0005. No geoblock workarounds; trading follows the geoblock check
- Status: Accepted
- Date: 2026-09-30
Context
Polymarket restricts trading by location and publishes a geoblock endpoint that reports whether the caller’s location is blocked. The development server for this project resolves to the US (Virginia), and the endpoint reports it as blocked. Read-only public endpoints still work from there. The user trades on Polymarket and must follow its terms and the law where they are.Decision
- The app never proxies, tunnels or relays venue traffic to change its apparent location, and never masks its location in any other way. No code, config or documentation for doing so is added.
- The backend queries the geoblock endpoint (
GEOBLOCK_URL) at startup and every 10 minutes, and logs the result. - Trading is disabled while the endpoint reports blocked. It is also disabled until a
check has succeeded; the API reports
blocked: truein that case. engine/riskchecks the geoblock status on every order, together withLIVE_TRADINGand the SAFE/ARMED switch. The UI state is not a safety control.- The check has no bypass or stub, including for development.
- Development from a blocked location uses read-only public endpoints only.
- Live trading, including the Phase 3 live verification, happens only from a location where the user is permitted to trade. Deployment (Phase 6) targets a server in a permitted region.
Consequences
- On the development server, trading stays disabled by design.
GET /api/healthshowstrading_enabled: falsewith the geoblock details. (Since ADR 0008 these fields are on the authenticatedGET /api/status.) - Trading features cannot be tested end to end with live orders from the development server. Signing and amount math are tested against golden vectors instead, and live verification waits for a permitted location.
- If the machine running the backend moves to a blocked location, trading turns off at the next check, within 10 minutes, without any action from the user.
- If the geoblock endpoint is unreachable at startup, trading stays off until it answers.
Alternatives considered
- Route venue traffic through a proxy or VPN. Rejected. It breaks the venue’s terms, may break the law, and puts the account at risk.
- A development flag that skips the check. Rejected. A bypass can reach production by mistake, and there is no need for live orders from the development server.
- Check only at startup. Rejected. The location of a running process can change, for example a laptop moving between networks.