Skip to content
Thenar

How it works

A funder escrows USDG for a robot task. You drive the SO-101 in your browser. The run is paid by a contract on Arbitrum Sepolia, not by us, and only after the checks below agree. Every corpus sale then pays USDG into the corpus shares the paid runs earned.

Who checks what
WhoWhat it doesWhat it cannot do
AxonProtocolV3 (the escrow)Holds each task's USDG. Pays a run only if the verifier signed its score, the operator's own passkey signed that exact run, the recording matches the hash that was scored, and the physics judge accepts it. Caps each account at 5 paid runs per task, refunds the funder at the deadline.Move escrow anywhere except to an operator for a checked run, or back to the funder.
RunJudge (Stylus)Replays the recording's physics on chain: the SO-101's forward kinematics, the payload moving only in a closed jaw near the tool, the right start, and the final placement within the goal radius.Be switched off once it is set on the escrow.
Your passkeySigns the exact run you are being paid for (Face ID, a fingerprint or a PIN). Checked on chain.Be used by anyone without your device. Nothing about you leaves it.
The verifier (our signer)Scores the run with the same code the station uses and signs the score, the run's hashes and an expiry.Pay a run on its own: without your passkey and the judge the escrow refuses it.
The relayer (our server)Submits what you signed and pays the gas, so you never need ETH.Change what you signed. A changed task, amount or run fails the signature check on chain.
What the physics judge can refuse
1 · START
The payload didn't start where the task puts it
2 · UNCARRIED
The payload moved with no jaw on it
3 · CLOCK
The recording's clock went backwards or ran too fast
4 · TOO_SHORT
The recording is too short
5 · MISSED
The payload missed the goal
6 · MALFORMED
The recording could not be read
Contracts on Arbitrum Sepolia

6 of 6 deployed.

Task escrow in USDG. A funder posts a task with one signature (EIP-3009); a run is paid only when the verifier's signature, the operator's own passkey over that exact run, and the physics judge all agree. Pays the operator, issues their corpus shares, and refunds whatever is unspent at the deadline.

14,710 bytescontracts/src/AxonProtocolV3.solused by /hub, /post, /station, /task, /run, /portfolio, /leaderboard

Binds a device passkey (P-256) to an address, registered by a signature so a relayer can pay the gas, and verifies WebAuthn assertions with OpenZeppelin's WebAuthn library.

Arbitrum Arbitrum's P-256 precompile (RIP-7212) checks the passkey's signature on chain for a few thousand gas.

8,113 bytescontracts/src/PasskeyRegistryV2.solused by /passkey, /station

The corpus as shares, held only by passkey holders and minted by AxonProtocolV3 at each payout. Data sales pay USDG straight into it; anyone can call distribute(), and every holder claims pro rata.

7,829 bytescontracts/src/CorpusSharesV2.solused by /portfolio, /corpus-token, /agents

Every corpus sale to an agent, with the sha256 of the bytes served, so a buyer can check its copy on chain.

1,753 bytescontracts/src/SalesLog.solused by /agents, /api/agent/sales

Replays a run's physics on chain: the SO-101's forward kinematics, the payload moving only in a closed jaw, the right start and the final placement. AxonProtocolV3 refuses to pay a run it rejects.

Arbitrum Written in Rust for Stylus, where checking thousands of samples of fixed-point maths per run is affordable.

9,121 bytesstylus/run-judgeused by /station, /contracts

Global Dollar, Paxos's regulated stablecoin. Every bounty, payout, data sale and dividend here is USDG.

170 bytesPaxosused by everywhere an amount is shown

Source for every contract is in this repository, and each is verified on Arbiscan when it is deployed. /api/contract returns the escrow contract’s address, chain and ABI.