Inspiration
Online viewers often cannot tell whether a broadcast is authentic, current, or even authorized by the creator. StreamProof was created to give audiences a simple trust signal while helping creators build a portable relationship with their followers across platforms.
What it does
StreamProof lets creators display a signed QR proof during a live broadcast. Viewers scan it with the Android app to verify that the creator authorized the broadcast and that the proof is still valid. Viewers can verify streams without creating an account. They can optionally sign in to follow creators and support StreamProof through Google Play Billing.
How I built it
- Ruby on Rails 8.1 backend
- Versioned Rails API
- Redis-backed live proof verification
- Cryptographically signed and rotating QR proofs
- React Native / Expo Android app
- Google OAuth
- RevenueCat for optional Supporter purchases
- Google Play Billing
- PostgreSQL, Render, and automated deployments
- Request, integration, and mobile tests
Challenges I ran into
The most difficult part was designing proof rotation and expiration as separate concepts. A QR can refresh frequently while remaining valid long enough to scan reliably. I also had to ensure that invalid signatures, modified payloads, replayed proofs, revoked sessions, and Redis outages always fail closed instead of accidentally displaying a verified state. Finally, configuring Google OAuth, Android builds, Google Play testing, RevenueCat, and production webhooks required coordinating several different platforms.
Accomplishments that I'm proud of
Built an end-to-end verification flow from creator session to viewer scan. Deployed the backend to production with a custom domain. Published the Android application through Google Play. Implemented fail-closed verification behavior. Added replay protection, idempotent webhooks, and entitlement synchronization. Tested the app on a real Android device. Created a foundation that can work across multiple streaming platforms.
What I learned
I learned that trust features must be designed around failure states first. “Verified” should only appear when every required condition is confirmed. I also learned how much complexity appears when connecting mobile authentication, Google Play, RevenueCat, backend webhooks, Redis, and cryptographic verification into one consistent product experience.
What's next for StreamProof
The next step is a dedicated creator experience inside the Android app, including registration, channel onboarding, QR generation, and live-session management. We also plan to add creator-focused paid plans, supporter benefits, creator analytics, more streaming platforms, richer verification history, and tools that help creators build portable audiences independent of any single platform.
Built With
- docker
- expo.io
- github
- google-oauth
- google-play
- postgresql
- qr-code
- react
- react-native
- redis
- render
- revenue-cat
- ruby-on-rails


Log in or sign up for Devpost to join the conversation.