A technical map · 2026

The gap Nostr fills
for the cannabis market.

Cannabis is one of the only legal industries structurally locked out of the standard rails — banking, card networks, ad platforms, app stores, and closed compliance vendors. Nostr's primitives map onto that exact vacuum. This is the honest, expanded map: where it fits, how it works, and where it doesn't.

9
Gaps Nostr fills
5
Core primitives
6
Honest limitations
20+
NIPs referenced
00

The problem cannabis actually has

Before mapping solutions, the constraints. Cannabis operators — fully licensed, taxpaying, state-legal — run on infrastructure that was never built for them. The exclusion is structural, not accidental.

🏦

Banking & payments

Even post-rescheduling, FinCEN's 2014 guidance and BSA/AML obligations remain. Visa and Mastercard run on federal rails and won't onboard cannabis merchants. Most operators are still cash-heavy as of 2026, creating security risk and an audit-trail gap.

Bloomberg · NBC · FinCEN 2014 guidance
📋

Tax distortion (280E)

IRC §280E, a 1982 rule, blocks Schedule I/II traffickers from deducting ordinary business expenses. Effective tax rates of 70–90% are routine. Rescheduling to Schedule III may relieve medical-lane operators, but adult-use remains in limbo.

IRC §280E · April 2025 Schedule III order
🔒

Vendor lock-in

State-mandated seed-to-sale systems (METRC, BioTrack) are closed, vendor-locked, single points of failure. B2B wholesale marketplaces (LeafLink) take fees and gate access. Operators have no open, vendor-neutral data layer.

METRC · BioTrack · LeafLink
🚫

Platform censorship

Meta and Google effectively ban cannabis ads. Instagram shadow-bans and suspends licensed dispensary accounts. App stores restrict cannabis apps. Operators cannot build audience on infrastructure they don't control.

Meta ad policy · Google ad policy · App Store review guidelines
🧪

Lab result integrity

COAs (Certificates of Analysis) are PDFs. They get Photoshopped, stale certs get reused, labs get pressured to inflate potency. There is no native, verifiable, tamper-evident way for a dispensary or consumer to trust a lab result.

Industry-reported · state regulator enforcement actions
⚔️

Cash security

Cash-heavy operations mean armed robbery is a real, ongoing risk for dispensaries and transport. Physical security costs scale with cash volume. Any rail that reduces on-hand cash is a direct safety improvement.

Industry security reports · DEA diversion data
01

Why Nostr maps onto this unusually well

Nostr isn't a blockchain. There's no consensus, no mining, no global ledger. It's a thin protocol for signed events published to replaceable relays. Those five properties happen to line up with exactly what cannabis is starved for.

01

Keypair identity, not accounts

Identity is a secp256k1 keypair you hold. No platform issues it, no platform can suspend it, no platform can KYC-gate it. An npub is yours the way a Bitcoin address is yours. For an industry routinely deplatformed, this is the foundation.

NIP-01NIP-19
02

Cryptographically signed events

Every record — a note, a sale, a lab result, a custody transfer — is a signed JSON event. Tamper-evident, independently verifiable, no trusted intermediary. The same data structure for a tweet and a batch record.

NIP-01secp256k1Schnorr
03

Dumb, replaceable relays

Relays are passive stores that anyone can run. No central server to subpoena, deplatform, or choke off. A cannabis operator can run their own relay and own their data layer entirely. Federation by default.

NIP-01NIP-11NIP-77
04

Lightning-native payments

NIP-57 zaps are censorship-resistant, near-instant, sub-cent micropayments over Lightning. They bypass Visa, Mastercard, and bank rails — the exact rails that won't touch cannabis. Native to the protocol, not bolted on.

NIP-57NIP-47LNURL
05

Real commerce primitives

The NIP ecosystem ships usable building blocks: encrypted DMs (NIP-17 + gift wrap), classifieds (NIP-99), file storage (NIP-96/Blossom), badges (NIP-58), long-form content (NIP-23), live events (NIP-53). Enough to build a real business on.

NIP-17NIP-99NIP-58NIP-23

The thesis

Nostr's value here isn't "decentralization for its own sake." It's that no single vendor can be deplatformed, acquired, or price-gouged, and every record is independently verifiable. That maps precisely onto what cannabis operators are actually frustrated by.

