carries a BSD-3-Clause-No-Military-License (a no-military-use restriction) — disclosed there for operators and redistributors.


Don't trust the project's marketing — verify it. Every claim in MORPHIT-BRAG-LIST.md points at code, an ADR, or a smoke that proves it. If you find one that doesn't, open an issue.