Skip to main content

System diagram

Participant roles

See Participants for a deeper breakdown per role.

Life of a paid delivery

  1. Client bootstrap — client generates a keypair, queries the on-chain registry for the active node set, and caches it.
  2. Discovery — the client takes candidate nodes from its own peer store or the registry; it runs no DHT lookup. A parallel probe confirms which of them will actually serve the wanted range, and how fast they answer. A fresh peer store lets the client skip the probe entirely.
  3. Selection — the client ranks holders by measured round-trip time alone. Price is not a rank key: the client pays the rate the node signs and can refuse a quote above a ceiling of its own. The client keeps no reputation score.
  4. Payment — the client pays from a USDC pool it opened once, off the fetch path, and reuses for every node (payments).
  5. Streaming + vouchers — node streams to the client; client signs a cumulative voucher and, on an optional hash chain, releases one preimage per 1 MiB chunk as bytes flow.
  6. Cache-miss fan-out — if the node doesn’t have the blob, it pulls from other holders (paid). Every byte delivered in the network is paid.
  7. Redemption — the node redeems its own vouchers on-chain whenever it likes; the owner closes the pool to reclaim the unspent remainder.

Key invariants

  • No external origin URL exists — content enters the network through origin-backed nodes whose backends are hidden.
  • A node cannot earn without delivering verifiable bytes — hash mismatch voids payment.
  • A node cannot join the mesh without bonding — registration enforces a capacity bond (bond = k × Mbps^α) scaled to declared bandwidth, rather than a flat minimum.
  • A node cannot register an identity it does not control — both keys must sign at registration.
  • Safety bounds on all governable parameters are hardcoded — governance cannot set fees to 100% or push the operator revenue share below its floor.
  • Being recognized as an origin is gated on-chain — governance vets a publisher wallet, and the vetted publisher seats its own origin operators per namespace. Configuring an origin backend locally without being seated means the node’s bytes are served only as cache.
  • A node cannot serve a blacklisted hash after the compliance window — doing so is slashable.