02

The 9 gaps Nostr can fill

Each one expanded: the problem, the mechanism, the concrete NIPs and event kinds, real-world mechanics, and an honest caveat. Ordered roughly by leverage, not by glamour.

01

Payments & financial rails

Critical · Highest leverage

The problem

As of 2026, licensed dispensaries still largely can't accept credit or debit cards. Visa and Mastercard operate on federal banking rails and decline cannabis merchants. Operators run cash-heavy, creating security exposure and an audit-trail gap. Even after rescheduling to Schedule III, FinCEN's 2014 guidance and BSA/AML obligations persist — the SAR-filing burden doesn't vanish. Banking access improves incrementally; card networks don't flip overnight.

How Nostr fills it

NIP-57 zaps deliver a payment rail that doesn't depend on any bank or card network. A dispensary publishes a Lightning invoice / zap endpoint; a customer pays from any Lightning wallet; settlement is near-instant, sub-cent, and non-custodial options exist. The same rail works B2B (dispensary → cultivator, cultivator → trim crew) and B2C.

Concrete primitives

NIP-57 · Zap request (kind 9734) / receipt (kind 9735) NIP-47 · Wallet Connect (programmatic wallet control) LNURL · Pay / Withdraw / Channel BOLT 11 · Invoices BOLT 12 · Offers (static, reusable) Hold invoices · B2B escrow Taproot Assets / RGB · Stablecoins on Lightning

Real-world mechanics

  • Point of sale: BTCPay Server (self-hosted, no custodian) generates a BOLT 11 invoice per sale; customer scans with wallet of choice (eNuts, Muun, Wallet of Satoshi, Cash App Lightning, Phoenix). Settlement in seconds, fee typically <1 cent.
  • B2B wholesale: Cultivator issues a hold invoice for a wholesale lot; payment is held in escrow until delivery confirmation, then released — Lightning-native escrow without a third party.
  • Trim crew / hourly labor: Streaming satoshi payments over Lightning — workers paid per pound trimmed in real time, not monthly. Sub-cent granularity enables new compensation models.
  • Treasury: Stablecoin channels (Taproot Assets) let operators hold USD-pegged balances on Lightning, sidestepping BTC volatility for working capital.
  • Micropayments: Pay-per-gram sampling, pay-per-view strain education content, tip-your-budtender — economic models that card rails' minimum fees make impossible.
Honest caveat: This is custodial and regulatory innovation, not a free pass. Money transmission laws, BSA/SAR obligations, and §280E all still apply to the business regardless of the rail. Nostr doesn't make taxable income disappear. A custodial Lightning wallet serving cannabis still has compliance exposure. What it removes is the processor chokepoint — the ability of Visa/Mastercard/Stripe to simply decline the category.
02

Supply-chain traceability — open & interoperable

High · Defensible

The problem

Today's seed-to-sale tracking is METRC (and BioTrack): closed, vendor-locked, state-mandated, RFID-tag-based, a single point of failure. StrainChain and others bolt private blockchain "backstops" onto METRC, but those are still private ledgers. Operators have no open, vendor-neutral verifiable layer; switching costs are enormous; consumer-facing transparency barely exists.

How Nostr fills it

A signed-event supply chain: each custody hand-off (cultivator → processor → lab → distributor → retailer) is a signed event from that licensee's keypair, referencing the prior event by ID. Tamper-evident chain of custody, open standard, no vendor lock-in. Regulators run their own relay; consumers scan a product and verify full signed provenance themselves.

Concrete primitives

NIP-33 · Parameterized replaceable events (kind 30000+) — keyed by batch ID NIP-78 · App-specific data (kind 30078) NIP-01 · Event references (e tags) — chain the custody events NIP-32 · Custom tag namespaces NIP-19 · npub / nprofile for licensee identity NIP-05 · State license verification mapping

