The Joule Standard

Money you can redeem for a kilowatt-hour

An open protocol for currencies backed by delivered energy — designed to resist inflation, speculation, and capture. Reference currency: the joulemark.

Spec v0.3.1 — draft for public comment · Status: open source · Licence: CC BY-SA 4.0 · Home: joulestandard.org

Abstract

What this document proposes

The Joule Standard is a protocol for currencies in which every unit is a burnable, rate-limited claim that settles one kilowatt-hour of billed energy at par. There is one monetary unit only; firm-delivery instruments exist as dated contracts, cover-accounted separately, and are never money (§2.1, §3.1). Coins are created only when energy is verifiably injected into a grid — net of energy the same connection point imported — and destroyed on redemption, so outstanding supply always equals the outstanding stock of audited, covered settlement claims.

The protocol’s reference currency is here called the joulemark; communities deploying the standard are expected — encouraged — to fork it and name their own (Part V). On top of the monetary core sit five subsystems: a financing layer that replaces most debt with risk-shared energy forwards and mutual credit; a stability layer in which a small holding fee (demurrage) — set by the measured physical cost of keeping energy ready — funds a strategic energy reserve governed by code rather than committees; an anti-capture constitution built on transparency-by-physics, separation of powers, and the right to fork; and a values layer that lets communities reward the energy they believe in through markets rather than ministries; and a deployment playbook for bootstrapping the first closed loops around the one bill every household and business already pays.

Nothing in this specification requires new physics or unproven technology. Every component — revenue-grade smart meters, nodal electricity pricing, power purchase agreements, mutual-credit clearing, proof-of-stake ledgers — already operates at scale somewhere in the world. What is new is the assembly.

In plain terms

Imagine prepaid power credits that anyone can earn by putting power into the grid and can always use to pay the power bill, one credit per kilowatt-hour — and which, as the system matures and the right licences arrive, can be spent at local shops too. Because everyone needs power every month, the credits never become worthless. And because no committee can create more of them without real energy entering the grid first, nobody can water down your savings by decision — though if energy itself becomes cheap and abundant, prices fall with it, which is the point.

The eight invariants

Everything in this document unfolds from eight rules. An implementation that violates any one of them is not the Joule Standard, whatever it calls itself. They are the conformance spine referenced throughout.

  1. No mint without proof. Coins are created only against certified proof-of-generation, reconciled against an independent grid balance.
  2. Cover invariant. Outstanding coins never exceed audited energy-settlement cover — the hedged procurement position plus reserve liquidity sufficient to honour par settlement, measured per delivery period against the coin stock’s modelled presentation profile, in both stock and flow terms (§4.5) — continuously, publicly, externally audited.
  3. Redemption burns. Delivery extinguishes the claim; redeemed coins are destroyed, never recirculated.
  4. Honest carry. Demurrage equals the audited physical cost of standing ready to deliver against held coins, and funds the reserve that provides that readiness — set by measurement, adjustable under stress only by pre-published formula (§4.3), never by discretion.
  5. No ethics in the mint. The mint formula prices firmness from observable markets only; values act through certificates, charters, and procurement — never through mint multipliers.
  6. No issuance interest. Authors and maintainers hold no founder allocation, pre-mine, or percentage of minting, ever.
  7. Exit before effect. Rule changes take effect only after a published delay sized to the system’s published redemption throughput, so holders can exit — by rate-limited redemption or by market conversion — before a change binds. No rule change may take effect during, or within a published cooling period after, any non-fully-backed state (§4.5).
  8. Forkability preserved. The ledger is exportable; any community can take its history and continue under new governance.
Part I — Why

The two failures this design answers

1.1  Fiat money fails by dilution

Modern fiat currency has no anchor. Its supply is set by committees, and its expansion functions as a hidden transfer: newly created money reaches asset owners, banks, and governments first, and wage-earners and savers last — by the time it reaches them, prices have already risen. This first-spender advantage has a name three centuries old: the Cantillon effect, after the Irish-French banker Richard Cantillon, who described in the 1730s how money creation enriches those closest to the spigot at the expense of those furthest from it. Inflation is not weather. It is a transfer mechanism, and its direction is not random.

In plain terms

When new money is printed, the people who get it first buy things at old prices. By the time it trickles down to your pay packet, everything costs more. You were taxed, but no law was passed and no vote was held.

1.2  Bitcoin fails by scarcity theatre

Bitcoin correctly diagnosed the dilution problem and then over-corrected. Its fixed cap of 21 million coins makes it a speculative vault rather than a working currency: a money whose supply cannot grow with the real economy rewards hoarding, starves circulation, and turns every price into a bet. Its proof-of-work consensus, meanwhile, burns nation-scale quantities of electricity to solve a problem — establishing trust among anonymous strangers — that an energy currency does not have, because every unit of energy already enters the world through a physical, certified, identifiable meter.

There is a symmetry worth stating once and remembering: Bitcoin destroys energy to create tokens. The joulemark creates tokens only when energy is delivered. The proof is the physics.

1.3  The design goal

A fair currency, then, must satisfy three constraints simultaneously: its supply must be impossible to expand by decree (unlike fiat); its supply must expand with real productive capacity (unlike Bitcoin); and its unit must be anchored to something universal, measurable, and impossible to counterfeit. There is exactly one candidate that sits beneath every other input to civilisation — beneath steel, food, computation, and transport — and that candidate is energy.

Lineage

Energy-backed money is not a new idea. Henry Ford proposed an “energy dollar” backed by kilowatt-hours in 1921, arguing it would end wars fought over gold. The Technocracy movement of the 1930s — including the geoscientist M. King Hubbert — designed “energy certificates” as a complete accounting system for an industrial continent. Buckminster Fuller reprised the argument in the 1960s–80s: since all wealth is ultimately organised energy, account for it directly. Each attempt failed on the same two rocks: energy could not then be measured cheaply at the edge of the network, and no mechanism existed to prevent the accounting authority from becoming a new central bank. Smart meters solved the first problem. This specification is an attempt at the second.

1.4  Three regimes of success — and which one this document claims

“Energy-backed currency” can mean three different ambitions, and conflating them invites both overclaim and misdirected criticism. This specification is explicit about which regime each design element serves:

RegimeGoalDesign emphasis
R1 — Complementary loopLocal earn / spend / redeem; the national currency remains the unit of accountSink-before-faucet ordering, tax-drain plumbing, stored-value regulation
R2 — Parallel mediumA material share of local trade settles in joulemarksBridge liquidity, multi-redeemer consortium, stronger AML at the edges
R3 — Unit of accountPrices quoted natively in energy claimsWage and contract conventions, indexation norms — largely social-layer, outside the protocol

This version optimises for R1 graduating into R2, and claims no R3 readiness. Two consequences follow honestly. The permanent fiat interface — taxes payable in national currency, at-par conversion for the tax portion — is a designed interface, not an embarrassment: Switzerland’s WIR has operated for ninety years precisely as a complement inside a strong national currency, and that is a success regime, not a consolation prize. And R3, if it ever arrives, arrives by adoption, not by declaration in a specification.

One base rate, stated so nobody discovers it later: no complementary currency inside a stable-fiat economy has yet reached a material share of local trade — WIR peaked well under one percent of Swiss SME turnover; the strongest modern performers clear tens of millions of euros in multi-billion-euro regional economies. Parallel media historically emerge under fiat distress. This design’s differentiating bet against that base rate is the universal sink (every prior failure lacked one), and R2 is therefore defined measurably so the bet is falsifiable: R2 is reached when conformant currencies settle at least five percent of business turnover within the federation’s declared geographic or membership boundary — a denominator fixed at declaration, so the metric cannot be reached by curating the participant set — sustained across a full seasonal cycle, with a published absolute floor.

Part II — The coin

A burnable claim on delivered energy

2.1  Definition: one coin, and what it promises

One joulemark is a transferable registered claim that settles one kilowatt-hour of the energy component of a bill at par, within published rate limits. There is exactly one joulemark — one monetary unit, fully fungible, no grades. Its performance obligation fits in three lines, and every other sentence in this document is subordinate to them:

  • The holder gets: par settlement of energy charges, one coin per kilowatt-hour, within the published rate limits (§4.4).
  • The holder does not get: dispatch priority, outage immunity, or unlimited on-demand physical delivery. Electrons reach a household through the same dispatch, network, and outage risk as everyone else’s; no payment instrument changes that physics. What the holder owns is immunity from the price of energy — the thing a currency can honestly deliver.
  • The obligor must: maintain audited energy-settlement cover such that par settlement remains solvent under the presentation profile and adequacy standard of §4.5, continuously and publicly.

Two further properties complete the unit. Rate-limited: redemption throughput is published protocol data (§4.4) — maximum latency, size bands, daily limits per holder class. A claim on the scarce thing cannot honestly be unlimited-on-demand; a stock of cover is not a flow of delivery, and every banking crisis in history lives in that gap (§4.5). Burnable: redemption extinguishes the claim; redeemed coins are destroyed, never recirculated.

Firm delivery is a contract, never a coin. Dated firm-delivery instruments — for counterparties with controllable physical delivery — exist in this design as the physical-settlement subtype of the Part III forwards family: named, dated, project- or tenor-specific contracts that may settle in joulemarks but are never themselves the monetary unit. There is no wholesale coin grade, and conformant implementations may not create one; a standardised, fully fungible “firm future” that trades as a unit of account is grade two rebuilt under an alias, and is non-conformant by that fact (§3.1). The full instrument taxonomy:

InstrumentFungible money?TransferableCover bookSettles how
JoulemarkYes — the only oneYes, by stage (§7.3)Coin book (§4.5)Burn against bill energy component; rate-limited redemption
Non-transferable prepaymentNoNoIssuing project’s bookOwn consumption
Dated firm / forward contractNoEligible counterparties only until S3Contract book, exclusive pledge (§3.1)Physical delivery, or JM from escrow/market purchase — never minted at settlement (§3.1)

Where firmness lives. Firmness — the scarce, expensive property — is priced at the mint by the firmness discount oracle (§2.8) and at redemption by nodal basis (§2.3). It lives in the prices, never silently inside the retail coin: a coin that embedded free winter-evening delivery would be a seasonal call option on scarce energy, and the resulting spring-buy/winter-redeem carry trade is speculation delivered by physics — the exact payoff structure this design exists to exclude.

In plain terms

A joulemark is prepaid electricity that actually works: it always pays the energy portion of your power bill at full value, one coin per kilowatt-hour, and once used it’s gone — like a stamp after posting. It doesn’t jump the queue during a blackout (no money can), and if everyone tries to cash out at once there’s a fair, published speed limit — like an ATM’s daily limit — instead of a stampede. Used coins vanish, and new ones only appear when real power enters the grid, so the coins in the world always match the power that can actually be claimed.

2.2  The conservation loop

The monetary core is a closed loop with a conservation law. Coins are minted only against cryptographically signed readings from certified revenue-grade meters, cross-checked against grid settlement data — energy entering the grid must equal energy leaving it plus losses, so phantom injection is detectable in reconciliation wherever independent settlement access exists (§5.1’s full-conformance tier) and above the market’s unaccounted-for-energy noise floor — a real constraint, stated precisely: system-level balancing detects aggregate imbalance; attribution to a connection point requires the settlement access §5.1 makes a conformance prerequisite. Coins circulate as ordinary money. Coins die at redemption. At every instant, outstanding supply = outstanding covered claims.

