Blueballs gives away the hardest part of starting a bank. What it gets back is the one thing every provider in this market is starving for and cannot buy: a founder at the exact moment they choose their sponsor bank, their card issuer, their KYC vendor and their liquidity. Six ways to charge for that, ranked, priced, and with the cold outreach written.
Everything after this is priced off distribution. So here is the distribution, measured today, not assumed. Two of these numbers are embarrassing and they are the most useful ones on the page — they decide the order you do things in.
You have a finished product and no audience. That rules out three of the six revenue lines for now — you cannot sell ad placement, directory position or managed hosting to an audience of one. But it makes two lines urgent rather than premature: the lifetime revenue share and the origination fee both cost a provider nothing until they work, so the price of that paper is the lowest it will ever be, today, while you have one star. Sign the contracts before the traffic arrives. That is the whole strategy in a sentence.
It is not a SaaS and it should never be priced like one. Read your own SANDBOX.md again — the Builder journey ends at a step you deliberately left un-automated: "Launch — connect deployment-owned identity, sponsor-bank, card, wallet, payment and compliance providers." That gap is not a missing feature. It is the cash register.
A team that has run the Builder has already declared its markets, currencies, capabilities, rails and audience in a structured form. That is a qualified brief, not a lead.
Fintech SaaS acquisition cost runs $1,461 SMB, $4,903 mid-market, $14,772 enterprise — the priciest vertical there is, because of compliance diligence.
You are undercutting their own funnel. That is the only posture in which a cold email from a 1-star repo gets answered.
Verified from vendor pricing pages, not blog posts. Two patterns dominate, and neither of them is what Blueballs should copy wholesale — the reason is in the last column.
| Who | What is free | What they charge, exactly | Model | Read-across for Blueballs |
|---|---|---|---|---|
| thirdweb | SDKs, contracts, docs | $99 Growth / $499 Scale / $1,499+ Pro per month, then $0.015 per wallet MAU, $1 /1k sponsored txns, $8 /M RPC — plus a 2.5% mainnet gas markup | Metered infra + a take rate on money moved | Closest to the model Josh named. The 2.5% is the important part — the subscription is the floor, the percentage is the business. Note the infra is not self-hostable; the take rate depends on that. |
| Hyperswitch (Juspay) | Whole orchestrator, Apache-2.0, self-host | Community free. Enterprise and Cloud both "Contact Us". Recovery, cost observability and reconciliation are paid add-ons | Open core + managed cloud | The direct structural twin — open source sitting above closed processors. And they publish no price. Nobody in this market has a rate card. |
| Formance | Core ledger, MIT | Enterprise annual subscription, price not published: connectors, wallets, reconciliation, console, designated engineer, 24/7 | Open core + support | Confirms the ceiling of the pure open-core play: you sell a person and an SLA, not a percentage. |
| Lerian / Midaz | Source-available ledger | Premium plugins and ancillary services; raised a $5.6M seed on it | Free core, paid modules | Same conclusion, with a funding round attached. Investors buy this story in this category right now. |
| Supabase | Full stack, Apache-2.0 / MIT, Docker self-host | $25 Pro, $599 Team → $170M ARR by May 2026, up from ~$101M | Self-host → cloud conversion | Proof the conversion model works at scale — and proof of what it takes: years and enormous adoption first. |
| n8n | Self-host, fair-code | $24 / $60 / $800 per month by executions | Usage-metered cloud | Shows the pricing metric matters more than the number. Theirs is executions. Yours would have to be settled volume. |
This is the shelf Blueballs is really on, and none of these companies sell software to the people using them.