Example: a custody transfer event

{
  "kind": 30078,
  "content": "",
  "tags": [
    ["d", "batch-7f3a-custody-transfer-2026-07-31"],
    ["batch_id", "7f3a9e1b"],
    ["prior_event", "9a1c...e4f2"],
    ["from_licensee", "npub1cultivator..."],
    ["to_licensee", "npub1processor..."],
    ["metrc_tag", "1A4000A123456780000001234"],
    ["mass_g", "4820"],
    ["strain", "Wedding Cake"],
    ["timestamp", "2026-07-31T14:22:00Z"],
    ["geo", "39.7392,-104.9903"],
    ["transport_temp_c", "18.5"]
  ],
  "pubkey": "npub1cultivator...",
  "created_at": 1753968120,
  "sig": "..."
}

Real-world mechanics

  • Anti-diversion: If product shows up outside the licensed chain, no signed custody event exists for it — diversion is immediately detectable.
  • Recall management: A failed lab result triggers a backwards walk through referenced events to find every downstream product that touched the source batch — in seconds, not days of METRC querying.
  • Consumer verification: A QR code on packaging resolves to the final retail event; the consumer's client walks the chain of references back to the cultivator, verifying every signature.
  • Multi-state operators: One open data layer across every state they operate in, instead of reconciling METRC + BioTrack + state-specific systems.
  • Complements, not replaces, METRC: METRC remains the state's system of record. Nostr is the open, verifiable, inter-business layer on top.
03

Manufacturing records & batch integrity

High · Defensible

The problem

Extractors and edibles manufacturers keep batch records in ERP databases or paper logs. Edits are quiet — a recall investigation often can't prove who changed what, when. SOP versioning is informal. Operator accountability is weak. This is the same problem pharma solved with FDA 21 CFR Part 11 electronic records, but cannabis has no equivalent open standard.

How Nostr fills it

Every batch record is a signed, parameterized replaceable event (NIP-33) keyed by batch ID. Input biomass lot IDs, SOP version, equipment ID, operator keypair, temperature logs, yield — all signed. QA signs off as a separate event referencing the batch. Deviations are signed amendments. The result is a tamper-evident manufacturing audit trail with provable operator accountability, portable across ERP systems.

Concrete primitives

NIP-33 · Batch records keyed by batch_id NIP-78 · Custom manufacturing data payloads NIP-07 · Per-operator keypair signing (browser extension pattern) NIP-46 · Nostr Connect (hardware signer / NCU support) NIP-44 · Encrypted payloads for trade-secret SOPs NIP-73 · External content references (SOP documents)

Real-world mechanics

  • 21 CFR Part 11 parallels: Signed events satisfy the same intent — attributable, tamper-evident, time-stamped electronic records — but on an open protocol instead of a vendor's database.
  • SOP versioning: Each SOP version is a signed event; a batch record references the exact SOP version it was executed against. No "we updated the SOP after the recall" revisionism.
  • Operator accountability: Every action (start batch, add solvent, log temp, sign off) carries the operator's signature. You always know who did what — and they can't repudiate it.
  • Equipment calibration: Calibration events for each piece of equipment are signed and timestamped; a batch referencing an out-of-calibration instrument is flagged automatically.
  • Yield reconciliation: Input biomass mass vs. output product mass across signed events — diversion or shrinkage becomes a math problem, not a forensics problem.
  • IoT / SCADA signing: Temperature, pressure, and humidity sensors can themselves hold keypairs and sign readings directly — machine-attested data, not human-keyed.
  • CAPA (corrective & preventive action): Deviations and their resolutions are signed amendment events chained to the original batch — a complete, auditable narrative.
04

Lab testing & Certificate of Analysis integrity

High · Low regulatory risk

The problem

COAs are PDFs. They get Photoshopped to inflate potency. Stale certificates get reused for new batches. Labs get pressured by cultivators to inflate THC numbers (a known industry scandal). Dispensaries and consumers have no native way to verify a COA is genuine, current, and unmodified.

How Nostr fills it

Labs sign COAs with their keypair and publish the hash as a Nostr event. The lab's npub is its identity. Anyone — dispensary, consumer, regulator — verifies the signature in seconds. A tampered or expired cert is immediately detectable. This is the lowest-regulatory-risk, highest-defensibility use case in the entire stack.

