Select Page
Own First, Pay When It Counts — Onboarding, Hosting, and Sharing for Swarm Desktop
Solar Punk logo

Solar Punk

Own first, pay when it counts: onboarding, hosting, and sharing for Swarm Desktop

Swarm Desktop asks new users for money before they own anything, hides the network's best trick — that any folder can be a website — behind raw hashes, and has no honest sharing verb at all.

This project redesigns those three journeys as one mechanism, built on a fact the product already has: your identity key is free and portable; only storage costs money, and it costs money by the calendar.

Every screen is designed to leave the user believing true things about their own data — what is public, until when, and what cannot be undone.


Executive summary

A product spec is a mechanism: the behavior it actually produces is its equilibrium, and if the behavior we want is not the user's natural move, they will deviate — quit at the money wall, publish something they thought they could take back, or trust a backup that only saved half their keys. So we redesign the payoffs and the information, not just the screens. Onboarding: create and back up the free identity first, use the app free, and meet the funding step only when a chosen upload makes it worth paying — quoted as a date, delivering both tokens in one step. Hosting: a Publish button on any folder makes a deliberate public copy with a stable address that survives every edit. Sharing: two plainly named verbs — hand a key to named people, or make a public copy — with the one-way doors stated before the click, and one panel that always answers "who can see what."

Select any line to jump to the section that develops it.

00The problem

Three failures, one root. New users hit a token-acquisition wall before the app has given them anything — so quitting is the rational move. The Files tab can technically publish a website, but it speaks in raw hashes next to a File Manager that speaks in names — two mental models, and the friendly one lacks the public path. And sharing barely exists as an action, even though the protocol underneath is precisely a sharing machine: per-person encrypted grants on one side, public references on the other.

The root: the product hides its own best structure. The identity key that makes files yours is free and works on any machine. Only storage costs money, and it costs money by the calendar. Public content is a copy into a commons that no one — including us — can pull back. Designed around instead of hidden, each of these becomes a feature.

01The method

We treat the specification as a mechanism, following the marketplace canvas:

rules + incentives + information + cognitive load + vigilance + monitoring stable action patterns + calibrated beliefs

A mechanism's equilibrium is the behavior the product actually produces. So every flow below is checked twice: is the desired action the user's easiest and most rewarding move at each step? And does the user walk away believing true things — about what is public, what is backed up, what expires when, and what cannot be undone? A design that produces the right clicks but the wrong beliefs has only postponed its failure.

02Actors, interactions, incentives

Five actors, and only one of them is a person sitting at this app. The owner holds the identity key and makes every real decision. The node is not a decision-maker at all — it is the owner's payment engine, buying dated storage time on command. A named recipient holds a wrapped key the owner handed them. A public visitor holds nothing but a link. And the commons — the network itself — is where all content actually lives, belonging to no one. A mechanism works when each arrow below is worth following for the actor at its tail, given only the information the product shows them.

THE OWNER holds the identity key free to create · works anywhere THE NODE the owner's payment engine buys storage time · never reads PUBLIC VISITOR holds nothing but a link zero setup · any gateway NAMED RECIPIENT holds a wrapped key, not a copy one link that simply opens chooses a write → funds it, quoted as a date keeps chunks alive until ~date publish: public copy + one stable link private share: hands a wrapped key — limits said before the click opens from anywhere — the key is enough reads the public copy THE COMMONS — WHERE ALL CONTENT ACTUALLY LIVES locked private files · public copies · the owner's own catalog — owned by no one, kept by paid time
One decision-maker, four roles around them. Every gold element is something the owner's key controls; every clay element is economics or plain access; the violet floor is the commons everyone reads from. Note what is absent: no arrow lets the node read anything, and no arrow lets anyone reach a locked file without a key the owner handed them.

The table below is the incentive audit: for each actor, what they do, why doing it beats not doing it, and what the product must tell them at the moment of decision. If any row's "why it's worth it" fails, that actor deviates — and the mechanism, not the actor, is at fault.

ActorWhat they doWhy it's worth itWhat they must be told, and when
Owner, arrivingCreates an identity, backs it up, tries the appOwnership and reading are free; every step gives more than it asks, so continuing always beats quittingWhat the key is (one sentence), what the backup protects — before anything else
Owner, storingFunds the node at their first uploadThe cost buys a concrete, dated thing they just chose; both tokens arrive in one step, so the path has no hidden dead end"This much data, kept until ~this date, if top-ups continue" — at the moment of the upload, not at the front door
Owner, publishingTurns a folder into a websiteOne verb on files they already organize; the link survives every edit, so it is worth giving outPublic copy · kept until ~date · unpublish removes the pointer, not the copy — before the click
Owner, sharingHands a key, or makes a public copyThe private verb is the easiest verb, so the safe act is also the low-friction actForward-only revocation (private) or non-recallable copy (open) — before the grant, never after
Named recipientOpens what was shared with themOne link simply opens, from any machine — no protocol lesson, no setup ceremonyWho shared it and what "you can open this" means; if they lack an identity, a one-time creation step with a plain reason
Public visitorReads a site or an open shareZero setup: the link is enough, through any gatewayNothing — needing to tell a visitor anything would itself be a design failure
The nodePays gas, buys batches, signs stampsStructural role, not a choice — it acts when the owner commands and never decidesNothing; but the owner must always see what it paid for, until when, and from which wallet

Two interactions deserve their own line because they are where trust is won or lost. Owner → node is the only place money moves, so it is the only place quotes and dates are mandatory — a funding step without a kept-until date is a rule violation, not a style choice. Owner → anyone else is the only place exposure is created, so it is the only place one-way facts must precede the click — and the single review panel exists so the owner can afterwards enumerate every arrow of this kind they have ever drawn.