Settlement data is provisional, and the mint must respect that. Every real reconciliation regime publishes provisional volumes that are revised for months afterward (New Zealand’s wash-up cycle extends past a year). Minting against provisional highs and never truing up is unbacked issuance by accounting artefact — no fraud required. Conformant minting therefore requires: half-hourly (interval) metering as a prerequisite for any minting connection point — profile-reconciled estimates may not mint; minting against provisional data less a published haircut, released at final wash-up through a per-minter true-up account; and a declared reconciliation run that constitutes “settlement data” for C-2 purposes. Revision-driven over-issuance is drawn back from the minter’s true-up account before it is anyone else’s problem. And the edge case, closed: a minter that becomes insolvent or is decertified while carrying a negative true-up balance leaves a deficit that is a first claim on that minter’s bond, logged as a §4.5 failure event — never socialised into silent supply inflation.

Figure 1 — The conservation loop. Money is created by verified energy injection and destroyed by delivery. No committee sits anywhere on this diagram.

2.3  Solving fungibility: standardise the claim, not the energy

Energy is famously non-fungible — a kilowatt-hour at 6 p.m. on a winter weekday is worth many times a kilowatt-hour at a remote solar farm at noon, and electricity is costly to store and to move. Earlier energy-money proposals foundered here. The resolution is borrowed from commodity markets, which solved the identical problem a century ago: crude oil is not fungible either, yet “West Texas Intermediate at Cushing, Oklahoma” trades as a single instrument, with every other grade and location priced as a basis differential against it.

The Joule Standard does the same. The coin is a standardised claim at a defined reference node; redemption elsewhere or at other times carries an algorithmic premium or discount derived from the grid’s own locational marginal prices — the nodal price surfaces that modern wholesale electricity markets (New Zealand, PJM, ERCOT, and others) already compute every few minutes at hundreds of points. Fungibility comes from standardising the claim; the map of energy’s true value across space and time already exists, published by the grid itself.

In plain terms

Not all electricity is equally useful — power on a freezing evening is worth more than power at sunny midday. The coin handles this the way airlines handle seats: one standard ticket, with surcharges or discounts if you fly at peak times or from smaller airports. The surcharge table isn’t set by anyone — it’s read straight off prices the power grid already publishes.

Where nodal prices don’t exist. Much of the world — Germany, France, and every single-zone market — publishes one price per zone, with congestion handled by operator redispatch that appears in no price a protocol can read. In zonal markets the basis mechanism degrades, and the degradation mode must be declared, not discovered: a conformant zonal federation publishes its substitute basis source (zonal price plus the operator’s published redispatch or imbalance cost allocation, or a declared intra-zonal flat basis) and names the party that bears the residual locational risk. And in every market, nodal prices stop at the transmission node: the constraint that binds a suburban prosumer is the local transformer and feeder, which no published price covers. The basis surface is honest about transmission and silent about distribution; the federation’s redemption terms must assign that residual too.

2.4  Minting without waste: proof of generation

Proof-of-work exists to manufacture trust among anonymous strangers; the burnt electricity is a substitute for identity. An energy currency has no anonymous strangers at the mint: every coin enters the world through a physical, certified, revenue-grade meter with a known owner at a known grid connection point. Identity is baked into the physics, so the burn is unnecessary.

Minting therefore requires two independent proofs: a cryptographically signed meter reading from a certified device, and consistency with grid settlement data — the system operator’s own energy balance, in which phantom injection is arithmetically visible. Transaction ordering runs on a low-energy mechanism — proof-of-stake or, more simply, a federated ledger validated by metering authorities, network companies, and system operators (parties that already exist, are already regulated, and already distrust one another professionally). Ethereum’s 2022 migration from proof-of-work to proof-of-stake cut its energy consumption by roughly 99.95%; consensus is no longer an excuse to burn anything.

2.5  Elastic supply, and what backs the “lifecycle cost”

Unlike Bitcoin, a Joule Standard currency has no artificial supply cap. As civilisation builds more firm, deliverable energy capacity, the money supply grows with it — monetary expansion literally requires building generation, storage, and transmission. Note the precise anchor: not raw generation (which balloons every time the sun shines on new panels) but firm delivered capacity, which is constrained by the genuinely scarce things — storage, transmission, and firming. The currency is pegged to the bottleneck, not the flood.

Costs of availability, firming, and cleanup are not encoded by a committee formula — a formula’s author would control the money supply. They are priced at the mint as an exchange rate: a kilowatt-hour of intermittent midday solar mints fewer coins than a kilowatt-hour of firm capacity, with the discount discovered from the market cost of firming that energy. The original design intuition — that a coin should embody energy’s full lifecycle cost — survives, but as a market price rather than a decree.

2.6  Which energy counts

Version one is electricity-only, because electricity has the strongest verification physics: delivery and consumption are simultaneous, the grid must balance, and revenue-grade meters are ubiquitous. Storable carriers — gas (already billed in energy units in much of the world), liquid fuels, heat — can be annexed later, but each requires mint-once-at-custody-transfer rules and chain-of-custody tracking to prevent the same joule being minted twice, refinery and pump. A practical hierarchy: electricity first, metered gas second, certified liquid fuels third.

Storage is the exception inside electricity, and it arrives in v1, not with the fuel annexes. A grid battery imports energy that already minted once at its original generator’s meter, and re-injects it later through its own certified meter. Every reading is genuine, the grid balances perfectly — and the same joules would mint twice, breaking the conservation identity without a single dishonest act. Minting is therefore defined net of metered import at each connection point: a storage facility’s mintable quantity is its discharge minus its charge, and its FDO class (§2.8) prices the firming-service delta it adds — the value of moving energy to when it is scarce — never the energy itself, which was already money. Without this rule, the most profitable use of a battery is buying low-factor coins and minting high-factor ones; with it, storage earns exactly its honest firming premium.

Figure 2 — The stack. Each layer depends only on the ones beneath it. The base layer is physics; the top layer is politics, deliberately caged.

2.7  The ledger requirement — what the blockchain is for, and what it isn’t

Bitcoin’s genuine invention was consensus among anonymous strangers: the mining and the tokens exist to manufacture truth where no institution can be trusted to hold it. The Joule Standard deliberately does not have that problem. Truth enters this system through certified meters with legally identified owners, reconciled against grid settlement data that must physically balance. The grid is the trust machine; the ledger’s job is not to create truth but to remember it, tamper-evidently. In Bitcoin, consensus creates the truth. Here, physics creates the truth, and the ledger is the memory.

Stated as requirements rather than technology, the ledger must be five things: append-only, so no party — including an anchor retailer — can rewrite history; validated by mutually adversarial parties (metering authorities, network companies, co-op representatives — the C-3 rivals); publicly verifiable, so anyone can run the C-2 reconciliation; exportable, because forkability (C-5) is constitutional and a departing community takes the ledger with it; and rule-enforcing in auditable code (C-4). A permissioned Byzantine-fault-tolerant ledger meets all five. So does something lighter still: signed transparency logs of the kind that already guard the web’s certificate system, with no blockchain and no token anywhere in sight. This specification therefore states the requirements and remains implementation-agnostic; any technology that satisfies them conforms.

Honesty also requires stating what a public blockchain’s headline property — censorship resistance — cannot buy here: this system can never outrun the state the way Bitcoin can, because its backing is a dam, a battery, and a retailer with a street address. The choke points are physical and jurisdictional regardless of the ledger. Public chains instead earn three narrow, genuine roles: checkpointing — each federation periodically publishes a hash of its ledger state to a durable public chain, so that even full collusion of a federation’s validators cannot quietly rewrite history without the discrepancy being provable by anyone, forever, for a negligible cost; the bridge layer — inter-federation exchange needs neutral ground that neither party controls, and a post-Merge public chain is a natural Switzerland for that settlement; and the certificate registries of Part VI, where public tradability is the point. Local sovereignty, global tamper-evidence.

In plain terms

Bitcoin needs thousands of strangers around the world to vote on what happened, because there’s no other way to know. This system doesn’t need the vote — the power meter on your wall already knows exactly what happened, and the grid’s own bookkeeping double-checks it. So all we need is a good notebook: one where pages can be added but never torn out or rewritten, kept by several people who don’t trust each other, that anyone is allowed to photocopy — so if the people keeping it ever go bad, everyone can walk out with a copy and carry on without them. And once in a while, we glue a snapshot of the latest page into a public newspaper that can never be un-printed. That way, if anyone ever claims the notebook used to say something different — anyone in the world can prove they’re lying.

2.8  The firmness discount oracle

Section 2.5 states that intermittent injection mints fewer coins than firm capacity, “with the discount discovered from the market cost of firming.” That sentence, left as prose, is a governance surface dressed as a market fact: someone computes the discount, and the moment real money rides on it, that someone will be lobbied. The discount therefore gets the same formal treatment as demurrage measurement — it becomes a specified instrument, the firmness discount oracle (FDO), with these normative properties:

  • Inputs: observable market instruments only. Firming PPA prices, cap and swap products, storage capacity prices, locational marginal price spreads, and loss factors. Nothing that requires a committee’s judgment about what energy should cost.
  • Output: a mint factor between zero and one per injection class — defined by location, time band, and intermittency class — applied identically to every conforming minter in that class.
  • Publication: signed, versioned, delayed-effective. New factors take effect only after a published notice period, in the same spirit as the constitution’s exit windows (C-4): nobody is mid-air when the rules change.
  • Adversarial audit: rotating auditors, an open challenge window on every published factor, and automatic freeze to the last audited-good factor if an audit fails or a challenge is upheld.
  • The anti-lobby rule: the FDO may never encode charter values, emissions preferences, or any ethical weighting. Values act through certificates, charters, and procurement (Part VI) — never through the mint factor. This is the fifth invariant, applied at the one place it will be tested hardest.

Any specific factor quoted in this document (the “0.6” of the deployment playbook) is illustrative only; the live factor is always the FDO output for the relevant injection class. The FDO’s measurement governance is demurrage measurement’s twin, and both are listed together in Part VIII as a single open problem: the design of gaming-resistant measurement is specified here as an interface, not yet proven as an institution.

Three hardening rules, added after adversarial review. Class boundaries are governed like factors: whoever draws the injection-class boundaries — time-band edges, location bins, intermittency definitions — holds a lever as lobbied as the factor itself, so boundary definitions are published, versioned, delayed-effective, and subject to the same challenge window and adversarial audit as the factors they shape. Inputs carry self-dealing and liquidity filters: instruments written between affiliated parties, or below published liquidity minimums, are excluded from the observable set — the entities writing firming contracts are often the entities being priced. Thin markets are named, not disguised: where observable instruments cannot support the required granularity, the FDO output is a modelled factor under audit, published as such, with the model versioned and challengeable — a committee’s judgment in a lab coat is only dangerous when it wears the coat in secret.

Part III — Financing

What if debt isn’t fundamental?

Strip debt to its function and it does one thing: it moves purchasing power through time. The loan — a fixed obligation enforced by collateral seizure — is merely one instrument for that job, and its fixity is where most of the cruelty and fragility of modern finance lives. the standard makes two older, gentler instruments native.

3.1  Energy forwards: financing without debt

Financing is native to this design — not because the coin is a financing instrument (it is a settlement credit, §2.1, and nothing more), but because the system’s other two instruments do the financing work debt does elsewhere: dated forward contracts share project risk with counterparties who can price it, and non-transferable prepayments let a community fund its own future consumption. A solar-and-storage developer does not need to borrow: it pre-sells tomorrow’s firm generation as discounted forwards — buyers pay, say, 0.9 coins today for 1.0 coin of energy delivered in 2028. The discount plays the role interest used to play, but with the risk structure inverted: if the project under-delivers, holders share the shortfall pro-rata. Nobody forecloses on anybody. Risk is shared like equity, not transferred like debt.