Concrete primitives

NIP-05 · Accreditation body verifies the lab's npub NIP-33 · COA events keyed by sample_id / batch_id NIP-58 · Badges for accredited labs NIP-56 · Reports for fraudulent results NIP-96 / Blossom · COA PDF storage with hash anchoring

The verification flow

  1. Lab receives sample, runs analysis, generates COA PDF.
  2. Lab hashes the PDF and publishes a signed Nostr event containing: hash, sample_id, batch_id, potency, contaminants, test_date, expiry, lab_npub.
  3. Lab's npub is NIP-05-verified against an accreditation body (e.g., ISO 17025 registrar, state agency).
  4. Dispensary intake scans a product QR code → fetches the COA event → verifies lab signature → confirms hash matches the PDF → confirms not expired.
  5. Consumer scans at point of sale → same verification in their phone. A Photoshopped PDF fails the hash check. A stale cert shows expired. A fraudulent lab loses its accreditation badge.

Why this lands first

  • No money transmission exposure — it's just signed data.
  • Regulators want it — state agencies have prosecuted potency-inflation scandals.
  • Consumers want it — potency is the #1 purchasing driver.
  • Labs want it — reputable labs are tired of being undercut by labs that inflate.
  • StrainChain already does this on a private chain — Nostr makes it an open standard anyone can implement.
05

B2B wholesale marketplace

Medium · Building block

The problem

Inter-licensee wholesale today runs through closed marketplaces (LeafLink, Jane Technologies) that charge fees, gate access, and can delist operators. Email + phone is still common. There is no open, serverless, no-platform-takes-a-cut wholesale layer.

How Nostr fills it

NIP-99 (classifieds) and NIP-15 (Nostr Marketplace — deprecated but implemented in NostrMarket and Plebeian Market) give you stall/product/listing primitives. Buyers browse across relays, negotiate terms over NIP-17 encrypted DMs, settle via Lightning. No platform takes a cut, no platform can delist a licensee.

Concrete primitives

NIP-99 · Classified listings (kind 30402) NIP-15 · Marketplace stalls (kind 30017) / products (kind 30018) NIP-17 · Encrypted negotiation (gift-wrapped, metadata-hidden) NIP-44 · Payload encryption NIP-57 · Lightning payment at settlement BOLT 12 · Static offers for recurring wholesale relationships Hold invoices · Escrow against delivery

Real-world mechanics

  • Cultivator lists wholesale lots: A NIP-99 listing with strain, biomass mass, lab result event reference, price per pound, harvest date, available-from date.
  • Buyer discovery: Dispensaries subscribe to cultivator npubs they trust; listings appear automatically — no marketplace algorithm intermediating.
  • Encrypted negotiation: Price, payment terms, delivery logistics negotiated over NIP-17 DMs — gift-wrapped so even the relay can't tell who's talking to whom.
  • Reputation: NIP-56 reports for bad actors; NIP-58 badges for verified licensees; NIP-32 custom tags for repeat-buyer status.
  • Genetics NFTs: Premium cultivars tokenized so breeders can prove lineage and protect IP — StrainChain already does this; Nostr makes the listing/transfer open.
  • Auctions: NIP-15 supported auction primitives for scarce micro-batches or limited-edition phenotype drops.
06

Marketing & community that can't be deplatformed

Medium · Real pain point

The problem

Meta and Google have effectively banned cannabis ads for years. Instagram routinely shadow-bans or suspends licensed dispensary accounts. App stores restrict cannabis apps. Operators spend years building audiences on infrastructure that can vanish overnight — and routinely does.

How Nostr fills it

A dispensary's Nostr profile + relay is uncensorable. They publish to their own relay, customers follow their npub, no algorithm suppresses them, no trust-and-safety team suspends them. The audience is portable — followers move with the dispensary across any Nostr client.