03Onboarding: own first, pay when it counts

The identity key costs nothing and is the user's one portable asset — so it comes first, with its backup, before money is ever mentioned. Reading the network is free at the protocol level — so the unfunded app is a working reader, not a locked demo. The funding step waits for the first upload the user actually chooses, and then it quotes a calendar, not tokens: "keep 2 GB for 12 months — until about July 2027." One in-app step delivers both required tokens, so the classic dead end — a wallet holding one token and not the other — never happens.

THE GATE MOVES: FROM THE FRONT DOOR TO THE USER'S OWN CHOICE the gate lives here now — attached to a choice, quoted as a date 1 · Own create + back up your identity — free 2 · Use browse & download free tier — no tokens 3 · Choose your first upload opens the gate 4 · Fund both tokens, one step "kept until ~date" the money wall used to stand here — before the user owned anything, quitting was the rational move
The gate moves. Ownership (gold) and free reading (violet) come before any cost. The funding gate (clay) interrupts an action the user just chose — and by then, leaving would cost them something they already value.
  • Two keys, two backups. The identity key and the payment wallet are backed up separately, each at the moment it first protects something. No screen ever says a bare "backed up" while only one is safe — that false belief is the most dangerous thing this product could manufacture.
  • Every promise carries a date. Never "saved" — always "kept until about this date, if top-ups continue," with early warnings and a one-tap top-up.
  • Portability is rehearsed. A short drill re-reads the user's catalog from the network with nothing but their key, turning "your files outlive this machine" from a slogan into something they have personally watched happen.

04Hosting: publish a folder you already have

Hosting stops being a separate raw-hash workflow and becomes one verb on the File Manager. Select a folder with a start page, press Publish. The app makes a deliberate public copy of it in the commons and wires a stable address — a pointer owned by the user's own key — so the link survives every edit. Editing the folder offers an update; version history gains a rollback; and because the address belongs to the identity key, the website itself is as portable as everything else the user owns.

YOUR FOLDER in the File Manager versioned · private by default edit → "Update site", same link Publish THE COMMONS public copy plain bytes · anyone can read kept until ~date STABLE ADDRESS a pointer your key owns survives every edit · rollback-able points at the current version VISITOR one link zero setup unpublish removes your pointer — the copy stays public until its date, and the app says so before you publish
Publish = a public copy + an address you own. The copy (violet) lives in the commons on its own dated storage; the address (gold) is part of the user's portable identity. The one-way door — a public copy cannot be recalled — is stated before the click, where it can still shape the decision.

05Sharing: two honest verbs

Every file gets one Share entry with two choices, named by their consequences. Hand a key to named people: the lock stays on, each person gets their own wrapped key, and the recipient receives one link that simply opens — from any machine. Make a public copy: the same gate as publishing, because it is the same door. The limits are said before the click: cutting someone off stops future versions but cannot un-read the past; a public copy cannot be recalled at all.

A FILE OF YOURS locked by default PRIVATE — HAND A KEY named people only · the lock stays on the recipient gets one link that just opens cut off future versions any time said before the click: past reads cannot be unread OPEN — MAKE A PUBLIC COPY anyone with the link · the lock comes off this copy kept until ~date, on its own storage this is what a published website is made of said before the click: a public copy cannot be recalled one review panel lists every grant, open share, and site — each control states what it cannot undo
Two verbs, named by consequences. Private sharing (gold) hands a key and keeps the lock; open sharing (violet) is a deliberate copy into the commons — the same primitive websites are built from. The irreversible facts are part of the choice, not the aftermath.

06The honesty rules

A short list of rules every surface obeys. Each one exists to prevent a specific false belief.

RulePrevents the false belief
Identity before money"This app wants my money before giving me anything" — and the quitting it causes.
Every promise carries a date"Saved means forever." Storage is a subscription; the date is always visible, warnings come early.
Two backups, never one word"I backed up" — when only one of two unrelated keys is safe.
Unpublish is not delete"I can take it back." Removing the pointer never recalls a public copy, and the app says so first.
Revocation is forward-only, said at grant time"Removing someone un-shares the past." It only protects the future.
One panel answers "who can see what""I probably haven't shared anything sensitive" — hope where a checkable list should be.
Friction follows irreversibility"Warnings are wallpaper." Reversible acts are one click; only true one-way doors get a gate, so the gate still means something.
Portability is rehearsed, not promised"My files are probably safe somewhere" — replaced by a recovery the user has personally watched succeed.

Everything above is specified in full — actors, flows, locked records, eight rule contracts with acceptance criteria, and a risk register keyed to belief distortions — in the companion canvas document. Each contract passes the strategy's leak test, so the same rules serve the File Manager wherever it is embedded, not only inside Swarm Desktop.

Solar Punk logo The user owns their identity for free, pays for time they can see, publishes copies they understand, and shares with verbs that mean what they say. The product's job is to make the safe path the easy path — and to leave every user believing true things about their own data.

Solar Punk · Desktop × File Manager brief · v1.0 · last updated 08 July 2026