Skip to content

Latest commit

 

History

285 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Prism Network

Validate OpenSSF Scorecard License Headless agent SDK MCP + x402 Wallet-signature auth

Prism Network is open infrastructure for metered GPU compute. The current system implements account and wallet onboarding, GPU offer discovery, USDG escrow, workload provisioning, time-limited access, metering, settlement and public receipt generation.

Prism has two execution paths:

  • Independent nodes: Ubuntu 24.04 x86-64 hosts run public OCI images in Kata VM-backed containers with exclusive NVIDIA VFIO passthrough. Access uses short-lived SSH or Jupyter credentials through an outbound-only mTLS tunnel.
  • Vast broker: a bonded broker provisions disposable instances across several NVIDIA classes and exposes direct SSH. This path relies on provider-reported readiness and evidence; it does not provide Kata/VFIO isolation, the Prism gateway, or Jupyter access.

All capacity served today comes from the broker path. prismd is not running on any host and no independent node is enrolled, so the isolation the independent path describes is written and tested but never reaches a customer.

Interactive raw GPU leases are what the network serves today, and a renter can end one early to stop the meter. A lease can also carry commands instead of a session, which the broker path runs and reports back. Managed inference runs as a separate pay-per-call endpoint.

Current state

Verified on 2026-09-07:

Area Status
Public web and API Live at prismnetwork.tech; online offers fluctuate between one and three
Robinhood Chain contracts Deployed on mainnet; the lease escrow is live and settling
Vast execution Live on mainnet, funded, with settled leases and published receipts
Independent Kata nodes Daemon, gateway, certificates, commands, tunnel and workspace lifecycle are implemented and integration-tested without physical GPU hardware; no node is enrolled
Settlement and proof Live; settlement receipts are published at prismnetwork.tech/proof
Early lease release Live; POST /v1/leases/{id}/release stops the meter and returns unused escrow
Batch commands Live on brokered capacity through the reproducible-run path; the independent-node command channel has never run on physical hardware
Managed inference Live; two models on the open tier and nine on the confidential tier, paid per call over x402

The contracts have not received an independent audit and the escrow caps are set low deliberately. Size any deposit accordingly.

What a supplier protects is stated per offer rather than as one blanket warning. Every offer, quote, lease and receipt carries a trust class (open, isolated, attested or confidential), and renters can require a minimum instead of trusting prose:

curl https://api.prismnetwork.tech/v1/offers?min_trust=isolated

The class is derived by the control plane from evidence it can check, never asserted by a supplier, and it is clamped to what the network can currently verify. isolated requires a GPU attestation report that validates to a pinned NVIDIA root and answers a challenge issued to the node presenting it, so a machine cannot claim that class for itself. attested requires a launch measurement of the guest that ran the lease, verified to AMD's root and bound to the SSH host key generated inside that guest, so the proof is about the session the renter is in. It proves what started and not that nobody watched. All capacity live today is open, which means the host operator can read anything the workload touches, and nothing above it is served until the reference material both classes check against is captured from real hardware and verifies. See docs/ATTESTATION.md for what is checked and docs/SECURITY_MODEL.md for what each class does and does not promise.

Private data does not have to live in a workspace to be useful. Cards, identity documents and credentials go in the vault, sealed on your machine under a key derived from a wallet signature and never sent, so Prism stores ciphertext and holds no way to read it:

await agent.vault.unlock();
const card = await agent.vault.put({ pan: "4111111111111111" }, { label: "billing" });

Every item carries the weakest class of workspace it may be shown to, and new items default to confidential — above what the network can serve — so handing one to today's capacity is refused rather than quietly allowed. The account, version and trust floor are authenticated into the ciphertext, which makes moving an item, replaying an old version, or lowering its floor a failed decrypt instead of a successful lie. docs/VAULT.md has the construction and its limits.

Mainnet contracts

The V1 contracts are non-upgradeable and LeaseEscrowV1 is live. They have not received an independent audit. Blockscout reports NodeRegistryV1 as fully source-verified and LeaseEscrowV1 as partially source-verified. The escrow's executable bytecode matches this tree, while its trailing Solidity metadata hash differs.

You do not have to take that on trust. ./scripts/verify-deployed-bytecode.sh rebuilds both contracts and compares them against the code live on chain using only the public RPC, masking immutables and reporting the metadata blob separately:

NodeRegistryV1 0xe3b7…8f01: executable code matches, metadata differs
LeaseEscrowV1  0x71Df…cDeD: executable code matches, metadata differs
Contract Address
Canonical USDG 0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168
NodeRegistryV1 0xa7Ca8e43c599b978095c391bd018A35BA6e7B71D
LeaseEscrowV1 0xfD4228eEEfC49e4b76A0CD40af9fdd546220B2FD
Governance Safe 0xAF1113cE9E65D79daA87005A729Ab9Bc1A9fc60a

Administration, emergency pause and dispute resolution are held by a 2-of-2 governance Safe. Network settings and the USDG address should always be checked against the official Robinhood Chain documentation and contract registry.