Concrete primitives

NIP-01 · Profile metadata (kind 0) NIP-23 · Long-form articles — strain education, terpene guides NIP-53 · Live events — harvest walkthroughs, budtender Q&A NIP-89 · Recommended clients/app handlers NIP-57 · Zap-powered content (tip-the-budtender, support-the-grower) NIP-72 · Moderated community spaces

Real-world mechanics

  • Strain education as long-form: NIP-23 articles on cultivar lineage, terpene profiles, expected effects — indexed by search engines, owned by the dispensary, not Medium or Substack.
  • Live harvest / processing streams: NIP-53 live events for transparency-minded brands — customers watch the cure in real time, zap the cultivator.
  • Medical patient education: Condition-specific content (CBD ratios for epilepsy, CBG for inflammation) without fear of platform takedowns.
  • Direct customer relationships: The follower graph belongs to the customer and the dispensary — no algorithmic reach throttling, no "boost your post for $50" tax.
  • Cross-dispensary discovery: Patients in new cities find licensed dispensaries by npub reputation, not by fighting Google Maps' cannabis filtering.
07

Customer data ownership & loyalty

Medium · Differentiated

The problem

A dispensary's loyalty program and customer list live inside some vendor's app — and that vendor can shut them down (it happens). When a SaaS loyalty provider pivots or fails, years of customer relationship data evaporates. Operators don't own the relationship; the platform does.

How Nostr fills it

The dispensary owns the relationship. Customers follow the dispensary's npub; loyalty badges (NIP-58) are signed events the customer holds in their own wallet; the whole thing is portable across clients. No app store can pull it. No vendor can hold it hostage.

Concrete primitives

NIP-58 · Badge award / badge definition events NIP-32 · Custom tags for tier (gold/silver/platinum) NIP-44 · Encrypted private purchase history (opt-in) NIP-17 · Encrypted patient communication (HIPAA-aware) NIP-05 · Identity verification by the dispensary

Real-world mechanics

  • Loyalty badges as portable assets: A "Gold Member" badge is a signed NIP-58 event the customer holds — they can carry it to a new dispensary client, display it, prove it.
  • Customer-owned purchase history: If the customer chooses, they publish encrypted purchase events only they can decrypt — they own their data, grant access selectively (e.g., to a new dispensary for recommendations).
  • Medical patient patterns: Recurring purchases for chronic conditions tracked by the patient, not the dispensary's CRM — privacy-preserving by default.
  • Privacy-preserving identity: Zero-knowledge age proofs (in-development NIPs) let customers prove 21+ without revealing name, DOB, or address.
  • No app store gatekeeper: A dispensary's customer base cannot be severed by Apple or Google policy — the npub relationship persists independent of any client app.
08

Compliance reporting to regulators

Medium · Political lift required

The problem

State regulators receive compliance data via METRC web forms — manual, attribution-weak, spoofable in principle. The regulator often can't cryptographically prove which licensee submitted a given record, only that someone with API credentials did. Audit trails are internal to a single vendor's database.

How Nostr fills it

The state regulator runs a relay. Licensees publish signed compliance events directly to it. The regulator gets a cryptographically attributable, tamper-evident feed — they always know which licensee's keypair signed what, and spoofing is impossible without the key. Structurally more trustworthy than web-form submissions.

Concrete primitives

NIP-01 · Signed compliance events NIP-05 · State license → npub mapping (the regulator is the verifier) NIP-11 · Relay metadata describing regulator relay policy NIP-33 · Replaceable events for current-state inventory NIP-09 · Deletion requests (regulated, auditable)

Real-world mechanics

  • Attribution by design: Every event carries a signature over the regulator-defined payload. No credential-sharing, no "the intern submitted it" ambiguity.
  • Real-time monitoring: Regulators subscribe to live events instead of pulling batch reports — diversion or anomaly detection in near-real time.
  • Audit-grade evidence: A signed event is admissible evidence of who said what, when. METRC web forms are not, by themselves.
  • Multi-state compacts: States that share cannabis data (e.g., for interstate commerce when it's legal) get an open wire format instead of bespoke API integrations.
  • Reduced regulator burden: Attribution, tamper-evidence, and timestamping are protocol-level, not regulator-built. The regulator just runs a relay and reads.
Honest caveat: This use case only lands if states accept signed Nostr events as compliance evidence. That's a political and procurement problem, not a technical one. Expect multi-year pilot programs before adoption. But the technical case is overwhelming — and the first state to adopt gets a defensible audit trail their competitors don't have.
09

Cross-jurisdiction & international

Medium · Long-tail

The problem

Legal cannabis markets exist in Canada, Uruguay, Germany, Malta, Thailand, parts of the US, and are expanding. Each has its own banking system, ad policies, and track-and-trace vendor. The CBD/hemp gray area (post-2018 Farm Bill) operates across borders with no coherent identity or provenance layer. There is no vendor-neutral international standard.