Lineage

This is not exotic. It is structurally the power purchase agreement — the contract that already finances most of the world’s renewable buildout — generalised into a transferable instrument. It is also what Islamic finance has insisted on for fourteen centuries: profit-and-loss sharing (musharakah, mudarabah) in place of fixed interest, on the moral argument that a lender who shares no risk deserves no certain return.

The fence, stated plainly. A discounted transferable claim on future output, sold with an expectation of gain from another’s efforts, is an investment contract in essentially every jurisdiction — the classification does not care what the document calls it. Conformant implementations therefore restrict transferable forwards to eligible counterparties (wholesale market participants and professional investors) until S3 licensure (§7.3). For households and local businesses before S3, the conformant instrument is the non-transferable prepayment: prepay for your own future consumption from a named project, with no resale and no return pitch — a purchase, not a security. This specification documents the forwards mechanism; it does not promote it, and any implementation offering transferable forwards to the retail public without the applicable licence is non-conformant by that fact alone.

Cover treatment: two books, one physics, and the rules that keep them honest. Coins and contracts are different paper pointing at the same physical world — the same dams, hedges, and PPAs. Without explicit rules, “separate cover books” is accounting cosmetics: mint coins against a hedge, sell firm contracts that quietly point at the same hedge, and stress reveals the double claim. The rules:

  • Exclusive pledge. Any unit of physical capacity or hedge notional is pledged to exactly one book — the coin cover pool or a single named contract series. No dual-use, no haircut regimes, no priority cascades: a registry lookup answers “what backs this?” in one row. (Dual-use collateral under priority rules is more capital-efficient and is how rehypothecation chains start; this design chooses the rule a spreadsheet can audit.)
  • The growth gate. No new contract series may open, and no contract open interest may increase, unless the coin book is Fully backed (§4.5) and has been for a published dwell time. The junior book does not expand while the senior book is stressed — seniority (§4.5) expressed as a growth rule, not just a bankruptcy rule.
  • The quality floor. Each federation publishes a minimum share of coin cover that must be physical — owned dispatchable capacity, storage, physically settled PPAs — governed with the same machinery as FDO factors (published, versioned, delayed-effective, challengeable). Exclusive pledge stops double-counting; the quality floor stops “coins on swaps, contracts on dams.”
  • The open-interest cap. Aggregate contract-book notional is hard-capped at a published multiple k of outstanding coin supply, with k and its basis (supply or coin cover) governed like FDO parameters — published, versioned, delayed-effective, challengeable. Without it, the default commercial shape drifts toward a thin prepaid wrapper over a huge subordinated forward book — an energy-money brand on a derivatives desk.
  • Pledge-split disclosure. The public dashboard shows pledged capacity and notional by book and by instrument class. A small-money/large-contract business model remains lawful; it does not remain invisible — holders and bridges can price what they see.
  • No mint-to-settle. Contracts settle by physical delivery, or in joulemarks sourced from escrow or market purchase. Coins are never minted at contract settlement — a mint-to-settle path would make the contract book a backdoor mint. The single exception is conservation-shaped, not discretionary: maturity conversion against the delivering project’s verified injection, through the ordinary mint and its full proof-of-generation machinery.
  • No demurrage shelter. Joulemarks escrowed as contract margin or settlement funding continue to demurrage. There is no demurrage-free vault labelled “I’m in a contract” — otherwise large holders park value in contracts to dodge carry and the liquidity premium this design abolished walks back in through the loading dock.

A dated cliff of future obligations is visible on its own dashboard, never hidden inside the coin’s.

Design decision — contracts stay heterogeneous. Firm-delivery contracts are named, dated, and project- or tenor-specific, permanently. A standardised, fully fungible firm future — tradable across projects as an undifferentiated unit — would be the wholesale coin grade rebuilt under an alias, recreating the two-claims-one-name problem this section exists to close. Clearing houses may net offsetting positions within a series; they may not melt series into a generic circulating instrument. Recorded here so drift into a “firm-JM” is a visible violation, not an innovation.

3.2  Mutual credit: money that appears when needed and vanishes when done

For daily commerce, the standard adopts mutual credit: when a plumber invoices a bakery, matching plus-and-minus entries appear on the ledger and extinguish when settled. Credit becomes a property of the trading network rather than a product sold by banks. Four rules govern how mutual credit and the monetary core interact — stated here, demonstrated with numbers in Appendix E: (i) demurrage applies to held joulemarks only — coins are claims on stored readiness, and readiness costs money; mutual-credit positions, positive or negative, are claims on the network, nobody stands ready for them, and they carry settlement deadlines within trust limits instead of decay (decaying one side of a matched pair breaks pair conservation; decaying the negative side pays people to owe); (ii) mutual-credit limits are network trust limits, entirely separate from the energy mint cap; (iii) mutual credit is not firm energy — it cannot mint, only circulate claims already issued or extend temporary network credit within trust limits; (iv) converting a mutual-credit position into redeemable joulemarks requires someone to supply joulemarks in settlement — never the mint.

Lineage

Switzerland’s WIR Bank has run exactly this system among small businesses since 1934. Its turnover demonstrably expands when ordinary bank lending contracts (Stodder 2009; Stodder & Lietaer 2016) — a counter-cyclical cushion for Swiss SMEs across nine decades. Cite the precedent accurately, though: WIR has operated under a Swiss banking licence, with full supervision, customer due diligence, and monitoring, for nearly all of that history. Ninety stable years of mutual credit are ninety years of regulated mutual credit — the precedent argues for supervised network credit, and §5.5 specifies the supervision.

3.3  The euthanasia of the rentier

A century-old argument — made by Silvio Gesell and taken seriously by John Maynard Keynes — splits interest into two parts: a risk premium, which is legitimate payment for genuine uncertainty, and a liquidity premium, which lenders extract simply because money can be hoarded costlessly while everything real decays. Remove costless hoarding (Part IV shows how, honestly) and the liquidity premium collapses. Lending does not disappear; the passive-extraction layer of finance does. Keynes, in the General Theory, named the endpoint himself: “the euthanasia of the rentier.” The phrase is his, and it has sat respectably in the canon for ninety years.

In plain terms

Some interest pays people for taking real risks — fair enough. But some interest is charged just because the lender’s money keeps forever while your need doesn’t. In this system, money has a small carrying cost like everything real, so that second kind of interest has nothing to feed on. People who fund real projects still earn; people who merely sit on money don’t.

Part IV — Stability

A shock absorber with no hands on it

4.1  Which deflation this money produces — and why it’s the safe kind

Economists distinguish two deflations. Demand-collapse deflation (the 1930s) is destructive: spending stops, money is hoarded, and a fixed money supply strangles the economy — Bitcoin’s design reproduces this pathology on purpose. Productivity deflation is benign: goods get cheaper because we get better at making them, as technology prices have for decades. a conformant currency is structurally biased toward the second kind — with one honestly stated exception. Hoarding raises the cost of monetary expansion rather than blocking it: hoarded coins remain outstanding and consume cover (Invariant 2), so new minting requires new cover, and demurrage makes the hoarder pay that carrying cost. But in an energy-scarcity season the bias reverses: cover tightens, minting throttles, and redemptions rise — the money supply contracts precisely when the community’s energy costs bite hardest, the gold standard’s defining pathology in miniature. This design accepts that trade-off knowingly rather than claiming immunity: the reserve’s counter-cyclical liquidity role (§4.3) and the mutual-credit layer exist to blunt it, and a federation should instrument the correlation between its coin-supply growth and its local scarcity index from day one, because that correlation is this currency’s most honest vital sign. And as manufacturing efficiency improves, goods priced in kilowatt-hours drift gently cheaper — a currency that quietly rewards civilisation for getting better at making things.

One consequence is worth naming rather than hiding: human labour — care, craft, presence, judgment — does not get more energy-efficient, so its price in joulemarks rises over time, and rises further as AI and robotics push the marginal cost of everything else toward its energy cost. That is not a currency failure; it is the truest price signal such an economy could send: human attention is the precious thing. Indeed, the more the economy automates, the more accurate an energy-denominated unit of account becomes, because energy converges toward being the marginal cost of nearly everything.

4.2  Demurrage: the carrying cost is real, so charge it honestly

Every joulemark is a claim someone must stand ready to honour indefinitely: batteries maintained, hydro headroom kept, standby capacity contracted. That readiness costs real resources, so holders pay it — a small annual decay on held coins, called demurrage, set not by policy but by the measured, audited cost of firm energy storage. This is the design’s quietest elegance: a mechanism usually dismissed as a monetary gimmick becomes simply the physical cost of carry of the underlying commodity, passed through. Nothing is arbitrary; there is no dial for a committee to turn — and under stress the rate moves only by the pre-published formula of §4.3, an exception the fourth invariant states on its face. One incidence honesty note: businesses obliged to hold working balances will price expected carry into their joulemark prices, passing part of the cost to customers — statutory incidence is not economic incidence, and at 0.33% per month the effect is small but not zero.

Lineage

Silvio Gesell proposed decaying money (Freigeld) in 1916 to keep currency circulating. The Austrian town of Wörgl tried it in 1932: the town is widely credited with a sharp local employment recovery while the surrounding depression deepened (a single-town natural experiment with public-works confounds — credited, not proven), until it was terminated when the central bank asserted its exclusive note-issuing rights. Gesell’s problem was that his decay rate was arbitrary. The joulemark’s is not — it is an invoice from physics.

4.3  The strategic reserve, funded by its own beneficiaries

Demurrage revenue flows directly into a strategic energy reserve — contracted battery capacity, hydro lake headroom, standby generation — the pool that keeps par settlement liquid when redemptions spike — the readiness the demurrage was always paying for. The people who benefit from firmness (holders) fund the thing that provides it, automatically, in proportion to how much money they hold. When stress arrives, hard-coded thresholds release reserve energy to honour redemptions or adjust the demurrage rate by published formula, using grid data nobody can fake because the grid must physically balance. (Release, never issuance: minting new coins against the buffer mid-crisis would dilute exactly when cover is degrading, and §4.5 forbids it.)

Two jobs, two instruments — because the arithmetic demands it. Demurrage revenue at plausible scale funds hours-to-days of redemption cover; a dry year is a weeks-to-months event costed in terawatt-hours. Conflating the two invites the sentence “the reserve turned out to be six hours of a small town.” The reserve is therefore split by name: the liquidity buffer — demurrage-funded, sized and published as an hours-of-cover metric against stressed redemption scenarios, the thing that meets a spike; and seasonal adequacy — carried entirely by the hedge and physical-cover standard of §4.5, the thing that meets a dry year. Each publishes its own metric; neither borrows the other’s job.

This is a central bank with the discretion amputated: a currency board whose reserve asset is joules and whose policy rule is executable code that anyone can audit. Panics are met with actual stored energy, not promises. Costless hoarding and discretionary issuance — the two levers every historical capture has pulled — are both absent by construction.

In plain terms

Instead of a committee deciding to print money in a crisis, this system keeps a real stockpile of energy — full dams, charged batteries — paid for by a tiny fee on everyone’s balance. If a panic hits, the rules (written in advance, visible to all, changeable by no one quickly) release the stockpile. It’s a fire sprinkler, not a fire brigade you have to phone and hope answers.