| Who | What they charge the provider | What Blueballs takes from it |
|---|---|---|
| Shopify App Store | Developers keep 100% of the first $1M lifetime app revenue, 15% above it. Merchant-referral partners earn up to 20% recurring | The threshold structure. Nobody pays until they are winning — which is exactly the shape that makes L2 signable at one star. |
| G2 | Vendors pay a subscription for lead generation and buyer-intent data. Cost per lead, no cut of the transaction | The closest analogue to L4, and the reason the first registry deal should be priced per qualified builder reached rather than as a revenue share. |
| Airbyte connector marketplace | Third-party connector maintainers get a share when their connector runs in paid cloud, and take on SLA duty for it. Percentage undisclosed | The structural twin of L3 and L6: maintenance obligation traded for a commercial position. It is also proof that "who maintains the adapter" is the negotiable asset. |
| Terraform Registry | Nothing. A Partner Premier badge buys distribution and legitimacy; HashiCorp monetises its own cloud instead | The cautionary one. A badge with no price attached is a giveaway — if L3 does not carry a fee and an expiry, it is Terraform's model by accident. |
| Lithic | Runs a named Integration Partner Program — co-built certified integrations, shared Slack channels, mutual referral terms. Commercial terms undisclosed | The best single first target in this whole document. A named programme and a named Head of Partnerships means the door already exists; you are not inventing the category for them. |
| Developer advertising | Carbon / EthicalAds $2–10 CPM, developer newsletters $60–150 CPM, conference sponsorship $5k–50k+ | The floor on what these providers already spend to reach developers — and they are spending it on impressions, not on someone standing at the selection moment. |
Every company above monetises the person running the software. That works when your users are venture-funded and numerous. Blueballs' users are pre-launch fintech founders — the least able to pay of any developer segment, and there are not many of them. Charging them is a small, slow, hard business.
The people with money in this picture are standing on the other side of the Launch step, and they spend $1,461–$14,772 to meet exactly the person you already have. Charge them instead.
A percentage of money moved beats a subscription, and it is collectable even from users who would never pay a monthly fee. thirdweb's 2.5% gas markup rides on infrastructure they host, which is why their SDK is open and their infra is not.
Blueballs cannot copy that directly — MIT means anyone can fork, self-host and never pay. So the take rate has to be collected from the provider, not the deployer. Same percentage logic, opposite counterparty. That inversion is the whole business case.
Ordered by how fast they produce a first invoice, not by size. L1 and L6 pay the rent. L2 is the actual business and it is the one that costs a counterparty nothing to sign today. L5 is last on purpose.
One-time cash when a deployment picks a provider adapter and goes live on real credentials. No volume required, no traffic required, no product change beyond attribution.
Not per signup. A slice of what the provider earns from every programme you originated, for as long as that programme runs. This is the compounding line and the one that makes the company worth something.
Your adapter standard already defines four maturity levels and an evidence bar: conformance suite, failure mapping, reconciliation, observability, runbook. That bar is a product. You are selling verification, not position.
A provider with no open-source footprint pays Blueballs to build and maintain the reference adapter against their API. Engineering-as-marketing for them, funded R&D for the repo, and it feeds straight into L3.
You already write these and you already write them honestly: docs/partners/BRIDGE.md records that Bridge's sandbox fires no payment webhooks and can return dummy data. Nobody else audits provider sandboxes from inside a running stack. That honesty is the asset.
Do not sell "hosted Blueballs". Sell precisely the two limitations your own README already admits: single-writer SQLite persistence, and a Builder Agent with no cost ceiling. Those are the only two things a serious team genuinely cannot run themselves.
The card case, drawn to scale. You are not taking a bite out of the founder's margin — you are taking a slice of the BaaS's slice, which is why the founder never feels it and never objects.
I read the tree. Nothing in the adapter descriptor, the Builder blueprint or the outbound provider links carries an origination token. Which means L1, L2 and L4 are unenforceable today — you would be asking a provider to self-report revenue owed to you, which no provider has ever done.
The fix is small and it is a product decision, not mine to make: a referral identifier in the capability descriptor, a Referred-By header on adapter calls, and tracked outbound links from the registry. Do not sign a revenue-share contract before this exists — you would be locking in a number you cannot invoice.
Owner: Josh + whoever holds the code lane. Not me — I have not touched code and will not.
Anyone can fork Blueballs, strip every reference to you and ship. So the revenue lines cannot depend on the repository — the repository is the free part and always will be.
What they depend on is the registry and the conformance gate, both of which are services you host and control. A fork gets the code. It does not get the certification, the badge, the directory listing or the conformance suite running green against a live provider API.
