How the network works
As an operator you sell inference into an open market.
Discovery: you advertise, clients choose
Your node publishes a public details document listing the models it serves, their prices, and its capabilities (see Serving models & pricing). Clients read it, along with your on-chain record, to build a live catalog. There is no central index that can delist you and no ranking you pay into. Clients discover every registered node and choose on price, capability, and measured performance.
The same model is usually served by several operators. The network keeps each node's time to first token and decode throughput on-chain as rolling averages, and faster, cheaper nodes get picked more often, including by users' Auto mode. See Health & compatibility.
Payment: paid per request, with a price you set
Each request is paid for separately. The price is agreed before any work, and the charge can be verified afterward:
- A client asks your node to reserve, and your node returns a signed ticket stating the maximum price for the request. You can't be made to serve below your price, and you can't charge above the ticket afterward.
- That maximum is escrowed on-chain, and your node confirms the escrow before serving.
- You run the model, stream back the reply, and issue a signed receipt stating the actual tokens used and the actual charge.
- On settlement the escrow pays your charge, refunds the rest to the user, and takes the protocol fee.
The payment flow covers the two-phase settle and the dispute path.
Trust: secured by signatures and stake, not by reputation alone
Neither you nor your users have to trust each other. The protocol relies on three things:
- Signatures. Your node's on-chain key signs your tickets and receipts. A client checks each receipt's signature, its charge against the ticket's ceiling, and its binding to the exact bytes received, and rejects a forged or inflated charge before it settles.
- Escrow. A smart contract locks the funds before you work and releases them at settlement. If the two sides disagree, the ticket freezes for off-chain arbitration instead of paying out.
- Stake. Registering locks a USDC stake, which is at risk if you misbehave. See Staking & economics.
Privacy: you serve prompts, not people
In standard mode, your node decrypts the prompt it serves. In confidential mode
(tee.mode), only the attested CVM holds the key (see
Confidential compute). Requests normally reach you
through a relay — another operator's node — so you see the relay's address,
not the user's, and no identity is attached beyond the payer's pseudonymous
on-chain address. A user who turns relaying off connects to you directly.
Your node relays for others in turn. A relay is never owned by the same operator as the target, so no single operator sees both who a user is and what they asked. See Relays.
What you control
- Which models you serve and under what content policy.
- Your prices, per model and per route (text, images, in-loop image tools).
- How many nodes you run, and which are staging vs. production.
- When you're available — take nodes down freely; the network routes around unreachable nodes and probes for your return.
What the protocol enforces
- You can't charge above the ticket you signed.
- You can't read a request that wasn't sealed to your key, so you can't read traffic you relay.
- You can't register or serve without a stake at risk.
Quick start takes you from nothing to a registered node serving its first paid request. It begins at the operator dashboard, operator.zerosignal.ai, where you add yourself as an operator and add your nodes.