4.4  The feedback structure

Systems thinkers — Donella Meadows gave the field its plainest language — distinguish balancing loops (labelled B), which push a system back toward a set point like a thermostat, and reinforcing loops (labelled R), which amplify whatever direction things are moving, like compound interest. A currency is safe when its balancing loops are automatic and its reinforcing loops are virtuous. the standard’s two load-bearing loops:

Figure 3 — The load-bearing loops. B1: if the coin trades below the value of what it settles, redemption becomes the cheaper way to pay a power bill and burn pressure restores the peg — in mature form via arbitrageurs, on day one via the bill sink (O-1); the body text prices the friction the diagram omits. R1: holding coins funds (via demurrage) the reserve that makes holding coins safe — the currency's credibility compounds on itself. Both loops run on physics and self-interest; neither has an operator.

One honesty note on B1, because the diagram is cleaner than the street. Arbitrage defends the peg only when redemption is cheap, fast, and available to enough actors: a discount persists whenever it is smaller than the sum of redemption friction, basis adjustment, fees, and time cost. Textbook arbitrage is therefore the mature defense, not the day-one one. Each federation must publish its redemption terms as protocol data — maximum redemption latency, minimum redemption size, retail versus wholesale redemption paths, and who may redeem — so the effective arbitrage band is knowable rather than discovered by disappointment. At MVP scale, the day-one peg anchor is not arbitrage at all: it is the guaranteed near-par sink of the power bill (rule O-1), sized to local acceptance. And one cross-reference the loops require: in the §4.5 shortfall states, rationing switches the arbitrage defense off exactly when discounts run widest — the state machine and the peg share a fate, which is why the machine’s thresholds are defined, banded, and hysteretic rather than improvised. Federations may additionally fund market-makers with published near-par buy mandates out of float or demurrage revenue — an optional secondary defense that is a standing order, not a committee.

4.5  Obligor and shortfall: what happens when delivery fails

Physics can detect over-minting; physics cannot make a bankrupt retailer deliver a kilowatt-hour. The conservation loop proves the books balance — it does not, by itself, guarantee performance. Every coin therefore exists under a named legal obligor class: a single anchor retailer at MVP stage, a federation reserve vehicle under multi-signature custody at consortium stage, a mutual or cooperative structure at maturity. And the bootstrap rule O-2 is hereby globalised into the second invariant, holding at every stage forever:

outstanding coins ≤ audited energy-settlement cover — the hedged procurement position plus reserve liquidity sufficient to honour par settlement of the energy component under the presentation profile and adequacy standard below — continuously, publicly, externally audited, with the following arithmetic discipline, absent which the invariant is a scalar with no units. (“Firm deliverable cover” was this document’s earlier vocabulary, from when the coin was a firm call option; a price-settlement coin is covered by a solvent hedge book, and the words now say so.)

  • Tenor structure. Cover is measured per delivery period against the coin stock’s modelled presentation profile, not as one number. Perpetual claims backed by a rolling short-tenor hedge book is the balance sheet of a bank; the per-period ledger makes the maturity mismatch visible and priceable instead of discovered at a roll date in a tight year.
  • The presentation profile is governed like the FDO — because it is the FDO’s twin. Whoever models “who redeems when” controls effective cover requirements as surely as whoever sets mint factors controls issuance. The profile methodology is therefore published, versioned, delayed-effective, and adversarially challengeable, with declared stress scenarios and freeze-to-last-good-version on audit failure — the full §2.8 treatment. This matters most from S1 onward: once balances transfer freely, presentation can shift from bill-shaped to run-shaped, and the model must be re-derived from observed behaviour on a published cadence, not assumed from S0 history.
  • Eligible instruments, with haircuts. Physical PPAs and owned dispatchable capacity count at face; cash-settled financial hedges carry published haircuts, increased where the counterparty’s own fuel position is correlated with the scarcity being hedged (a swap against a dry year, written by a hydro gentailer, hedges price and concentrates delivery risk).
  • A named adequacy standard. Cover is firm against a declared hydrological/weather percentile — this specification’s default is a 1-in-20 year — published per federation and auditable against it.
  • Flow as well as stock. Each federation publishes a redemption coverage ratio in flow terms: maximum deliverable energy per day (reserve discharge + spot procurement capacity + hedge deliveries maturing within seven days) over trailing peak seven-day redemption demand, stress-tested at published multiples. A stock of cover is not a rate of delivery, and the ratio is where that truth lives.
  • Thresholds with teeth and dampers. T1 and T2 are published formula outputs of the tenor-structured ratio, with hysteresis bands and minimum dwell times so the machine cannot oscillate, and per-class mint rate limits so a predictable downgrade cannot be front-run by concentrating mint volume ahead of a crossing.
  • Disclosure that audits without arming the run. Conformance state (which band the ratio is in) is public and continuous; the exact ratio is published with a short lag. Continuous exact-cover telemetry plus a known threshold is a countdown clock any speculator can read — the design discloses conformance, not attack timing.
  • The property right that completes the physics. Reserve assets and minter bonds are held on trust (or an equivalent segregated vehicle) for holders, as a conformance requirement. “Backed” without segregation means unsecured creditor in an insolvency, and every backing representation in this document assumes the trust exists. One staging honesty note: at S0, a full multi-party trust vehicle is heavy for a single-retailer prepaid loop, and a provisional custody tier — client-money account plus published cover, labelled as such on the dashboard — is conformant, graduating to the full trust structure as an S1 gate. What is never conformant is using the word “backed” in the mature sense while operating the provisional tier unlabelled.
  • Seniority: coin holders first. In Default, joulemark holders are senior; contract holders are junior; equity is last. Not sentiment — allocation of risk to the party equipped to price it: contract holders are eligible counterparties who can read the obligor’s books and charge for subordination in the forward curve, and households cannot. The Cantillon logic of this whole document, expressed as a queue.
  • Seniority that cannot be undone procedurally. Paper seniority dies by margin drain, so: contract margin is series-segregated collateral, posted to the named series, never drawn from the coin reserve or the holders’ trust corpus (joulemarks posted as margin are the counterparty’s own escrowed coins, still demurraging, per §3.1); pre-Default contract settlements from shared assets are limited to that series’ posted margin and series-pledged capacity; and close-out or termination amounts exceeding a series’ own collateral become junior claims in the waterfall — they queue behind coin holders, they do not vault over them by being labelled “margin.” A shared minter bond is coin-senior by default; a contract series wanting bonded performance posts its own.

When cover degrades anyway — a dry year, a failed generator, an obligor in distress — the protocol response is a frozen state machine, written before the first coin exists, because a shortfall waterfall improvised during a crisis is just a committee with extra steps:

StateMeaningProtocol response
Fully backedCover ratio at or above threshold T1Normal mint and redemption
Soft stressCover between T1 and T2Reserve and demurrage rules fire by formula (§4.3); minting throttles automatically
Hard shortfallCover at or below T2, or verified failure events (below)Pro-rata rationing of redemption throughput across presenting holders; minting suspended except against new eligible cover
DefaultObligor cannot performBond slashed, certification revoked, reconciliation published; the Default sequence runs (below) — coin holders senior, contract holders junior, equity last

The shortfall waterfall, in fixed order: first the reserve is drawn; second, a temporary published surcharge applies to non-firm redemptions; third, redemption throughput is rationed pro-rata across presenting holders; fourth, bonds are slashed and the minter suspended. What never happens, under any state: silent redefinition of what a coin is owed. A kilowatt-hour claim that becomes “a kilowatt-hour, subject to committee interpretation” has died as money, whatever its market price.

Default is not Soft stress with extra steps. The waterfall above is going-concern law — the obligor still performing, the machine keeping it honest. Default ends the fiction of performance, and what follows is distribution, in fixed sequence: mint frozen and rule changes already frozen (C-4); contract series closed out on their own pledged capacity and posted margin only (§3.1’s exclusive pledge means that capacity was never the coin book’s); remaining coin-book cover, liquidity buffer, and bond proceeds distributed to joulemark holders by published claim priority; residuals, including any contract close-out amounts that exceeded their series collateral, to junior claims; equity last. The going-concern waterfall does not run “underneath” Default as a route for junior claims to keep drawing on the reserve while seniority is being decided.

Failure is a first-class ledger event — with sensors that actually exist at retail. A household paying its bill in coins tests the retailer’s bookkeeping, not its solvency; electricity flows to premises regardless, so a rotted hedge book produces no redemption symptom until the default. The alarm therefore watches the cover, not the burns. Countable failure events, each recorded on-ledger per obligor: a missed reconciliation publication; cover-data staleness beyond its published cadence; a refused or delayed redemption within published rate limits; a refused or delayed settlement at the fiat drain (§7.4, FM-4); and — because contract stress is real stress even when the coin book looks calm — the contract book’s own events: a missed physical delivery, a failed margin call, a cover breach on any series. Staleness is itself an alarm state: the one thing a distressed obligor reliably does first is stop publishing.

Design decision — pro-rata rationing over forced conversion. The primary hard-shortfall rule chosen here is pro-rata rationing of redemption throughput. The considered alternative — a forced conversion window, redeeming claims into fiat at a published rate — was rejected as the primary rule because it reintroduces a fiat dependency at exactly the moment the system is being tested, converts a delivery promise into a price promise (the thing this design exists to avoid), and creates a run incentive to be first through the conversion window. Rationing shares a physical shortage the way physical shortages are honestly shared: everyone gets less, visibly, pro-rata, with the claim itself intact. Federations may offer voluntary conversion alongside rationing; they may not substitute it.

Part V — Governance

The anti-capture constitution

Design assumption: capture will be attempted, continuously, forever, by intelligent and well-funded people. Every monetary system in history has eventually been taken through the same door — control of the rules of issuance. The constitution’s job is not to forbid capture but to make it unprofitable and immediately visible.

The warning precedent is Bitcoin itself: a system engineered to be trustless re-centralised anyway — into mining pools, core-developer politics, and exchanges — because concentration pressure never sleeps. A serious design treats decentralisation as a maintained property, not a birthright. Five interlocking mechanisms:

C-1
Redemption is sacred, and the cover is the alarm system. Fiat capture is invisible because inflation is diffuse. Here, every capture path — over-minting, reserve raiding, crony rates — drains the same reservoir: the cover that keeps par settlement solvent. The primary alarm is therefore the published cover state and the on-ledger failure events of §4.5 — continuous, public, uncountable only by shutting the lights off, which is itself an alarm. The millions of bills paid monthly are the demand path and a perpetual bookkeeping check; they are not the solvency oracle, because a bill settles against the retailer’s ledger, not its hedge book. The alarm watches the hedge book.
C-2
Transparency by physics. Every mint event reconciles against grid settlement data that system operators already collect. Coins minted must equal metered injection, cryptographically signed, verifiable by anyone. The books cannot be cooked, because the grid must physically balance — a proof-of-reserves no fiat or crypto system has ever had.
C-3
Separation of powers, staffed by pre-existing rivals. Meter certification sits with national metrology bodies (independent, already exist everywhere). Solvency audits rotate among adversarial parties. Ledger validators are a different actor set from minters. Reserve custody is multi-signature across parties who professionally distrust one another. Minters post bonds that are automatically slashed on over-issuance. And hard concentration caps: no entity above a fixed share of outstanding mint, ever.
C-4
Constitution-in-code with mandatory exit windows. Mint-cap formula, demurrage derivation, reserve triggers — all executable, all public. Changing them requires a supermajority plus a long delay before effect, so any holder who dislikes a change can redeem and leave first. That delay is a guillotine over governance: a captured consortium that votes itself favourable rules watches the currency redeem itself away during the notice period. Two honest qualifications, stated where the right is stated: the exit runs at the published redemption throughput (§2.1, §4.4) — it is a guaranteed queue, not a guaranteed instant — and no rule change may take effect during, or within a published cooling period after, any non-fully-backed state (§4.5), so stress can never be engineered as cover for a rule change. Three mechanical clauses so nothing must be derived: Soft stress is a non-fully-backed state and is inside the freeze — stated, not inferred; a federation that enters any non-fully-backed state mid-notice-period restarts the notice clock from re-entry into Fully backed plus the cooling period; and notice periods are sized against redemption throughput under published stress scenarios, not normal load, so a deep queue while technically Fully backed cannot strand exiting holders either.
C-5
Forkability: the protocol is open, so there is no throne. the standard propagates as a protocol — like email or TCP/IP — not as one global currency ruled by one body. Any community stands up its own federation; if a governing consortium rots, the community forks the ledger and walks, taking the network with it. Credible exit disciplines everyone who stays.
Figure 4 — The alarm loop. Every path to stealing from this system runs through degrading the cover, and cover state is published continuously with failure events counted on-ledger (§4.5). The theft consumes its own prize in public before the thief can carry it out the door — which is what deters the attempt (the loop closes as prevention, not just punishment).

5.1  The data-rights prerequisite: what C-2 actually requires

“Transparency by physics” (C-2) quietly assumes that grid settlement data is available to reconcile against. In many markets it is not free: settlement data can be delayed, commercially licensed, or contractually restricted. Without system-operator cooperation or a regulated right to meter data, C-2 degrades from “verified by the grid” to “trust the metering authority” — still better than pure fiat, but not the same claim, and the difference must not be papered over. Conformance is therefore tiered by the independence of the evidence behind each mint event:

Evidence basisConformance level
System-operator settlement data plus certified meterFull C-2 conformance
Dual independent metrology (two separately certified measurement chains)Full C-2 conformance
Single certified meter plus delayed or aggregated settlement dataProvisional conformance — MVP stage only, with a mandatory published upgrade path
Self-declared generationNon-conformant for minting, always

A federation is fully C-2 conformant only when mint events reconcile against grid, settlement, or meter data sources independent of the minter, available to auditors and — ideally, possibly delayed or aggregated — to the public. Securing that data access is a deployment prerequisite, named as such in the playbook, not an assumed feature of physics. Two further conformance floors, so the word “audited” never degrades into “attested”: the minimum audit standard per tier is defined — independent auditor, mandatory rotation, full-procedure audits (not attestations) at a published frequency that tightens for provisional-tier federations — and interval (half-hourly) metering is a prerequisite for any minting connection point (§2.2); profile-estimated volumes may not mint at any tier.

5.2  The intellectual scaffolding

Lineage

Elinor Ostrom won the Nobel in economics (2009) for documenting how commons — fisheries, forests, irrigation systems — are governed successfully for centuries without kings or privatisation, and distilling the design principles that make it work. An open monetary protocol is a commons. Albert Hirschman’s Exit, Voice, and Loyalty (1970) supplies the other pillar: institutions stay honest when members have a credible way to leave. Forkability is exit, made credible.

Ostrom principleJoule Standard implementation
Defined boundariesEach federation has explicit membership: certified minters, named validators, a defined grid region.
Rules fit local conditionsMint rates and demurrage derive from each grid’s own measured firming and storage costs — a Norwegian hydro federation and a desert solar federation will differ, correctly.
Collective choiceRule changes by supermajority of holders and minters — with the C-4 delay.
Monitoring by accountable monitorsAuditors are rotating, adversarial, and publish reconciliations against grid data anyone can check.
Graduated sanctionsBond slashing scales with violation size; certification loss is the capital penalty.
Cheap conflict resolutionDisputes resolve against physical evidence — meter logs and settlement data — not testimony.
Right to organiseAnyone may deploy the protocol; no licence from an incumbent federation is required.
Nested enterprisesLocal federations handle local rules; a thin bridge layer handles only inter-federation exchange.

5.3  Topology: a federation of villages, no palace

The global picture is not one currency but one language spoken by many local loops — a Bavarian energy co-op, a Kerala microgrid, a Texan retailer, an Auckland industrial precinct — each independently governed under the same open protocol, bridged for exchange. Would-be captors arrive at the palace and find there isn’t one.

Figure 5 — No throne. The protocol propagates like email: many independent federations, one shared language, thin bridges for exchange. Any community can fork away from a rotten federation and remain part of the network. There is no centre, so there is nothing to capture.

5.4  Naming convention: fork this, and say so

The protocol is The Joule Standard. Currencies built on it belong to the communities that deploy them, and each names its own: Waiheke Watts, a Joule Standard currency; Bayern-Joule, konform mit dem Joule Standard. The reference implementation described in this document is the joulemark. Forking is not tolerated — it is the propagation mechanism, and the licence (CC BY-SA) carries attribution with every copy at zero enforcement cost.

The only mark protection this document endorses is a conformance mark — “Joule Standard–conformant,” usable by any federation that passes the C-2 reconciliation audit, deniable to any that fails it. This is the certified-organic pattern: it polices fraud at the boundary (Ostrom’s first principle) without granting anyone ownership of the movement.

5.5  The compliance layer: identity, obligated entities, and the borders

Adversarial review established that this design’s financial-crime posture cannot live in one sentence. The mint is well defended — proof-of-generation survived every attack made on it — but a currency’s crime surface is holding, transfer, credit, certificates, and conversion, and each needs a named control and a named owner. The following are conformance requirements, with their costs to the project’s openness stated rather than hidden.

Tiered identity. Wallets below published balance and monthly-transfer thresholds may operate with light identification (the simplified-due-diligence pattern of regulated e-money); above them, full customer identification applies. Wholesale-scale redemption is available to identified wallets only — §4.4’s “who may redeem” field is where the gate lives. Traceability is not identity: a pseudonymous ledger everyone can read is what Bitcoin has, and it satisfies no examiner. The cost is real: the federation now runs an identification function, holds personal data, and can exclude — a genuine narrowing of open participation, chosen because the alternative is an unidentifiable transferable instrument no regulator will permit past a closed loop.

An obligated entity from day one. The anchor retailer — minter, redeemer, and fiat-settlement rail — is the federation’s named compliance entity from S0: risk-based customer due diligence (leveraging the account relationships it already holds), monitoring calibrated to this system’s economics, suspicious-activity reporting to the national financial-intelligence unit, and sanctions screening at any fiat settlement. Two calibration rules the economics dictate: velocity baselines must be actor-class-relative, because demurrage makes rapid movement rational for everyone and absolute-velocity flags degrade into noise; and monitoring must aggregate across acceptance points, because published per-business acceptance caps (O-1) are otherwise a structuring template — value fanned across many businesses at just-under-cap volumes must be visible as one flow from common origins.

Capital behind the meter. Proof-of-generation verifies electrons, not the money that bought the panels. Minter onboarding above a published capacity threshold includes source-of-funds and beneficial-ownership verification, performed by the federation or its retailer — never by the metrology body, whose job is measurement. Household-scale prosumers ride the retailer’s existing customer relationship; the risk lives in acquired portfolios and commercial-scale installs, and the threshold is set accordingly.

Credit networks are vetted networks. Mutual credit creates transferable value on the strength of an invoice, and fictitious invoicing is the oldest laundering typology in the file. Credit-network membership carries the same identification as identified wallets; trust limits are evidence-based and published per member class; and credit creation above thresholds is monitored for the classic patterns — value outliers against declared business type, circular credit, rapid create-and-settle. This is what the licensed operators of durable mutual credit actually do (§3.2), and small federations should weigh the obligation before switching the layer on.

Certificates are registered instruments. The values layer’s certificates (Part VI) are a second transferable asset, and the regulated markets they imitate learned the hard way — carousel fraud in emissions registries cost European treasuries billions before account-level identification became standard. Certificate registries require identified accounts; transfers above thresholds carry the same data envelope as bridge transfers; provenance attestation sits under the C-2 audit machinery.

Wrapped instruments are orphans. Third-party “wrapped” joulemarks on permissionless chains would bypass every control above. They are non-conformant and — the part with teeth — redemption-ineligible: redemption requires an identified in-federation wallet, so a wrapper can never touch the kilowatt-hour and its peg is stillborn. Stated here so the market prices it before anyone builds one.

The borders, and the sanctions question. Bridges between federations are where value crosses jurisdictions, and “thin” is a description of their protocol role, not their legal one. A bridge operator is a named, licensed entity under the law of its own seat; inter-federation transfers carry an originator/beneficiary data envelope as protocol message fields (the travel-rule pattern, whose cross-border mismatches are themselves a deployment constraint the jurisdictional survey must map); and bridges refuse transfers from federations without the conformance mark. On sanctions, the design’s position is deliberate: the conformance mark certifies measurement integrity only — it is a physics certificate and takes no political criterion — while every bridge operator complies with the sanctions law applicable in its own jurisdiction, as a stated conformance requirement rather than an unstated legal fact. An open protocol cannot prevent deployment by sanctioned actors; what it ensures is that association is refused at the borders, where law actually operates, by the parties who actually bear it. A rogue fork can run; it runs unmarked, unbridged, and alone.

Part VI — Values

Values without a ministry

Different communities will want to reward different energy: solar over coal, ethically mined storage minerals over the alternative. The constraint is absolute: the moment the mint formula contains an ethics multiplier, someone sets the weights, that someone controls the money supply, and every lobbyist on earth relocates to their doorstep. Values must act on price through markets — never through the mint.

6.1  Attribute certificates: the provenance travels, the money stays fungible

Electricity markets already solved this exact problem. A renewable electron and a coal electron are physically identical, so renewable energy certificates detach the attribute from the commodity: the kilowatt-hour trades as a kilowatt-hour, and its “renewableness” trades separately, at whatever premium voluntary demand discovers. The Joule Standard adopts the pattern: every mint event carries cryptographically signed provenance metadata — source type, emissions intensity, third-party ethical-sourcing certification where one exists — but the coin itself remains perfectly fungible. The attribute is a detachable token riding alongside. A wallet can display “this balance is 78% renewable-minted”; a values-driven buyer pays a premium for solar-vintage certificates; a business advertises that it preferentially holds certified coins. Nobody dictated a price. Demand did what demand does — and monetary fungibility, the property a currency dies without, is never broken.

In plain terms

Think of fair-trade coffee. The beans work in any machine; the label is what you choose to pay extra for. Here, every coin can carry a label saying where its energy came from — and you, your shop, or your whole town can decide what the label is worth to you. The system never decides for you.

6.2  Federation charters: virtue as a competitive strategy

Ostrom’s second principle — rules fit local conditions — does double duty here. Each federation writes its own charter of admissible minting sources: one charters itself renewables-only with audited supply chains; another admits gas; a third demands certified labour standards on storage minerals. The protocol is neutral; the charters carry the values. The indirect pricing then happens at the bridges: federations’ coins trade against one another, and the bridge exchange rate becomes the market’s continuous verdict on each charter. If holders worldwide prefer strict-charter coins, those coins command a premium — which flows back as cheaper capital and better mint economics for generators inside those federations, pulling investment toward the supply chains people actually value. No committee set the premium; it is the aggregated preference of everyone choosing what to hold, priced continuously, capturable by no one because anyone can write a new charter.

6.3  Reserve procurement: the demand-side lever

The demurrage-funded strategic reserve is each federation’s largest standing buyer of firming capacity. A charter may direct its reserve to procure only from certified sources — green public procurement, a mechanism with decades of track record: it moves markets through demand pull, raises returns for aligned suppliers, and dictates a price to no one.

6.4  External anchors, never invented weightings

Where a jurisdiction operates an audited external price for an externality — a carbon price, an emissions trading scheme — the protocol references it rather than inventing its own. Even the environmental adjustment arrives as a market signal. The test all four mechanisms pass, and the ethics-multiplier fails: does it create a discretionary lever attached to money creation? Certificates, charters, procurement, and external anchors all operate downstream of the mint, in voluntary markets, with exit available at every layer. Neutral core, expressive edges — the same architecture that resists capture (Part V) is what lets a thousand moral communities share one monetary language without fighting over whose ethics get hard-coded. It is, not coincidentally, how the internet survived: the protocol carries everything and endorses nothing.

Part VII — Bootstrap

The deployment playbook

Every community currency in history — Bristol Pound, Ithaca Hours, Circles UBI’s Berlin pilot, dozens more — died the same death: businesses accumulated balances they couldn’t spend, a discount appeared, trust evaporated. They had faucets but no sink. The joulemark has the one sink every local currency lacked: the power bill — the invoice every household and every business pays, every month, forever.

7.1  The minimum viable loop

The loop below is the S1 picture — the destination of the first licence, not day one. Day one is deliberately smaller. S0 is a genuinely closed loop: a household with rooftop solar earns prepaid credits on export and spends them on exactly one thing — its own power bill. No merchant acceptance, no person-to-person transfer, one redeemer. Regulatorily this is a prepaid power account, the least classifiable instrument in the payments universe; operationally it proves every hard subsystem — minting, burning, the FDO, the cover invariant, the audits — with real meters and real people before any licence money is spent. The e-money/payments licence then is the S1 unlock: merchant acceptance and person-to-person transfer arrive with the licence that makes them legal, not before (§7.3). Liquidity is the graduation prize, not the opening bet. (Custody stages with it: S0 runs the provisional custody tier — client-money account plus published cover, labelled as such — with the full trust vehicle of §4.5 as an S1 conformance gate.)

At S1, three actor types close the circle. Households earn coins on export; they spend them at local businesses; businesses pay their power bills with them; the anchor energy retailer burns those coins and mints new ones on the next injection. One leak is plumbed deliberately: taxes must be paid in the national currency, and are settled by the retailer directly to the tax authority against filed liability (FM-4) — a drain, not a rupture, and not a window.

Figure 6 — Sink before faucet. The loop closes because it terminates in the one bill everyone must pay. The fiat leak (taxes) is plumbed by direct settlement to the tax authority (FM-4) rather than left to rupture the peg.

A note on where such loops can legally live. Beyond the New Zealand-flavoured example above, the European Union has already legislated the vessel this loop needs: citizen energy communities and renewable energy communities (Electricity Market Directive; Renewable Energy Directive 2018/2001) are recognised legal entities through which citizens collectively generate, share, and trade energy, with peer-to-peer trading defined in law and live implementations across the Netherlands, Germany, Italy, Spain, and the Nordics. These are, structurally, federations awaiting a monetary layer — pre-built with metering, settlement plumbing, and trading rights. The recurring finding from European pilots is that the technology works and the governance stalls them — pricing-fairness disputes among neighbours — which is precisely the layer Parts V and VI of this document exist to supply. EU energy-community law is therefore a serious candidate bootstrap vessel — with one controlling caveat this document refuses to bury: the EU is also the jurisdiction where the coin’s own classification is hardest. MiCA’s asset-referenced and e-money token regimes, and in particular its caps and restrictions on non-euro tokens used widely as a means of exchange, aim at exactly the R2 ambition of §1.4. Until the MiCA analysis in the jurisdictional survey (Part VIII) is resolved, the EU is the best vessel and the hardest instrument jurisdiction simultaneously — both facts, stated together.

7.2  Who gains, on day one

ActorDay-one gain
Prosumer households (rooftop solar, batteries, EVs)Export earns spendable coins at better effective value than the miserly buyback tariffs most retailers pay (often a third of the retail rate) — value you can explain at a barbecue.
Anchor retailer (a challenger retailer or community energy trust — not an incumbent)Sharply reduced churn (people holding your energy claims rarely switch — though conformance requires unredeemed balances be portable on switching, §5.5, so the lock is loyalty, not hostage-taking), free acquisition through every accepting shop, and — at S2/S3 with the right licences — forwards as risk-shared capital for building generation. Not on the list: the float. Outstanding-coin backing sits in the trust structure (§4.5) earning the system’s credibility, not the retailer’s yield; a retailer whose business case is spending the float is running a bank without a licence, and the invariant exists to make that impossible.
Local businessesPayment acceptance at ~0% versus 1–2% card interchange, a loyal customer badge, and a guaranteed sink in their own power bill — no stranded balances.

One number matters more than any other: the retailer must not mint 1:1. A kilowatt-hour of intermittent midday solar is not a kilowatt-hour of firm winter-evening delivery; it might mint on the order of 0.6 coins — illustrative only; the live factor is always the firmness discount oracle’s output for that injection class (§2.8). This is where the coin’s “lifecycle cost” lives — as an audited market price, never a committee formula. And one economics note the redefinition of §2.1 makes essential: retail coins redeem against the energy component of the bill — network, metering, and levy components remain billed normally — so a coin redeemed is a coin the retailer’s own hedge book already covered at mint, and the unit economics close by construction rather than by hope. The mint factor internalises delivery losses for its injection class: a coin is a claim on a delivered kilowatt-hour, and the FDO prices the difference between injected and delivered.

7.3  The four ordering rules

O-1
Sink before faucet. Grow redemption capacity (bills, EV charging, supplier payments) ahead of acceptance volume. Cap each business’s joulemark intake near its own bill-sized flow until the sink widens.
O-2
Hedge before mint. Outstanding coins never exceed the retailer’s hedged firm position. On day one the strategic reserve is empty — the retailer’s existing hedge book is the seed reserve, and mint cap equals hedge cover, externally audited from the first coin.
O-3
Proportionate regulation, engaged early. At MVP scale the instrument genuinely is closed-loop stored value — small balances, a single redeemer, no investment expectation — and should be regulated as such, graduating into derivatives and clearing regimes as its risk profile actually grows into those categories. Enter regulatory sandboxes voluntarily and invite supervision: a project that requests oversight is difficult to mischaracterise.
O-4
Audit before scale. The single-retailer MVP is a tolerable single point of failure only if its mint-cap reconciliation is published from day one. That audit habit is the embryo of the consortium; the moment a second retailer joins and coins clear between them, the single point of failure dissolves.

Rule O-3’s staging, made concrete. Each stage names the instrument’s actual character, its likely regulatory bucket, and — critically — what is forbidden until the next licence exists. The recurring failure of payment innovations is doing S3 things with S0 paperwork; this table exists so nobody can claim the line was unclear. It is a map of instrument character, not legal advice: the per-jurisdiction survey (Part VIII) remains critical-path work before any pilot.

StageInstrumentLikely bucketAllowedForbidden until licensed
S0 — Closed loopSingle redeemer, own-bill sink, no transferPrepaid account / closed-loop stored valueEarn on export; pay your own power billMerchant acceptance; person-to-person transfer; public trading; any yield or appreciation marketing
S1 — Local transferMulti-business spend, one redeemer classE-money / payment institution (the licence is the S0→S1 gate)Merchant acceptance; person-to-person and person-to-business transfer under the licence’s identity tiers (§5.5)Secondary markets; investment framing
S2 — Multi-redeemerConsortium clearing between retailersPayments plus energy-retail overlayInter-retailer clearingAny unhedged mint
S3 — Forwards marketExplicit dated firm claims, traded among eligible counterparties; retail only under full securities licensureDerivatives / commodities regulationWholesale energy forwards; licensed retail offerings where a regime existsAny retail offering without its regime; calling them “just vouchers”

One rule holds at every stage and is hereby protocol ethics rather than contributor guidance: no price-appreciation promises, ever, at any stage. An implementation marketing its currency as an investment is non-conformant regardless of its technical fidelity.

7.4  Known failure modes

FM-1

Velocity mismatch

A café’s power bill is 2–4% of revenue; if it accepts coins on 10% of sales, balances pile up and a discount emerges — the Bristol Pound death.

CounterAcceptance caps sized to each sink (O-1); widen sinks before faucets.

FM-2

The scarcity-season run

In hydro- or gas-tight systems, a dry year or cold snap is a slow-motion redemption run: redemption demand peaks exactly when the cover standing behind par settlement is most expensive to hold.

CounterSeasonal adequacy is carried by the tenor-structured hedge and cover standard (§4.5, 1-in-20 default), tested per delivery period — never by the reserve. The demurrage-funded liquidity buffer meets redemption spikes (hours of cover, published); the §4.5 state machine rations throughput pro-rata if cover degrades anyway. Two instruments, two jobs, both dashboards public.

FM-3

Regulatory classification

Publicly traded energy forwards look like derivatives to most securities regulators; licensing can kill an MVP before its first coin.

CounterStage the instrument to match its actual risk category (O-3), jurisdiction by jurisdiction; use sandbox regimes and early regulator engagement.

FM-4

The fiat leak

Taxes are payable in national currency; if converting out is hard, businesses discount the coin to compensate. But a standing at-par conversion window is worse than the leak: it is a run door (in stress, everyone’s “tax portion” grows), an e-money classification magnet, and an unlicensed exchange function.

CounterDirect settlement, no window: the retailer pays the tax authority directly against the business’s filed return, debiting coins at par and remitting fiat to the business’s tax account — capped at the filed liability, backed by a disclosed fiat buffer, suspended in the §4.5 non-fully-backed states. The holder never receives fiat; there is nothing to run on, and inflating a “tax portion” means filing a false return, a crime with its own enforcement agency. (Third parties settling tax on a business’s behalf is established New Zealand practice via tax-pooling intermediaries — precedent, not invention.)

FM-5

Anchor capture

One retailer minting, burning, and holding the hedge book is a miniature central bank — the exact disease this design treats.

CounterThe full Part V constitution, phased in: published reconciliation from coin one (C-2), consortium at the second retailer (C-3), forkability always (C-5).

Part VIII — Open problems

What this specification does not solve

A design document earns trust by listing its own unfinished edges. These are genuinely open:

  • The rights boundary. An energy currency can denominate everything manufactured — with enough cheap energy, even raw materials reduce largely to energy (mining, smelting, recycling, desalination are energy plus machines made of energy). But scarcity-by-property and scarcity-by-politics — land, mineral rights, water consents, spectrum, IP — sit outside the system. the standard prices production; it does not dissolve property or geopolitics. Critics will push here, and the honest answer is: correct, and out of scope. (Status: permanent boundary, not a to-do.)
  • Bridge-layer governance. Local federations are capture-resistant; the thin exchange layer between them is a new surface. It must stay thin — a clearing standard, not a bank — and how thin it can remain under growth is unproven. (Status: open; no v0.3.0 change.)
  • Storable-fuel custody. Extending minting beyond electricity requires chain-of-custody guarantees against double-minting that are institutionally solvable (carbon accounting wrestles the same problem) but not physics-enforced. (Status: open; electricity-only minting stands until solved — and storage inside electricity is now handled by net-mint accounting, §2.6.)
  • Measurement governance — the demurrage rate, the firmness discount oracle, and the presentation profile. “The audited cost of readiness,” the FDO’s mint factors (§2.8), and the presentation profile that cover is measured against (§4.5) are triplets: each must resist gaming, each sits on every coin, and each needs the adversarial-audit institutions this document specifies as interfaces but has not yet proven in operation. (Status: interfaces specified in v0.2.0 — §2.8, §4.2; institutional design open.)
  • Labour and long-contract conventions. If human services drift more expensive in joulemarks while goods drift cheaper, wage-setting and long-dated contracts need indexation conventions this document has not designed — deliberately left at the social layer (regime R3, §1.4), outside the monetary core. Scope note: income supplements such as pensions and benefits are fiscal and social-insurance design — claims on baskets or funded assets — not a property of the unit of account, and no monetary pathology should be invented for them. (Status: parked at social layer; no protocol work planned.)
  • Jurisdictional survey — critical path. The staged pathway of §7.3 works in some legal systems and not others, and transferable general-purpose balances are frequently reclassified regardless of branding. A per-jurisdiction regulatory map is critical-path work for any pilot, with three named chapters: instrument classification (in the EU, specifically MiCA’s asset-referenced and e-money token regimes and their means-of-exchange caps, which target this project’s R2 ambition almost by name); the compliance architecture’s local fit (§5.5’s obligated-entity, identity-tier, and travel-rule mappings); and the licensing sequence for the S0→S1 gate. (Status: open; first targets NZ and the EU.)
  • Technology dilution — the Cantillon effect’s honest cousin. Part I promises nobody can water down savings; §2.5 celebrates supply that grows with capacity. Both true — and jointly they mean a storage or generation cost collapse dilutes existing holders honestly, through the mint, with first-spender advantage accruing to whoever deploys the new technology fastest. The anti-dilution promise is therefore precise: this design eliminates dilution by decision; dilution by innovation is real, is the point of an energy-abundant future, and this document’s own convergence thesis (§4.1) predicts it. Falsifiers, so the bet stays honest: if energy’s share of marginal production cost falls for a decade rather than rises, or AI-era demand is met by cost declines fast enough that energy claims steadily cheapen against consumption baskets, the energy-money era was called early or called wrong. A federation should publish its coin’s purchasing-power series against a local basket from day one; this open problem is measured there. (Status: named, bounded, instrumented; not solvable by design.)
Appendix A

Anticipated objections

These are the strongest attacks the design expects, stated at full strength before being answered. A specification that publishes its own cross-examination leaves less for others to discover.

AO-1

“Private money undermines monetary sovereignty and macroeconomic management.”

The standard complements national currency rather than replacing it: taxes, legal tender, and macro policy remain where they are, and the fiat interface is plumbed deliberately (FM-4). Switzerland’s WIR has circulated alongside the franc for ninety years without impairing the SNB. At any scale where opt-in energy money genuinely constrained macro policy, it would be because millions of people had voluntarily chosen it — which is a verdict, not a malfunction.

AO-2

“Demurrage erodes ordinary people’s savings.”

The demurrage is small, disclosed in advance, derived from an audited physical cost, and funds the reserve that guarantees every holder’s redemption. Compare the incumbent: fiat’s erosion is larger in most decades, undisclosed, variable at committee discretion, and funds nothing the holder can claim. Savers seeking growth hold energy forwards (Part III), which yield; the spending balance carries the storage fee, exactly as a warehouse would.

AO-3

“Untraceable energy money will launder value.”

Minting is anchored to certified meters with legally identified owners — the best-defended link in the chain, and adversarial review left it standing. But traceability is not identity, and the honest benchmark is regulated e-money, not banknotes: the crime surface is holding, transfer, credit, certificates, and conversion, and §5.5 assigns each a named control and a named owner — tiered wallet identification, an obligated compliance entity from day one, source-of-funds behind commercial-scale meters, vetted credit networks, registered certificates, licensed bridges carrying travel-rule data, and a fiat drain that settles directly to the tax authority. The claim this design makes is the defensible one: obligations attach at mint, at transfer thresholds, and at conversion — by architecture, not by afterthought.

AO-4

“This is wildcat banking — the 1830s will happen again.”

The free-banking era’s failures had a specific mechanism: reserves were opaque, information travelled at horse speed, and note-holders could not verify backing. C-2 inverts every term — reserves reconcile against physical grid data, continuously, publicly. The failure mechanism this objection cites is the precise thing the constitution removes.

AO-5

“This is company scrip — the coal town’s truck system with better branding.”

Scrip’s abuses required a monopoly employer-issuer, a captive workforce, a company store, and non-transferability. A Joule Standard currency is transferable by definition, redeemable at audited par, open to any accepting business, and issued — beyond the MVP stage — by a consortium under concentration caps, with exit (C-4) and fork (C-5) rights constitutional. Every element that made scrip exploitative is structurally absent; the comparison illuminates the constitution rather than indicting it.

AO-6

“Energy prices are volatile — a terrible anchor.”

Spot electricity is volatile; the coin is not pegged to spot. It settles the energy component of bills at par, and what stands behind that settlement is energy-settlement cover — a tenor-structured hedge book plus reserve liquidity (§4.5) — whose cost is set by the capital stock of the energy system (generation, storage, transmission) and moves slowly. Spot volatility lives in the FDO’s mint factors and the basis adjustments, and is absorbed by the hedge book, exactly as retail tariffs absorb it today: households on fixed tariffs already live inside a hedged energy price without knowing it; this design makes that hedge auditable. And every anchor is a choice of what to be stable against (§4.1); this document makes its trade-off explicit, which is more than the incumbent can say.

AO-7

“This isn’t an energy standard — it’s a prepaid electricity credit scheme with a regulated PPA desk bolted on.”

Correct — and the document has said so since §1.4. The circulating unit is deliberately a conservation-backed settlement instrument: it guarantees the energy line of a bill at par, not a bearer claim on scarce winter electrons, because the latter is a seasonal call option and options are what speculators trade (§2.1). Firmness is sold where it belongs — as dated, named contracts among counterparties who can price it, junior to the money in a default (§4.5). If “prepaid credits plus a regulated forwards desk, with conservation-law issuance, published cover, and no committee” sounds unglamorous, note that the objection has conceded every substantive claim and is now arguing about glamour. The ambition is R1→R2 (§1.4); the standard is the unit of settlement, not a wholesale firmness token — and a project that survives its adversarial reviews by becoming more honestly described is doing this exactly right.

Appendix B

Glossary

Joulemark
The single monetary unit of a conformant currency: a transferable registered claim settling one kilowatt-hour of the energy component of a bill at par, within published rate limits. There are no grades. Plainly: prepaid power credits — one coin, one kilowatt-hour off the energy part of your bill.
Energy component
The portion of a bill charging for energy itself, as distinct from network, metering, and levy components. Joulemarks settle this component; the rest is billed normally. Plainly: the coin pays for the power, not the poles and wires.
Firm energy
Energy deliverable at a committed time backed by storage or dispatchable capacity — the scarce, expensive property of an energy system. In this design firmness is priced (at mint by the FDO, at redemption by basis) and sold as dated contracts; it is never an entitlement embedded in the retail coin. Plainly: guaranteed-when-you-want-it power — priced and contracted for, not silently promised to every coin.
Rate-limited redemption
Published redemption throughput — maximum latency, size bands, daily limits per holder class — as protocol data. The honest alternative to pretending unlimited on-demand conversion. Plainly: a fair, published speed limit on cashing out, like an ATM’s daily limit.
Proof of generation
Minting authorised only by cryptographically signed readings from certified meters, reconciled against grid settlement data, net of metered import at the connection point. Plainly: coins appear only when a tamper-proof meter swears real power went in — and the grid’s own bookkeeping agrees.
Net mint
Mintable quantity = metered export minus metered import per connection point, so storage cannot re-mint energy that already minted at its original generator. Plainly: a battery earns coins for the service it adds, not twice for the same electrons.
Firmness discount oracle (FDO)
The published, versioned, challengeable mechanism deriving per-class mint factors from observable market prices of firming. Class boundaries are governed with the same machinery as the factors. Plainly: the market, not a committee, decides how many coins a midday solar kilowatt-hour is really worth.
Presentation profile
The modelled schedule of when outstanding coins are expected to present for redemption, against which cover is measured per delivery period. Governed like the FDO: published, versioned, delayed-effective, challengeable. Plainly: the system’s forecast of when people will cash in — audited, because whoever controls the forecast controls the safety margin.
Energy-settlement cover
The hedged procurement position plus reserve liquidity sufficient to honour par settlement under the presentation profile and adequacy standard — measured in stock and flow terms, per delivery period, tenor-structured, externally audited. Plainly: proof the coins can actually be honoured, counted the hard way.
Liquidity buffer / seasonal adequacy
The reserve’s two named jobs: a demurrage-funded buffer sized in hours-of-cover for redemption spikes; and dry-year adequacy, carried entirely by the hedge and cover standard, never by the buffer. Plainly: a cash-drawer for busy days, and insurance for bad years — two different things, never confused.
Coin book / contract book
The two cover ledgers. Every unit of capacity or hedge notional is pledged exclusively to one: the coin cover pool, or a single named contract series. Plainly: nothing backs two promises at once.
Exclusive pledge
The rule that cover assets appear in exactly one book — auditable by registry lookup, with no dual-use haircut regimes. Plainly: one wind farm, one promise.
Growth gate
Contract open interest may not grow unless the coin book has been Fully backed for a published dwell time. Plainly: the professionals’ product doesn’t expand while the households’ product is stressed.
Forward claim / dated firm contract
A named, dated, project- or tenor-specific right to future energy — the Part III family. Transferable forms are restricted to eligible counterparties until S3; contracts may settle in joulemarks from escrow or market purchase but are never minted at settlement, and are never money. Plainly: a contract for future power — an investment for professionals, not coins.
Demurrage
A small, published carrying charge on held joulemarks, equal to the audited physical cost of standing ready to honour them; funds the liquidity buffer. Never applies to mutual-credit positions; escrowed coins still decay. Plainly: a storage fee, like a warehouse charges — because standing ready costs real money.
True-up account
The per-minter account through which provisional-settlement minting is reconciled at final wash-up; deficits are a first claim on the minter’s bond and a logged failure event. Plainly: if early data over-paid a minter, the correction comes out of their bond, not everyone’s money.
Locational marginal price
The wholesale price of electricity computed at each grid node, reflecting generation cost, congestion, and losses. Plainly: what power actually costs right here, right now — published by the grid itself.
Nodal basis
The published price relationship between grid locations, used to translate a claim at one node into its honest value at another. Plainly: the exchange rate between places on the grid.
Demurrage-funded reserve
See liquidity buffer. Held on trust for holders (provisional custody tier at S0, labelled). Plainly: the emergency stockpile, legally ring-fenced so it’s yours, not the company’s.
Conformance states (Fully backed → Default)
The §4.5 state machine: Fully backed, Soft stress, Hard shortfall, Default — entered and exited by published formula with hysteresis and dwell times, each with defined obligations. Plainly: the system’s health states, with automatic rules instead of emergency meetings.
Stages S0–S3
The regulatory staging ladder: S0 closed own-bill loop (no transfer), S1 licensed local transfer, S2 multi-redeemer wholesale participation, S3 forwards markets. Each stage’s activities wait for its licence. Plainly: crawl, walk, run — with the paperwork done before each speed.
Provisional conformance
The §5.1 tier for federations whose settlement-data access is incomplete: lower caps, shorter audit intervals, identified wallets, and a published upgrade deadline. Plainly: allowed to operate, with training wheels and a deadline.
Mutual credit
Network-issued bilateral credit within published, evidence-based trust limits; positions carry settlement deadlines, never demurrage. Plainly: the community tab — vouched, capped, and settled by a date.
Attribute certificate
A registered, tradeable attestation of how energy was produced (the REC pattern), separate from the coin. Values price in certificates; the mint stays blind. Plainly: the “how it was made” label, sold separately from the money.
Conformance mark
Certification that a federation meets this specification’s measurement and cover requirements. It certifies physics, never politics; bridges refuse unmarked federations and follow their own jurisdiction’s law. Plainly: the “real, audited energy money” stamp — about measurement, not about whose side anyone is on.
Appendix C

