Work

Two systems I built and ran in production, then hackathon, bounty and open source work. The code for the first two is private, but I'm happy to walk through it in an interview.

  • Chain-Fi: OAuth server, backend API and vault

    CTO · May 2024 – February 2026 · company closed in 2026

    I wrote an OAuth 2.0 server from scratch, plus the API, SDK and mobile app built around it.

    How the pieces fit together

    Clients

    • Third-party app

      134

      Embeds the JavaScript SDK for QR login and signing requests.

    • Mobile app (React Native)

      45

      Holds the user's key. Scans QR codes and signs.

    • Dashboard and developer portal

      12

      Consent screen, app registration, client credentials and usage stats.

    Backend · Express, PostgreSQL

    • OAuth 2.0 server

      1

      Authorization code and refresh grants, opaque tokens, rotation, revocation, 9 scopes.

    • REST API and Socket.IO

      234

      87 endpoints, scope checks per route, real-time signing sessions.

    • Relayer

      5

      Checks the user and second-factor signatures, pays gas from a server wallet.

    • Listener

      6

      Follows vault activity and pushes it to clients over WebSocket.

    On-chain · EVM testnets

    • Vault factory

      5

      Deploys one minimal-proxy clone (EIP-1167) per user.

    • User vault

      56

      Every withdrawal or transfer requires an EIP-712 signature.

    1. 1Sign-in: the app sends the user to the consent screen. Once they approve, the OAuth server returns a code, then access and refresh tokens.
    2. 2Setup: developers register their app, scopes and redirect URIs in the portal, and get client credentials.
    3. 3API calls: the app calls the API with its access token. Each route checks the token's scopes.
    4. 4Signing: the SDK opens a Socket.IO session and shows a QR code. The user scans it with the mobile app, which signs with their key.
    5. 5Transactions: the relayer checks both signatures and calls the factory or the vault. It pays the gas, so users never need funds for fees.
    6. 6Updates: the listener sees vault activity and pushes it to connected clients.

    Chain-Fi was building accounts where users keep their own key, on their phone. Other apps could sign users in and ask them to approve transactions. So we needed a login system for developers, and a vault where users could hold assets without paying gas.

    I wrote the OAuth 2.0 server myself, without a library. It handles authorization codes and refresh tokens, rotates refresh tokens, supports revocation and checks nine scopes. Users approve apps on a consent screen. Developers register their apps in a portal, get client credentials and see usage per app. Behind it sits the main API: 87 REST endpoints on Express and PostgreSQL, with plain SQL. It ships in Docker, and GitHub Actions runs unit and integration tests against Postgres and Redis. I also wrote the JavaScript SDK that other apps embed for QR-code login and signing, and the React Native app that holds the user's key and approves requests.

    On-chain, I wrote the vault and its factory in Solidity. Each user gets their own small proxy contract (EIP-1167), and nothing leaves it without an EIP-712 signature. A relayer service checks two signatures, the user's and a second factor, then sends the transaction and pays the gas. Stripe handles billing. A Node.js listener watches vault activity on the Base, Arbitrum and Optimism testnets and pushes it to clients over WebSocket. The main rule: the backend never holds a user's key. The product ran on testnets until the company closed in February 2026.

  • Smarteaming: scheduling SaaS for shift-based teams

    Founder and sole engineer · 2020 – present · in production since 2020

    A B2B app I built alone and have kept running since 2020. About ten companies and a few hundred users rely on it.

    Companies with shift-based teams were planning in spreadsheets and group chats. Then they typed the same data again for invoices and payroll. Smarteaming does all of it in one place: availability, schedules, shifts, invoices, payroll and Dimona declarations (the Belgian employment registration).

    I built every part and I still run it. The backend is a Node.js/Express API on MySQL, with hand-written SQL. Socket.IO pushes schedule changes in real time, and scheduled jobs send reminders. The web app is React and TypeScript, in English, French and Dutch. The iOS and Android apps wrap the web app in React Native and add push notifications. The API runs on a DigitalOcean server behind Nginx, managed with PM2. The web app is a static React build, hosted separately on Hostinger.

    It's multi-tenant and I'm the only engineer. Payroll and social-security data can't be wrong, and if something breaks, I'm the one who fixes it. The API server has rebooted three times since August 2023, each time for under two minutes. It's now stable and in light maintenance. I keep a deployment runbook, a decision log and a list of known issues.

Other projects

  • Smart contract audit service (LLM plus static analysis)

    Paid Conflux bounty · submission merged

    A service that reviews Solidity contracts with an LLM (Claude or GPT-4) and two static analyzers. I didn't write the analyzers. I plugged in Slither and Mythril, each in its own Docker container, with several Solidity compiler versions. What I built is everything around them: the job pipeline, mapping findings to SWC and CWE categories, batch audits from a CSV, signed webhooks (HMAC), rate limiting, PostgreSQL with Prisma, Redis, a Next.js interface and Jest tests.

  • GigShield: stablecoin escrow for freelance work

    Main prize and Best AxCNH Integration, Conflux Global Hackfest 2026

    Escrow for freelance jobs, paid in stablecoins (USDT0, AxCNH). The client pays the full amount up front, and the money is released one milestone at a time. If the client goes quiet for 7 days, it's released automatically. If there's a dispute, three arbitrators vote and two out of three wins. It's one Solidity contract (OpenZeppelin, Hardhat tests with coverage), live on Conflux eSpace mainnet, with a Next.js and viem frontend.

  • Vorka: two-key self-custody on USB drives

    Personal project · open source (MIT)

    A self-custody setup that splits your keys across two USB drives. The everyday key signs, and a recovery key stays offline and can replace it without moving any funds. Each user gets their own vault contract in Solidity, and a desktop app in TypeScript and Electron creates the encrypted keys and signs. Withdrawals always go to the owner, so a stolen key can't redirect them. Signatures expire, and recovery uses its own nonce so it can't be blocked. There are 55 tests across the contracts and the app. It hasn't been audited yet.

Also: FluxPad, AI agents that run on-chain tasks. Second place at the Conflux AI Agent Hackathon 2025. Repo ↗Demo ↗

How I deliver

Whether it's a job or a contract, here's what you get:

  • a repository with reviewable pull requests
  • deployment notes and a runbook
  • architecture notes explaining the main decisions
  • tests for the parts that matter
  • monitoring and alerting in production

Hiring for a backend role?

I'm looking for a full-time remote backend job. Email me or message me on LinkedIn.