Architecture

Browser + wallet
       |
       v
Next.js web -----> Rust control plane -----> PostgreSQL
                         |
              +----------+-----------+
              |                      |
              v                      v
      lifecycle worker       settlement/proof workers
              |                      |
       +------+-------+              v
       |              |       Robinhood Chain
       v              v
Vast instance    access gateway
direct SSH       mTLS tunnel/relay
                       |
                       v
               prismd + Kata/VFIO

The repository contains:

  • apps/web: Next.js account, marketplace, supplier, operator and proof UI.
  • crates: shared Rust protocol and persistence libraries.
  • services: Rust control plane, access gateway and operations monitor.
  • workers: lifecycle, settlement and proof workers.
  • node/prismd: independent-node runtime and workspace supervisor.
  • contracts: PRISM bond, USDG escrow and administration contracts.
  • sdk: headless agent SDK for wallet-signature USDG leasing.
  • mcp: Model Context Protocol server exposing leasing to MCP clients.
  • x402: pay-per-job GPU execution over HTTP 402.
  • inference: managed inference, a warm ollama lease behind an x402-paid endpoint.
  • integrations: LangChain, CrewAI, AG2/AutoGen, elizaOS and Virtuals GAME adapters.
  • examples/trading: agents that rent a GPU for research, then trade on what it finds.
  • examples/confidential: an agent pays for TEE-served inference and verifies the attestation itself.
  • deploy/ec2: lean Vast launch topology with the web application on Render.
  • deploy/lightsail: full single-host reference topology.
  • deploy/node: Ubuntu node service units and configuration.
  • infra: an AWS reference architecture, not the active lean deployment.
  • docs: design, security boundary, proof format and release documentation.

See architecture, security model and release gates before operating the system.

Agent access

Autonomous agents integrate without a browser. An agent proves control of its funding wallet by signing a short-lived challenge, exchanges it for a bearer session, and drives the same renter surface — offer discovery and the lease lifecycle — over the /api/agent endpoints. Escrow, readiness, metering and settlement are identical to the browser path, and the agent boundary reaches only renter routes.

  • sdk — @prismnetwork/agent-sdk, headless USDG-funded leasing for Node.
  • mcp — @prismnetwork/mcp, the same leasing exposed as Model Context Protocol tools.
  • x402 — @prismnetwork/x402, pay-per-job GPU execution over HTTP 402.
  • integrations — the same tools in the dialect of LangChain, CrewAI, AG2/AutoGen, elizaOS, Virtuals GAME and Coinbase AgentKit, plus how to pair Prism with Robinhood's agentic trading MCP.

The Node and Python packages are published under the @prismnetwork npm scope and as prismnetwork/prism-* on PyPI. An agent workspace is still a disposable environment, not confidential computing; anything an agent needs to keep private belongs in its vault, which the same SDK reaches through agent.vault.

Verification

The fast pull-request gate checks the web application, production build, secrets and repository isolation:

pnpm install --frozen-lockfile
pnpm check

The full local gate additionally runs the Rust and Solidity suites, audits and security scanners, PostgreSQL and Valkey integrations, Anvil lifecycle tests, mTLS relay tests, load and recovery checks, deployment validation and observability checks:

pnpm check:full

The full gate passed locally on 2026-07-20 with 23 web tests, 57 Rust tests and 18 Foundry tests, including fuzz and invariant coverage. That run used simulated/containerized infrastructure; it is not evidence of physical NVIDIA/Kata/VFIO execution or a funded mainnet lease.

The hosted full gate is manual and has not yet produced a public run:

gh workflow run full-validate.yml --ref <branch>

Required toolchains are Node.js 24.14, pnpm 10.34.5, Rust 1.94.1, Foundry 1.5, Docker with Compose and ripgrep.

Remaining release gates

Funded mainnet leases now settle end to end and their receipts are public, so the deposit-through-settlement gate and the first-receipt gate are closed. What is still open:

  • Validate CUDA readiness, Kata isolation, VFIO assignment, egress controls and teardown on physical NVIDIA hardware, which no enrolled node has done.
  • Complete live KMS signing and failure-recovery evidence for lifecycle and settlement workers.
  • Exercise real Privy signup, external and embedded wallets, SSH access and Jupyter access against the release deployment.
  • Test the independent daily digest outbox.
  • Run applied-host backup/restore, load, failover and incident-response drills.
  • Obtain independent smart-contract and infrastructure security review before raising contract caps.

Copy only the example environment files needed for your target. Never commit environment files, credentials, deployment outputs or generated artifacts.

Contributing

Read CONTRIBUTING.md, the Code of Conduct and governance before opening a change. Security reports must follow SECURITY.md and must not be filed as public issues.

License

Code is licensed under the Apache License 2.0. The Prism Network name and visual identity are governed separately by TRADEMARKS.md.

About

Marketplace, control plane and proof infrastructure for metered GPU compute

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages