| Term | Definition |
|---|---|
| Bao | The BLAKE3 verified-streaming encoding used for all delivery. Interleaves content with hash proofs so any requested range verifies against the root once aligned to its enclosing 16 KiB chunk-group boundary. |
| Blob | A content-addressed byte sequence. Every blob is identified by its hash; clients verify received bytes against the known hash. |
| Bond (capacity) | TOKEN locked in CapacityBond proportional to a node’s declared bandwidth (bond = k × Mbps^α) — the only TOKEN-side requirement to join the mesh; the bond scales with declared capacity rather than a flat minimum. Returned on deregistration after an unbonding period. |
| Capability | An owner-signed authorization letting one key spend up to a cap from a pool until an expiry. Node-agnostic — valid at every node — and registered on-chain once, on that signer’s first redemption. |
| Chain root | The head of a hash chain committed in a voucher. The payer releases one preimage per megabyte delivered, advancing the amount owed without another signature; a preimage proves its own position by hashing forward to the root. |
| Client | A lightweight QUIC endpoint that streams content and pays per MB. No stake, no on-chain registration, no network role. |
| Coverage | Which 64 MiB blocks of a blob a holder will serve, carried as a bitmap in DHT records and probe responses. Lets a requester route a wanted range to a holder that actually has it. |
| Credit window | The unpaid balance a node will carry on one lane before it pauses delivery. Starts at a floor and ramps as the lane pays, bounding what a non-paying counterparty can extract. |
| DHT | Kademlia-subset content discovery. Nodes self-publish records, with coverage, when caching a blob. |
| Full holder | A node caching a complete blob, as opposed to a partial holder caching only some blocks. Both are eligible sources for a multi-source fetch. |
| Hash sequence | An ordered collection of blob hashes (a directory or manifest equivalent). |
| Lane | The payment relationship between one signer and one node: an independent running total with its own watermark, hash chain, and credit window. A pool backs many lanes at once. |
| Multi-source fetch | Fetching one large blob from several holders in parallel, each serving disjoint segments, up to a configurable maximum (max_sources) and at most one node per operator. Each source is an ordinary paid stream — no new wire protocol. |
| Namespace | A publisher-owned identifier for a content set, and the unit of origin addressing. A request pairs it with the blob hash; the default namespace names no publisher and no authorized origins. |
| Node | A bonded QUIC endpoint that caches and delivers blobs. Some are origin-backed; others are pure caches. |
| Origin-backed node | A node configured with an S3-compatible store, NFS mount, or local disk — the canonical source for specific blobs. Never experiences a true cache miss for blobs in that store; for anything else it is a cache node. |
| Origin backend | The opaque storage behind an origin-backed node (S3, R2, B2, MinIO, NFS, local disk). Never exposed to the network. |
| Outboard | A blob’s BLAKE3 hash tree, stored separately from its content. An origin-cold node must import or build the outboard before it can serve verified ranges. |
| Payment chunk | The payment quantum: 1 MiB, a protocol constant. One released preimage pays for exactly one chunk. Distinct from the 16 KiB bao chunk group, which is the unit of verification. |
| Peer mesh | The flat set of all bonded nodes. Membership comes from the on-chain registry’s active set; content location comes from the DHT. |
| Pool (payment) | One on-chain USDC deposit that backs off-chain vouchers from many capped signers to many nodes. Opened once by its owner and reused; the owner reclaims the unspent remainder at close, after a grace window that lets nodes redeem first. |
| Probe | Parallel latency, availability and coverage check that runs before any delivery commitment. Its signed fields are on-chain slash evidence. |
| Publisher | An address that owns at least one namespace. Once governance has vetted the publisher wallet, it seats and unseats the origin operators for its own namespaces directly. |
| Segment | A contiguous, verifiably-aligned byte range assigned to a single source during a multi-source fetch. Independently verifiable, so it can be split or reassigned without re-reading from the start. |
| Selection score | The ranking a node uses to pick an upstream holder on a cache miss, combining advertised price, observed latency, and its local reputation score. Lower is better. Clients do not use it: they rank by measured round-trip time alone. |
| Slashing window | The 30 seconds for which a node’s last probe-quoted rate is binding. A stream opened inside it must be served at or below that quote; serving higher is slashable. |
| TOKEN | The deCDN bonding/governance token: locked as a node’s capacity bond and burned by the buyback sink. Not used for payments; governance weight comes from delivered bytes, not TOKEN balance. |
| USDC | The payment currency for all delivery. Fixed at deployment; pools deposit, voucher, and settle in USDC. |
| Voucher | A signed off-chain payment message naming its payee node and carrying a cumulative amount owed. The highest amount settles; a re-submitted voucher pays zero. |
Overview
Glossary
Definitions for the core deCDN terms — bao verified streaming, blobs, capacity bonds, payment pools, vouchers, namespaces, probes, nodes, and clients.