How Nostr fills it

Nostr has no borders. An identity + payments + provenance layer that doesn't depend on any one country's banks or platforms is a real asset for cross-jurisdiction operators and the gray-area hemp/CBD trade. One open standard, every jurisdiction.

Concrete primitives

NIP-01 · Borderless identity NIP-05 · Jurisdiction-specific verifiers (Health Canada, BfArM, etc.) NIP-57 · Lightning payments work in every country NIP-73 · External content references to local regulatory URLs NIP-32 · Jurisdiction tags (CA, DE, TH, US-CA, US-NY)

Real-world mechanics

  • Multi-jurisdiction operators: A Canadian LP with US hemp operations uses one identity and provenance stack across both — no reconciling Health Canada's system with a US state's.
  • Hemp/CBD gray area: The 2018 Farm Bill made hemp (<0.3% Δ9-THC) federally legal in the US, but CBD companies still face payment processor chilling effects. Lightning rails sidestep this.
  • Emerging markets: Germany's 2024 legalization, Malta's licenses, Thailand's market — all need identity + provenance + payments. An open standard lets new markets adopt without re-inventing.
  • Standards body play: Nostr NIPs are an open IETF-style process. A cannabis-industry working group proposing domain-specific NIPs (cannabis event kinds, COA schemas) gets a seat at a standards table that METRC never had.
  • International genetics trade: Strain NFTs and signed provenance events enable legal international genetics licensing where jurisdictions permit.
03

What Nostr does not solve

Honest accounting. Overhyping Nostr here helps no one. These six things are real constraints, and pretending otherwise gets operators in trouble.

01

§280E & the tax burden

Rescheduling to Schedule III may relieve medical-lane operators from §280E, but adult-use remains in limbo as of 2026. Nostr has zero bearing on the IRS tax code. A Lightning payment is still taxable revenue; a signed batch record doesn't change what's deductible. This is a legislative problem, full stop.

02

Money-laundering / BSA / SAR

Using Lightning doesn't exempt a cannabis business from FinCEN reporting. A custodial Lightning wallet provider serving cannabis still has BSA/AML exposure and SAR obligations. The 2014 FinCEN guidance persists post-rescheduling. Nostr moves the rail; it doesn't move the compliance perimeter.

03

KYC & age gating

Nostr is pseudonymous by design. Age and ID verification must be layered on — via a NIP-05 verifier run by the state licensing authority, a zero-knowledge age proof, or a vetted custodial wallet that performs KYC. The protocol gives you the identity primitive; it doesn't give you age-gating out of the box.

04

Physical security of cash

Lightning reduces cash on hand — and that helps the armed-robbery problem — but it doesn't eliminate it overnight. Most customers don't have Lightning wallets yet. Vaults, armored transport, and on-site guards remain operational realities for years regardless of payment rail adoption.

05

Volatility & treasury management

Lightning balances are in BTC by default; most operators need fiat treasury. That requires a BTC↔fiat off-ramp — which loops back to the banking problem. Stablecoin channels (Taproot Assets, RGB) mitigate this but are early. Treasury management on Nostr is a 2027+ story, not a 2026 one.

06

Regulator adoption

The supply-chain and compliance-reporting use cases only land if states accept signed Nostr events as evidence. That's a political, procurement, and legal problem — not a technical one. Expect multi-year pilot programs, RFPs, and standards-body work. The technical case is easy; the institutional one is hard.

04

Where to actually start

The glamorous use case (payments) is the one with the most legal landmines. The highest-leverage, lowest-regulatory-risk entry point is the defensive verifiability stack. Build that first; payments follow once the trust layer exists.

Phase 1

Verifiability foundation

0–6 months · Low risk
  • Signed COAs (Gap 4) — labs sign, dispensaries verify, consumers scan. No money transmission, no regulatory lift.
  • Signed batch/manufacturing records (Gap 3) — internal audit trail, 21 CFR Part 11 parallels.
  • Open provenance layer on top of METRC (Gap 2) — complementary, not competitive, with state systems.
Phase 2

Commerce & community

6–18 months · Medium risk
  • B2B wholesale marketplace (Gap 5) — NIP-99 listings, encrypted negotiation, Lightning settlement.
  • Marketing & community (Gap 6) — uncensorable dispensary presence, long-form education, live events.
  • Customer data & loyalty (Gap 7) — NIP-58 badges, customer-owned history, no vendor lock-in.
Phase 3

Payments & compliance rails

12–36 months · Higher risk
  • Lightning payments (Gap 1) — POS integration, B2B settlement, labor micropayments. Requires compliance guardrails.
  • Regulator-facing compliance (Gap 8) — state relay pilots, signed compliance events. Political lift.
  • Cross-jurisdiction (Gap 9) — standards-body play, international operator stack.

The pitch in one sentence

"No single vendor can be deplatformed, acquired, or price-gouged — and every record is independently verifiable." That's the differentiator. That's what maps onto what cannabis operators are actually frustrated by. Everything else is implementation.

05

Current vs. Nostr-based: side by side

Where the open standard actually beats the incumbent, and where the incumbent still wins. No spin.

Capability Current (incumbent) Nostr-based Winner
Card payments at POS Mostly unavailable Lightning zaps, instant Nostr
Seed-to-sale tracking METRC (closed, locked) Open signed events on top Both (complementary)
COA integrity PDFs, easily forged Signed, hash-anchored, verifiable Nostr
Batch record audit ERP database, quiet edits Tamper-evident signed events Nostr
B2B wholesale LeafLink (fees, gating) NIP-99, serverless, no cut Nostr
Marketing reach Meta/Google (banned) Self-hosted, uncensorable Nostr
Customer loyalty data Vendor-locked apps Customer-owned, portable Nostr
Fiat treasury management Credit unions, CBank Immature (stablecoin channels early) Incumbent
KYC / age verification Mature, integrated Layered on, still maturing Incumbent
Regulator compliance submission METRC (state-accepted) Open standard, needs adoption Incumbent (today)
§280E tax relief Rescheduling (legislative) No bearing Incumbent (legislature)
06

NIP reference glossary

Every NIP referenced in this map, with status and the cannabis use case it serves.

NIP Name Status Cannabis use case
NIP-01Protocol basics · events, tags, relaysFinalFoundation for everything
NIP-05Verification (npub → domain)FinalState license / lab accreditation verification
NIP-07Browser extension signerFinalPer-operator keypair signing in web clients
NIP-09Deletion requestsFinalRegulated, auditable record deletion
NIP-11Relay metadataFinalRegulator relay policy description
NIP-15Nostr MarketplaceDeprecated (implemented)B2B wholesale stalls & products
NIP-17Private Direct MessagesActiveEncrypted B2B negotiation, patient comms
NIP-19npub / nprofile encodingFinalLicensee identity encoding
NIP-23Long-form contentFinalStrain education, terpene guides
NIP-32Custom tag namespacesDraftJurisdiction tags, loyalty tiers, batch schemas
NIP-33Parameterized replaceable eventsFinalBatch records, COAs, current-state inventory
NIP-44Encrypted payloads (versioned)ActiveEncrypted SOPs, private purchase history
NIP-46Nostr ConnectDraftHardware signer / NCU for high-value ops
NIP-47Wallet ConnectActiveProgrammatic Lightning wallet control for POS
NIP-53Live eventsDraftHarvest streams, budtender Q&A
NIP-56ReportingActiveBad-actor reputation, fraudulent labs
NIP-57Lightning ZapsFinalPayments — B2C, B2B, micropayments
NIP-58BadgesActiveLoyalty tiers, lab accreditation badges
NIP-59Gift WrapActiveMetadata-hidden DMs (with NIP-17)
NIP-72Moderated communitiesDraftCurated dispensary/patient spaces
NIP-73External content referencesDraftSOP docs, regulatory URL references
NIP-77Negentropy syncingDraftEfficient relay sync for large supply-chain data
NIP-78App-specific dataDraftCustom manufacturing & custody payloads
NIP-89Recommended handlersDraftClient routing for cannabis-specific apps
NIP-96File storageDraftCOA PDF hosting with hash anchoring
NIP-99ClassifiedsDraftWholesale lot listings