Skip to main content

The operator network

ZeroSignal doesn't run the AI models you talk to. They're served by operators: independent parties who run inference hardware and sell its output on an open network.

If you want to run a node, start at What is an operator.

What an operator is​

An operator runs the node software in front of an AI backend and registers on-chain: their payout address, the public key their node signs with, the endpoint to reach it, and optionally a human-readable name. Their node advertises the models they serve and the prices they charge, and the model picker shows them live.

There's no application process and no gatekeeper: the registry is a smart contract. Anyone can register an operator, and any user can transact with any operator (see Why use crypto?).

How a request is paid​

Neither side has to trust the other:

Quote​

Before sending, your client asks the operator for a signed ticket stating the maximum price for the request. The operator can't raise the price afterward.

Escrow​

That maximum is locked in the escrow contract on-chain. The operator can see the funds are real but can't take them yet.

Receipt​

After the response streams back, the operator signs a receipt stating the actual tokens used and the actual amount charged.

Verification​

Your client checks the receipt before settlement: the signature must match the operator's on-chain key, the amount must not exceed the ticket's maximum, and a hash in the receipt must match the response you received.

Settlement​

The escrow pays the operator its charge in full, sends the protocol fee to the treasury, and refunds the rest to you. You pay the fee on top; it isn't taken from the operator's charge. The result is final on-chain.

So the per-message cost in the app isn't an estimate. It's an operator-signed amount your client verified, under a ceiling you saw up front.

What you trust, and what you verify​

Verified by your client, automatically:

  • The price ceiling: an operator can never charge more than the ticket said.
  • The receipt signature: charges come from the operator's registered key.
  • Response integrity: the receipt is bound to the bytes you received.
  • The encryption keys: the key your prompt is sealed to is signed by the operator's on-chain identity, so a relay can't substitute its own.

Trusted, with skin in the game:

  • Prices are set by each operator, but the receipt check means an operator can't charge you more than it quoted. Latency isn't advertised: it's recorded on-chain from settled requests.
  • The answering node decrypts your prompt to run the model. On a standard node its operator could read the prompt while the model runs; on a confidential (TEE) node it is decrypted only inside attested hardware the operator can't read. See What the operator can see. Confidential nodes are live but not the default.
  • Either way, the operator doesn't learn who you are: it sees only a pseudonymous payer address, and by default requests arrive through a relay.

Relays​

Every operator node also acts as a relay for other operators. By default, your request reaches its target through one relay hop:

  • The relay sees your IP address but can't read the request: the envelope is sealed to the target operator's key.
  • The target operator never sees your IP address, only the relay's.
  • Each request uses a fresh relay, never owned by the target's owner, so no single operator sees both who you are and what you asked. See how relays get chosen.
info

If no eligible relay is available for a target, the app refuses to send directly. It fails closed rather than expose your address.

Health and compatibility​

The app continuously probes every registered operator: whether it's reachable, what it serves, and whether it speaks a compatible protocol version. Unreachable or incompatible operators are flagged in the picker and skipped by Auto mode, so requests go only to nodes that can answer them.

Running an operator​

If you run AI hardware, you can sell inference on it by running a node and registering on-chain. See What is an operator to get started, and operator.zerosignal.ai to register. It's also the public directory of everyone already serving.