Lineage & further reading

This design assembles a century and a half of prior thought. In roughly chronological order:

  • Richard Cantillon, Essai sur la nature du commerce en général (c. 1730) — who benefits from money creation, and in what order.
  • Silvio Gesell, The Natural Economic Order (1916) — demurrage, the liquidity premium, money that circulates because it decays.
  • Henry Ford, energy-dollar proposal (1921) — currency backed by kilowatt-hours as an alternative to gold.
  • Technocracy Inc. (Howard Scott, M. King Hubbert), energy certificates (1930s) — continental energy accounting as a monetary system.
  • Wörgl experiment (Austria, 1932) — demurrage currency field-tested; terminated by assertion of the central bank’s note-issuing monopoly, not by economic failure.
  • WIR Bank (Switzerland, 1934–present) — mutual credit at national scale, counter-cyclical for ninety years.
  • John Maynard Keynes, General Theory ch. 23 (1936) — the serious hearing for Gesell; “the euthanasia of the rentier.”
  • Buckminster Fuller, energy-wealth accounting (1969–1981) — all wealth as organised energy.
  • Albert Hirschman, Exit, Voice, and Loyalty (1970) — why credible exit keeps institutions honest.
  • Islamic finance (classical, ongoing) — risk-sharing instruments in place of fixed interest.
  • Locational marginal pricing (Schweppe et al., Spot Pricing of Electricity, 1988) — the grid’s own map of energy value in space and time.
  • Elinor Ostrom, Governing the Commons (1990) — design principles for commons governed without kings or privatisation.
  • Chris Cook, Energy Clearing Union proposals (2000s–2010s) — an international unit redeemable in energy, developed by a former International Petroleum Exchange director; the most complete pre-blockchain articulation of an energy standard, and a direct ancestor of this document’s monetary core.
  • Donella Meadows, Thinking in Systems (2008) — balancing and reinforcing loops; leverage points.
  • Bitcoin (Nakamoto, 2008) — the proof that non-state digital money is possible, and the cautionary tale of fixed supply, proof-of-work, and re-centralisation.
  • Ethereum’s Merge (2022) — consensus without the burn: a ~99.95% energy reduction in production, at scale.

C.1  A note on the name

“The Joule Standard” as a phrase predates this document — notably as the title of a 2013 essay in the resilience literature arguing that a mechanised economy already runs on an implicit joule standard — and “energy standard” has been used both by Chris Cook’s clearing-union work and, more recently, by Bitcoin advocates arguing that proof-of-work already constitutes one. This specification inherits the phrase knowingly and with attribution. The claim made here is not to the idea’s paternity — the lineage list above is the paternity — but to its most complete engineering to date: a deployable protocol with a minting mechanism, a firmness oracle, obligor and shortfall law, a stability layer, and a governance constitution — with the honest caveat that the measurement institutions those interfaces require remain unproven in operation (Part VIII).

The following projects are the nearest neighbours as of mid-2026, listed with the specific design choice that separates each from this standard. Their existence is evidence the territory is real; their gaps are why this document exists.

  • E-Stablecoin (Lawrence Livermore National Laboratory, 2022) — a peer-reviewed proof-of-concept for a token minted with, and burnable back into, one kilowatt-hour, secured by statistical mechanics. The closest intellectual ancestor of the monetary core, and independent validation that physicists find the peg mechanism sound. It remained a theoretical paper: no treatment of fungibility, firmness, governance, or deployment.
  • SolarCoin (2014–present) — mints one token per verified solar kilowatt-hour. A reward token rather than a currency: uniform mint rate regardless of firmness or location, no burn-on-redemption, and a freely floating speculative price — the design this standard’s conservation loop and firming discount exist to correct.
  • Daylight / DayFi (GRID, sGRID) (2025–present) — a well-capitalised, live protocol financing distributed solar through DeFi. Its GRID stablecoin is pegged to the US dollar (Treasury-backed), and sGRID pays investors a yield from electricity revenue. It solves the financing problem this standard’s Part III addresses — but as dollar-denominated investment yield. It is the clearest live demonstration of the model this specification rejects: energy as an asset class for investors rather than a monetary standard for users, with issuance economics accruing to insiders.
  • Powerledger, Energy Web, WePower (2016–present) — mature platforms for tokenised renewable certificates, peer-to-peer energy trading, and fractionalised power purchase agreements. Working proof that the attribute-certificate markets of Part VI function at scale. None carries unit-of-account ambition, an elastic monetary core, or a governance constitution.
  • EU energy communities (2018–present) — citizen and renewable energy communities under the EU’s Electricity Market and Renewable Energy Directives: legislated legal vessels for collective generation, sharing, and peer-to-peer trading, live across several member states. Settlement remains in euros — energy is netted and traded, never spent as money — but these entities are structurally federations awaiting a monetary layer, and constitute adjacent infrastructure rather than competition (§7.1).
  • Grassroots Economics / Sarafu (Kenya, 2010s–present) — blockchain mutual credit with demurrage across tens of thousands of small businesses; field evidence for the Part III and Part IV mechanisms in an economy where they matter most.
  • Circles UBI (Berlin) — mutual credit with 7% demurrage whose flagship pilot failed when participating businesses converted ~90% of balances straight to euros: the velocity-mismatch failure (FM-1) documented in the wild, and the empirical case for this standard’s sink-before-faucet ordering rule.
  • Chris Cook’s Energy Clearing Union (2000s–2010s) — see the lineage list; the design exists in essays and interviews but was never given a protocol, an implementation, or an anti-capture constitution.

Summary of the gap this document fills: every component above exists somewhere, tried by someone, usually in isolation. No prior project combines proof-of-generation minting, claim standardisation with nodal basis, burn-on-redemption, financing without debt, physically derived demurrage funding a rule-bound reserve, and a written anti-capture constitution — while refusing issuance profit. The contribution is the assembly, and the discipline.

Appendix D

Sustaining development

Open projects that stay silent about money invite suspicion, so this appendix states the position plainly.

The authors and maintainers of this specification will never hold an issuance interest. No founder allocation, no pre-mine, no percentage of minting, no token sale — in this protocol or in any conformant currency. The design’s central claim is that nobody owns the spigot; its authors do not get an exemption. Any project presenting itself as the Joule Standard while granting its creators an issuance interest is, by that fact alone, non-conformant.

Development is sustained the way open infrastructure has always been sustained — downstream of the standard, never inside it. Nobody owns TCP/IP; companies sold the routers. Nobody owns Linux; support and services built durable businesses on it. Legitimate models around this protocol include: deployment software and hosted services for federations; independent reconciliation auditing and conformance certification (never both, for the same client — auditor independence is the point); operating or advising anchor retailers; and consulting, research, and education. A Joule Standard Foundation — funded by member organisations on the open-standards model — is the intended long-term home for the specification, the conformance mark, and salaried maintainers, so that no private party ever owns the movement’s name or its rulebook.

The distinction to hold onto: earning money by making the standard work is honest; earning money from the creation of the money is the disease this document exists to cure.

In plain terms

The people who wrote this don’t get free coins — not now, not ever, not even a little. They earn a living the same way a good electrician does: by being useful, not by owning the electricity.

Appendix E

Worked example: mutual credit, demurrage, and redemption in one month

Prose glides; numbers catch bugs. This thirty-day sequence exercises every interaction between the monetary core (Part II), mutual credit (§3.2), demurrage (§4.2), and the fiat drain (§7.1). Actors: a café with rooftop solar, a bakery, a plumber, and the anchor retailer. Demurrage is illustratively 4% per annum (≈0.33% per month); the FDO factor for the café’s injection class is illustratively 0.6.

  • Day 1 — Mint. The café exports 500 kWh of midday solar. The FDO factor for this class is 0.6 — a factor that already internalises intermittency and delivery losses for the class — so 300 JM are minted to the café against the retailer’s audited settlement cover. The cover invariant is checked at mint: outstanding coins remain below audited hedge plus reserve.
  • Day 5 — Mutual credit created. The plumber repairs the bakery’s oven and invoices 100 JM. No coins move and none are minted: matching entries appear — plumber +100, bakery −100 — inside the bakery’s network trust limit. This credit is not firm energy and confers no redemption right.
  • Day 12 — Settlement in coins. The café buys 80 JM of bread, paying in held joulemarks. The bakery now holds 80 JM (an asset) against its −100 credit position, and uses all 80 to settle: the plumber receives 80 JM, and the credit pair shrinks to plumber +20 / bakery −20. Note what happened: converting credit into redeemable coins required someone (the café) to supply coins — rule (iv), the mint was never touched.
  • Day 20 — Demurrage ticks. Monthly demurrage (0.33%) applies to long balances only: the café’s remaining 220 JM pays ≈0.73 JM to the reserve; the plumber’s 80 JM pays ≈0.27 JM. Neither side of the credit pair decays: the plumber’s +20 is a claim on the network (nobody stands ready to deliver against it) and the bakery’s −20 is an obligation, not a hoard — instead, the −20 carries a settlement deadline within the bakery’s trust limit (rule i, §3.2). Total demurrage revenue (≈1 JM) flows to the liquidity buffer.
  • Day 25 — The sink. The café pays its 150 JM power bill. The retailer burns 150 JM: outstanding supply falls, delivery capacity is freed, and the conservation loop closes. The bakery, holding no coins, earns 25 JM selling bread to the plumber — settled net: 20 JM of the price extinguishes the existing credit pair (both positions return to zero) and only the residual 5 JM changes hands as coins, which the bakery puts toward its own bill. (Implementers: book the netting, not a 25 JM transfer plus a separate credit clearance. Figures throughout are shown pre-rounding; the café’s post-demurrage balance is ≈219.73 JM, displayed as 220.)
  • Day 30 — The fiat drain. The bakery owes GST on its joulemark revenue and files its return as normal — its accountant, its numbers, nothing new. At payment time it instructs the retailer: settle the filed liability, debit coins at par. The retailer remits fiat directly to the tax authority against the bakery’s tax account and burns the coins (FM-4’s direct drain — the bakery never receives fiat, so there is no conversion window to run on). End state: every credit position extinguished, ≈1 JM in the reserve, burned coins re-mintable only against the next verified injection, and no balance anywhere that decayed when it shouldn’t have or survived when it shouldn’t have.

Design decision — demurrage on held coins only. Two alternatives were considered and rejected. Symmetric decay (both sides of a credit pair) hands debtors a windfall for delay and incentivises running maximally negative. Decay on positive credit positions only — this document’s own earlier rule — fails differently: it breaks pair conservation (the network’s books stop summing to zero) and taxes a claim nobody is standing ready to deliver against. Demurrage is the storage invoice for readiness, and readiness exists only behind coins; mutual-credit positions carry trust limits and settlement deadlines instead. Two independent adversarial reviewers caught the earlier rule’s arithmetic failing in this very appendix — the numbers did their job.