That is the moat. Build it deliberately. Every hour spent making the certification more rigorous is an hour spent on the only defensible asset in the plan — and it happens to be the thing the repo is already best at.
Ranked by three tests, each of which you can check in five minutes without talking to anyone: does it have a self-serve sandbox (proves developer-first), does it have a public partner or affiliate page (proves it already pays for distribution), and is it already named in your repo (proves you have a reason to write). Highlighted names score on all three.
Fastest movers, developer-first, self-serve sandboxes, and structurally hungry for exactly the distribution you have. Two of them are already sitting in docs/partners/. Start here.
Where Blueballs is genuinely unique — nobody else ships an open, policy-gated, reserve-before-firm FX runtime with a Solidity kernel. Highest differentiation, so the highest-quality first conversation.
Easiest to sign and lowest per-deal value — which makes them the right place to prove the mechanism works before you spend a swing on a big card deal. Sumsub already runs a public three-track partner programme with referral and reseller margins.
The biggest lifetime value by far — interchange compounds — and the slowest, most compliance-gated door, with one exception. Lithic runs a named Integration Partner Program with a named Head of Partnerships — certified integrations, shared channels, mutual referral terms. That door already exists, so it belongs in your first batch even though the segment as a whole comes third.
Leverage worth knowing before any of these calls: roughly 45% of BaaS programmes sit with banks under formal enforcement action. These providers do not need more leads — they need cleaner, better-qualified ones. A platform that pre-qualifies a builder before they arrive is selling the thing they are actually short of.
Not a revenue line — a distribution line, and the cheapest fix available for the 1-star problem. Blueballs runs on Cloudflare Workers with Durable Object SQLite; that is a case study Cloudflare's developer marketing wants and pays for in reach rather than cash. TigerBeetle and Formance are category-adjacent rather than competitive: co-marketing, not conflict.
This is the part that is genuinely new, and the standard playbook fails here — a partnership email from an unknown 1-star repo goes in the bin, correctly. So do not send a partnership email.
For every target, publish the honest capability descriptor first — exactly like docs/partners/DAKOTA.md already does. Then you are not asking for anything. You are a fact in their world that arrived without permission, and you did unpaid work about their product.
Order: Developer Relations / Developer Experience → Partnerships / Ecosystem → Growth. DevRel replies because you shipped something about their API. Sales does not reply to unknown open-source projects, and partnerships will not move without an internal advocate. Title patterns to search: Head of Developer Relations, Ecosystem Partnerships, Partner Engineering.
Not "Partnership opportunity with Blueballs". Something more like "We mapped Bridge into an open-source neobank stack — 4 things your sandbox doesn't do". One is a request. The other is information they cannot get anywhere else, about themselves.
Hi {name} — we maintain Blueballs, an MIT open-source neobank stack
(181 banking operations, double-entry ledger, FX engine, self-hostable).
We mapped {provider} into it and published what we found, including
that {specific honest finding — e.g. "your sandbox doesn't fire
payments webhooks"}.
{link to the descriptor}
Nothing to sell. Just tell me if we got anything wrong.
Subject: we mapped {provider} into an open-source bank stack —
{n} gaps in your sandbox
{Name},
Blueballs is MIT-licensed open source for building a neobank: 181
banking operations, a double-entry ledger, a stablecoin FX engine,
running at blueballs.tech. Founders clone it, describe the product
they want, and get a working environment in minutes.
At the end of that flow they choose a sponsor bank, a card issuer,
a KYC vendor and a liquidity provider. Right now that screen is
blank.
We already publish a capability map for {provider}: {link}
Two questions. Do you want the reference adapter built and
maintained, and do you want to be the default in that screen?
Happy to do the first one before we talk about the second.
{Josh} — {role}, Blueballs
Short version of the commercial shape, so you can route it
internally.
Now, no money: we build and maintain the {provider} adapter
against your public sandbox. You review the PR. It ships in the
repo either way — we would rather it were correct.
If you want it certified: we run a conformance suite against your
live API and keep it green. That carries a dated production badge
that expires if the suite goes red. {$X}/year per capability.
The part worth your attention: when a deployment picks you at the
launch step, that programme was originated here. We would like
{10–20}% of your revenue on those programmes, for the life of
the programme.
Two things about that number. It costs you nothing until it
works — there is no floor, no minimum, no fee. And your own
acquisition cost in this segment is four figures at the low end,
which is the arithmetic this is priced against.
We are early and we are asking early. Terms will not be this
cheap once the funnel is running.
| "You have one star." | Correct, and that is why the revenue share is free to you and why you should sign it now. You are not buying traffic. You are buying an option on traffic, at the only price it will ever be. |
| "We don't do open source." | You do not have to. We maintain the adapter, you review it. Your name appears on a capability map, not in your repo. |
| "What's the catch — do we have to pay for ranking?" | No, and it is written down publicly with a date on it. The inclusion policy separates whether we claim a relationship from whether the integration is technically mature. We sell the click. We have never sold the order. |
| "Legal will take six months." | Then start with the descriptor, which needs no paper at all, and the adapter, which is an ordinary vendor SOW. The revenue share can follow. |
| "How do we verify what you originated?" | Fair, and today the honest answer is that you cannot — which is why this is the one thing being built before any contract is signed. Do not bluff this one. |
Sequence, not a schedule. Each step unblocks the next one; nothing here waits on a date.
Referral identifier in the capability descriptor, a Referred-By header on adapter calls, tracked outbound links from the registry. Small, and it gates three of the six lines. Code lane, not mine.
What is for sale (adapters, certification, clicks) and what is not (position, ranking, the word "production"). This is the document you link in every cold email, and it is the reason the answer to "what's the catch" is a URL rather than a promise.
Rain, Zero Hash, BVNK, Sumsub, Lithic, Modern Treasury. Same shape as DAKOTA.md and BRIDGE.md, same honesty about what their sandbox does and does not do. Each one is a reason to write to that company that is not a pitch.
Descriptor → Discord question → DevRel DM → partnerships email. Nothing about money in any of them. Measure replies, not sends.
One paid, named integration does more for lines 1–5 than any amount of further outreach, because it turns "we mapped your API" into "we maintain their integration".
Including — especially — the ones who are not paying you anything else. It costs them nothing, which is exactly why you can get it now and not later.
L4 and L5 become real at roughly 2,000 monthly developer sessions and a few dozen live deployments. Pitching them earlier teaches providers that your numbers are aspirational, which is expensive to undo.
Repository facts read at origin/main 8bd5747, 25 Aug 2026: README.md, VISION.md, ROADMAP.md, SANDBOX.md, docs/ADAPTER-STANDARD.md, docs/partners/{README,DAKOTA,BRIDGE}.md. Live facts from blueballs.tech — /v2/site/stats returned 181/181 operations, 33 accounts, 15 customers, 0 transfers, source commit 5739476 (the live deploy is three commits behind main). GitHub: 1 star, 0 forks, 0 watchers, created 2026-08-06. No code was modified.
External sources, primary where a primary source exists:
Second research pass, folded in after first publication. The Kast milestone ladder and its $250 ceiling, Synctera's published 70/15/15 split, the $500k-TPV payback arithmetic, the ~45% enforcement-action figure, the Shopify / G2 / Airbyte / Terraform / Lithic precedents and the developer-advertising CPMs come from Fizz-Claude-5's three research sweeps posted in the same thread (full versions in .scratch/biz-case/sweep-{1,2,3}-*-FULL.md). The src/ecosystem/providers.ts inventory was flagged by the same agent and reproduced here against origin/main 8bd5747: 56 entries, counted. Also confirmed there: daxota.xyz does not resolve — the company is Dakota, dakota.xyz, already mapped in docs/partners/DAKOTA.md.
One honest note on the sources. Not one provider in this market publishes its referral or revenue-share terms — not Stripe, not Sumsub, not Lithic, not Vercel for its own marketplace. I checked. That is not a gap in the research; it is the finding. Every number in section 04 is a number you propose, not a number you accept, and the first side to name one usually sets the range.
Bumble · 25 August 2026 · research and commercial assessment only · no code touched · attribution dependency in section 05 is unresolved and owned by the code lane