{"id":"f3a3453d-bd40-421f-a16b-ba710521897c","entityType":"agent","slug":"clawhub-ivaavimusic-x402-compute","name":"x402 Compute","canonicalUrl":"https://www.xpersona.co/agent/clawhub-ivaavimusic-x402-compute","canonicalPath":"/agent/clawhub-ivaavimusic-x402-compute","generatedAt":"2026-10-09T23:35:33.890Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T06:47:25.959Z","emptyReason":null},"description":"This skill should be used when the user asks to \"provision GPU instance\", \"integrate agent pods over an API\", \"create pods for my customers\", \"pod webhooks\", \"pod events\", \"spin up a cloud server\", \"list compute plans\", \"browse GPU pricing\", \"deploy AI machine\", \"one-click GPU running an LLM\", \"deploy a private LLM endpoint\", \"OpenRouter-ready endpoint\", \"agent deploy GPU\", \"spin up my own OpenAI-compatible endpoint\", \"extend compute instance\", \"resize compute instance\", \"destroy server instance\", \"check instance status\", \"list my instances\", \"top up compute credits\", \"check credit balance\", \"run inference on the grid\", \"decentralized inference\", \"OpenAI-compatible API\", \"multimodal embeddings\", \"EmbeddingGemma 2\", \"embed image\", \"embed audio\", \"embed video\", \"mixed media vectors\", \"local embeddings\", \"confidential / TEE inference\", \"list grid models\", \"check grid capacity\", \"Laya\", \"System One\", \"Jev-compatible decisions\", \"typed decision model\", \"private Laya\", \"serve Laya from the node app\", \"run a node\", \"provide compute\", \"become a grid node\", \"node operator\", \"join the grid\", \"stake to run a node\", \"serve a model on the grid\", \"earn from compute\", \"deploy an always-on AI agent\", \"deploy a hosted OpenClaw agent\", \"spin up a ClawPod\", \"agent pod\", \"hosted agent with its own wallet\", \"free agent trial\", \"deploy a processor\", \"sell my code per call\", \"monetize an endpoint\", \"publish a paid API\", \"connect a processor as an MCP tool\", \"back up my agent\", \"agent backup\", \"restore my agent\", \"migrate my agent\", \"agent vault\", \"snapshot my agent's memory\", \"move my agent to a new machine\", or manage Singularity Cloud Network compute. Seven jobs: SGL Machines (GPU/VPS provisioning across Vultr & DigitalOcean), AI Machines (one-click GPU running an LLM — deploy a private OpenAI-compatible endpoint, or join the grid & earn), SGL Grid (decentralized, confidential, OpenAI-compatible inference, multimodal embeddings, plus Laya/System One typed decisions — consume it), Provide Compute (run a TEE node on the grid to serve inference and earn USDC + SGL), and Agent Pods (deploy an always-on hosted OpenClaw agent with its own crypto wallet, memory, preinstalled x402 skills, and owner/platform customization for identity, instructions, and self-check heartbeat prompts — managed or BYOK, tiers, free 24h trial), and Processors (publish your own code as a paid endpoint — buyers pay you directly in USDC via x402, you pay only for runtime; every processor is also a connectable MCP server, so agents, harnesses and LangGraph nodes can call it with just a URL), and Agent Vault (zero-knowledge encrypted backup, restore & migration for OpenClaw/Hermes agents — snapshot an agent's memory and soul, store it encrypted, restore or migrate it to any machine or pod). Pay with USDC on Base, Solana or Arc, USDm on MegaETH, USDG on Robinhood Chain via x402, optional MPP/Mppx, or pre-loaded USD credits. Arc: accepted for credit top-ups AND direct machine/AI-machine provision and extension payments (direct Arc payments floor at $5 — Arc gas is USDC; smaller prepayments go through Arc-funded credits). Includes optional OWS-backed auth and management flows.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 3.8K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s179r9z3n07jxsdszy7pdwqans83tjq8:x402-compute","sourceUrl":"https://clawhub.ai/ivaavimusic/x402-compute","homepage":"https://clawhub.ai/ivaavimusic/skills/x402-compute","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/ivaavimusic/x402-compute","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/ivaavimusic/skills/x402-compute","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":56,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"x402 Compute technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T06:47:25.959Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T06:47:25.959Z","emptyReason":null},"stars":null,"forks":null,"downloads":3800,"packageName":null,"latestVersion":"1.31.0","tractionLabel":"3.8K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T06:47:25.959Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T06:47:25.959Z","lastCrawledAt":"2026-10-09T06:47:25.959Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T06:47:25.959Z","lastVerifiedAt":null,"highlights":[{"version":"1.31.0","createdAt":"2026-10-07T08:19:40.079Z","changelog":"Adds production-ready EmbeddingGemma 2 multimodal embeddings for text, image, audio, video, mixed batches, MRL dimensions, exact billing, failover, and node operation.","fileCount":30,"zipByteSize":110357},{"version":"1.30.1","createdAt":"2026-09-29T08:26:52.805Z","changelog":"Add safe Agent Pod customization for platform builders: API-managed identity, owner instructions, heartbeat prompt, and heartbeat cadence without raw AGENTS.md replacement.","fileCount":28,"zipByteSize":100438},{"version":"1.30.0","createdAt":"2026-09-23T17:49:38.743Z","changelog":"Adds Laya/System One typed decisions, private sealed Laya guidance, and desktop node-app serving instructions.","fileCount":28,"zipByteSize":97426},{"version":"1.29.0","createdAt":"2026-09-16T16:07:40.546Z","changelog":"Arc USDC now pays for machine/AI-machine provisioning and extensions directly (--network arc, EIP-3009 chainId 5042). Direct Arc payments floor at $5 (gas is USDC); smaller prepayments use Arc-funded credits. Credit top-ups unchanged.","fileCount":27,"zipByteSize":93892},{"version":"1.28.0","createdAt":"2026-09-16T15:34:53.568Z","changelog":"Arc mainnet USDC: credit top-ups with network arc (EIP-3009 transferWithAuthorization on chainId 5042, USDC domain v2, $5 minimum since Arc gas is paid in USDC). Signer gains arc in EVM_ASSETS; docs updated across SKILL.md, api-reference and worker-served references.","fileCount":27,"zipByteSize":93712},{"version":"1.26.0","createdAt":"2026-09-09T09:34:43.907Z","changelog":"Editable model prompt: manifest.prompt, read with await SGL.prompt.get(). Editing it costs no new isolate and no daily config change because it is resolved per request rather than baked in. Not a secret.","fileCount":26,"zipByteSize":88339},{"version":"1.25.0","createdAt":"2026-09-08T06:31:00.772Z","changelog":"Processors control plane over a compute API key (x402c_): deploy and manage a processor with no Solana keypair. processors:write is full control of that wallet's processors, delete and secrets included; processors:read is read-only. Documents the two routes a key never reaches, why run() still wants the invoke token, and the three places this is weaker than a Cloudflare token (no expiry, no audit log, delete burns the slug).","fileCount":26,"zipByteSize":87521},{"version":"1.24.0","createdAt":"2026-09-03T12:37:51.230Z","changelog":"Datasets: every row is now checked by a second model and regenerated if it breaks your house rules. Managed jobs use a frontier judge; grid jobs are checked on-network so data never leaves it. Priced separately per 100.","fileCount":26,"zipByteSize":86316}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s179r9z3n07jxsdszy7pdwqans83tjq8:x402-compute","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s179r9z3n07jxsdszy7pdwqans83tjq8:x402-compute` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/ivaavimusic/x402-compute before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T23:35:33.886Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-ivaavimusic-x402-compute/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T06:47:25.959Z","emptyReason":null},"readme":"Skill: x402 Compute\n\nOwner: ivaavimusic\n\nSummary: This skill should be used when the user asks to \"provision GPU instance\", \"integrate agent pods over an API\", \"create pods for my customers\", \"pod webhooks\", \"pod events\", \"spin up a cloud server\", \"list compute plans\", \"browse GPU pricing\", \"deploy AI machine\", \"one-click GPU running an LLM\", \"deploy a private LLM endpoint\", \"OpenRouter-ready endpoint\", \"agent deploy GPU\", \"spin up my own OpenAI-compatible endpoint\", \"extend compute instance\", \"resize compute instance\", \"destroy server instance\", \"check instance status\", \"list my instances\", \"top up compute credits\", \"check credit balance\", \"run inference on the grid\", \"decentralized inference\", \"OpenAI-compatible API\", \"multimodal embeddings\", \"EmbeddingGemma 2\", \"embed image\", \"embed audio\", \"embed video\", \"mixed media vectors\", \"local embeddings\", \"confidential / TEE inference\", \"list grid models\", \"check grid capacity\", \"Laya\", \"System One\", \"Jev-compatible decisions\", \"typed decision model\", \"private Laya\", \"serve Laya from the node app\", \"run a node\", \"provide compute\", \"become a grid node\", \"node operator\", \"join the grid\", \"stake to run a node\", \"serve a model on the grid\", \"earn from compute\", \"deploy an always-on AI agent\", \"deploy a hosted OpenClaw agent\", \"spin up a ClawPod\", \"agent pod\", \"hosted agent with its own wallet\", \"free agent trial\", \"deploy a processor\", \"sell my code per call\", \"monetize an endpoint\", \"publish a paid API\", \"connect a processor as an MCP tool\", \"back up my agent\", \"agent backup\", \"restore my agent\", \"migrate my agent\", \"agent vault\", \"snapshot my agent's memory\", \"move my agent to a new machine\", or manage Singularity Cloud Network compute. Seven jobs: SGL Machines (GPU/VPS provisioning across Vultr & DigitalOcean), AI Machines (one-click GPU running an LLM — deploy a private OpenAI-compatible endpoint, or join the grid & earn), SGL Grid (decentralized, confidential, OpenAI-compatible inference, multimodal embeddings, plus Laya/System One typed decisions — consume it), Provide Compute (run a TEE node on the grid to serve inference and earn USDC + SGL), and Agent Pods (deploy an always-on hosted OpenClaw agent with its own crypto wallet, memory, preinstalled x402 skills, and owner/platform customization for identity, instructions, and self-check heartbeat prompts — managed or BYOK, tiers, free 24h trial), and Processors (publish your own code as a paid endpoint — buyers pay you directly in USDC via x402, you pay only for runtime; every processor is also a connectable MCP server, so agents, harnesses and LangGraph nodes can call it with just a URL), and Agent Vault (zero-knowledge encrypted backup, restore & migration for OpenClaw/Hermes agents — snapshot an agent's memory and soul, store it encrypted, restore or migrate it to any machine or pod). Pay with USDC on Base, Solana or Arc, USDm on MegaETH, USDG on Robinhood Chain via x402, optional MPP/Mppx, or pre-loaded USD credits. Arc: accepted for credit top-ups AND direct machine/AI-machine provision and extension payments (direct Arc payments floor at $5 — Arc gas is USDC; smaller prepayments go through Arc-funded credits). Includes optional OWS-backed auth and management flows.\n\nTags: AI:1.10.0, AI agents:1.10.0, AI inference:1.10.0, CPU:1.6.1, Compute on Mega:1.6.1, DePIN:1.10.0, Decentralised AI:1.6.1, DeepSeek:1.10.0, GPU:1.10.0, GPU cloud:1.10.0, GPU rental:1.10.0, Gemma:1.10.0, LLM:1.10.0, LLM inference:1.10.0, Llama:1.10.0, MCP:1.10.0, Mega:1.6.1, MegaETH:1.6.1, Mistral:1.10.0, OpenAI API:1.10.0, OpenAI-compatible:1.10.0, Phi:1.10.0, Qwen:1.10.0, Robinhood:1.10.0, SGL:1.10.0, SGL Compute:1.10.0, Singularity Compute:1.10.0, Singularity Layer:1.10.0, TEE:1.10.0, USDm:1.6.1, VPS:1.10.0, agent payments:1.10.0, agent tools:1.10.0, agentic:1.10.0, agentic compute:1.10.0, agentic payments:1.10.0, agentic-compute:1.8.1, api:1.10.0, autonomous agents:1.10.0, base:1.10.0, chat completions:1.10.0, cloud GPU:1.10.0, cloudflare:1.6.0, compute:1.10.0, compute grid:1.10.0, compute marketplace:1.10.0, compute network:1.10.0, compute provider:1.10.0, confidential compute:1.10.0, cpu:1.8.1, cpu rent:1.6.1, cpu-rental:1.8.1, crypto payments:1.10.0, decentralised compute:1.6.0, decentralized AI:1.10.0, decentralized compute:1.10.0, decentralized inference:1.10.0, decentralized-ai:1.8.1, dedicated endpoint:1.10.0, deploy LLM:1.10.0, earn:1.10.0, gpu:1.8.1, gpu rent:1.6.1, gpu-rental:1.8.1, grid:1.10.0, inference:1.10.0, latest:1.31.0, machine payment protocol:1.6.1, machine payments:1.10.0, machine-payment-protocol:1.8.1, megaeth:1.10.0, metered billing:1.10.0, mpp:1.8.1, mpp compute:1.6.1, node operator:1.10.0, one-click deploy:1.10.0, open source models:1.10.0, ows:1.1.0, pay-per-use:1.10.0, payments:1.10.0, prepaid credits:1.10.0, private LLM:1.10.0, provisioning:1.10.0, run a node:1.10.0, self-hosted LLM:1.10.0, serverless:1.10.0, sgl:1.8.1, sgl-compute:1.8.1, singularity-compute:1.8.1, solana:1.10.0, stablecoin:1.10.0, tempo:1.8.1, usd.e:1.8.1, usdc:1.10.0, usdm:1.8.1, web3:1.10.0, x402:1.10.0, x402 Protocol:1.10.0, x402 Singularity Layer:1.10.0, x402-protocol:1.8.1, x402Compute.cc:1.10.0\n\nVersion history:\n\nv1.31.0 | 2026-10-07T08:19:40.079Z | user\n\nAdds production-ready EmbeddingGemma 2 multimodal embeddings for text, image, audio, video, mixed batches, MRL dimensions, exact billing, failover, and node operation.\n\nv1.30.1 | 2026-09-29T08:26:52.805Z | user\n\nAdd safe Agent Pod customization for platform builders: API-managed identity, owner instructions, heartbeat prompt, and heartbeat cadence without raw AGENTS.md replacement.\n\nv1.30.0 | 2026-09-23T17:49:38.743Z | user\n\nAdds Laya/System One typed decisions, private sealed Laya guidance, and desktop node-app serving instructions.\n\nv1.29.0 | 2026-09-16T16:07:40.546Z | user\n\nArc USDC now pays for machine/AI-machine provisioning and extensions directly (--network arc, EIP-3009 chainId 5042). Direct Arc payments floor at $5 (gas is USDC); smaller prepayments use Arc-funded credits. Credit top-ups unchanged.\n\nv1.28.0 | 2026-09-16T15:34:53.568Z | user\n\nArc mainnet USDC: credit top-ups with network arc (EIP-3009 transferWithAuthorization on chainId 5042, USDC domain v2, $5 minimum since Arc gas is paid in USDC). Signer gains arc in EVM_ASSETS; docs updated across SKILL.md, api-reference and worker-served references.\n\nv1.26.0 | 2026-09-09T09:34:43.907Z | user\n\nEditable model prompt: manifest.prompt, read with await SGL.prompt.get(). Editing it costs no new isolate and no daily config change because it is resolved per request rather than baked in. Not a secret.\n\nv1.25.0 | 2026-09-08T06:31:00.772Z | user\n\nProcessors control plane over a compute API key (x402c_): deploy and manage a processor with no Solana keypair. processors:write is full control of that wallet's processors, delete and secrets included; processors:read is read-only. Documents the two routes a key never reaches, why run() still wants the invoke token, and the three places this is weaker than a Cloudflare token (no expiry, no audit log, delete burns the slug).\n\nv1.24.0 | 2026-09-03T12:37:51.230Z | user\n\nDatasets: every row is now checked by a second model and regenerated if it breaks your house rules. Managed jobs use a frontier judge; grid jobs are checked on-network so data never leaves it. Priced separately per 100.\n\nv1.23.0 | 2026-09-02T07:53:14.655Z | user\n\nDatasets: house rules (what the assistant must never do) and an always-on consistency rule; prices halved; 20-model catalog.\n\nv1.22.0 | 2026-08-31T17:12:43.044Z | user\n\nDatasets over x402: agents can buy a generated fine-tuning dataset with a wallet (quote, pay, poll, download JSONL). Adds references/datasets.md.\n\nv1.21.0 | 2026-08-21T19:39:43.919Z | user\n\nAgent Vault plans are now payable directly with x402 (USDC on Base/Solana, USDG on Robinhood Chain, USDm on MegaETH) — an agent holding stablecoins but no credits can buy Pro or Max in one call. Vault tiers updated: Free 1 GB / 1 rolling snapshot, Pro $3mo or $30yr for 10 GB and the last 10 snapshots of each agent, Max $5mo or $50yr for 50 GB and unlimited history. A downgrade or missed payment never deletes a snapshot.\n\nv1.19.0 | 2026-08-18T12:23:02.560Z | user\n\nAgent Vault universal mode: back up ANY directory as an agent with agentvault backup --path <dir> --name <n> (any harness). Hermes support proven end-to-end.\n\nv1.18.1 | 2026-08-18T10:07:38.977Z | user\n\nAgent Vault pricing: free tier = 1 rolling snapshot (1 GiB); Vault Pro = $3/month from credits, unlimited snapshots (5 GiB).\n\nv1.18.0 | 2026-08-18T07:06:30.127Z | user\n\nAgent Vault: zero-knowledge encrypted agent backup, restore & migration — new seventh job (agentvault CLI, pod one-click backups, cross-machine/pod migration). New reference: agent-vault.md.\n\nv1.17.0 | 2026-08-13T11:13:32.722Z | user\n\nRobinhood Chain is now offered on request rather than by default: the reference x402 client rejects an entire accepts array containing a chain name it does not recognise, which would stop it paying on Solana or Base either. Send X-Accept-Networks: solana,base,robinhood to be offered every chain a processor accepts.\n\nv1.16.0 | 2026-08-13T08:31:42.675Z | user\n\nA processor payment is FINAL — there are no refunds. The payment goes directly to the publisher and the platform never holds it, so the recovery path for a failed paid run is re-sending the same X-Payment header, which returns the run already bought rather than charging again. Before paying, read failure_rate_30d.\n\nv1.15.0 | 2026-08-13T01:10:52.130Z | user\n\nProcessors now take Solana, Base and Robinhood Chain. A publisher declares a payout address per chain and the 402 carries one accepts entry per declared chain — read the array. One price covers all three, since every asset is a 6-decimal stablecoin.\n\nv1.14.1 | 2026-08-12T19:15:04.943Z | user\n\nProcessors is LIVE via the CLI (both money flags on) and the reference no longer says publishing is closed. Adds TypeScript+npm bundling, per-run console output, SGL.kv / SGL.files with signed expiring download links, secrets[].mode env, pause/resume, GET methods, and pricing computed from the buyer input. Processor payments are USDC on SOLANA ONLY — the other x402 rails are for Machines, Pods and credits.\n\nv1.13.0 | 2026-08-07T11:51:09.008Z | user\n\nSECURITY: skill scripts no longer auto-load .env files. Credentials are read only from exported environment variables — if you kept keys in a .env, export them or source the file yourself first. Previously load_dotenv() walked up from the script's own directory, so a .env in the project you installed the skill into (or any parent) could supply signing credentials; combined with OWS_WALLET + OWS_BIN it could point wallet operations at an arbitrary binary. OWS_BIN is now validated: absolute path, symlinks resolved, must exist, must be executable, refused if world-writable. The unpinned 'npx -y @open-wallet-standard/core' fallback is removed — wallet operations no longer fetch their own signer at runtime; install @open-wallet-standard/core@0.5.0 explicitly. Also brings everything since 1.10.0: Agent Pods (one-click hosted OpenClaw agents with their own wallet, OpenAI-compatible adapter, curated templates) and Processors (publish your code as a paid endpoint — buyers pay you directly in USDC via x402, and every processor is a connectable MCP server).\n\nv1.10.0 | 2026-07-11T16:19:26.939Z | user\n\n- Added Robinhood Chain (EVM) as a supported network for payments and authentication.\n- Introduced USDG (Robinhood Chain) as a supported currency.\n- Updated environment variables and documentation to include Robinhood Chain in wallet setup and chain selection.\n\nv1.9.1 | 2026-07-06T16:39:32.896Z | user\n\n- Introduced AI Machines: One-click GPU instances preloaded with an LLM, offering either a private OpenAI-compatible endpoint or joining the grid to earn rewards.\n- Added new documentation file: references/ai-machines.md.\n- Removed obsolete file: skill-card.md.\n- Updated description and script references to highlight AI Machines and their deployment/usage options.\n- Clarified and expanded product lineup to include Machines, AI Machines, Grid, and Provide Compute.\n\nv1.8.1 | 2026-06-17T18:53:10.757Z | user\n\nGrid inference (/v1/chat/completions, /v1/models) now documents Bearer auth:\nthe API key can be passed as `Authorization: Bearer x402c_…` (standard OpenAI style) in addition to `X-API-Key: x402c_…`.\n\nv1.8.0 | 2026-06-16T07:50:21.374Z | user\n\nMarketplace pricing + node security (cumulative since 1.6.x).\n\n- **Operator custom pricing** — set your own per-token price with `sgl price show/set/reset`, within an allowed band (suggested ×0.5–×5). You earn 80% of whatever you charge; a model\n  with no custom price bills the suggested rate.\n- **Provider discovery** — `GET /v1/providers?model=…` lists every node serving a model with its effective price (cheapest-first); pin one via `node=` in the API/SDKs.\n- **Caller price cap** — pass `max_price` (USD per 1M tokens) on chat/reserve to route only to nodes at/under your budget; never billed above it.\n- **Node security** — `sgl service install --sandbox` (macOS Seatbelt) walls off SSH keys, wallets, and keychains from the inference process; Linux gets equivalent systemd hardening automatically.\n\nv1.6.1 | 2026-06-15T09:18:06.211Z | user\n\nx402-compute 1.7.0\n\n- Node operators can now set a custom per-token price within a defined band using the `sgl price set` command.\n- Callers can compare node prices via `GET /v1/providers`.\n- Documentation for node operator pricing and discovery has been added and clarified.\n- Removed the sample file: skill-card.md.\n\nv1.6.0 | 2026-06-08T09:56:09.974Z | user\n\n**Singularity Cloud Network (x402-compute) 1.6.0 — Major grid/inference and node operator support**\n\n- Adds SGL Grid: decentralized, confidential TEE inference API (OpenAI-compatible), plus documentation links and grid/inference instructions.\n- Introduces workflows and references for providing compute and running a node (node operator), including staking and earning SGL/USDC.\n- Updates description and documentation URLs to cover Machines, Grid, and node operation.\n- Removes legacy skill card; adds dedicated node-operator reference file.\n- Clarifies credit/payment/staking options, and unifies SKILL.md resources for combined machine/grid/node workflows.\n\nv1.4.1 | 2026-05-20T14:07:49.724Z | user\n\nx402-compute 1.4.1 adds support for credit top-up and credit-based provisioning and extends environment documentation.\n\n- Added support for pre-loaded USD credits to provision or extend instances with `use_credits: true` (no payment step required).\n- New commands in the description: \"top up compute credits\" and \"check credit balance\".\n- Updated environment variables section, now listing keys for EVM, Solana, API key, and OWS details.\n- Clarified supported payment methods (USDC, USDm, MPP, and credits) throughout documentation.\n- Small documentation improvements for wallet setup, credit workflows, and security guidance.\n\nv1.3.1 | 2026-05-13T18:32:03.672Z | user\n\n**Adds in-place instance resize capability.**\n\n- New `resize_instance.py` script to resize an instance to a different plan.\n- SKILL.md updated to describe resize workflow and script.\n- Instance management now includes \"resize\" alongside provision, extend, and destroy.\n- Resize is an authenticated management action (no new payment flow; recalculates expiration for new plan rate).\n\nv1.3.0 | 2026-05-11T12:41:40.934Z | user\n\nx402-compute 1.3.0\n\n- Added support for provisioning and managing DigitalOcean compute instances in addition to Vultr.\n- Introduced MegaETH network with USDm as a payment option alongside Base (USDC) and Solana (USDC).\n- Updated instructions and scripts to reflect multi-provider and multi-currency (USDC/USDm) support.\n- Clarified SSH key requirements for DigitalOcean (password login not available).\n- Revised documentation reflecting new providers, payment flows, and added MegaETH and DigitalOcean usage examples.\n\nv1.2.0 | 2026-04-17T20:09:44.792Z | user\n\nx402-compute 1.2.0 adds Multi-Provider Payments (MPP) support and updates payment/management flows.\n\n- Introduced MPP/Mppx payment options: Users can now provision and manage GPU/VPS with Tempo or Stripe/card (when enabled) in addition to x402 (USDC on Base/Solana).\n- Updated documentation and quick start to cover MPP usage with `mppx` CLI and environment variable setup for management API keys.\n- Clarified protocol usage: `X-Payment` for x402, `Authorization: Payment` for MPP.\n- Added instructions for extending instances via MPP and handling responses with management API keys.\n- Adjusted wording to reflect support for both x402 and MPP methods throughout workflows and API descriptions.\n\nv1.1.0 | 2026-04-03T12:45:57.664Z | user\n\nx402-compute 1.1.0 introduces optional OpenWallet/OWS-based authentication and expands management options.\n\n- Added OpenWallet (OWS) support as an optional authentication and agent key management layer.\n- New script: ows_cli.py for running OWS wallet, sign-message, and key commands.\n- Auth/environment setup now includes OWS options; direct signing still supported.\n- Documentation expanded: see references/openwallet-ows.md for OWS usage and details.\n- No breaking changes to existing direct wallet/private key provisioning or payment flows.\n\nv1.0.7 | 2026-02-20T13:53:57.206Z | user\n\n- Updated environment variable documentation for clarity, grouping EVM and Solana payment options under explicit \"Option A\" and \"Option B\".\n- Changed recommended authentication in metadata: now prefers COMPUTE_API_KEY over raw private keys for management.\n- Updated credential configuration to prioritize API key usage.\n- No code changes or functionality updates; documentation only.\n\nv1.0.6 | 2026-02-20T13:40:56.818Z | user\n\nx402-compute 1.0.6 introduces support for daily instance provisioning and updates workflows for short-duration compute.\n\n- Adds support for `--days` flag to provision instances by day, enabling short-term \"daily\" and \"cheaper use-and-throw\" compute.\n- Updates documentation with examples for provisioning and extending instances by days, in addition to by month.\n- Workflow examples now include provisioning for 1 or 3 days, and extending instances by 1 day or 1 month.\n- No code or file changes; changelog reflects updated docs and usage patterns only.\n\nv1.0.5 | 2026-02-20T06:16:04.816Z | user\n\nx402-compute v1.0.5\nRelease Date: 2026-02-20\n\nOverview\nThis release adds full Solana payment support to all compute scripts and fixes\nan authentication issue that caused 401 errors during paid retries.\n\nChanges\n\nAdded\n- Full Solana payment support for extend_instance.py\n- The --network solana flag is now fully supported for extend operations\n- Builds and signs a Solana VersionedTransaction\n- Uses SPL transferChecked instruction for USDC payments\n- Automatically creates the recipient USDC token account if it does not exist\n- Payment flow now matches provision.py\n\nFixed\n- Fixed 401 Unauthorized errors during paid retry requests\n- Removed stale compute authentication headers (X-Auth-*) from paid retries\n- Fix applied to both provision.py and extend_instance.py\n\nRemoved\n- Removed all legacy AWAL mode references from extend_instance.py\n\nTechnical Notes\n- The 401 issue was caused by nonce reuse\n- The nonce from the initial 402 response was already recorded by the backend\n- Re-sending X-Auth-* headers on the paid retry caused authentication failure\n- The x402 X-Payment header alone is sufficient for authentication\n- On-chain USDC payment verifies the payer\n- No additional auth headers are required during the payment step\n\nv1.0.4 | 2026-02-19T12:59:53.119Z | user\n\n- Added Solana network support for provisioning and managing compute instances.\n- Introduced scripts/solana_signing.py for internal Solana x402 payment signing.\n- Updated environment variables to support Solana keys (SOLANA_SECRET_KEY, SOLANA_WALLET_ADDRESS, COMPUTE_AUTH_CHAIN).\n- Clarified workflows and script usage for both Base (EVM) and Solana modes.\n- Removed deprecated AWAL bridge script.\n\nv1.0.3 | 2026-02-18T20:59:59.420Z | user\n\nv1.0.3 Changelog:\n\n- Bumped x402-compute skill version to 1.0.3.\n- Added one-time password fallback support docs and script (`get_one_time_password.py`).\n- Added AWAL support for `provision.py` and `extend_instance.py`.\n- AWAL mode now requires `COMPUTE_API_KEY` for compute management auth.\n- Added `awal_bridge.py` helper for AWAL CLI integration.\n- Improved `provision.py` handling for `201 Created` success responses.\n- Improved AWAL error messages when `COMPUTE_API_KEY` is missing.\n- Updated plan-list script to support current API pricing fields.\n- Updated list/details scripts to show plan and region correctly from API response.\n- Added SSH-key-first guidance with explicit key generation example (`ssh-keygen ... ~/.ssh/x402_compute`).\n- Synced skill updates to SGL docs skill folder.\n- Updated old worker hosted skill manifest/installer to include new script and guidance.\n- Added compute UI \"Password\" action in Your Fleet cards with one-time credential modal.\n- Created external changelog file outside skill folder (as requested).\n\nv1.0.2 | 2026-02-18T12:22:04.525Z | user\n\nx402-compute v1.0.2 Changelog\n\nFixed:\n- Registry metadata fix: Removed X402_USE_AWAL and X402_AUTH_MODE from required env vars(they are optional)\n- Added credentials.primary: PRIVATE_KEY declaration to properly indicate the primary credential\n\nv1.0.1 | 2026-02-18T12:00:26.803Z | user\n\nx402-compute v1.0.1\n\nFixed:\n- instance_details.py now displays VPS credentials (root password, IPv6) when available\n- Previously, the API returned vultr_default_password but the script wasn't showing it   \n- Added a note in the provisioning workflow to clarify that users should wait 2-3 minutes after provisioning for Vultr setup to complete before fetching instance credentials.\n- No other changes or feature updates included in this version.\n\nv1.0.0 | 2026-02-18T11:28:16.465Z | user\n\nx402-compute 1.0.0 – Initial release\n\n- Provision and manage GPU/VPS cloud instances with USDC payment on Base or Solana networks via x402 payment protocol.\n- Supports operations like listing compute plans, provisioning or destroying GPU/VPS servers, extending instance lifetime, and checking status.\n- CLI scripts provided for browsing plans, provisioning, instance management, and payment handling.\n- Requires local wallet credentials or integration with Coinbase Agentic Wallet for signing transactions.\n- Security guidance included for handling private keys and wallet setup.\n- Detailed environment variable and workflow documentation is provided in SKILL.md.\n\nArchive index:\n\nArchive v1.31.0: 30 files, 110357 bytes\n\nFiles: references/agent-pods-api.md (12756b), references/agent-pods.md (17402b), references/agent-vault.md (5337b), references/ai-machines.md (9802b), references/api-reference.md (19612b), references/datasets.md (7868b), references/multimodal-embeddings.md (10449b), references/node-operator.md (8527b), references/openwallet-ows.md (2531b), references/processors.md (23797b), references/systemone-laya.md (4269b), requirements.txt (64b), scripts/agent_pod.py (16426b), scripts/browse_plans.py (1764b), scripts/browse_regions.py (860b), scripts/create_api_key.py (1618b), scripts/destroy_instance.py (2499b), scripts/extend_instance.py (6147b), scripts/get_one_time_password.py (2143b), scripts/grid_embeddings.py (10801b), scripts/instance_details.py (2032b), scripts/list_instances.py (1467b), scripts/ows_cli.py (6548b), scripts/provision.py (11914b), scripts/resize_instance.py (2653b), scripts/solana_signing.py (11403b), scripts/wallet_signing.py (19506b), skill-card.md (2308b), SKILL.md (52781b), _meta.json (132b)\n\nFile v1.31.0:SKILL.md\n\n---\nname: x402-compute\nversion: 1.31.0\ndescription: |\n  This skill should be used when the user asks to \"provision GPU instance\",\n  \"integrate agent pods over an API\", \"create pods for my customers\",\n  \"pod webhooks\", \"pod events\",\n  \"spin up a cloud server\", \"list compute plans\", \"browse GPU pricing\",\n  \"deploy AI machine\", \"one-click GPU running an LLM\", \"deploy a private LLM endpoint\",\n  \"OpenRouter-ready endpoint\", \"agent deploy GPU\", \"spin up my own OpenAI-compatible endpoint\",\n  \"extend compute instance\", \"resize compute instance\", \"destroy server instance\", \"check instance status\",\n  \"list my instances\", \"top up compute credits\", \"check credit balance\",\n  \"run inference on the grid\", \"decentralized inference\", \"OpenAI-compatible API\",\n  \"multimodal embeddings\", \"EmbeddingGemma 2\", \"embed image\", \"embed audio\",\n  \"embed video\", \"mixed media vectors\", \"local embeddings\",\n  \"confidential / TEE inference\", \"list grid models\", \"check grid capacity\",\n  \"Laya\", \"System One\", \"Jev-compatible decisions\", \"typed decision model\",\n  \"private Laya\", \"serve Laya from the node app\",\n  \"run a node\", \"provide compute\", \"become a grid node\", \"node operator\", \"join the grid\",\n  \"stake to run a node\", \"serve a model on the grid\", \"earn from compute\",\n  \"deploy an always-on AI agent\", \"deploy a hosted OpenClaw agent\", \"spin up a ClawPod\",\n  \"agent pod\", \"hosted agent with its own wallet\", \"free agent trial\",\n  \"deploy a processor\", \"sell my code per call\", \"monetize an endpoint\",\n  \"publish a paid API\", \"connect a processor as an MCP tool\",\n  \"back up my agent\", \"agent backup\", \"restore my agent\", \"migrate my agent\",\n  \"agent vault\", \"snapshot my agent's memory\", \"move my agent to a new machine\",\n  or manage Singularity Cloud Network compute. Seven jobs: SGL Machines\n  (GPU/VPS provisioning across Vultr & DigitalOcean), AI Machines (one-click GPU\n  running an LLM — deploy a private OpenAI-compatible endpoint, or join the grid & earn),\n  SGL Grid (decentralized, confidential, OpenAI-compatible inference, multimodal embeddings,\n  plus Laya/System One typed decisions — consume it),\n  Provide Compute (run a TEE node on the grid to serve inference and earn USDC + SGL), and\n  Agent Pods (deploy an always-on hosted OpenClaw agent with its own crypto wallet, memory,\n  preinstalled x402 skills, and owner/platform customization for identity, instructions,\n  and self-check heartbeat prompts — managed or BYOK, tiers, free 24h trial), and\n  Processors (publish your own code as a paid endpoint — buyers pay you directly in USDC via\n  x402, you pay only for runtime; every processor is also a connectable MCP server, so agents,\n  harnesses and LangGraph nodes can call it with just a URL), and Agent Vault\n  (zero-knowledge encrypted backup, restore & migration for OpenClaw/Hermes agents —\n  snapshot an agent's memory and soul, store it encrypted, restore or migrate it to any\n  machine or pod). Pay with\n  USDC on Base, Solana or Arc, USDm on MegaETH, USDG on Robinhood Chain via x402, optional MPP/Mppx, or\n  pre-loaded USD credits. Arc: accepted for credit top-ups AND direct machine/AI-machine provision\n  and extension payments (direct Arc payments floor at $5 — Arc gas is USDC; smaller prepayments go\n  through Arc-funded credits). Includes optional OWS-backed auth and management flows.\nhomepage: https://docs.x402layer.cc/agentic-access/x402-compute\nmetadata:\n  clawdbot:\n    emoji: \"🖥️\"\n    homepage: https://cloud.x402compute.cc\n    os:\n      - linux\n      - darwin\n    requires:\n      bins:\n        - python3\n      env:\n        - name: PRIVATE_KEY\n          description: EVM private key for Base/MegaETH/Robinhood payment signing (use a dedicated low-balance wallet)\n          sensitive: true\n          optional: true\n        - name: WALLET_ADDRESS\n          description: EVM wallet address corresponding to PRIVATE_KEY\n          optional: true\n        - name: SOLANA_SECRET_KEY\n          description: Solana signer key for Solana payment signing (use a dedicated low-balance wallet)\n          sensitive: true\n          optional: true\n        - name: SOLANA_WALLET_ADDRESS\n          description: Solana wallet address\n          optional: true\n        - name: COMPUTE_API_KEY\n          description: Reusable API key for management endpoints (created via POST /compute/api-keys)\n          sensitive: true\n          optional: true\n        - name: COMPUTE_AUTH_CHAIN\n          description: Auth chain override — base, megaeth, robinhood, or solana\n          optional: true\n        - name: OWS_BIN\n          description: Explicit path to a locally installed OWS binary (avoids runtime npx downloads)\n          optional: true\nallowed-tools:\n  - Read\n  - Write\n  - Edit\n  - Bash\n  - WebFetch\n---\n\n\n# Singularity Cloud Network — Compute & Grid\n\nProducts share one credit balance and one set of wallet/API-key auth:\n\n- **SGL Machines** — provision, manage, resize, and extend GPU/VPS instances on Vultr or DigitalOcean. **API base:** `https://compute.x402layer.cc`\n- **AI Machines** — one-click deploy of a **GPU already running an LLM**, mode chosen at deploy: `private` (your own **OpenAI-compatible** endpoint — returns URL + API key) or `grid` (serve as a node & earn USDC + SGL, needs 50k SGL staked). Same x402 lifecycle as Machines; add `model_id` + `mode` to provision. **Standard tier (not confidential).** See [AI Machines](#ai-machines--one-click-llm-gpu) below and `references/ai-machines.md`.\n- **SGL Grid** — decentralized, confidential, **OpenAI-compatible** inference across capability-qualified nodes; token streaming + end-to-end encryption. It serves chat, **EmbeddingGemma 2 multimodal embeddings** at `POST /v1/embeddings`, and **Laya/System One** typed decisions at `POST /v1/systemone`. EmbeddingGemma 2 is release-gated and must appear in `GET /v1/models?type=embedding` before use. **API base:** `https://grid.x402compute.cc` (see [SGL Grid — Inference](#sgl-grid--inference), `references/multimodal-embeddings.md`, and `references/systemone-laya.md`)\n- **Provide Compute (run a node)** — turn a capable machine into a grid node: stake $SGL, register, attest when supported, serve a model, earn USDC + SGL. Agentic via the `sgl` CLI. Operators can serve GGUF chat models, Laya/System One, or the release-gated pinned EmbeddingGemma 2 runtime from the desktop node app. Operators can set a **custom per-token price** within a band (`sgl price set`, suggested × 0.5–× 5); callers compare nodes via `GET /v1/providers`. See [Provide Compute](#provide-compute-run-a-node) below and `references/node-operator.md`.\n- **Agent Pods** — deploy an **always-on hosted AI agent** (OpenClaw \"ClawPod\") on a dedicated CPU machine: it chats on Telegram & Discord (more channels soon) + the dashboard, has its own crypto wallet + memory, and comes with the `x402-compute` + `x402-layer` skills preinstalled. Managed (we run the LLM, tiered) or BYOK; a **free 24h trial** is available. Platforms can customize the agent's layered identity/instructions and its quiet self-check heartbeat prompt without replacing the managed `AGENTS.md` safety base. **Curated templates** give a pod a job out of the box — `community-manager` (**TGPod**) runs a Telegram community; run `agent_pod.py templates` for the live list. Same x402 / API-key + credits lifecycle as Machines. **API base:** `https://compute.x402layer.cc` (see [Agent Pods](#agent-pods--always-on-hosted-agents) below).\n- **SGL Processors** — deploy ONE function, get a paid HTTP endpoint **and a live MCP server**. Buyers pay the PUBLISHER directly via x402 (no platform cut); the publisher pays only for compute (~$0.0003/run, held then rebated to actual). Runs in isolated V8 sandboxes — **NOT a TEE**. Deny-by-default egress + server-side secret injection. **LIVE via the CLI** (`npm i -g @singularity-layer/cli`); the dashboard UI is still dark. Supports TypeScript + npm via local bundling, captured `console.log` per run, persistent `SGL.kv` / `SGL.files` state with signed download links, per-secret `mode: \"env\"`, publisher pause/resume, pricing computed from the buyer's input, **buyer payment on Solana, Base or Robinhood Chain** via a per-chain `payout` map, and **signed webhooks** (ping-to-activate, HMAC-signed `sale.completed`/`run.failed` deliveries with retries + auto-disable). See `references/processors.md`.\n- **Datasets** — buy a validated **JSONL fine-tuning dataset** generated from one sentence plus 5-20 example conversations. Priced **per 100 examples** (fast $0.50 / balanced $0.75 / best $1.50 / decentralized grid $0.35), 50-2000 rows. Every row is **checked by a second model** against your house rules and rewritten if it breaks them (managed = frontier judge; **grid checks its own work on-network, so nothing leaves it even to be verified**). Fully agentic over x402: quote (402) → pay → **202 with a claim token in ~1s** → poll or signed webhook → presigned JSONL download. Generation takes minutes, so it NEVER blocks the request. Managed models or the confidential **encrypted grid**. Failed jobs refund. See `references/datasets.md`.\n\nPay with x402, MPP, or pre-loaded credits — the same `x402c_…` API key and prepaid credit balance work across Machines and Grid.\n\n**x402 Networks:** Base (EVM) • Solana • MegaETH • Robinhood Chain (EVM)\n**PROCESSORS accept Solana, Base and Robinhood Chain — NOT MegaETH.** A publisher declares a `payout` address per chain (default: USDC on Solana at their deploying wallet), and the 402 carries ONE `accepts` ENTRY PER DECLARED CHAIN — read the array, do not assume one entry. `maxAmountRequired` is the same integer on every entry because all three assets are 6-decimal. **Robinhood is offered only on request** (`X-Accept-Networks: solana,base,robinhood`) because the reference x402 client rejects an entire `accepts` array containing a name it does not know. Owner/CLI auth is still a Solana signature. **A processor payment is FINAL — there are no refunds**; the recovery path for a failed paid run is re-sending the same `X-Payment` header, which returns the run already bought rather than charging again. See `references/processors.md`.\n**x402 Currency:** USDC (Base/Solana) • USDm (MegaETH) • USDG (Robinhood Chain)\n**MPP Methods:** Tempo • Stripe/card when enabled by the service\n**Credits:** Pre-load USD via x402 topup, then provision/extend (`use_credits: true`) or call the Grid with `X-API-Key`\n**Protocol:** HTTP 402 Payment Required (`X-Payment` for x402, `Authorization: Payment` for MPP)\n**$SGL:** native token, live on Solana — mint `5c4HyD2rSShqnTsf5z3SaoD2H3GE452u2CUuYjviBAGS` (staking secures the grid; see [staking.x402layer.cc](https://staking.x402layer.cc))\n\nThis section below (Machines) covers provisioning. Jump to **[SGL Grid — Inference](#sgl-grid--inference)** for the OpenAI-compatible inference API.\n\n**Access Note:** Preferred access is SSH public key. If no SSH key is provided, a one-time password fallback can be fetched once via API.\n**DigitalOcean Note:** DigitalOcean instances require SSH key access because one-time root passwords are not exposed through the DigitalOcean API.\n\n---\n\n## Quick Start\n\n### 1. Install Dependencies\n```bash\npip install -r {baseDir}/requirements.txt\n```\n\n### 2. Choose Wallet Mode\n\n#### Option A: Direct signing keys (Base, MegaETH, Robinhood, or Solana)\n\n> **Use a dedicated low-balance wallet.** Never use your primary custody wallet.\n\n> **Credentials must be exported.** These scripts read the process environment only — they do\n> not load `.env` files. If your keys live in a `.env`, `source` it yourself first.\n\n```bash\n# Base (EVM) — same keys work for MegaETH and Robinhood Chain\nexport PRIVATE_KEY=<your-evm-private-key>\nexport WALLET_ADDRESS=<your-evm-wallet-address>\n\n# MegaETH (uses same EVM keys as Base)\nexport PRIVATE_KEY=<your-evm-private-key>\nexport WALLET_ADDRESS=<your-evm-wallet-address>\nexport COMPUTE_AUTH_CHAIN=\"megaeth\"\n\n# Robinhood Chain (uses same EVM keys as Base; pays with USDG)\nexport PRIVATE_KEY=<your-evm-private-key>\nexport WALLET_ADDRESS=<your-evm-wallet-address>\nexport COMPUTE_AUTH_CHAIN=\"robinhood\"\n\n# Solana\nexport SOLANA_SECRET_KEY=<your-solana-secret-key>\nexport SOLANA_WALLET_ADDRESS=<your-solana-wallet-address>\nexport COMPUTE_AUTH_CHAIN=\"solana\"\n```\n\n#### Option B: OpenWallet / OWS (optional-first)\n```bash\nnpm install -g @open-wallet-standard/core@0.5.0\nexport OWS_WALLET=\"compute-wallet\"\nexport COMPUTE_AUTH_MODE=\"ows\"\n```\n\nCreate `COMPUTE_API_KEY` (optional) for management endpoints:\n```bash\npython {baseDir}/scripts/create_api_key.py --label \"my-agent\"\n```\n\nOWS is best for compute auth and routine management flows. Direct x402 provision and extend still use local payment-signing paths. MPP provision/extend should use `mppx` or Tempo Wallet.\n\nResize is a management action, not a second payment flow. The API preserves remaining prepaid dollar credit by recalculating `expires_at` for the target hourly rate after the provider accepts the resize.\n\n---\n\n## ⚠️ Security Notice\n\n> **IMPORTANT**: This skill handles private keys for signing blockchain transactions.\n>\n> - **Never use your primary custody wallet** - Create a dedicated wallet with limited funds\n> - **Private keys are used locally only** - They sign transactions locally and are never transmitted\n> - **For testing**: Use a throwaway wallet with minimal USDC/USDm\n\n---\n\n## Scripts Overview\n\n| Script | Purpose |\n|--------|---------|\n| `browse_plans.py` | List available GPU/VPS plans with pricing |\n| `browse_regions.py` | List deployment regions |\n| `provision.py` | Provision a new instance (x402 payment, `--months` or `--days`). Add `--model-id` + `--mode private\\|grid` to deploy an **AI Machine** (GPU running an LLM). |\n| `create_api_key.py` | Create an API key for agent access (optional) |\n| `list_instances.py` | List your active instances |\n| `instance_details.py` | Get details for a specific instance |\n| `get_one_time_password.py` | Retrieve one-time root password fallback |\n| `extend_instance.py` | Extend instance lifetime (x402 payment) |\n| `resize_instance.py` | Resize an instance in place (compute auth only) |\n| `destroy_instance.py` | Destroy an instance |\n| `ows_cli.py` | Run OpenWallet / OWS wallet, sign-message, and key commands |\n| `agent_pod.py` | Deploy an **Agent Pod** (`POST /pods`), create an `sk-sglpod-int-*` integration key, and call the pod's **OpenAI adapter** (`catalog`/`list`/`get`/`deploy`/`create-key`/`chat`) |\n| `grid_embeddings.py` | Build and call text or ordered multimodal Grid embedding requests; hash/base64 media locally; supports `--dry-run` |\n| `solana_signing.py` | Internal helper for Solana x402 payment signing |\n\n---\n\n## Intent Router\n\nMap the user's request to the script + reference to load (progressive disclosure — only open the\nreference you need).\n\n| User intent | Script | Reference |\n|-------------|--------|-----------|\n| \"provision a GPU/VPS\", \"spin up a server\", \"extend/resize/destroy instance\" | `provision.py` / `extend_instance.py` / `resize_instance.py` / `destroy_instance.py` | `references/api-reference.md` |\n| \"deploy a private LLM endpoint\", \"one-click GPU running an LLM\", \"OpenRouter-ready endpoint\" | `provision.py --model-id … --mode private` | `references/ai-machines.md` |\n| \"join the grid & earn\", \"run a node\", \"provide compute\" | `sgl` CLI or Singularity Node app (see below) | `references/node-operator.md` |\n| \"run inference on the grid\", \"confidential/TEE OpenAI-compatible inference\" | curl / any OpenAI SDK → `grid.x402compute.cc` | `references/api-reference.md` |\n| **\"multimodal embeddings\"**, \"EmbeddingGemma 2\", \"embed image/audio/video\", \"mixed media vectors\" | **`grid_embeddings.py`** → `POST /v1/embeddings` | **`references/multimodal-embeddings.md`** |\n| **\"local embeddings\"**, \"embed media on my Mac\", \"Node app embeddings\" | Singularity Node app → Local → Embeddings | **`references/multimodal-embeddings.md`** |\n| \"use Laya\", \"System One\", \"Jev-compatible typed decisions\", \"private Laya\" | curl / private sealed System One → `grid.x402compute.cc` | `references/systemone-laya.md` |\n| \"serve Laya from my node\", \"node app Laya\", \"System One node operator\" | Singularity Node app v1.7.4+ or `sgl` CLI with a local Laya sidecar | `references/systemone-laya.md` + `references/node-operator.md` |\n| **\"deploy an agent pod\"**, \"hosted OpenClaw/ClawPod\", \"always-on AI agent with its own wallet\", \"free 24h agent trial\" | **`agent_pod.py deploy`** (or `catalog`/`list`/`get`) | **`references/agent-pods.md`** |\n| **\"call my pod via the OpenAI API\"**, \"give my pod an OpenAI-compatible endpoint\", \"get an API key for my agent pod\" | **`agent_pod.py create-key` then `agent_pod.py chat`** | **`references/agent-pods.md`** |\n| **\"telegram community manager\"**, \"TGPod\", \"moderate my telegram group\", \"bot that answers members and removes scams\", \"discord community manager\" (soon) | **`agent_pod.py templates`** then **`agent_pod.py deploy --template community-manager`** | **`references/agent-pods.md`** |\n| **\"integrate agent pods into my product\"**, \"pods over an API key\", \"create pods for my customers\", \"pod webhooks / events\", \"no wallet, just an API key\" | `curl` / `PodsClient` (both SDKs) → `/pods/v1` | **`references/agent-pods-api.md`** |\n| **\"back up my agent\"**, \"restore/migrate my agent\", \"agent vault\", \"snapshot my agent's memory\" | **`npx @singularity-layer/agentvault`** (`login`, `backup --all`, `restore`) | **`references/agent-vault.md`** |\n| **\"buy a training dataset\"**, \"generate fine-tuning data\", \"make me a JSONL dataset\", \"synthetic training data for my model\" | `POST /datasets/x402/synth` (402 → pay → poll) or the MCP dataset tools | **`references/datasets.md`** |\n\nAgent Pod quick path:\n```bash\npython {baseDir}/scripts/agent_pod.py catalog                              # pick tier/plan/model\npython {baseDir}/scripts/agent_pod.py templates                            # curated pods with a job (TGPod …)\npython {baseDir}/scripts/agent_pod.py deploy --ai-mode managed --tier pro \\\n    --plan <plan_id> --prepaid-hours 720 --telegram <bot_token> --use-credits\npython {baseDir}/scripts/agent_pod.py create-key <pod_id> --name my-integration   # → sk-sglpod-int-…\npython {baseDir}/scripts/agent_pod.py chat <pod_id> \"What's on my calendar?\" --key sk-sglpod-int-…\n```\n\nSystem One / Laya quick path:\n```bash\ncurl \"https://grid.x402compute.cc/v1/models?type=systemone\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\"\n\ncurl -X POST https://grid.x402compute.cc/v1/systemone \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"model\":\"convaiinnovations/laya\",\"state\":{\"text\":\"refund request from pro customer\"},\"questions\":{\"route\":{\"type\":\"choice\",\"instructions\":\"Pick the best team.\",\"criteria\":{\"billing\":\"Billing/refund issue\",\"support\":\"Technical issue\"}}}}'\n```\n\nMultimodal embeddings quick path:\n```bash\npython {baseDir}/scripts/grid_embeddings.py models\npython {baseDir}/scripts/grid_embeddings.py embed --text \"A searchable document\" \\\n  --input-type document --dimensions 256\npython {baseDir}/scripts/grid_embeddings.py embed --text \"Product demo\" \\\n  --image ./frame.png --audio ./narration.mp3 --audio-seconds 4.2 \\\n  --input-type document --dimensions 256\n```\n\n---\n\n## Instance Lifecycle\n\n```\nBrowse Plans → Choose Provider/Plan → Provision (x402/MPP/Credits) → Active → Extend / Destroy → Expired\n```\n\nInstances expire after their prepaid duration. Extend before expiry to keep them running.\n\n---\n\n## Workflows\n\n### A. Browse and Provision\n\n```bash\n# List GPU plans\npython {baseDir}/scripts/browse_plans.py\n\n# Filter by type (gpu/vps/high-performance)\npython {baseDir}/scripts/browse_plans.py --type vcg\n\n# Check available regions\npython {baseDir}/scripts/browse_regions.py\n\n# Generate a dedicated SSH key once (recommended for agents)\nssh-keygen -t ed25519 -N \"\" -f ~/.ssh/x402_compute\n\n# Provision an instance for 1 month (triggers x402 payment)\npython {baseDir}/scripts/provision.py vcg-a100-1c-2g-6gb lax --months 1 --label \"my-gpu\" --ssh-key-file ~/.ssh/x402_compute.pub\n\n# DigitalOcean plans are prefixed with do:\n# They require SSH key access.\npython {baseDir}/scripts/provision.py do:s-1vcpu-1gb nyc3 --days 1 --label \"do-test\" --ssh-key-file ~/.ssh/x402_compute.pub\n\n# Provision a daily instance (cheaper, use-and-throw)\npython {baseDir}/scripts/provision.py vc2-1c-1gb ewr --days 1 --label \"test-daily\" --ssh-key-file ~/.ssh/x402_compute.pub\n\n# Provision for 3 days\npython {baseDir}/scripts/provision.py vc2-1c-1gb ewr --days 3 --label \"short-task\" --ssh-key-file ~/.ssh/x402_compute.pub\n\n# Provision on Solana\npython {baseDir}/scripts/provision.py vc2-1c-1gb ewr --months 1 --label \"my-sol-vps\" --network solana --ssh-key-file ~/.ssh/x402_compute.pub\n\n# Provision on MegaETH (pays with USDm)\npython {baseDir}/scripts/provision.py vc2-1c-1gb ewr --months 1 --label \"my-mega-vps\" --network megaeth --ssh-key-file ~/.ssh/x402_compute.pub\n\n# Provision on Robinhood Chain (pays with USDG — same EVM keys as Base)\npython {baseDir}/scripts/provision.py vc2-1c-1gb ewr --months 1 --label \"my-usdg-vps\" --network robinhood --ssh-key-file ~/.ssh/x402_compute.pub\n\n# Provision via MPP / mppx (Tempo by default; Stripe/card if your mppx config supports it)\nnpx mppx https://compute.x402layer.cc/compute/provision \\\n  -X POST \\\n  -J '{\"plan\":\"vc2-1c-1gb\",\"region\":\"ewr\",\"os_id\":2284,\"label\":\"mpp-vps\",\"prepaid_hours\":24,\"ssh_public_key\":\"ssh-ed25519 AAAA... agent\"}'\n\n# If the response includes management_api_key, store it for later instance management:\nexport COMPUTE_API_KEY=\"x402c_...\"\n\n# ⚠️ After provisioning, wait 2-3 minutes for Vultr to complete setup\n# Then fetch your instance details (IP, status):\npython {baseDir}/scripts/instance_details.py <instance_id>\n```\n\n### B. Manage Instances\n\n```bash\n# Optional: create a reusable API key (avoids message signing each request)\npython {baseDir}/scripts/create_api_key.py --label \"my-agent\"\n\n# List all your instances\npython {baseDir}/scripts/list_instances.py\n\n# Get details for one instance\npython {baseDir}/scripts/instance_details.py <instance_id>\n\n# Optional fallback if no SSH key was provided during provisioning\npython {baseDir}/scripts/get_one_time_password.py <instance_id>\n\n# Extend by 1 day\npython {baseDir}/scripts/extend_instance.py <instance_id> --hours 24\n\n# Extend by 1 month\npython {baseDir}/scripts/extend_instance.py <instance_id> --hours 720\n\n# Extend on Solana\npython {baseDir}/scripts/extend_instance.py <instance_id> --hours 720 --network solana\n\n# Extend on MegaETH (pays with USDm)\npython {baseDir}/scripts/extend_instance.py <instance_id> --hours 720 --network megaeth\n\n# Extend on Robinhood Chain (pays with USDG)\npython {baseDir}/scripts/extend_instance.py <instance_id> --hours 720 --network robinhood\n\n# Extend via MPP. MPP extension requires compute auth; use the management API key\n# returned from MPP provisioning or normal wallet signature auth.\nnpx mppx https://compute.x402layer.cc/compute/instances/<instance_id>/extend \\\n  -X POST \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -J '{\"extend_hours\":720}'\n\n# Resize via bundled helper script\npython {baseDir}/scripts/resize_instance.py <instance_id> vc2-2c-4gb\n\n# Resize in place with management auth only (no x402 or MPP payment)\ncurl -X POST https://compute.x402layer.cc/compute/instances/<instance_id>/resize \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"plan\":\"vc2-2c-4gb\"}'\n\n# DigitalOcean disk growth is irreversible and must be confirmed explicitly\ncurl -X POST https://compute.x402layer.cc/compute/instances/<instance_id>/resize \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"plan\":\"do:s-2vcpu-4gb\",\"confirm_disk_resize\":true}'\n\n# Destroy\npython {baseDir}/scripts/destroy_instance.py <instance_id>\n```\n\n### C. OpenWallet / OWS\n\n```bash\n# List local OWS wallets\npython {baseDir}/scripts/ows_cli.py wallet-list\n\n# Sign a Base-compatible compute auth message\npython {baseDir}/scripts/ows_cli.py sign-message --chain eip155:8453 --wallet compute-wallet --message \"hello\"\n\n# Sign a MegaETH-compatible compute auth message\npython {baseDir}/scripts/ows_cli.py sign-message --chain eip155:4326 --wallet compute-wallet --message \"hello\"\n\n# Sign a Solana-compatible compute auth message\npython {baseDir}/scripts/ows_cli.py sign-message --chain solana --wallet compute-wallet --message \"hello\"\n\n# Create an OWS agent key\npython {baseDir}/scripts/ows_cli.py key-create --name codex-compute --wallet compute-wallet\n```\n\n### D. Credits (payment-free provisioning)\n\n```bash\n# Top up credits via x402 payment (one-time)\n# network: base | solana | megaeth | robinhood | arc  (Arc minimum $5 — gas is paid in USDC there)\ncurl -X POST https://compute.x402layer.cc/compute/credits/topup \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"amount\": 100, \"network\": \"base\"}'\n# Returns 402 → pay → credits added to wallet balance\n\n# Check credit balance\ncurl https://compute.x402layer.cc/compute/credits/balance \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\"\n\n# Provision using credits (no x402/MPP payment needed)\ncurl -X POST https://compute.x402layer.cc/compute/provision \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\n    \"plan\": \"vc2-1c-1gb\",\n    \"region\": \"ewr\",\n    \"os_id\": 2284,\n    \"label\": \"credit-vps\",\n    \"prepaid_hours\": 720,\n    \"ssh_public_key\": \"ssh-ed25519 AAAA... agent\",\n    \"use_credits\": true\n  }'\n\n# Extend using credits\ncurl -X POST https://compute.x402layer.cc/compute/instances/<instance_id>/extend \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"extend_hours\": 720, \"use_credits\": true}'\n```\n\nCredits are scoped per wallet. If the cloud provider rejects the instance after credits are deducted, the full amount is automatically refunded.\n\n---\n\n## x402 Payment Flow\n\n1. Request provision/extend → server returns `HTTP 402` with payment requirements\n2. Script signs payment locally:\n   - Base: USDC `TransferWithAuthorization` (EIP-712)\n   - MegaETH: USDm ERC-2612 `permit` (EIP-712) — gasless for the user, facilitator settles on-chain\n   - Robinhood Chain: USDG `TransferWithAuthorization` (EIP-3009, EIP-712) — gasless for the user, facilitator settles on-chain in a single tx (domain `name=\"Global Dollar\"`, `version=\"1\"`, chainId `4663`)\n   - Solana: signed SPL transfer transaction payload\n3. Script resends request with `X-Payment` header containing signed payload\n4. Server verifies payment, settles on-chain, provisions/extends instance\n\nMegaETH uses an embedded facilitator (no external CDP dependency). The user signs an off-chain ERC-2612 permit, and the facilitator calls `permit()` + `transferFrom()` on MegaETH (~10ms blocks, near-zero gas).\n\nRobinhood Chain also uses an embedded facilitator (no third party). The user signs an off-chain EIP-3009 `TransferWithAuthorization` for USDG (`0x5fc5360D0400a0Fd4f2af552ADD042D716F1d168`, 6 decimals), and the facilitator submits `transferWithAuthorization()` on Robinhood Chain (chainId 4663) in a single transaction — the contract self-verifies the signature, nonce, and balance on-chain.\n\nFor Solana, transient facilitator failures can happen. Retry once or twice if you get a temporary 5xx verify error.\n\n## MPP Payment Flow\n\nMPP is available side-by-side with x402 on the same paid endpoints.\n\n1. Request provision/extend -> server returns `HTTP 402` with `WWW-Authenticate: Payment`\n2. `mppx` or Tempo Wallet creates an MPP credential\n3. Client retries with `Authorization: Payment ...`\n4. Server verifies the MPP payment, provisions/extends the instance, and returns `Payment-Receipt`\n\nNotes:\n- `POST /compute/provision` can be paid via MPP without wallet auth. In that case the response includes `management_api_key`; store it because it is shown once and is required for later management.\n- `POST /compute/instances/:id/extend` via MPP requires compute auth, usually `X-API-Key: $COMPUTE_API_KEY`.\n- `POST /compute/instances/:id/resize` uses compute auth only. It preserves remaining prepaid value by changing expiry instead of charging again.\n- x402 remains fully supported through the Python scripts and `X-Payment` header flow.\n- MPP methods are service-configured. Tempo is used by default by `mppx`; Stripe/card requires a Stripe-capable MPP client/config.\n\n---\n\n## AI Machines — One-Click LLM GPU\n\nOne-click deploy of a **GPU that comes up already running an LLM**. Same x402 lifecycle as any\nMachine (provision / extend / resize / destroy) — you just add `model_id` + `mode` to provision.\nTwo modes, chosen at deploy:\n\n- **`private`** — your own **OpenAI-compatible** endpoint. The box runs `llama-server` exposing\n  `POST /v1/chat/completions` and `GET /v1/models`; the provision response returns the **endpoint URL\n  + API key**. Works with any OpenAI-compatible client/agent/router → **OpenRouter-ready**. (Listing it\n  *as an OpenRouter provider* is a separate OpenRouter approval — roadmap only.)\n- **`grid`** — serve as a grid node and **earn USDC + SGL** (requires **≥ 50,000 $SGL staked**).\n\n**Tier:** Standard (**not** confidential/TEE — for confidential inference use the Grid below or a TEE\nnode). **Managed:** kept alive, auto-updates (allowlist-gated), SSH available. An **agent with a\nfunded wallet can deploy + extend + destroy entirely via x402.**\n\n```bash\n# Deploy a PRIVATE OpenAI-compatible LLM endpoint (returns endpoint + API key)\npython {baseDir}/scripts/provision.py vcg-a100-1c-2g-6gb lax --days 1 --label \"my-llm\" \\\n    --model-id llama-3.2-3b --mode private\n\n# Deploy a GRID node (join the grid & earn; wallet needs 50k SGL staked)\npython {baseDir}/scripts/provision.py vcg-a100-1c-2g-6gb lax --months 1 --label \"grid-node\" \\\n    --model-id llama-3.2-3b --mode grid\n\n# Use a private endpoint (OpenAI-compatible)\ncurl -X POST <ENDPOINT>/v1/chat/completions \\\n  -H \"Content-Type: application/json\" -H \"Authorization: Bearer <RETURNED_API_KEY>\" \\\n  -d '{\"model\":\"llama-3.2-3b\",\"messages\":[{\"role\":\"user\",\"content\":\"Hello\"}]}'\n\n# Extend runtime before it expires (most-used lifecycle action)\npython {baseDir}/scripts/extend_instance.py <instance_id> --hours 720\n\n# Destroy when done\npython {baseDir}/scripts/destroy_instance.py <instance_id>\n```\n\nControl API: `POST /compute/provision` (add `model_id`+`mode`; base fields `plan`,`region`,`os_id`),\n`GET /compute/instances`, `GET /compute/instances/:id`, `POST /compute/instances/:id/extend`,\n`POST /compute/instances/:id/resize`, `POST /compute/instances/:id/password`,\n`DELETE /compute/instances/:id`, `POST /compute/credits/topup`. Full detail + the end-to-end agent\ndeploy example → **`references/ai-machines.md`**.\n\n---\n\n## SGL Grid — Inference\n\nDecentralized, confidential inference across attested TEE nodes — **OpenAI-compatible**, so any OpenAI SDK works by pointing `base_url` at the grid. Requests are end-to-end encrypted and can stream token-by-token.\n\n**API base:** `https://grid.x402compute.cc`\n**Auth:** `X-API-Key: x402c_…` (billed to your prepaid credits — same key/credits as Machines) **or** per-request x402 via `X-Payment`.\n**Billing:** pay-per-token in USDC (credits or x402). No subscription.\n\n| Method | Path | Purpose |\n|--------|------|---------|\n| `GET`  | `/v1/models` | List models currently served by active attested nodes |\n| `POST` | `/v1/chat/completions` | OpenAI-compatible chat (set `\"stream\": true` to stream) |\n| `POST` | `/v1/embeddings` | Text and release-gated EmbeddingGemma 2 text/image/audio/video/mixed vectors |\n| `POST` | `/v1/systemone` | Laya/System One typed decisions (`convaiinnovations/laya`) |\n| `GET`  | `/grid/capacity` | Live capacity: active nodes, TEE types, served models, `at_capacity` |\n\n```bash\n# 1) Reuse your compute API key (x402c_…) + prepaid credits, or create one:\npython {baseDir}/scripts/create_api_key.py --label \"my-agent\"   # → x402c_...\n# Top up credits in the dashboard: Settings → Credits (cloud.x402compute.cc).\n\n# 2) Check what's being served + whether the grid has capacity\ncurl https://grid.x402compute.cc/v1/models -H \"X-API-Key: $COMPUTE_API_KEY\"\ncurl https://grid.x402compute.cc/grid/capacity            # active_nodes, models, at_capacity\n\n# 3) OpenAI-compatible chat (billed to credits)\ncurl -X POST https://grid.x402compute.cc/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"model\":\"llama-3.2-3b\",\"messages\":[{\"role\":\"user\",\"content\":\"Hello\"}]}'\n\n# Streaming: add \"stream\": true and read the SSE token chunks.\n# Pay-per-request with x402 instead of credits: send the X-Payment header\n# (same 402 → sign → resend flow as provision/extend) and omit X-API-Key.\n```\n\nUse any **OpenAI SDK** by setting `base_url=https://grid.x402compute.cc/v1` and `api_key=$COMPUTE_API_KEY`. Before a large batch, check `/grid/capacity` and back off / retry if `at_capacity` is true.\n\n**EmbeddingGemma 2:** call `POST /v1/embeddings`, not chat. It preserves string and string-array\ninput and adds ordered text/image/audio/video parts. Omitted `input_type` defaults to `query`;\n`unspecified` is an explicit prefix opt-out. Only use it when\n`GET /v1/models?type=embedding` lists `embeddinggemma-2`; absence means the default-off release\ngate or exact node capability requirement is not satisfied. Build media requests with\n`grid_embeddings.py` and read `references/multimodal-embeddings.md` for dimensions, limits,\nstable errors, Local mode, sealed transport, and billing.\n\n**Laya/System One:** call `POST /v1/systemone`, not `/v1/chat/completions`. Use\n`GET /v1/models?type=systemone` to discover it. For end-to-end private Laya, use the reserve +\nsealed-submit flow in `references/systemone-laya.md`.\n\n---\n\n## Provide Compute (run a node)\n\nThe other side of the grid: turn a **TEE-capable machine** into a node that serves confidential,\nOpenAI-compatible inference and **earns USDC + SGL** per settled job. Fully agentic — the installer\nand the `sgl` CLI are shell commands. Full runbook (requirements, flags, maintenance, slashing,\nearnings) → **`references/node-operator.md`**.\n\n**Prerequisites:** a supported TEE (e.g. Apple Secure Enclave `apple_se`, Intel TDX/SGX, AMD SEV-SNP,\nAWS Nitro), `llama.cpp` + a GGUF model for chat or a local Laya sidecar for System One, and **≥ 50,000 $SGL staked** to your operator (Solana) wallet.\n\n```bash\n# 1. Stake ≥50,000 SGL to your operator wallet (agentic via the x402-layer skill / Staking Engine API,\n#    or at https://staking.x402layer.cc). Non-custodial; slashable only for proven tampering.\n\n# 2. Install the node CLI + runtime, get a model\ncurl -sSf https://grid.x402compute.cc/install.sh | sh     # installs `sgl` (Singularity-Layer/sgl-network-node)\nbrew install llama.cpp                                     # local inference runtime (macOS)\n#   download a GGUF, e.g. ~/models/Llama-3.2-3B-Instruct-Q4_K_M.gguf\n\n# 3. Register the node under the staked wallet (headless / agentic)\nsgl init --wallet <STAKED_WALLET> --tee-type apple_se --models llama-3.2-3b\n#   (interactive alternative: `sgl login`)\n\n# 4. Attest the enclave (required before jobs; re-run after any binary update)\nsgl attest\n\n# 5. Serve as a background service (production)\nsgl service install \\\n  --model-path ~/models/Llama-3.2-3B-Instruct-Q4_K_M.gguf \\\n  --model-name llama-3.2-3b \\\n  --resource-percent 50\n\n# verify\nsgl status\ncurl https://grid.x402compute.cc/grid/capacity            # your node raises active_nodes / models\n```\n\nFor Laya, use the Singularity Node desktop app v1.7.4+ and select Models → System One → Laya. The app\nstarts the loopback sidecar and the normal node service. CLI fallback:\n`sgl service install --model-name convaiinnovations/laya --systemone-sidecar-url http://127.0.0.1:8765 --max-jobs 1`.\n\n**Maintenance:** `sgl off-grid` (stop new jobs cleanly for planned downtime — no penalty) / `sgl on-grid`\n(resume). Honest downtime is never slashed; only proven tampering is. Re-run `sgl attest` after binary\nupdates. Docs: `https://docs.x402layer.cc/cloud/provide/node-setup`.\n\n---\n\n## Agent Pods — always-on hosted agents\n\nDeploy a persistent AI agent (\"ClawPod\", built on OpenClaw) on a dedicated CPU machine. It stays online 24/7, chats on **Telegram & Discord** (Slack / WhatsApp / Signal are coming soon) **and** from the dashboard, has its own **crypto wallet** (Coinbase CDP — EVM + Solana, keys in a TEE) and **persistent memory**, and ships with the `x402-compute` + `x402-layer` skills preinstalled — wired to your account with capped, revocable credentials — so it can buy confidential compute and pay x402 endpoints itself. Platforms building on Agent Pods can layer owner identity, owner instructions, and a custom self-check heartbeat prompt over the managed base.\n\n**API base:** `https://compute.x402layer.cc`\n**Auth:** pod endpoints **always require compute auth** (`X-API-Key`, a signed compute session, or `X-Auth-*` wallet signature) — even when paying with x402, because a pod is owned by your wallet. (This differs from `POST /compute/provision`, which accepts anonymous x402.)\n**Pay:** platform **credits** (`use_credits: true`) or **x402** (omit `use_credits` → the deploy answers `402 Payment Required`; settle with the `X-Payment` header like any provision, and add `\"network\"` for a non-Base chain).\n**Only `openclaw` is deployable today** (`agent_id: \"openclaw\"`, display name \"ClawPod\"); HermPod (`hermes`) appears in the catalog marked \"coming soon\" and is rejected by deploy.\n\n### Catalog (public, no auth)\n```bash\n# Agents, managed tiers (models per tier), channels, memory backends, pricing\ncurl -s https://compute.x402layer.cc/pods/catalog\n```\n\n### Deploy a pod — `POST /pods`\nTwo AI modes:\n- **`managed`** — we run the LLM and meter it from your credits. Pick a `tier`: `starter` (text chat), `pro` (adds vision + computer-use), `max` (top reasoning + vision). Each tier bundles a machine RAM floor + a curated model menu the agent can switch among at runtime (`/model`). Managed pods include a small prepaid inference allowance.\n- **`byok`** — bring your own OpenAI-compatible key + any machine `plan`. You pay CPU + a small service % only; your AI runs on your key.\n\n```bash\n# Managed Pro pod, paid from credits, with a Telegram bot\ncurl -s -X POST https://compute.x402layer.cc/pods \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\n    \"agent_id\": \"openclaw\",\n    \"ai_mode\": \"managed\",\n    \"tier\": \"pro\",\n    \"plan\": \"<plan_id from /compute/plans>\",\n    \"prepaid_hours\": 720,\n    \"channels\": { \"telegram\": \"<bot_token>\" },\n    \"agent_identity\": \"You are Atlas, Acme Cloud's support agent.\",\n    \"agent_instructions\": \"Answer as Acme support. Be concise and cite the current integration step.\",\n    \"heartbeat_prompt\": \"Check open support escalations and renew yourself if runway is low. Stay silent if clear.\",\n    \"agent_heartbeat_minutes\": 30,\n    \"use_credits\": true\n  }'\n\n# BYOK pod (your own model + key), paid from credits\ncurl -s -X POST https://compute.x402layer.cc/pods \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\n    \"agent_id\": \"openclaw\", \"ai_mode\": \"byok\",\n    \"plan\": \"<plan_id>\", \"prepaid_hours\": 720,\n    \"llm_base_url\": \"https://openrouter.ai/api/v1\",\n    \"llm_api_key\": \"<your_llm_key>\", \"llm_api\": \"openai-completions\",\n    \"model\": \"openai/gpt-4o-mini\",\n    \"use_credits\": true\n  }'\n```\nThe response includes the new `pod.id` (this **is** the compute order id — use it for all pod + lifecycle calls) and, for managed pods, a one-time `managed_ai_key` (the pod's key to our managed LLM proxy — shown once).\n\n**Deploy body fields:**\n- `agent_id` — `\"openclaw\"` (only deployable agent today).\n- `ai_mode` — `\"managed\"` | `\"byok\"`.\n- `tier` — managed only: `\"starter\"` | `\"pro\"` | `\"max\"`.\n- `plan` (+ optional `plan_ram_mb` for a pre-flight RAM check) — the machine; managed tiers enforce a RAM floor (pro/max run a browser on the box).\n- `prepaid_hours` — e.g. `720` = 1 month (min 24).\n- `model` — managed: an override that must be in the chosen tier's model list (else it falls back to the tier default); byok: your model id.\n- `llm_base_url`, `llm_api_key`, `llm_api` — byok only. `llm_api` ∈ `openai-completions` (default) | `openai-responses` | `anthropic-messages` | `google-generative`.\n- `channels` — `{ telegram?: token, discord?: token }` (validated against the agent's supported channels; unsupported channels are rejected).\n- `memory` — byok only: `{ backend: \"raw\"|\"mem0\", api_key?, lcm? }` (managed memory is tier-driven). Applies only when the memory feature is enabled.\n- `agent_identity` — optional owner/platform identity text (max 8000 chars), rendered into the managed `AGENTS.md` customization section and `/opt/pod/workspace/IDENTITY.md`.\n- `agent_instructions` — optional owner/platform instructions (max 8000 chars), rendered into the managed `AGENTS.md` customization section.\n- `heartbeat_prompt` — optional quiet self-check prompt (max 4000 chars), used by the agent heartbeat. It replaces the default survival/check-work prompt only for this pod.\n- `agent_heartbeat_minutes` — optional self-check cadence (`0` disables; otherwise 15-1440 minutes).\n- `use_credits`, `network`, `ssh_public_key`, `region`, `os_id` — passed straight through to the audited provision path.\n\n`AGENTS.md` is not raw-editable over the API. Singularity Layer keeps the platform-managed base so wallet survival, spend caps, x402 safety, and tool boundaries remain intact; your text is appended in a bounded owner/platform section. Use `PATCH /pods/<id>/settings` with empty string or `null` to clear a custom field.\n\n### Free 24-hour trial — `POST /pods/trial`\nA free Starter/Pro pod with **no upfront payment** (funded by a one-time credit grant; gated behind a live campaign, so it can answer `503` when off or fully claimed). One per wallet + device. The pod is **auto-destroyed at 24h** (never renews) and its managed-AI allowance is capped.\n```bash\ncurl -s -X POST https://compute.x402layer.cc/pods/trial \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\n    \"agent_id\": \"openclaw\",\n    \"tier\": \"starter\",\n    \"plan\": \"<plan_id>\",\n    \"device_hash\": \"<sha256 hex device fingerprint>\",\n    \"channels\": { \"telegram\": \"<bot_token>\" }\n  }'\n```\n`tier` must be `starter` or `pro`; `device_hash` is a 64-char sha256 hex. `ai_mode` (managed), `prepaid_hours` (24) and `use_credits` are forced server-side — you supply the tier, plan, device_hash, and any channels.\n\n### Manage a pod\n```bash\ncurl -s https://compute.x402layer.cc/pods       -H \"X-API-Key: $COMPUTE_API_KEY\"   # list yours\ncurl -s https://compute.x402layer.cc/pods/<id>  -H \"X-API-Key: $COMPUTE_API_KEY\"   # details + live heartbeat + masked credential state\n\n# Lifecycle action: restart | redeploy | stop | update | diagnose | logs | pair-approve | cron\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/actions \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" -d '{\"action\":\"restart\"}'\n\n# Link a chat: the bot shows a pairing code in Telegram/Discord; approve it\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/actions \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"action\":\"pair-approve\",\"channel\":\"telegram\",\"code\":\"T64WUC8Q\"}'\n\n# Add/replace channels later (queues a redeploy)\ncurl -s -X PATCH https://compute.x402layer.cc/pods/<id>/channels \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"channels\":{\"discord\":\"<bot_token>\"}}'\n\n# Tune the agent self-check heartbeat, identity, and instructions\ncurl -s -X PATCH https://compute.x402layer.cc/pods/<id>/settings \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"agent_heartbeat_minutes\":30,\n       \"agent_identity\":\"You are Atlas, Acme Cloud support.\",\n       \"agent_instructions\":\"Use Acme terminology and escalate billing questions.\",\n       \"heartbeat_prompt\":\"Review open escalations and renew yourself if needed. Stay silent if clear.\"}'\n```\nActions apply on the pod worker's next poll (≤ 60s). The `cron` action drives the agent's scheduler: `{\"action\":\"cron\",\"verb\":\"add|enable|disable|remove|run\", ...}` (add takes `kind`/`schedule`/`name`/`message`).\n\n### Agent wallet & delegated skill access\n```bash\n# The pod's own wallet — addresses + balances (fund it so the agent can pay for things)\ncurl -s https://compute.x402layer.cc/pods/<id>/wallet -H \"X-API-Key: $COMPUTE_API_KEY\"\n\n# Owner controls: per-tx spend cap + arm sending (default OFF; clamped to a platform ceiling)\ncurl -s -X PATCH https://compute.x402layer.cc/pods/<id>/wallet/settings \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"send_enabled\":true,\"spend_cap_usd\":10}'\n\n# Send from / pay an x402 endpoint with the pod wallet (gated; owner is uncapped, the agent is cap-bound):\n#   POST /pods/<id>/wallet/send      {chain, to, token, amount, idempotency_key}\n#   POST /pods/<id>/wallet/x402/pay  {url, method?, headers?, body?, max_amount_usd?}\n```\n`GET /pods/<id>` returns a masked `credentials` block — the preinstalled skills' pod-scoped Compute key + Studio PAT (for the marketplace / MCP) and its daily cap. Manage it with `POST /pods/<id>/credentials` (`{\"action\":\"enable\"|\"regenerate\"|\"set-cap\"|\"byok\", ...}`) or `DELETE /pods/<id>/credentials` to revoke. Delegated creds, native Singularity MCP, wallet sending, and memory are **feature-gated** and may be dark until launch.\n\n### Extend / destroy\nA pod is a compute order, so use the **Machines endpoints with the pod id as the instance id**:\n```bash\n# Extend early (credits or x402, same as any Machine)\ncurl -s -X POST https://compute.x402layer.cc/compute/instances/<pod.id>/extend \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" -d '{\"extend_hours\":720,\"use_credits\":true}'\n# Destroy (revokes the pod's delegated creds, refunds remaining prepaid time)\ncurl -s -X DELETE https://compute.x402layer.cc/compute/instances/<pod.id> -H \"X-API-Key: $COMPUTE_API_KEY\"\n```\nManaged pods can also **auto-renew** from your credits at expiry (with a grace window) when that feature is enabled; trials never renew. The agent wallet's funds survive destruction (withdraw from the Wallet tab).\n\n### OpenAI-compatible adapter (talk to your pod like any OpenAI endpoint)\nPoint any OpenAI SDK at a pod. **v1 is Chat Completions only, non-streaming, `usage:null`**; the model\nis always `agent-pod` (the pod uses its own configured LLM). The adapter surface is **feature-flagged**\n(dark by default) — it answers `404` until enabled.\n```bash\n# 1) Mint a pod-scoped integration key (owner / compute auth). Raw key shown ONCE.\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/api-keys \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" -d '{\"name\":\"my-integration\"}'\n# → { \"key\": \"sk-sglpod-int-…\", \"base_url\": \"https://compute.x402layer.cc/pods/<id>/v1\" }\n\n# 2) Call it with Authorization: Bearer <key> (NOT compute auth)\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/v1/chat/completions \\\n  -H \"Authorization: Bearer sk-sglpod-int-…\" -H \"Content-Type: application/json\" \\\n  -d '{\"model\":\"agent-pod\",\"stream\":false,\"messages\":[{\"role\":\"user\",\"content\":\"Hello\"}]}'\n```\nKeys are bound to the pod, carry a daily request cap (default 1000/day → `429` over-cap), and are\nrevocable (`DELETE /pods/<id>/api-keys/<keyId>`). Full body fields, response shapes, and error codes\n→ **`references/agent-pods.md`**. Scripted end-to-end: `scripts/agent_pod.py` (`deploy` → `create-key`\n→ `chat`).\n\n---\n\n## Agent Vault — encrypted agent backup & migration\n\nZero-knowledge encrypted snapshots of an agent's entire state (memory, soul,\nconfig, skills) for OpenClaw and Hermes — restorable on any machine or pod.\nEncryption happens on the agent's own machine; the platform stores ciphertext\nit cannot read, so **a lost passphrase is unrecoverable**. Plans: FREE = one\nrolling snapshot (new replaces old), 1 GB. VAULT PRO = $3/month or $30/year —\n10 GB, the last 10 snapshots of each agent. VAULT MAX = $5/month or $50/year —\n50 GB, unlimited snapshots. Paid from credits — or directly with x402 (USDC on Base/Solana, USDG on\nRobinhood, USDm on MegaETH) — via\n`POST /backups/subscribe {\"plan\":\"pro|max\",\"interval\":\"month|year\"}`, adding\n`\"pay\":\"x402\",\"network\":\"base\"` for the x402 rail, or dashboard → Upgrade.\nThe FREE tier needs no call at all.\n\n```bash\nnpm i -g @singularity-layer/agentvault\nagentvault login          # browser wallet approval (or --api-key)\nagentvault backup --all   # encrypt + upload every detected agent\nagentvault backup --path ~/my-agent --name \"My Agent\"   # ANY directory (universal)\nagentvault restore        # bring an agent back, anywhere\n```\n\nPods back up one-click from their dashboard **Backups** tab — no install.\nCross-restoring a snapshot onto a different pod or machine IS migration.\nFull flows, HTTP API, and agent safety rules: `references/agent-vault.md`.\n\n## Plan Types\n\n| Type | Plan Prefix | Description |\n|------|-------------|-------------|\n| GPU | `vcg-*` | GPU-accelerated (A100, H100, etc.) |\n| VPS | `vc2-*` | Standard cloud compute |\n| High-Perf | `vhp-*` | High-performance dedicated |\n| Dedicated | `vdc-*` | Dedicated bare-metal |\n| DigitalOcean | `do:*` | DigitalOcean Droplets (provider-prefixed size slugs) |\n\n---\n\n## Environment Reference\n\n| Variable | Required For | Description |\n|----------|--------------|-------------|\n| `PRIVATE_KEY` | Base/MegaETH/Robinhood payment signing | EVM private key (0x...) |\n| `WALLET_ADDRESS` | Base/MegaETH/Robinhood direct-signing mode | EVM wallet address (0x...) |\n| `SOLANA_SECRET_KEY` | Solana direct-signing mode | Solana signer key (base58 or JSON byte array) |\n| `SOLANA_WALLET_ADDRESS` | Solana direct-signing mode | Solana wallet address (optional if derivable from secret) |\n| `COMPUTE_AUTH_CHAIN` | Chain auth override | `base`, `megaeth`, `robinhood`, or `solana` |\n| `COMPUTE_API_KEY` | Optional | Reusable API key for compute management endpoints |\n| `COMPUTE_AUTH_MODE` | Optional | `auto`, `private-key`, or `ows` |\n| `OWS_WALLET` | OWS aut\n\nFile v1.31.0:_meta.json\n\n{\n  \"ownerId\": \"kn73xndw522wt8y06avyd39a8h7ztbeh\",\n  \"slug\": \"x402-compute\",\n  \"version\": \"1.31.0\",\n  \"publishedAt\": 1791361180079\n}\n\nFile v1.31.0:references/agent-pods-api.md\n\n# Agent Pods API — `/pods/v1` (API-key surface)\n\nThe endpoints in `agent-pods.md` are the **dashboard's** surface: they expect a wallet\nsignature or a compute session, which is right for a human at a browser and awkward for a\nprogram. `/pods/v1` is the same product behind **one API key**, meant for building on top of\npods rather than clicking them.\n\nUse this reference when the caller holds an `x402c_…` key and no wallet. Use `agent-pods.md`\nwhen signing with OWS.\n\n- **Base:** `https://compute.x402layer.cc/pods/v1`\n- **Auth:** `X-API-Key: x402c_…` on every route\n- **Mint a key:** dashboard → Settings → API Keys\n\n---\n\n## Two rules that will cost you if you skip them\n\n**Create is idempotent and the header is required.** `POST /pods` refuses without\n`Idempotency-Key`, because the call provisions a machine and charges for it. Replaying the\nsame key returns the original response byte for byte instead of making a second pod; the same\nkey with a *different* body is a `409` with `details.code = idempotency_mismatch`, since that\nis a bug in the caller and swallowing it would hide it.\n\nUse an id you already have — an order number, a job id. A generated UUID protects a retry\ninside one process; only a stable id protects a retry after that process dies.\n\n**Delete is not instant.**\n\n| Response | Meaning |\n|---|---|\n| `200` `destroyed` | the machine is confirmed gone |\n| `202` `destroying` | accepted, provider would not delete yet, **may bill a few minutes more** |\n\nA provider refuses to remove a machine that is still installing. Treating `202` as done is how\na pod keeps billing after you thought you deleted it. Poll `GET /pods/{id}` until `destroyed`.\n\n---\n\n## Create, then talk to it\n\n```bash\nPOD=$(curl -s -X POST https://compute.x402layer.cc/pods/v1/pods \\\n  -H \"X-API-Key: $SGL_API_KEY\" \\\n  -H \"Idempotency-Key: order-4471\" \\\n  -H 'content-type: application/json' \\\n  -d '{\n    \"tier\": \"starter\",\n    \"name\": \"support agent\",\n    \"external_ref\": \"customer-42\",\n    \"agent_identity\": \"You are Atlas, Acme Cloud support.\",\n    \"agent_instructions\": \"Answer as Acme support. Be concise and cite the current integration step.\",\n    \"heartbeat_prompt\": \"Check open escalations and renew yourself if runway is low. Stay silent if clear.\",\n    \"agent_heartbeat_minutes\": 30\n  }' | jq -r .pod.id)\n\n# Booting takes a few minutes. status goes provisioning -> online.\ncurl -s \"https://compute.x402layer.cc/pods/v1/pods/$POD\" -H \"X-API-Key: $SGL_API_KEY\" | jq -r .pod.status\n```\n\n`external_ref` is **your** id. It comes back on every read and filters `GET /pods`, so you can\nfind a pod again from your own database without storing ours.\n\n### Customizing the agent\n\nPlatforms can customize a pod without taking over the managed runtime files:\n\n| Field | Create | PATCH | Meaning |\n|---|---:|---:|---|\n| `agent_identity` | yes | yes | Owner/platform identity text, max 8000 chars. Rendered into managed `AGENTS.md` and `IDENTITY.md`. |\n| `agent_instructions` | yes | yes | Owner/platform operating instructions, max 8000 chars. Rendered into managed `AGENTS.md`. |\n| `heartbeat_prompt` | yes | yes | Prompt for the quiet self-check heartbeat, max 4000 chars. |\n| `agent_heartbeat_minutes` | yes | yes | Heartbeat cadence: `0` disables; otherwise 15-1440 minutes. |\n\n`AGENTS.md` itself is **not** raw-editable through the API. The platform-managed base keeps\nwallet survival, spend caps, x402 payment safety, and tool boundaries intact. Your text is\nrendered into a bounded owner/platform section; send `\"\"` or `null` on PATCH to clear a\ncustom text field and restore the default heartbeat prompt.\n\n`GET /pods/{id}` returns:\n\n```json\n{\n  \"pod\": {\n    \"id\": \"pod_...\",\n    \"customization\": {\n      \"agent_identity\": \"You are Atlas, Acme Cloud support.\",\n      \"agent_instructions\": \"Answer as Acme support.\",\n      \"heartbeat_prompt\": \"Check open escalations. Stay silent if clear.\"\n    },\n    \"agent_heartbeat_minutes\": 30\n  }\n}\n```\n\nOnce `online`, mint a pod key and use any OpenAI client. The model id is **`agent-pod`**:\n\n```bash\nKEY=$(curl -s -X POST \"https://compute.x402layer.cc/pods/v1/pods/$POD/keys\" \\\n  -H \"X-API-Key: $SGL_API_KEY\" -H 'content-type: application/json' -d '{}' | jq -r .key.secret)\n\ncurl -s -X POST \"https://compute.x402layer.cc/pods/$POD/v1/chat/completions\" \\\n  -H \"Authorization: Bearer $KEY\" -H 'content-type: application/json' \\\n  -d '{\"model\":\"agent-pod\",\"messages\":[{\"role\":\"user\",\"content\":\"summarise today\"}]}'\n```\n\nStreaming works (`\"stream\": true`, SSE). The pod key is returned **once**; it is not the same\nthing as the account key and cannot manage pods.\n\n---\n\n## Routes\n\n| Method | Path | Notes |\n|---|---|---|\n| `POST` | `/pods` | `Idempotency-Key` required. `201`, `status: provisioning` |\n| `GET` | `/pods` | Newest first. `?external_ref=`, `?cursor=`, `?limit=` |\n| `GET` `PATCH` `DELETE` | `/pods/{id}` | PATCH: `name`, `model`, `slug`, `auto_renew`, `agent_identity`, `agent_instructions`, `heartbeat_prompt`, `agent_heartbeat_minutes` |\n| `POST` `GET` | `/pods/{id}/keys` | Pod endpoint keys; secret shown once |\n| `DELETE` | `/pods/{id}/keys/{keyId}` | Takes effect immediately |\n| `GET` | `/pods/{id}/usage` | AI spend and token counts |\n| `POST` `GET` | `/pods/{id}/actions` | `restart`, `stop`, `redeploy`, `update`, `diagnose`, `logs` |\n| `GET` `POST` | `/pods/{id}/tasks` | Scheduled tasks |\n| `PATCH` `DELETE` | `/pods/{id}/tasks/{jobId}` | |\n| `GET` `PATCH` | `/pods/{id}/wallet` | Cap field is `per_tx_cap_usd` |\n| `GET` `PATCH` | `/pods/{id}/updates` | Who decides when this pod takes our updates |\n| `POST` | `/pods/{id}/wallet/send` | Move funds. Needs `pods:wallet:write` |\n| `POST` | `/pods/{id}/wallet/x402/pay` | Pay an x402 endpoint from the pod wallet |\n| `GET` `POST` `DELETE` | `/pods/{id}/connectors` | MCP connectors |\n| `GET` `PATCH` | `/pods/{id}/backups` | |\n| `POST` | `/pods/{id}/chat-ticket` | Ticket for the streaming socket |\n| `POST` `GET` | `/pods/{id}/channels/telegram/join-code` | POST mints, GET polls |\n| `POST` | `/pods/{id}/channels/telegram/connect` | Attaches the group that claimed the code |\n| `POST` | `/pods/{id}/channels/{channel}/pair` | Approves someone to DM the agent |\n| `GET` | `/events` | Account event log, paged by `seq` |\n| `POST` `GET` | `/webhooks` · `PATCH` `DELETE` `/webhooks/{id}` | |\n\n### Actions are queued, not immediate\n\n`POST /actions` returns **202**. The pod applies it on its next check-in, usually within a\nminute. `diagnose` and `logs` write their output back through the heartbeat — read it from\n`GET /actions` as `last_result`, and expect a minute or two, not a second.\n\nSame for `tasks` and `connectors`: a `202` means the pod has been told, not that it is done.\n`GET /tasks` reports what the pod itself says it has, so it lags the write by a heartbeat.\n\n### Pairing: who may DM the agent\n\nA stranger who finds the bot's username can DM it, and unlike a group that conversation is\nprivate. So the agent refuses unknown people, shows them a short code, and waits. `POST\n.../channels/{channel}/pair` with that `code` approves them.\n\nThe code must come from the agent, so this approves a pairing somebody already started — it\ncannot add a person who never asked.\n\n### Deciding when a pod takes an update\n\nWe ship updates to the pod's scripts, and by default a pod applies ours within six hours,\nrestarting its gateway for about forty seconds. That is fine for a pod you run for yourself.\nIt is not fine if you run pods for customers, because their agents all blink offline at a\nmoment you did not choose.\n\n`PATCH /pods/{id}/updates` with `{\"mode\":\"manual\"}` and we keep answering that pod's version\npoll with the version it already has, so it never updates itself. You apply the update when it\nsuits you:\n\n```bash\ncurl -X POST \".../pods/v1/pods/$POD/actions\" -H \"X-API-Key: $KEY\" \\\n  -H 'content-type: application/json' -d '{\"action\":\"update\"}'\n```\n\n`GET /pods/{id}/updates` tells you whether one is waiting, and `pod.update_available` fires in\nthe event log when a release arrives that a held pod has not taken.\n\n**The hold expires after 30 days.** Security fixes ride these bundles, so a pod pinned\nindefinitely stops being your scheduling choice and becomes an unpatched machine. The response\nalways names the date, and `hold_expired: true` says plainly when the window has passed.\n\n\n---\n\n## Scopes\n\nOrdinary work needs `compute:read` / `compute:write`. Two powers are deliberately separate, so\na general key cannot use them:\n\n| Scope | Grants |\n|---|---|\n| `pods:wallet:write` | Send from a pod wallet, pay x402 endpoints with it, raise its caps, set a backup passphrase |\n| `pods:control:write` | Add/remove connectors, and a full-power control socket (pod files, skills, backups) |\n\nWithout `pods:control:write` a chat ticket is issued at **`chat`** scope: the socket accepts\nconversation and nothing else. That is the intended default. Ask for the scope only when you\nneed the workspace, and expect a `403` naming it if you did not.\n\n---\n\n## Events and webhooks\n\n**The log is the source of truth; webhooks are one way to read it.** A failed delivery is\ngone, the log is not — so if you miss one, page `GET /events` and catch up.\n\nPage by **`seq`**, never by timestamp. `seq` only goes up. Two events can share a millisecond,\nand a timestamp cursor either skips one or repeats it forever.\n\n```bash\ncurl -s \"https://compute.x402layer.cc/pods/v1/events?after=41&limit=50\" -H \"X-API-Key: $SGL_API_KEY\"\n# { \"events\": [...], \"next_after\": 92, \"has_more\": true }\n```\n\nTypes: `pod.created`, `pod.active`, `pod.destroyed`, `pod.destroy_failed`,\n`pod.action.queued`, `pod.status.changed`, `pod.renewed`, `pod.renewal_failed`,\n`pod.expiring`, `pod.backup.completed`, `pod.backup.failed`, `pod.update_available`.\n\n### Verifying a delivery\n\nHTTPS only. The signing secret is returned **once** at creation. Omit `event_types` for\neverything; an empty array is refused, because subscribing to nothing is a webhook that\nsilently never fires.\n\n```\nx-sgl-signature: t=<unix>,v1=<hmac-sha256 of \"<t>.<raw body>\">\nx-sgl-event-type: pod.status.changed\nx-sgl-event-id: <uuid>\n```\n\n**Verify against the raw body.** Parsing and re-encoding JSON changes key order and spacing,\nand the signature covers the bytes we sent — re-serialise and a genuine delivery will fail to\nverify. Both SDKs ship a helper (`verifyPodWebhook`, `verify_pod_webhook`) that also enforces\nthe timestamp window; without that window, putting the timestamp inside the signature buys\nnothing, because an old capture would still verify.\n\nFailures back off (1, 5, 15, 60, 180, 360, 720 minutes) and then stop. When we give up,\n`disabled_by_us_at` is set — deliberately distinct from `enabled: false`, which is you turning\nit off. From the outside both look like silence.\n\n---\n\n## Errors and limits\n\n```json\n{ \"error\": { \"code\": \"conflict\", \"message\": \"...\", \"details\": { \"code\": \"idempotency_mismatch\" } } }\n```\n\nBranch on `code`, not the message: `invalid_request`, `unauthorized`, `forbidden`,\n`not_found`, `conflict`, `limit_exceeded`, `capability_disabled`, `rate_limited`,\n`not_implemented`, `internal`.\n\nEvery response carries **`x-request-id`**. Send your own and it is echoed; quote it in a\nsupport message and it can be found in our logs.\n\n| Limit | |\n|---|---|\n| Reads | 240/min per account |\n| Writes | 60/min per account |\n| **Creates** | **60/hour**, a separate bucket — this one provisions machines and charges |\n| Body | 128 KB |\n| Wallet moves | 30/hour, its own bucket |\n| Webhooks | 10 per account |\n| Event retention | 30 days |\n\n---\n\n## SDKs\n\nBoth published clients wrap this surface and are kept feature-equal:\n\n```ts\nimport { PodsClient } from \"@singularity-layer/grid\";\nconst pods = new PodsClient({ apiKey: process.env.SGL_API_KEY! });\nconst pod = await pods.createPod({\n  tier: \"starter\",\n  idempotencyKey: `order-${id}`,\n  agentIdentity: \"You are Atlas, Acme Cloud support.\",\n  agentInstructions: \"Answer as Acme support and cite the integration step.\",\n  heartbeatPrompt: \"Check open escalations. Stay silent if clear.\",\n  agentHeartbeatMinutes: 30,\n});\nawait pods.waitForOnline(pod.id);\n```\n\n```python\nfrom singularity_grid import PodsClient\npods = PodsClient(api_key=os.environ[\"SGL_API_KEY\"])\npod = pods.create_pod(\n    tier=\"starter\",\n    idempotency_key=f\"order-{id}\",\n    agent_identity=\"You are Atlas, Acme Cloud support.\",\n    agent_instructions=\"Answer as Acme support and cite the integration step.\",\n    heartbeat_prompt=\"Check open escalations. Stay silent if clear.\",\n    agent_heartbeat_minutes=30,\n)\npods.wait_for_online(pod[\"id\"])\n```\n\n`waitForDestroyed` / `wait_for_destroyed` exist for the same reason the `202` above does: they\nhold until the machine is genuinely gone rather than until we accepted the request.\n\nFile v1.31.0:references/agent-pods.md\n\n# Agent Pods — deploy & drive an always-on hosted agent\n\nAn **Agent Pod** (\"ClawPod\", built on **OpenClaw**) is a persistent AI agent that runs 24/7 on\na dedicated CPU machine. It chats on **Telegram & Discord** (Slack / WhatsApp / Signal coming\nsoon) and from the dashboard, has its own **crypto wallet** (Coinbase CDP — EVM + Solana, keys in\na TEE), **persistent memory**, and ships with the `x402-compute` + `x402-layer` skills preinstalled\n(wired to your account with capped, revocable credentials) so it can buy confidential compute and\npay x402 endpoints itself. Owner/platform customization is supported through structured fields:\nidentity, instructions, and the quiet self-check heartbeat prompt.\n\nA pod **is a compute order** — the `pod.id` returned by deploy is the compute order id. Lifecycle\n(extend / destroy) reuses the Machines endpoints with that id as the instance id.\n\n- **API base:** `https://compute.x402layer.cc`\n- **Only `openclaw` is deployable today** (`agent_id: \"openclaw\"`, display name \"ClawPod\").\n  `hermes` (\"HermPod\") shows in the catalog marked *coming soon* and is rejected by deploy.\n\n## Auth model (important)\n\nPod endpoints split into two auth surfaces:\n\n| Surface | Endpoints | Auth |\n|---------|-----------|------|\n| **Owner** (manage the pod) | `POST /pods`, `GET/PATCH /pods/{id}`, `POST /pods/{id}/actions`, `GET/POST/DELETE /pods/{id}/api-keys*`, wallet, credentials | **Compute auth** — `X-API-Key: x402c_…`, a signed compute session, or an `X-Auth-*` wallet signature. Required even when paying with x402, because a pod is owned by your wallet. |\n| **Adapter** (talk to the agent) | `GET /pods/{id}/v1/models`, `POST /pods/{id}/v1/chat/completions` | **`Authorization: Bearer sk-sglpod-int-…`** — a pod-scoped integration key you mint via `POST /pods/{id}/api-keys`. NOT compute auth. |\n\nThe catalog (`GET /pods/catalog`) is public (no auth).\n\n## 1. Catalog (public)\n\n```bash\ncurl -s https://compute.x402layer.cc/pods/catalog\n```\nReturns deployable agents, managed **tiers** (with each tier's model menu + RAM floor), supported\n**channels**, memory backends, and pricing. Read it first to pick a `tier`/`plan`/`model`.\n\n## 2. Deploy — `POST /pods` (owner / compute auth)\n\nTwo AI modes:\n\n- **`managed`** — we run the LLM and meter it from your platform **credits**. Pick a `tier`:\n  - `starter` — text chat.\n  - `pro` — adds vision + computer-use (runs a browser on the box → higher RAM floor).\n  - `max` — top reasoning + vision.\n  Each tier bundles a machine RAM floor + a curated model menu the agent can switch among at\n  runtime (`/model`). Managed pods include a small prepaid inference allowance.\n- **`byok`** — bring your own OpenAI-compatible key + any machine `plan`. You pay CPU + a small\n  service % only; your AI runs on your key.\n\n**Pay:** platform **credits** (`use_credits: true`) or **x402** (omit `use_credits` → the deploy\nanswers `402 Payment Required`; settle with the `X-Payment` header like any provision, and add\n`\"network\"` for a non-Base chain).\n\n### Deploy body fields\n| Field | Mode | Notes |\n|-------|------|-------|\n| `agent_id` | both | `\"openclaw\"` (only deployable agent today). |\n| `ai_mode` | both | `\"managed\"` \\| `\"byok\"`. |\n| `tier` | managed | `\"starter\"` \\| `\"pro\"` \\| `\"max\"`. |\n| `plan` | both | Machine plan id (from `GET /compute/plans`). Add optional `plan_ram_mb` for a pre-flight RAM check; managed tiers enforce a RAM floor. |\n| `prepaid_hours` | both | e.g. `720` = 1 month (min 24). |\n| `model` | both | managed: an override that must be in the chosen tier's model list (else falls back to the tier default); byok: your model id. |\n| `llm_base_url`, `llm_api_key`, `llm_api` | byok | `llm_api` ∈ `openai-completions` (default) \\| `openai-responses` \\| `anthropic-messages` \\| `google-generative`. |\n| `channels` | both | `{ telegram?: token, discord?: token }` — validated against the agent's supported channels; unsupported channels are rejected. |\n| `memory` | byok | `{ backend: \"raw\"\\|\"mem0\", api_key?, lcm? }` (managed memory is tier-driven; feature-gated). |\n| `template`, `template_config` | both | Curated template — what the pod is FOR. See **Templates** below. |\n| `agent_identity` | both | Owner/platform identity text, max 8000 chars. Rendered into the managed `AGENTS.md` customization section and `/opt/pod/workspace/IDENTITY.md`. |\n| `agent_instructions` | both | Owner/platform instructions, max 8000 chars. Rendered into the managed `AGENTS.md` customization section. |\n| `heartbeat_prompt` | both | Custom prompt for the agent's quiet self-check heartbeat, max 4000 chars. |\n| `agent_heartbeat_minutes` | both | Self-check cadence: `0` disables; otherwise 15-1440 minutes. |\n| `use_credits`, `network`, `ssh_public_key`, `region`, `os_id` | both | Passed straight through to the audited provision path. |\n\n`AGENTS.md` is platform-managed and is not raw-editable through the API. This is intentional:\nwallet survival, x402 spend boundaries, security rules, and tool permissions stay intact while\nyour owner/customer text is layered into a bounded customization section. Send an empty string\nor `null` to `PATCH /pods/{id}/settings` to clear one of the custom text fields.\n\n### Templates — curated pods with a job\n\nA template layers a purpose on top of the engine: it supplies the persona, the channel\npolicy and the briefing schedule. Everything else (tiers, BYOK, wallet, self-extend,\nskills) works exactly as on a bare pod. `GET /pods/catalog` returns `templates[]` with the\nsetup keys each one needs, and `templates_enabled` saying whether deploy will accept one.\n\n| Template | Name | What it is |\n|----------|------|------------|\n| `community-manager` | **TGPod** | Runs a Telegram community: answers members, removes scam links and impersonators, and sends the owner a private briefing on a schedule. |\n| `discord-community` | **DiscordPod** | Announced, not yet buildable — deploy refuses it. |\n\n`community-manager` setup keys (`template_config`): `group_id` (required; comma-separate\nseveral, up to the tier's `max_groups` — 1 Starter / 3 Pro / 10 Max, BYOK gets the top of\nthat ladder), `owner_id` (required — the Telegram user id the briefings go to),\n`project_summary`, `agent_name`, `house_rules`, `tone`, `digest_minutes`. The template\nrequires its channel: deploy a `community-manager` **with** `channels.telegram` or it is\nrejected before anything is charged.\n\nThe bot token belongs to the pod's moderation process, which must be Telegram's single\n`getUpdates` consumer for that bot. Do not point another program at the same token.\n\n```bash\n# TGPod: a Pro community manager for one Telegram group\npython scripts/agent_pod.py deploy --ai-mode managed --tier pro --plan <plan_id> \\\n  --use-credits --telegram \"$BOT_TOKEN\" \\\n  --template community-manager \\\n  --template-config group_id=-1001234567890 \\\n  --template-config owner_id=987654321 \\\n  --template-config project_summary=\"Singularity Layer — decentralised confidential compute\"\n```\n\nPods report their template back on `list` / `get` / deploy as `template`, so an agent\nrunning a fleet can tell a community manager from a bare pod.\n\n```bash\n# Managed Pro pod, paid from credits, with a Telegram bot\ncurl -s -X POST https://compute.x402layer.cc/pods \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\n    \"agent_id\": \"openclaw\",\n    \"ai_mode\": \"managed\",\n    \"tier\": \"pro\",\n    \"plan\": \"<plan_id>\",\n    \"prepaid_hours\": 720,\n    \"channels\": { \"telegram\": \"<bot_token>\" },\n    \"agent_identity\": \"You are Atlas, Acme Cloud's support agent.\",\n    \"agent_instructions\": \"Answer as Acme support. Be concise and cite the current integration step.\",\n    \"heartbeat_prompt\": \"Check open support escalations and renew yourself if runway is low. Stay silent if clear.\",\n    \"agent_heartbeat_minutes\": 30,\n    \"use_credits\": true\n  }'\n\n# BYOK pod (your own model + key), paid from credits\ncurl -s -X POST https://compute.x402layer.cc/pods \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\n    \"agent_id\": \"openclaw\", \"ai_mode\": \"byok\",\n    \"plan\": \"<plan_id>\", \"prepaid_hours\": 720,\n    \"llm_base_url\": \"https://openrouter.ai/api/v1\",\n    \"llm_api_key\": \"<your_llm_key>\", \"llm_api\": \"openai-completions\",\n    \"model\": \"openai/gpt-4o-mini\",\n    \"use_credits\": true\n  }'\n```\n\n**Deploy response** includes a `pod` object:\n```json\n{\n  \"pod\": {\n    \"id\": \"<order_id>\",              // == compute order id; use for ALL pod + lifecycle calls\n    \"agent_id\": \"openclaw\",\n    \"display_name\": \"ClawPod\",\n    \"ai_mode\": \"managed\",\n    \"tier\": \"pro\",\n    \"model\": \"<model>\",\n    \"channels\": [\"telegram\"],\n    \"managed_ai_key\": \"sk-sglpod-…\",  // managed only, shown ONCE (pod's key to our LLM proxy)\n    \"managed_ai_key_note\": \"Shown once — this is the pod's key for our managed LLM proxy.\"\n  }\n}\n```\nThe `managed_ai_key` is the pod's own internal key to our managed LLM proxy (not the integration\nkey you call the adapter with). It is shown once.\n\n### Free 24-hour trial — `POST /pods/trial`\nA free Starter/Pro pod with **no upfront payment** (funded by a one-time credit grant; gated behind\na live campaign, so it can answer `503` when off or fully claimed). One per wallet + device.\nAuto-destroyed at 24h (never renews); managed-AI allowance capped.\n```bash\ncurl -s -X POST https://compute.x402layer.cc/pods/trial \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{ \"agent_id\": \"openclaw\", \"tier\": \"starter\", \"plan\": \"<plan_id>\",\n        \"device_hash\": \"<sha256 hex device fingerprint>\",\n        \"channels\": { \"telegram\": \"<bot_token>\" } }'\n```\n`tier` must be `starter` or `pro`; `device_hash` is a 64-char sha256 hex. `ai_mode` (managed),\n`prepaid_hours` (24) and `use_credits` are forced server-side.\n\n## 3. Manage a pod (owner / compute auth)\n\n```bash\ncurl -s https://compute.x402layer.cc/pods       -H \"X-API-Key: $COMPUTE_API_KEY\"   # list yours\ncurl -s https://compute.x402layer.cc/pods/<id>  -H \"X-API-Key: $COMPUTE_API_KEY\"   # details + heartbeat + masked creds\n\n# Lifecycle action: restart | redeploy | stop | update | diagnose | logs | pair-approve | cron\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/actions \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" -d '{\"action\":\"restart\"}'\n\n# Approve a chat pairing code the bot showed in Telegram/Discord\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/actions \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"action\":\"pair-approve\",\"channel\":\"telegram\",\"code\":\"T64WUC8Q\"}'\n\n# Add/replace channels later (queues a redeploy)\ncurl -s -X PATCH https://compute.x402layer.cc/pods/<id>/channels \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"channels\":{\"discord\":\"<bot_token>\"}}'\n\n# Tune knobs: agent self-check heartbeat, customization, managed model, auto-renew\ncurl -s -X PATCH https://compute.x402layer.cc/pods/<id>/settings \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"agent_heartbeat_minutes\":30,\n       \"agent_identity\":\"You are Atlas, Acme Cloud support.\",\n       \"agent_instructions\":\"Use Acme terminology and escalate billing questions.\",\n       \"heartbeat_prompt\":\"Review open escalations and renew yourself if needed. Stay silent if clear.\"}'\n```\nActions apply on the pod worker's next poll (≤ 60s). The `cron` action drives the agent's scheduler:\n`{\"action\":\"cron\",\"verb\":\"add|enable|disable|remove|run\", ...}` (add takes `kind`/`schedule`/`name`/`message`).\n\n`GET /pods` and `GET /pods/{id}` return:\n\n```json\n{\n  \"customization\": {\n    \"agent_identity\": \"You are Atlas, Acme Cloud support.\",\n    \"agent_instructions\": \"Use Acme terminology and escalate billing questions.\",\n    \"heartbeat_prompt\": \"Review open escalations and renew yourself if needed. Stay silent if clear.\"\n  },\n  \"agent_heartbeat_minutes\": 30\n}\n```\n\n### Agent wallet & delegated skill access\n```bash\ncurl -s https://compute.x402layer.cc/pods/<id>/wallet -H \"X-API-Key: $COMPUTE_API_KEY\"   # addresses + balances\n\n# Owner controls: per-tx spend cap + arm sending (default OFF; clamped to a platform ceiling)\ncurl -s -X PATCH https://compute.x402layer.cc/pods/<id>/wallet/settings \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"send_enabled\":true,\"spend_cap_usd\":10}'\n```\n`GET /pods/<id>` returns a masked `credentials` block (the preinstalled skills' pod-scoped Compute\nkey + Studio PAT and its daily cap). Manage with `POST /pods/<id>/credentials`\n(`{\"action\":\"enable\"|\"regenerate\"|\"set-cap\"|\"byok\", ...}`) or `DELETE /pods/<id>/credentials` to\nrevoke. Delegated creds, native Singularity MCP, wallet sending, and memory are feature-gated and\nmay be dark until launch.\n\n### Extend / destroy (Machines endpoints, pod id as instance id)\n```bash\ncurl -s -X POST https://compute.x402layer.cc/compute/instances/<pod.id>/extend \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" -d '{\"extend_hours\":720,\"use_credits\":true}'\ncurl -s -X DELETE https://compute.x402layer.cc/compute/instances/<pod.id> -H \"X-API-Key: $COMPUTE_API_KEY\"\n```\nManaged pods can auto-renew from credits at expiry (grace window) when enabled; trials never renew.\nThe agent wallet's funds survive destruction (withdraw from the Wallet tab).\n\n## 4. OpenAI-compatible adapter — call your pod like any OpenAI endpoint\n\nThe adapter turns `POST /pods/{id}/v1/chat/completions` into **one agent turn** on your pod, run\nthrough the same Worker → PodChannel → outbound-tunnel path as dashboard/Telegram chat (so wallet\npolicy, autonomy mode, credits, lifecycle + audit all stay enforced). The VM is never exposed.\n\n**v1 is intentionally minimal: Chat Completions only, non-streaming, no fake token usage.**\n\n- **Model:** always `agent-pod` (the pod picks its own configured LLM internally).\n- **Streaming:** NOT supported — you must send `\"stream\": false` (or omit it). `stream:true` → 400.\n- **`usage`** is `null` in v1 (token counts are not faked).\n- **Feature flag:** the whole adapter surface is dark by default (server flag\n  `POD_OPENAI_ADAPTER_ENABLED`). When off, key management + adapter routes return `404`.\n\n### 4a. Create an integration key — `POST /pods/{id}/api-keys` (owner / compute auth)\n```bash\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/api-keys \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" -H \"Content-Type: application/json\" \\\n  -d '{\"name\":\"my-integration\"}'\n# → { \"key\": \"sk-sglpod-int-…\", \"base_url\": \"https://compute.x402layer.cc/pods/<id>/v1\", \"row\": {…} }\n```\n- The **raw key (`sk-sglpod-int-…`) is returned ONCE** — store it. Only its SHA-256 hash is kept.\n- The key is **bound to this pod**; using it against a different pod fails as `invalid_key`.\n- Each key has a **daily request cap** (default 1000/day, rolling 24h window); over-cap → `429`.\n- List: `GET /pods/{id}/api-keys` (masked). Revoke: `DELETE /pods/{id}/api-keys/{keyId}`.\n\n### 4b. Call the adapter — `Authorization: Bearer sk-sglpod-int-…`\n```bash\n# List the (single) model the adapter exposes\ncurl -s https://compute.x402layer.cc/pods/<id>/v1/models \\\n  -H \"Authorization: Bearer sk-sglpod-int-…\"\n\n# One agent turn (non-streaming)\ncurl -s -X POST https://compute.x402layer.cc/pods/<id>/v1/chat/completions \\\n  -H \"Authorization: Bearer sk-sglpod-int-…\" -H \"Content-Type: application/json\" \\\n  -d '{\"model\":\"agent-pod\",\"stream\":false,\n       \"messages\":[{\"role\":\"user\",\"content\":\"What is on my calendar today?\"}]}'\n```\nResponse is a standard `chat.completion` object with `choices[0].message.content` and `usage:null`.\n\nPoint any **OpenAI SDK** at the pod:\n```python\nfrom openai import OpenAI\nclient = OpenAI(\n    base_url=\"https://compute.x402layer.cc/pods/<id>/v1\",\n    api_key=\"sk-sglpod-int-…\",\n)\nresp = client.chat.completions.create(\n    model=\"agent-pod\",\n    messages=[{\"role\": \"user\", \"content\": \"Summarize my unread DMs\"}],\n    stream=False,\n)\nprint(resp.choices[0].message.content)\n```\n\n### Adapter error shapes (OpenAI-style `{ \"error\": {…} }`)\n| Status | code | Meaning |\n|--------|------|---------|\n| `401` | `missing_key` / `invalid_key` | No bearer key, or key not valid for this pod. |\n| `404` | `pod_unavailable` | Adapter disabled, or the pod is destroyed. |\n| `403` | `pod_expired` | The pod's prepaid time ran out. |\n| `429` | `daily_cap` | The key's daily request cap is exhausted. |\n| `400` | `stream_unsupported` | You sent `stream:true`. |\n| `503` | `pod_offline` | Agent offline — retryable, not charged. |\n| `504` | `timeout` | Agent took too long — retryable. |\n\n## Helper script\n`scripts/agent_pod.py` wraps all of the above (owner calls use the shared compute-auth loader;\nadapter calls use the integration key). See the Intent Router in `SKILL.md`.\n```bash\npython scripts/agent_pod.py catalog\npython scripts/agent_pod.py deploy --ai-mode managed --tier pro --plan <plan_id> --prepaid-hours 720 \\\n    --telegram <bot_token> --use-credits\npython scripts/agent_pod.py create-key <pod_id> --name my-integration      # → sk-sglpod-int-…\npython scripts/agent_pod.py chat <pod_id> \"What's on my calendar?\" --key sk-sglpod-int-…\n```\nCredentials are read only from explicit env vars (`COMPUTE_API_KEY` or wallet keys for owner calls;\n`POD_INTEGRATION_KEY` or `--key` for the adapter). No `.env` auto-loading.\n</content>\n</invoke>\n\nFile v1.31.0:references/agent-vault.md\n\n# Agent Vault — encrypted agent backup & migration\n\nZero-knowledge encrypted backup, restore, and migration for AI agents\n(OpenClaw `~/.openclaw`, Hermes `~/.hermes`). Snapshot an agent's entire\nself — memory, soul/workspace, config, skills — and bring it back anywhere:\na new machine, a fresh Agent Pod, or the same box after a bad day.\n\n**Zero-knowledge, for real:** every backup is sealed on the machine it lives\non (scrypt key derivation + AES-256-GCM, AAD-bound to the snapshot identity).\nThe platform stores ciphertext it cannot read. That cuts both ways — **a lost\npassphrase is unrecoverable by anyone, including Singularity Layer.** Tell the\nuser to write it down before the first backup.\n\nDashboard: https://cloud.x402compute.cc/network/backups\nPlans (all paid from platform credits):\n  FREE      — 1 GB, 1 rolling snapshot (each new backup replaces the previous).\n  VAULT PRO — 10 GB, the last 10 snapshots OF EACH AGENT. $3/month or $30/year.\n  VAULT MAX — 50 GB, unlimited snapshots, full history. $5/month or $50/year.\nYearly is two months free. The FREE tier needs no call and no payment — every\nwallet starts there. Subscribe with\n`POST /backups/subscribe {\"plan\":\"pro\"|\"max\",\"interval\":\"month\"|\"year\"}`\n(credits), or add `\"pay\":\"x402\",\"network\":\"base\"|\"solana\"|\"robinhood\"|\"megaeth\"`\nto pay directly: the route answers 402 with an x402 challenge when a charge is\nrequired and credits are short, then activates on the retry carrying\n`X-Payment`. The challenge quotes the FULL plan price; proration means the real\ndebit can be lower and the remainder stays as credits. Cancels and scheduled\ndowngrades never produce a challenge. The payer must be the authenticated\nwallet, and a replayed `X-Payment` cannot double-charge. The dashboard route is\nAgent Vault → Upgrade.\n\nUpgrades charge now, PRORATED against the unused part of the period already\npaid for, and start a fresh period; downgrades and `\"plan\":\"free\"` (cancel)\ntake effect at the end of the period already paid for, and never charge. An\nx402 challenge is therefore only ever issued for an action that actually costs\nmoney. A failed renewal downgrades behavior only; stored\nbackups are never deleted. Per-snapshot cap: 2 GiB.\n\n## CLI (the normal path)\n\n```bash\nnpm i -g @singularity-layer/agentvault\n\nagentvault login              # browser wallet approval (device flow)\nagentvault login --api-key    # headless: paste a compute API key instead\nagentvault backup --all       # detect, encrypt, upload every local agent\nagentvault backup --path <dir> --name <n>   # UNIVERSAL: vault any directory (any harness)\nagentvault list               # agents + snapshot counts\nagentvault restore            # pick snapshot -> passphrase -> safe unpack\nagentvault restore --dest ~/x # restore into a specific directory\nagentvault passphrase set     # store passphrase in the OS keychain\nagentvault daemon install --frequency weekly   # automatic backups\n```\n\nNon-interactive (cron/agents): store the passphrase once with\n`agentvault passphrase set`, then `agentvault backup --non-interactive`.\n\n## Migration recipes\n\n- **Machine → machine:** `backup --all` on the old box; `login` + `restore`\n  on the new one. Same wallet, snapshots appear automatically.\n- **Machine → pod / pod → pod:** back up anywhere, then open the destination\n  pod's **Backups** tab in the dashboard and restore the snapshot onto it\n  (the pod restarts itself with the restored state).\n- **Pod → machine:** the pod's snapshots appear in `agentvault list` on any\n  machine logged into the same wallet — `agentvault restore`.\n\n## Pods (one click, no install)\n\nPod detail page → **Backups** tab → passphrase → **Back up now**. The pod\nencrypts on-box and uploads directly; restore (including from another pod or\na local machine snapshot of the same wallet) is the same tab.\n\n## HTTP API (for agents that cannot run the CLI)\n\nAll routes on `https://compute.x402layer.cc`, auth `X-API-Key` (compute API\nkey). The flow mirrors the CLI: reserve → presigned PUT → verified complete.\n\n| Method | Route | Purpose |\n|---|---|---|\n| GET | `/backups/agents` | list registered agents |\n| POST | `/backups/agents` | `{name, framework}` find-or-create |\n| POST | `/backups` | `{agentId, sizeBytes}` → `{backupId, r2Key, uploadUrl}` |\n| PUT | *presigned `uploadUrl`* | upload the encrypted blob |\n| POST | `/backups/{id}/complete` | `{sha256}` of the uploaded blob |\n| GET | `/backups?agentId=` | list complete snapshots |\n| GET | `/backups/{id}/restore` | → `{downloadUrl, r2Key}` |\n| DELETE | `/backups/{id}` | delete a snapshot |\n| GET | `/backups/usage` | bytes used/reserved + caps |\n\nEncryption is CLIENT-side: encrypt before PUT (scrypt N=2^17 r=8 p=1,\nAES-256-GCM envelope; AAD = `{userId, agentId, backupId, formatVersion:1}`\nparsed from `r2Key` = `backups/{wallet}/{agentId}/{backupId}/blob.enc`).\nPrefer the CLI unless you must integrate directly.\n\n## Safety rules for agents using this skill\n\n- NEVER echo, log, or store the user's passphrase; prompt at point of use.\n- Restore REPLACES agent state (previous state is parked `.pre-restore` on\n  pods). Confirm with the user before restoring over a live agent.\n- If a restore errors \"argon2id key derivation; restore with the agentvault\n  CLI\", the snapshot predates the scrypt default — run it through the CLI.\n\nFile v1.31.0:references/ai-machines.md\n\n# AI Machines — One-Click GPU Running an LLM\n\n**AI Machines** are the fastest path from \"I want an LLM\" to a running model: provision a GPU\ninstance that comes up **already running an LLM**, with the serving mode chosen at deploy time. It's\nthe same x402-native lifecycle as any SGL Machine (provision / manage / resize / extend / destroy),\njust with one extra **nested** deploy object — `ai_machine` (private) or `deploy_node` (grid).\n\n- **API base:** `https://compute.x402layer.cc`\n- **Tier:** **Standard** (not confidential / not TEE). For confidential inference, use the SGL Grid\n  (see the main SKILL \"SGL Grid — Inference\") or run a TEE node (`references/node-operator.md`).\n- **Fully managed:** the box is kept alive, auto-updates are applied (allowlist-gated), and SSH stays\n  available for you.\n- **Agent-friendly:** an agent with a funded wallet can deploy, extend, and destroy an AI Machine\n  entirely over x402 — no dashboard needed.\n\n---\n\n## The two modes (chosen at deploy)\n\nEach mode is a **nested object** on the provision body. They are **mutually exclusive** (the server\nrejects a request that includes both):\n\n- **Private** → `\"ai_machine\": { \"model_id\": \"<id>\", \"mode\": \"private\" }` (`mode` must be `\"private\"`).\n- **Grid** → `\"deploy_node\": { \"model_id\": \"<id>\" }`.\n\n### 1. `ai_machine` (private) — your own OpenAI-compatible endpoint\n\nDeploys a GPU running `llama-server`, which exposes an **OpenAI-compatible** API on port `8080`:\n\n- `POST /v1/chat/completions`\n- `GET /v1/models`\n\nThe provision response returns an `ai` object — `{ model_id, api_key, port: 8080, endpoint }` — on the\norder metadata. The private endpoint is OpenAI-compatible at `<endpoint>/v1`; for VM providers the\nendpoint derives from the instance IP + port (`http://<ip>:8080/v1`) once the IP lands (read it back\nvia `GET /compute/instances/:id`). Authenticate with `Authorization: Bearer <api_key>`. Point any\nOpenAI-compatible client, agent framework, or router at it (`base_url` = `<endpoint>/v1`,\n`api_key` = the returned key).\n\n> **OpenRouter-ready:** because it speaks the OpenAI schema, it works with any OpenAI-compatible\n> client out of the box. Listing it *as a provider on OpenRouter itself* is a separate OpenRouter\n> approval process and is **roadmap**, not something this deploy does for you.\n\n### 2. `deploy_node` (grid) — join the grid & earn\n\nDeploys the machine as a **grid node** that serves inference to the SGL Grid and earns **USDC + SGL**\nper settled job. Requires **≥ 50,000 $SGL staked** to the wallet (the same requirement as any node —\nsee `references/node-operator.md`). This is the \"provide compute / earn\" side rather than \"I want a\nprivate endpoint\" side.\n\n| Mode | Deploy object | You get | Requires |\n|------|---------------|---------|----------|\n| private | `ai_machine: { model_id, mode:\"private\" }` | Your own OpenAI-compatible endpoint (URL + API key) | funded wallet for the **x402 deploy** (credits not accepted) |\n| grid | `deploy_node: { model_id }` | Node that serves the grid and earns USDC + SGL | funded wallet **+ 50,000 SGL staked** |\n\n---\n\n## Deploy (x402)\n\nAdd the nested `ai_machine` (private) or `deploy_node` (grid) object to deploy an AI Machine.\nEverything else is the normal provision request (`plan`, `region`, `os_id`, duration). `os_id` is the\nprovider GPU image id from the machine catalog (it varies by provider — do not hardcode it).\n\n### Via the bundled script\n\n```bash\n# Private OpenAI-compatible endpoint, 1 day\npython scripts/provision.py vcg-a100-1c-2g-6gb lax --days 1 --label \"my-llm\" \\\n    --model-id llama-3.2-3b --mode private\n\n# Join the grid & earn (wallet must have 50k SGL staked), 1 month\npython scripts/provision.py vcg-a100-1c-2g-6gb lax --months 1 --label \"grid-node\" \\\n    --model-id llama-3.2-3b --mode grid\n\n# Pay on Solana instead of Base\npython scripts/provision.py vcg-a100-1c-2g-6gb lax --days 1 --label \"my-llm\" \\\n    --model-id llama-3.2-3b --mode private --network solana\n```\n\nOn success in `private` mode the script prints the OpenAI-compatible **endpoint** and the **API key**\n(shown once — store it).\n\n### Raw x402 (what the script does)\n\n`POST /compute/provision` with the nested `ai_machine` object, then the standard 402 → sign → resend\nflow:\n\n```json\n{\n  \"plan\": \"vcg-a100-1c-2g-6gb\",\n  \"region\": \"lax\",\n  \"os_id\": \"<provider-gpu-image-id>\",\n  \"label\": \"my-llm\",\n  \"prepaid_hours\": 720,\n  \"network\": \"base\",\n  \"ai_machine\": { \"model_id\": \"llama-3.2-3b\", \"mode\": \"private\" }\n}\n```\n\nGrid deploy uses `\"deploy_node\": { \"model_id\": \"llama-3.2-3b\" }` instead (mutually exclusive with\n`ai_machine`).\n\n1. Server returns `402` with `accepts[]` (Base USDC / Solana / MegaETH USDm / Robinhood USDG).\n2. Sign the payment locally (USDC `TransferWithAuthorization` on Base, USDG `TransferWithAuthorization` on Robinhood Chain, SPL transfer on Solana).\n3. Resend with the `X-Payment` header.\n4. Server settles on-chain and provisions the GPU with the model running.\n\n> Private **AI Machines** require an **x402 wallet payment** — `\"use_credits\": true` is rejected for\n> `ai_machine`. Prepaid credits work for bare and grid machines (authenticate with `X-API-Key`; see\n> the main SKILL \"Credits\" workflow).\n\n---\n\n## Using a private endpoint\n\nOnce `private` mode returns the endpoint + API key, it's a drop-in OpenAI endpoint:\n\n```bash\n# List the model(s) the box serves\ncurl <ENDPOINT>/v1/models -H \"Authorization: Bearer <RETURNED_API_KEY>\"\n\n# Chat completion\ncurl -X POST <ENDPOINT>/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Authorization: Bearer <RETURNED_API_KEY>\" \\\n  -d '{\"model\":\"llama-3.2-3b\",\"messages\":[{\"role\":\"user\",\"content\":\"Hello\"}]}'\n```\n\nAny OpenAI SDK / agent framework / router (Cursor, opencode, LibreChat, LangChain, etc.) works by\nsetting `base_url=<ENDPOINT>/v1` and `api_key=<RETURNED_API_KEY>`.\n\n> This is your **own dedicated box**, distinct from the shared, confidential SGL Grid at\n> `https://grid.x402compute.cc`. Pick AI Machines when you want a private, dedicated LLM endpoint;\n> pick the Grid when you want confidential, pay-per-token, multi-node inference.\n\n---\n\n## Full control API (same lifecycle as any Machine)\n\nAll management endpoints use compute auth (`X-API-Key: x402c_…` or wallet-signature headers).\n\n| Method | Path | Purpose |\n|--------|------|---------|\n| `POST`   | `/compute/provision` | Deploy. For an AI machine add the nested `ai_machine` (private) or `deploy_node` (grid) object. Required base fields: `plan`, `region`, `os_id`. Provision uses `prepaid_hours`. |\n| `GET`    | `/compute/instances` | List your instances |\n| `GET`    | `/compute/instances/:id` | Instance details (IP, status, expiry) |\n| `POST`   | `/compute/instances/:id/extend` | **Extend runtime** (x402/MPP/credits) — the most-used action; extend before expiry |\n| `POST`   | `/compute/instances/:id/resize` | Resize in place (compute auth only; no new payment — preserves prepaid value via new expiry) |\n| `POST`   | `/compute/instances/:id/password` | One-time SSH root password fallback (Vultr; used once, then `409`) |\n| `DELETE` | `/compute/instances/:id` | Destroy |\n| `POST`   | `/compute/credits/topup` | Top up prepaid USD credits via x402 |\n\nExtend is the one to remember: AI Machines expire after their prepaid duration, so keep them alive by\nextending before `expires_at`.\n\n```bash\n# Extend an AI machine by a month\npython scripts/extend_instance.py <instance_id> --hours 720\n\n# Or raw (credits):\ncurl -X POST https://compute.x402layer.cc/compute/instances/<id>/extend \\\n  -H \"Content-Type: application/json\" -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"extend_hours\":720,\"use_credits\":true}'\n```\n\n---\n\n## Agent deploys an AI Machine (end-to-end, x402)\n\nA funded-wallet agent can run the whole lifecycle with no human in the loop. This reuses the skill's\nexisting x402 payment path (`scripts/wallet_signing.py` / `scripts/solana_signing.py`) — no new\npayment scheme.\n\n```bash\n# 0. One dedicated low-balance wallet for the agent\nexport PRIVATE_KEY=<evm-private-key>        # Base (default); same key works for MegaETH + Robinhood (set COMPUTE_AUTH_CHAIN). For Solana set SOLANA_SECRET_KEY + COMPUTE_AUTH_CHAIN=solana\nexport WALLET_ADDRESS=<evm-wallet-address>\n\n# 1. Deploy a private LLM endpoint, non-interactive (-y skips the confirm prompt)\npython scripts/provision.py vcg-a100-1c-2g-6gb lax --days 1 --label \"agent-llm\" \\\n    --model-id llama-3.2-3b --mode private -y\n#   → prints Endpoint + API Key (capture from stdout / the returned JSON)\n\n# 2. Use it — it's an OpenAI-compatible endpoint (see \"Using a private endpoint\" above)\n\n# 3. Keep it alive if the task runs long\npython scripts/extend_instance.py <instance_id> --hours 24 -y\n\n# 4. Tear it down when done\npython scripts/destroy_instance.py <instance_id>\n```\n\nSpend guard: `provision.py` / `extend_instance.py` refuse to pay above `COMPUTE_MAX_SPEND_USD`\n(default $500) unless overridden with `--max-spend`. Keep the agent wallet low-balance.\n\n---\n\n## Managed & SSH notes\n\n- **Kept alive + auto-updated:** the platform maintains the box and applies allowlisted updates. You\n  don't babysit the process.\n- **SSH:** provide `ssh_public_key` at provision for key access (recommended). On Vultr, if you skip\n  the key you can fetch a one-time root password once via `POST /compute/instances/:id/password`.\n  DigitalOcean plans require an SSH key (no password fallback).\n- **Standard tier:** AI Machines are not confidential. Don't send data you need cryptographically\n  shielded from the host — for that, use the confidential SGL Grid or a TEE node.\n\n---\n\n## Roadmap (not shipped)\n\n- Listing a private AI Machine **as a provider on OpenRouter** (their approval flow). Today the box is\n  OpenRouter-*ready* (OpenAI-compatible), not an approved OpenRouter provider.\n\nFile v1.31.0:references/api-reference.md\n\n# x402Compute API Reference\n\nBase URL: `https://compute.x402layer.cc`\n\nPaid endpoints support both protocols:\n\n- **x402**: server returns JSON `accepts[]`; client retries with `X-Payment`.\n- **MPP**: server returns `WWW-Authenticate: Payment`; client retries with `Authorization: Payment ...`; success includes `Payment-Receipt`.\n\nCompute plans can be backed by multiple providers:\n\n- `provider: \"vultr\"` uses existing Vultr plan IDs, regions, OS images, and password fallback support.\n- `provider: \"digitalocean\"` uses DigitalOcean Droplet sizes prefixed as `do:<size_slug>`.\n- DigitalOcean instances require SSH key access because the DigitalOcean API does not expose initial root passwords.\n\n## Endpoints\n\n### Authentication (Required for management endpoints)\n\nAll **instance management** endpoints require authentication. Provision/extend accept x402 payment without compute auth headers. Choose one for management:\n\n- **Signature Auth (wallet signing)**  \n  Required headers:\n  - `X-Auth-Address`: wallet address\n  - `X-Auth-Chain`: `base`, `megaeth`, `robinhood`, or `solana`\n  - `X-Auth-Signature`: signature over the request\n  - `X-Auth-Timestamp`: epoch millis\n  - `X-Auth-Nonce`: unique nonce\n  - `X-Auth-Sig-Encoding`: `hex` (EVM: base/megaeth/robinhood) or `base64` (Solana)\n\n- **API Key Auth (agent access)**\n  Required header:\n  - `X-API-Key`: compute API key (create via `POST /compute/api-keys`)\n\n### Agent Pods\n\nAgent Pod endpoints use the same compute auth (`X-API-Key`, signed session, or wallet\nsignature). A pod is a compute order, so the returned `pod.id` is also the instance id for\nextend/destroy.\n\n| Endpoint | Purpose |\n|----------|---------|\n| `GET /pods/catalog` | Public catalog: agents, tiers, channels, templates, pricing |\n| `POST /pods` | Deploy a managed or BYOK Agent Pod |\n| `GET /pods` | List owned pods |\n| `GET /pods/{id}` | Pod details, heartbeat, masked credentials, customization |\n| `PATCH /pods/{id}/settings` | Model/provider/settings/customization update |\n| `POST /pods/{id}/actions` | Queue lifecycle action: restart, redeploy, update, diagnose, logs, cron |\n| `POST /pods/{id}/api-keys` | Mint a pod-scoped `sk-sglpod-int-*` key for the OpenAI adapter |\n| `POST /pods/{id}/v1/chat/completions` | OpenAI-compatible chat with the pod via `Authorization: Bearer sk-sglpod-int-*` |\n\n`POST /pods` and `PATCH /pods/{id}/settings` accept the platform customization layer:\n\n| Field | Max | Notes |\n|-------|-----|-------|\n| `agent_identity` | 8000 chars | Owner/platform identity text rendered into managed `AGENTS.md` and `IDENTITY.md`. |\n| `agent_instructions` | 8000 chars | Owner/platform instructions rendered into managed `AGENTS.md`. |\n| `heartbeat_prompt` | 4000 chars | Custom quiet self-check prompt. Empty or `null` on PATCH restores the default. |\n| `agent_heartbeat_minutes` | server bounded | `0` disables self-checks; otherwise 15-1440 minutes. |\n\nRaw `AGENTS.md` replacement is intentionally not exposed. The managed base keeps wallet\nsurvival, x402 spend controls, security boundaries, and tool permissions intact; custom text is\nlayered into a bounded owner/platform section. Full pod details are in\n`references/agent-pods.md`; the platform API-key surface is in `references/agent-pods-api.md`.\n\n### GET /compute/plans\n\nList available compute plans with pricing.\n\n**Query Parameters:**\n- `type` (optional): Filter by plan type — `vps`, `vhp`, `vdc`, `vcg` (GPU)\n\n**Response:**\n```json\n{\n  \"plans\": [\n    {\n      \"id\": \"vcg-a100-1c-2g-6gb\",\n      \"vcpu_count\": 12,\n      \"ram\": 120832,\n      \"disk\": 1600,\n      \"bandwidth\": 10240,\n      \"monthly_cost\": 90,\n      \"type\": \"GPU\",\n      \"gpu_vram_gb\": 80,\n      \"gpu_type\": \"NVIDIA A100\",\n      \"locations\": [\"lax\", \"ewr\", \"ord\"]\n    }\n  ],\n  \"count\": 1\n}\n```\n\nPrices include the platform markup and are in USD. Plans now include `our_daily` pricing (hourly × 24). The x402 payment amount is calculated from the hourly rate times `prepaid_hours`, converted to stablecoin atomic units (6 decimals — USDC on Base/Solana, USDm on MegaETH, USDG on Robinhood Chain).\n\n---\n\n### GET /compute/regions\n\nList available deployment regions.\n\n**Response:**\n```json\n{\n  \"regions\": [\n    {\n      \"id\": \"lax\",\n      \"city\": \"Los Angeles\",\n      \"country\": \"US\",\n      \"continent\": \"North America\"\n    }\n  ]\n}\n```\n\n---\n\n### GET /compute/os\n\nList available operating system images.\n\n**Response:**\n```json\n{\n  \"os_options\": [\n    {\n      \"id\": 2284,\n      \"name\": \"Ubuntu 24.04 LTS x64\",\n      \"arch\": \"x64\",\n      \"family\": \"ubuntu\"\n    }\n  ]\n}\n```\n\n---\n\n### GET /compute/credits/balance\n\nGet credit balance for the authenticated wallet.\n\n**Headers:**\n- Auth headers (see Authentication above)\n\n**Response (200):**\n```json\n{\n  \"wallet\": \"0x...\",\n  \"balance\": \"150.00\",\n  \"total_deposited\": \"200.00\",\n  \"total_spent\": \"50.00\"\n}\n```\n\nIf no credits have been deposited, returns `{ \"balance\": 0, \"total_deposited\": 0, \"total_spent\": 0 }`.\n\n---\n\n### POST /compute/credits/topup\n\nTop up credits via x402 payment. Returns `402 Payment Required` if no `X-Payment` header.\n\n**Request Body:**\n```json\n{\n  \"amount\": 50,\n  \"network\": \"base\"\n}\n```\n\n- `amount`: USD to deposit (minimum $1 — **$5 on Arc**, because Arc gas is paid in USDC and comes off the sale)\n- `network`: `base`, `solana`, `megaeth`, `robinhood`, or `arc` (base/solana/arc = USDC, megaeth = USDm, robinhood = USDG). Arc is EIP-3009 `transferWithAuthorization` like Base/Robinhood — same signing flow, domain name `\"USDC\"` version `\"2\"` chainId `5042`; explorer: explorer.arc.io. **Machines, AI Machines and extensions also accept `network: \"arc\"` directly** — direct Arc payments carry the same $5 minimum; smaller prepayments go through credits.\n\n**Headers:**\n- Auth headers (see Authentication above)\n- `X-Payment`: Base64-encoded x402 payment payload (after 402 challenge)\n\n**Success Response (200):**\n```json\n{\n  \"success\": true,\n  \"deposited\": 50,\n  \"new_balance\": \"150.00\",\n  \"tx_hash\": \"0x...\"\n}\n```\n\n---\n\n### POST /compute/provision\n\nProvision a new compute instance. Returns `402 Payment Required` with x402 and, when configured, MPP payment challenges — unless `use_credits` is `true`.\n\n**Request Body:**\n```json\n{\n  \"plan\": \"vc2-1c-1gb\",\n  \"region\": \"ewr\",\n  \"os_id\": 2284,\n  \"label\": \"my-daily-instance\",\n  \"prepaid_hours\": 24,\n  \"ssh_public_key\": \"ssh-ed25519 AAAA... user@host\",\n  \"provider\": \"vultr\",\n  \"network\": \"base\",\n  \"use_credits\": false\n}\n```\n\n**Notes:**\n- `prepaid_hours` minimum is **24** (1 day). Use `24` for daily, `72` for 3 days, `168` for 1 week, `720` for 1 month, etc.\n- Provide `ssh_public_key` to enable SSH access. Passwords are not returned by the API.\n- If you do not provide an SSH key, use one-time fallback endpoint `POST /compute/instances/:id/password`.\n- For DigitalOcean plans, `ssh_public_key` or existing `ssh_key_id(s)` is required. Password fallback is Vultr-only.\n- DigitalOcean plan IDs are prefixed, for example `do:s-1vcpu-1gb`.\n- Set `use_credits: true` to deduct from pre-loaded credit balance instead of requiring x402/MPP payment. Auth is required for the credit path. If balance is insufficient, returns `402` with the shortfall.\n- `network` also accepts `\"arc\"` (USDC on Arc, EIP-3009 chainId 5042). **Direct Arc payments carry a $5 minimum** — Arc gas is USDC and comes off the sale — so a 24-hour micro-instance is refused with a pointer to credits; `use_credits: true` with an Arc-funded balance has no floor. Same for `/compute/instances/:id/extend`.\n- **AI Machine:** add a **nested** object to deploy a GPU that comes up running an LLM. The two are mutually exclusive:\n  - `\"ai_machine\": { \"model_id\": \"<id>\", \"mode\": \"private\" }` — a dedicated **OpenAI-compatible** endpoint (`mode` must be `\"private\"`). The success order's `metadata.ai = { model_id, api_key, port: 8080, endpoint }`; the box exposes `/v1/chat/completions` and `/v1/models` at `<endpoint>/v1`, authenticated with `Authorization: Bearer <api_key>`. For VM providers `endpoint` derives from the instance IP + port (`http://<ip>:8080/v1`) once the IP lands (read via `GET /compute/instances/:id`). **Requires an x402 wallet payment — `use_credits: true` is rejected for `ai_machine`.**\n  - `\"deploy_node\": { \"model_id\": \"<id>\" }` — joins the grid to serve inference and earn USDC + SGL (requires ≥ 50,000 $SGL staked to the paying wallet; x402 Solana payment).\n  - `os_id` is the provider GPU image id from the catalog (varies by provider). AI Machines are the **Standard** tier (not confidential/TEE). Full detail in `references/ai-machines.md`.\n\n**Headers:**\n- Auth headers (see Authentication above)\n- `X-Payment`: Base64-encoded x402 payment payload (after 402 challenge)\n- `Authorization: Payment ...`: MPP credential (after MPP challenge)\n\n**402 Challenge Response:**\n```json\n{\n  \"x402Version\": 1,\n  \"accepts\": [\n    {\n      \"scheme\": \"exact\",\n      \"network\": \"base\",\n      \"maxAmountRequired\": \"90000000\",\n      \"resource\": \"https://compute.x402layer.cc/compute/provision\",\n      \"payTo\": \"0x...\",\n      \"extra\": { \"name\": \"USD Coin\", \"version\": \"2\" }\n    }\n  ]\n}\n```\n\nFor Solana challenges, `network` may be `solana` (or facilitator-style `solana:*`) and may include `extra.feePayer`.\n\n**MPP Example:**\n```bash\nnpx mppx https://compute.x402layer.cc/compute/provision \\\n  -X POST \\\n  -J '{\"plan\":\"vc2-1c-1gb\",\"region\":\"ewr\",\"os_id\":2284,\"label\":\"mpp-vps\",\"prepaid_hours\":24,\"ssh_public_key\":\"ssh-ed25519 AAAA... agent\"}'\n```\n\nIf MPP provisioning is paid without wallet/API-key auth, the success response includes a one-time `management_api_key`. Store it and use it for `GET /compute/instances`, `POST /compute/instances/:id/resize`, `POST /compute/instances/:id/extend`, password retrieval, and destroy.\n\n**Success Response (200):**\n```json\n{\n  \"success\": true,\n  \"order\": {\n    \"id\": \"uuid\",\n    \"vultr_instance_id\": \"...\",\n    \"plan\": \"vcg-a100-1c-2g-6gb\",\n    \"region\": \"lax\",\n    \"status\": \"active\",\n    \"ip_address\": \"1.2.3.4\",\n    \"expires_at\": \"2026-03-17T00:00:00Z\"\n  },\n  \"tx_hash\": \"0x...\"\n}\n```\n\n**Additional MPP-only fields when no wallet/API-key auth was supplied:**\n```json\n{\n  \"management_api_key\": \"x402c_...\",\n  \"management_api_key_id\": \"uuid\",\n  \"management_api_key_last4\": \"abcd\",\n  \"management_note\": \"Store this API key securely. It is shown once...\"\n}\n```\n\n---\n\n### GET /compute/instances\n\nList your active instances.\n\n**Headers:**\n- Auth headers (see Authentication above)\n\n---\n\n### GET /compute/instances/:id\n\nGet details for a specific instance.\n\n**Headers:**\n- Auth headers (see Authentication above)\n\n---\n\n### DELETE /compute/instances/:id\n\nDestroy an instance immediately.\n\n**Headers:**\n- Auth headers (see Authentication above)\n\n---\n\n### POST /compute/instances/:id/password\n\nRetrieve one-time root password fallback (only if SSH key was not used).\n\n**Headers:**\n- Auth headers (see Authentication above)\n\n**Response (200):**\n```json\n{\n  \"success\": true,\n  \"access\": {\n    \"method\": \"one_time_password\",\n    \"username\": \"root\",\n    \"ip_address\": \"1.2.3.4\",\n    \"password\": \"example-password\"\n  }\n}\n```\n\nSubsequent calls return `409`.\n\n---\n\n### POST /compute/instances/:id/extend\n\nExtend an instance's lifetime. Returns `402 Payment Required` with x402 and, when configured, MPP payment challenges — unless `use_credits` is `true`.\n\n**Request Body:**\n```json\n{\n  \"extend_hours\": 720,\n  \"network\": \"base\",\n  \"use_credits\": false\n}\n```\n\n**Headers:**\n- Auth headers (see Authentication above)\n- `X-Payment`: Base64-encoded x402 payment payload (after 402 challenge)\n- `Authorization: Payment ...`: MPP credential (after MPP challenge)\n\nMPP extension requires compute auth because MPP card/Stripe payments do not always identify a wallet owner. Use the `management_api_key` returned from MPP provisioning:\n\n```bash\nnpx mppx https://compute.x402layer.cc/compute/instances/<instance_id>/extend \\\n  -X POST \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -J '{\"extend_hours\":720}'\n```\n\nSet `use_credits: true` to extend using pre-loaded credits instead of x402/MPP payment. Auth is required, and the wallet must own the instance.\n\n---\n\n### POST /compute/instances/:id/resize\n\nResize an active instance in place on its current provider.\n\n**Request Body:**\n```json\n{\n  \"plan\": \"vc2-2c-4gb\"\n}\n```\n\n**Optional confirmation for irreversible disk growth:**\n```json\n{\n  \"plan\": \"do:s-2vcpu-4gb\",\n  \"confirm_disk_resize\": true\n}\n```\n\n**Headers:**\n- Auth headers (see Authentication above)\n\n**Behavior:**\n- Resize is a management action only. It does **not** create a new x402 or MPP payment challenge.\n- The API preserves remaining prepaid dollar credit and recalculates `expires_at` for the target hourly rate.\n- Resize stays on the current provider and region.\n- Vultr is upgrade-only.\n- DigitalOcean disk increases are irreversible and require `confirm_disk_resize: true`.\n\n**Example:**\n```bash\ncurl -X POST https://compute.x402layer.cc/compute/instances/<instance_id>/resize \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\" \\\n  -d '{\"plan\":\"vc2-2c-4gb\"}'\n```\n\n---\n\n### POST /compute/api-keys\n\nCreate an API key for agent access (signature auth required).\n\n**Request Body:**\n```json\n{\n  \"label\": \"my-agent\"\n}\n```\n\n**Response (201):**\n```json\n{\n  \"api_key\": \"x402c_...\",\n  \"id\": \"uuid\",\n  \"label\": \"my-agent\",\n  \"created_at\": \"2026-02-18T00:00:00Z\"\n}\n```\n\n---\n\n### GET /compute/api-keys\n\nList API keys for your wallet.\n\n**Response:**\n```json\n{\n  \"api_keys\": [\n    {\n      \"id\": \"uuid\",\n      \"label\": \"my-agent\",\n      \"key_last4\": \"abcd\",\n      \"created_at\": \"2026-02-18T00:00:00Z\",\n      \"revoked_at\": null\n    }\n  ]\n}\n```\n\n---\n\n### DELETE /compute/api-keys/:id\n\nRevoke an API key (signature auth required).\n\n---\n\n## SGL Grid — Inference (base: `https://grid.x402compute.cc`)\n\nDecentralized, confidential, **OpenAI-compatible** inference. Auth with your API key as **either** `Authorization: Bearer x402c_…` (standard OpenAI style — works with the OpenAI SDK, Cursor, opencode, LibreChat, etc.) **or** `X-API-Key: x402c_…` (billed to prepaid credits — same key/credits as Machines), or per-request x402 via `X-Payment`. Pay-per-token in USDC.\n\n### GET /v1/models\n\nList models currently served by active nodes that satisfy the requested tier and model capability.\n\n```bash\ncurl https://grid.x402compute.cc/v1/models -H \"X-API-Key: x402c_...\"\ncurl \"https://grid.x402compute.cc/v1/models?type=embedding\" -H \"X-API-Key: x402c_...\"\ncurl \"https://grid.x402compute.cc/v1/models?type=systemone\" -H \"X-API-Key: x402c_...\"\n```\n\n### POST /v1/embeddings\n\nOpenAI-compatible input-only embeddings. Existing text models accept a string or string array.\nThe release-gated `embeddinggemma-2` model adds ordered text, image, audio, video, and mixed\nitems at 768/512/256/128 dimensions. It is callable only while listed by\n`GET /v1/models?type=embedding`.\n\nMultimodal media is inline canonical base64 with its lowercase SHA-256. Audio/video also require\nverified `duration_seconds`. The 24 MiB encoded body, media, batch, and 8,192 processed-token\nlimits are enforced before payment and again at the runtime boundary. See the complete contract,\nstable error table, and Local app path in `references/multimodal-embeddings.md`.\n\nOmitted EmbeddingGemma 2 `input_type` defaults to `query`; send `unspecified` only to opt out\nof retrieval prefixing. Legacy omission retains each model's existing behavior. The sealed input\nenvelope becomes purge-eligible 30 minutes after terminal status and the encrypted result after\none hour. Because cleanup runs hourly, practical upper bounds are about 90 minutes and two hours.\nPlaintext node failure details are never persisted.\n\n```bash\npython {baseDir}/scripts/grid_embeddings.py embed \\\n  --text \"A searchable document\" --input-type document --dimensions 256\n```\n\n### POST /v1/chat/completions\n\nOpenAI-compatible chat completion. Set `\"stream\": true` for token streaming (SSE; each chunk is end-to-end encrypted). Body matches the OpenAI schema (`model`, `messages`, optional `temperature`, `max_tokens`, `stream`). Works with any OpenAI SDK via `base_url=https://grid.x402compute.cc/v1`.\n\n```bash\ncurl -X POST https://grid.x402compute.cc/v1/chat/completions \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: x402c_...\" \\\n  -d '{\"model\":\"llama-3.2-3b\",\"messages\":[{\"role\":\"user\",\"content\":\"Hello\"}]}'\n```\n\nErrors: `401` invalid/revoked API key · `402` payment required (resend with `X-Payment`) or insufficient credits (top up in Settings → Credits).\n\n### POST /v1/systemone\n\nLaya/System One typed decisions. Current model: `convaiinnovations/laya` (aliases: `laya`,\n`laya-system-one`, `systemone-laya`). This is not OpenAI chat; sending Laya to\n`/v1/chat/completions` returns `wrong_endpoint_for_model`.\n\n```bash\ncurl -X POST https://grid.x402compute.cc/v1/systemone \\\n  -H \"Content-Type: application/json\" \\\n  -H \"X-API-Key: x402c_...\" \\\n  -d '{\"model\":\"convaiinnovations/laya\",\"state\":{\"ticket\":\"refund request\"},\"questions\":{\"route\":{\"type\":\"choice\",\"instructions\":\"Pick the best team.\",\"criteria\":{\"billing\":\"Billing or refund\",\"support\":\"Technical support\"}}}}'\n```\n\nQuestion types: `choice`, `score`, `noul`. Limits: 64 KiB state, 32 questions, 64 criteria per\nquestion, 16,384 input tokens, 256 KiB request, 1 MiB response. Billing is input-only. For\nend-to-end private Laya, first call `POST /v1/systemone/reserve`, encrypt locally to the returned\nnode key, then submit the sealed payload to `POST /v1/systemone`. See `references/systemone-laya.md`.\n\n### GET /grid/capacity\n\nLive grid capacity — active node count, TEE types, served models, and an `at_capacity` flag. No auth. Check before a large batch and back off if `at_capacity` is true.\n\n```bash\ncurl https://grid.x402compute.cc/grid/capacity\n```\n\n### GET /v1/providers\n\nCompare the nodes serving a model, with each node's effective per-token price (custom if the operator set one, else the suggested reference), sorted cheapest-first. No auth. Optional `cluster` filter. Pass a chosen `node` to `/v1/chat/completions` (or the `node=` arg in the SDKs) to pin that provider; omit it to let the grid route.\n\n```bash\ncurl \"https://grid.x402compute.cc/v1/providers?model=llama-3.2-3b\"\n# {\"model\":\"llama-3.2-3b\",\"count\":2,\"providers\":[\n#   {\"node_id\":\"…\",\"input_per_m\":0.004,\"output_per_m\":0.004,\"blended_per_1k\":4e-06,\"is_custom\":true,\"online\":true}, …]}\n```\n\n**Price cap (`max_price`):** instead of picking a node, add `\"max_price\": <USD per 1M tokens, blended>` to your `/v1/chat/completions` (or `/v1/reserve`) request — the grid routes only to nodes at/under that rate and never bills above it. Returns `price_cap_unmet` if none qualify. Available as `max_price` (Python) / `maxPrice` (TS) in the SDKs.\n\n### GET /grid/nodes/:id/prices\n\nPublic. A node's per-model prices: the `reference` (suggested) rate, the allowed `floor`/`ceiling` band, the operator's `custom` price (or `null`), and the `effective` price billed.\n\n```bash\ncurl https://grid.x402compute.cc/grid/nodes/<NODE_ID>/prices\n```\n\n### POST /grid/nodes/:id/prices\n\nOperator-only — set or reset a model's price. Auth with the node token (`X-Node-Auth`, used by `sgl price …`) **or** an owner wallet signature. Band-enforced (suggested × 0.5 … × 5), the model must be one the node advertises, and there's a short cooldown between changes. Body: `{ \"model\": \"...\", \"input_per_m\": 0.004, \"output_per_m\": 0.004 }` (or `{ \"model\": \"...\", \"reset\": true }`).\n\n```bash\ncurl -X POST https://grid.x402compute.cc/grid/nodes/<NODE_ID>/prices \\\n  -H \"X-Node-Auth: <node-token>\" -H \"Content-Type: application/json\" \\\n  -d '{\"model\":\"llama-3.2-3b\",\"input_per_m\":0.004,\"output_per_m\":0.004}'\n```\n\nFile v1.31.0:references/datasets.md\n\n# Datasets: buy fine-tuning data with a wallet\n\nGenerate a validated JSONL training dataset from a one-sentence description\nplus a handful of example conversations. Pay per example in USDC. No account,\nno dashboard, no human: an agent can buy its own training data.\n\n**API base:** `https://compute.x402layer.cc`\nDashboard (wallet-session users): https://cloud.x402compute.cc/network/datasets\n\n## The shape of the flow (read this first)\n\nGeneration takes MINUTES (a 2000-row job can take far longer), so the purchase\nnever waits on it:\n\n```\nPOST /datasets/x402/synth                  -> 402 + quote (price, rows, model)\nPOST /datasets/x402/synth  (X-Payment)     -> 202 + dataset_id + claim_token   (~1s)\nGET  /datasets/x402/jobs/<id>  (Bearer claim_token) -> progress, then download\n```\n\nDo NOT hold a connection waiting for the file, and do not treat the 402 as an\nerror: it is the price quote. Poll the status URL, or pass `webhook_url` and be\ntold when it is done.\n\n## Pricing\n\n`GET /datasets/config` (no auth) returns everything needed to quote a job:\n\n```json\n{ \"synth\": { \"rates_per_100_usd\": {\"fast\":0.2,\"balanced\":0.35,\"best\":1.0,\"grid\":0.15},\n             \"verify_rate_per_100_usd\": {\"managed\":0.1,\"grid\":0.03},\n             \"max_rows\": 2000,\n             \"models\": [{\"id\":\"deepseek-v3.1\",\"tier\":\"fast\",\"in_per_m\":0.55,\"out_per_m\":1.65}, …20 models] } }\n```\n\n**Price = (generation rate + verification rate) x rows / 100.** Every dataset is\nCHECKED by default (see below), and that check is its own price line, so quote\nwith both: 200 rows managed `fast` = $0.60, 200 rows on the grid = $0.36, 2000\non `best` = $22. Send `\"verify\": false` to skip checking and pay generation only.\nThe per-million-token numbers are the provider's published rates, shown for\ncomparison only: the buyer pays the flat per-example price, never per token.\n\nSizes: 50 to 2000 rows. Seeds: 5 to 20 example conversations (required, they\nteach the generator the format and tone).\n\n**House rules** (`rules`, up to 12 strings of 200 chars): what the assistant must\nNEVER do, e.g. \"Never promise a refund\", \"Never state a delivery time you cannot\nverify\". Set them whenever the task involves policy, money, or commitments: a\nstanding instruction says what to do, rules say what is forbidden, and without\nthem the model invents a policy and applies it differently every row (a real\n200-row support set produced twelve different refund offers). Policy/figure\nconsistency is enforced by default even with no rules.\n\n## Verification (on by default)\n\nEvery generated row is read back by a SECOND model and scored against the house\nrules before it is allowed into the dataset. A row that breaks a rule is thrown\naway and regenerated, so the buyer gets a full-size dataset of rows that passed,\nnot a full-size dataset with failures in it.\n\nWHO CHECKS depends on the provider, and this is the important part:\n\n- **Managed** jobs are checked by a separate FRONTIER model, never the model\n  that wrote the rows (a model marks its own homework badly). $0.10 per 100.\n- **Grid** jobs are checked BY THE GRID, using the network's own models, so\n  nothing leaves the confidential network even to be verified. $0.03 per 100.\n  Honest trade: on-grid models are smaller, so it is a weaker check than the\n  frontier judge, which is why it costs a third as much.\n\nThe status response carries the receipt: `checked`, `rejected` (thrown away and\nregenerated) and, if the call budget ran out before a batch could be judged,\n`unchecked`. A job never claims a check it did not perform.\n\nWHY this exists: a real 200-row support dataset generated WITHOUT rules or\nchecking invented twelve different compensation policies, including 13 full\nrefunds, because nothing ever verified the output against a policy. Rules are\nprevention; verification is the check.\n\n**Two providers.** Managed models (`model_tier` fast/balanced/best, or an exact\n`model_id` from the catalog) are fastest with the best data quality. The\ndecentralized grid (`grid_model`, implies `provider: \"grid\"`) runs on our own\nconfidential end-to-end encrypted network, so nothing goes to an outside\nprovider: cheaper, slower, and if a node drops mid-job the next most\nappropriate model on the network takes over automatically.\n\n## Buying it\n\n1. **Quote.** POST the job with no payment header. The 402 carries the standard\n   x402 `accepts` array plus a `singularity` block: `quote_id`, `rows`, `tier`,\n   `price_usd`, `quote_expires_at`.\n\n```bash\ncurl -X POST https://compute.x402layer.cc/datasets/x402/synth \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"description\":\"Classify a support message as billing, technical, or account\",\n       \"seed_examples\":[ …5 to 20 {\"messages\":[{\"role\":\"user\",…},{\"role\":\"assistant\",…}]} … ],\n       \"target_rows\":200, \"model_tier\":\"fast\", \"network\":\"base\",\n       \"rules\":[\"Never promise a refund\"], \"verify\":true}'\n```\n\n2. **Pay.** Send the SAME body plus `quote_id`, with the signed `X-Payment`\n   header. Returns **202** with `dataset_id`, `status_url`, `claim_token`,\n   `price_paid_usd`, `tx_hash` (and `webhook_secret` if a webhook was given).\n\n3. **Collect.** `GET /datasets/x402/jobs/<dataset_id>` with\n   `Authorization: Bearer <claim_token>`:\n   - running -> `{\"status\":\"generating\",\"rows_done\":120,\"rows_target\":200,\"checked\":120,\"rejected\":4}`\n   - done -> `{\"status\":\"complete\",\"row_count\":205,\"download_url\":\"…\",\"format\":\"jsonl\"}`\n     (presigned, 5 minutes, re-issued on every poll)\n   - failed -> `{\"status\":\"failed\",\"refund_status\":\"applied\"|\"pending\"}`\n\n## Rules that will bite you if ignored\n\n- **SAVE THE CLAIM TOKEN.** It is returned once, stored only as a hash, and is\n  the only way to read the job or download the file. Lost token = lost dataset.\n- **The payment is bound to the quoted job.** The server hashes the job\n  definition; paying with a different body is refused. Send the identical body\n  on both calls (a `webhook_url` may differ, it does not change the goods).\n- **Quotes expire in 10 minutes**, and the price is snapshotted at quote time,\n  so a rate change can never alter what is charged.\n- **Validate before quoting, not after paying:** an invalid body returns 400 at\n  the quote step, never a 402 you would then pay against.\n- **Refunds are credits, not on-chain reversals**, and `refund_status` is read\n  from the ledger rather than asserted.\n- **Behind a WAF:** send a real `User-Agent`. Default library agents get 403.\n\n## Chains\n\nUSDC on **Base** and **Solana**, USDG on **Robinhood Chain**, USDM on\n**MegaETH** (18-decimal, the rest are 6). Choose with `\"network\"`; the\nchallenge returns the right asset and amount.\n\n## Webhooks\n\nPass `webhook_url` (public HTTPS) at quote time and the terminal state is\nPOSTed to it, so polling is optional:\n\n```\nX-SGL-Signature: t=<unix>,v1=<hex hmac>\nbody: {\"event\":\"dataset.synth.completed\",\"event_id\":\"<order>:completed\",\"dataset_id\":…,\"download_url\":…}\n```\n\nVerify `HMAC-SHA256(webhook_secret, \"<t>.<raw body>\")` against `v1` and reject a\nstale `t` (that timestamp is what makes a captured delivery non-replayable).\nRedirects are not followed; only 2xx counts. Three attempts (1m, 5m, 25m) then\nit stops. Delivery never affects the job, so polling is always the fallback.\n\n## MCP\n\nThe same flow as four tools on `https://mcp.x402layer.cc/mcp`:\n`list_dataset_pricing`, `request_dataset_payment`,\n`create_dataset_with_payment`, `get_dataset_status`.\n\n## What the buyer actually gets\n\nNot raw model output. Every line is schema-checked and dropped if malformed;\nnear-duplicate and reworded repeats of an earlier scenario are rejected instead\nof padding the count; generation is steered across a rotating set of coverage\naxes so edge cases appear rather than fifty variants of one; and every row\ncarries the same standing instruction so the file is uniform. If the usable\nfloor is not reached, the fee is refunded.\n\nFile v1.31.0:references/multimodal-embeddings.md\n\n# EmbeddingGemma 2 — multimodal embeddings\n\nUse this reference for:\n\n- text, image, audio, video, or mixed vectors;\n- the exact `POST /v1/embeddings` wire contract;\n- Local mode in the Singularity Node app;\n- dimensions, limits, billing, privacy, and retry behavior.\n\n## Availability\n\nEmbeddingGemma 2 is a **release candidate and default off**. The pinned runtime has passed real\nApple Silicon text/image/audio/video/mixed tests, but production discovery and traffic remain\nclosed until the release migration, packaged desktop lifecycle, and live billing/failover\ncanaries pass.\n\nAlways discover it first:\n\n```bash\npython {baseDir}/scripts/grid_embeddings.py models\n# or:\ncurl \"https://grid.x402compute.cc/v1/models?type=embedding\"\n```\n\nProceed only if the response contains `embeddinggemma-2`. A catalog row alone cannot make the\nmodel callable. Grid admission also requires an active node with the exact ready protocol,\nruntime, processor revision, requested dimensions/modalities, sealed-input encoding, and model id.\n\n## Grid request contract\n\n**Endpoint:** `POST https://grid.x402compute.cc/v1/embeddings`\n\n**Credits auth:** `X-API-Key: x402c_...` with `grid:write`.\n\n**x402:** omit the API key, read the `402` response's `accepts[]`, sign the payment, and retry\nwith `X-Payment`.\n\nFields:\n\n| Field | Values |\n|---|---|\n| `model` | `embeddinggemma-2` |\n| `input` | String, string array, or 1-16 multimodal items. One vector per top-level item. |\n| `dimensions` | `768` (default), `512`, `256`, or `128` |\n| `input_type` | Optional: `query` (default when omitted), `document`, or `unspecified`. Use `unspecified` only to opt out of a retrieval prefix. |\n| `encoding_format` | Omit or use `float` |\n| `tier` | Optional `standard` or `confidential` |\n\nLegacy text remains valid:\n\n```json\n{\n  \"model\": \"embeddinggemma-2\",\n  \"input\": [\"first item\", \"second item\"],\n  \"input_type\": \"query\",\n  \"dimensions\": 256\n}\n```\n\nA multimodal item has 1-16 ordered `content` parts:\n\n```json\n{\n  \"model\": \"embeddinggemma-2\",\n  \"input_type\": \"document\",\n  \"dimensions\": 256,\n  \"input\": [{\n    \"content\": [\n      { \"type\": \"text\", \"text\": \"Product demo\" },\n      {\n        \"type\": \"image\",\n        \"media\": {\n          \"encoding\": \"base64\",\n          \"mime_type\": \"image/png\",\n          \"data\": \"iVBORw0KGgo...\",\n          \"sha256\": \"<64 lowercase hex characters>\"\n        }\n      },\n      {\n        \"type\": \"audio\",\n        \"duration_seconds\": 4.2,\n        \"media\": {\n          \"encoding\": \"base64\",\n          \"mime_type\": \"audio/mpeg\",\n          \"data\": \"SUQzBAAAAA...\",\n          \"sha256\": \"<64 lowercase hex characters>\"\n        }\n      }\n    ]\n  }]\n}\n```\n\nMedia is inline only. The Grid never fetches media URLs. `sha256` is the lowercase hash of the\ndecoded bytes, and `data` is canonical base64 for those exact bytes. Audio and video require\n`duration_seconds`; the runtime verifies real decoded duration and rejects understatement.\n\nOmitting `input_type` is exactly equivalent to `\"input_type\":\"query\"` for EmbeddingGemma 2.\nThe Grid seals that explicit value with the ordered input, so admission, the quote, and runtime\nprefixing cannot disagree. `unspecified` is an explicit opt-out and is never the default.\n\nUse `grid_embeddings.py` to hash and encode files without loading credentials from a `.env`:\n\n```bash\nexport COMPUTE_API_KEY=\"x402c_...\"\n\npython {baseDir}/scripts/grid_embeddings.py embed \\\n  --text \"Product demo\" \\\n  --image ./frame.png \\\n  --audio ./narration.mp3 --audio-seconds 4.2 \\\n  --input-type document --dimensions 256\n\n# Inspect the exact JSON without sending:\npython {baseDir}/scripts/grid_embeddings.py embed \\\n  --part text:\"Product demo\" \\\n  --part image:./frame.png \\\n  --part audio:./narration.mp3@4.2 \\\n  --dimensions 256 --dry-run\n```\n\nRepeat `--part` to preserve an arbitrary text/media order. Convenient `--text`, `--image`,\n`--audio`, and `--video` flags build text → images → audio → video. Use `--request-json`\nfor multi-item batches or a prebuilt body.\n\n## Exact limits\n\n| Limit | Value |\n|---|---:|\n| Encoded JSON body | 24 MiB |\n| Top-level items | 1-16 |\n| Parts per item | 1-16 |\n| Images | Up to 8 per item; JPEG/PNG/WebP; 8 MiB each; 8 MiB total image bytes per item; 16 MP each |\n| Audio | One per item; WAV/FLAC/MP3; 8 MiB; 30 seconds |\n| Video | One per item; MP4; 16 MiB; 32 seconds; sampled at up to 1 fps and 32 frames |\n| Decoded media | 20 MiB per request |\n| Aggregate UTF-8 text | 10 MiB |\n| Processed context | 8,192 tokens per item, including retrieval prefix, 12 template tokens, and media expansion |\n\nThe runtime verifies magic bytes, image shape, audio/video duration, bounded decoded work,\nprocessor usage, output dimensions, finite floats, ordering, and unit normalization.\n\n## Response and billing\n\nThe response is OpenAI-shaped:\n\n```json\n{\n  \"object\": \"list\",\n  \"data\": [\n    { \"object\": \"embedding\", \"index\": 0, \"embedding\": [0.014, -0.031] }\n  ],\n  \"model\": \"embeddinggemma-2\",\n  \"usage\": {\n    \"prompt_tokens\": 313,\n    \"total_tokens\": 313,\n    \"cost_usd\": 0.000001,\n    \"breakdown\": { \"text\": 32, \"image\": 256, \"audio\": 25, \"video\": 0 }\n  },\n  \"processor_revision\": \"30f177f03cbcb42bc2f65496458de79f51b80c28\",\n  \"embedding_protocol\": \"embedding-multimodal-v1\"\n}\n```\n\nVectors are returned in top-level input order and are normalized again after 768/512/256/128\nMatryoshka truncation. Billing is input only at the catalog input-token rate. The Grid validates\nvectors and actual processor usage before debiting credits or settling x402.\n\nWhen an x402 capture succeeds but its durable accounting finalizer still needs recovery, the\nsuccessful response also contains `\"billing_pending\":true` and a `job_id`. Do not resubmit that\npaid request. The idempotent billing outbox completes the operator/platform split by job id.\n\n## Privacy and retention\n\nThe orchestrator seals the complete ordered input and explicit effective `input_type` to the\nselected node with negotiated v2/base64 X25519 transport. There is no plaintext media fallback.\nThe job row temporarily persists that **encrypted envelope**, not plaintext media. Node results\nare also persisted as encrypted envelopes.\n\nAfter a job becomes terminal, `input_payload` becomes eligible for deletion at **30 minutes**\nand `encrypted_result` at **one hour**. The purge runs hourly, so the practical upper bounds are\nabout **90 minutes** for input and **two hours** for results.\n\nNode failure text can contain prompts, media, paths, or tracebacks. Node-supplied failure text is\nclassified transiently and persisted only as `embedding_input_invalid`,\n`embedding_context_overflow`, or `embedding_runtime_failed`. Orchestrator-owned validation\npaths can store bounded service reasons, but `GET /v1/jobs/{id}` normalizes every EG2 runtime\nfailure to the same stable public codes.\n\n## Public errors\n\n| HTTP | Type/code | Action |\n|---:|---|---|\n| 400 | `invalid_request_error` | Fix JSON, MIME/base64/SHA, duration, batch, encoding, or dimensions. |\n| 400 | `invalid_request_error / embedding_input_invalid` | Decoded media or supported input shape failed runtime validation. Reduce/fix input. Not charged and no paid failover. |\n| 400 | `invalid_request_error / embedding_context_overflow` | Reduce the item. Not charged and no paid failover. |\n| 401 | `invalid_api_key` | Replace an invalid or revoked API key. |\n| 401 | `invalid_session` | Reconnect the wallet session used with `use_credits:true`. |\n| 403 | `insufficient_scope` | Use a key with `grid:write`. |\n| 402 | `payment_required` | Complete x402 payment or use credits. |\n| 402 | `insufficient_credits` | Top up credits or reduce the request. |\n| 402 | `pod_cap_reached` | Raise the pod's daily compute cap or wait for reset. |\n| 402 | `payment_error` | Verification or a definitively rejected settlement failed. Follow the message; a definite rejection is not charged. |\n| 404 | `model_not_found` | Correct the model id. If the embeddings feature itself is off, the route returns plain `Not found`. |\n| 413 | `invalid_request_error` | Encoded JSON exceeds 24 MiB. |\n| 500 | `server_error` | Dispatch or billing infrastructure failed. Read the charge/retry statement in the message. |\n| 502 | `inference_error` | Node output failed validation. The Grid may fail over; invalid vectors are not returned or billed. |\n| 503 | `model_not_available` | Release flag, confidential transport, or an exact capable ready node is unavailable. |\n| 503 | `node_not_available` | A claimed node lost the negotiated confidential transport boundary. Not charged; the Grid may fail over. |\n| 503 | `server_error` | The payment service is not configured in this environment. Wait for configuration repair. |\n| 504 | `timeout` | Timed out and not charged. Credits may fail over once. |\n\nThe request endpoint returns client-safe messages. `GET /v1/jobs/{id}` can expose only the\nstable stored failure reason: `embedding_input_invalid`, `embedding_context_overflow`, or\n`embedding_runtime_failed`. Plaintext node reason text is never persisted.\n\n## Local mode\n\nOn a supported Apple Silicon Mac:\n\n1. Open Singularity Node.\n2. Choose **Local → Embeddings → EmbeddingGemma 2**.\n3. Download the pinned BF16 snapshot.\n4. Add/reorder text, images, audio, or video.\n5. Choose `query`, `document`, or `unspecified`, then 768/512/256/128 dimensions.\n6. Start Local AI and select **Generate embedding**.\n\nThe Local runtime binds loopback only after real text/image/audio/video/mixed startup vectors\npass. During the candidate phase, builds need `VITE_EMBEDDINGGEMMA2_ENABLED=true` and the native\nruntime needs `SGL_EMBEDDINGGEMMA2_ENABLED=true`. Both values must be the exact lowercase\nstring `true`. These opt-ins are for release testing and do not enable production Grid traffic.\n\nLocal request errors are deliberately bounded:\n\n- `400 {\"error\":\"Invalid embedding input.\"}` for expected client input failures.\n- `413 {\"error\":\"Request body exceeds the limit.\"}`.\n- `503 {\"error\":\"Embedding runtime unavailable.\"}` for runtime or output-accounting failure;\n  readiness is removed.\n\n## Immutable candidate\n\n- Official model: `google/embeddinggemma-2@914f7f89142e33e77833254d9c9b90c3cef7303b`\n- Apple BF16 model: `mlx-community/embeddinggemma-2-bf16@1a4ffddb7905d3f63486748deabe091a01fb6201`\n- MLX: `0.32.3`\n- Transformers: `5.19.0`\n- MLX-VLM / processor: `30f177f03cbcb42bc2f65496458de79f51b80c28`\n\nFP16 is rejected. Keep the model, processor, runtime, asset hashes, and startup fixtures pinned\ntogether.\n\nFile v1.31.0:references/node-operator.md\n\n# SGL Grid — Provide Compute (Run a Node)\n\nBecome a **grid node operator**: serve confidential, OpenAI-compatible inference from your own\nTEE-capable machine and earn **USDC + SGL** on every settled job. This is the *provider* side of\nthe grid (the consumer side — calling inference — is in the main SKILL under \"SGL Grid — Inference\").\n\nEverything here is agent-runnable: the installer and the `sgl` CLI are plain shell commands. The\nonly step that needs an on-chain wallet transaction is **staking** (see Step 1), which is itself\nagentic via the staking API / the `x402-layer` skill.\n\nNode software (open source): `https://github.com/Singularity-Layer/sgl-network-node`\n\n---\n\n## Requirements (check before starting)\n\n- **A TEE-capable machine.** A supported Trusted Execution Environment is mandatory — it's what lets\n  the node serve prompts it cannot read. Examples: Apple Secure Enclave (`apple_se`), Intel TDX/SGX,\n  AMD SEV-SNP, AWS Nitro.\n- **Compute for the model** you'll serve — CPU/RAM (+ GPU/Metal where available). 3B-class models run\n  on modest hardware; larger models need more.\n- **≥ 50,000 $SGL staked** to your operator wallet (the minimum to register a compute node; the live\n  figure is shown in the staking app). Non-custodial, withdrawable after a cooldown.\n- **A Solana wallet** holding the stake — the node is bound to it.\n- **Local inference runtime** `llama.cpp` (`brew install llama.cpp`) and a **GGUF model file** for\n  chat models, or the Singularity Node app v1.7.4+ for Laya/System One.\n- Reliable power + network (uptime = job matching; honest downtime is never penalized).\n\n---\n\n## Step 1 — Stake $SGL (bond the operator wallet)\n\nStake at least the minimum (**50,000 SGL**) to the wallet you'll run the node under. Staking is\nnon-custodial and **only slashable for proven tampering — never for honest downtime**.\n\nAgentic options:\n- Use the **`x402-layer` skill** (staking module) or the **Staking Engine API**\n  (`docs.x402layer.cc/staking` · API reference under \"Staking Engine\") to stake programmatically.\n- Or stake in the app: `https://staking.x402layer.cc`.\n\nToken: `$SGL` mint `5c4HyD2rSShqnTsf5z3SaoD2H3GE452u2CUuYjviBAGS` (Solana). Full model (tiers,\ncooldowns, rewards, slashing) → `https://docs.x402layer.cc/staking/introduction`.\n\n---\n\n## Step 2 — Install the node CLI + runtime\n\n```bash\n# 1. Install the sgl node CLI (Singularity-Layer/sgl-network-node release)\ncurl -sSf https://grid.x402compute.cc/install.sh | sh\n\n# 2. Local inference runtime\nbrew install llama.cpp            # macOS; see repo README for Linux\n\n# 3. A GGUF model to serve, e.g.\n#    ~/models/Llama-3.2-3B-Instruct-Q4_K_M.gguf\n\nsgl --help                        # verify install\n```\n\n---\n\n## Step 3 — Register the node (bind to the staked wallet)\n\nAgentic / headless (no browser) — recommended for agents:\n\n```bash\nsgl init --wallet ...","readmeExcerpt":"Skill: x402 Compute Owner: ivaavimusic Summary: This skill should be used when the user asks to \"provision GPU instance\", \"integrate agent pods over an API\", \"create pods for my customers\", \"pod webhooks\", \"pod events\", \"spin up a cloud server\", \"list compute plans\", \"browse GPU pricing\", \"deploy AI machine\", \"one-click GPU running an LLM\", \"deploy a private LLM endpoint\", \"OpenRouter-ready endpoint\", \"agent deploy G","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"pip install -r {baseDir}/requirements.txt"},{"language":"bash","snippet":"# Base (EVM) — same keys work for MegaETH and Robinhood Chain\nexport PRIVATE_KEY=<your-evm-private-key>\nexport WALLET_ADDRESS=<your-evm-wallet-address>\n\n# MegaETH (uses same EVM keys as Base)\nexport PRIVATE_KEY=<your-evm-private-key>\nexport WALLET_ADDRESS=<your-evm-wallet-address>\nexport COMPUTE_AUTH_CHAIN=\"megaeth\"\n\n# Robinhood Chain (uses same EVM keys as Base; pays with USDG)\nexport PRIVATE_KEY=<your-evm-private-key>\nexport WALLET_ADDRESS=<your-evm-wallet-address>\nexport COMPUTE_AUTH_CHAIN=\"robinhood\"\n\n# Solana\nexport SOLANA_SECRET_KEY=<your-solana-secret-key>\nexport SOLANA_WALLET_ADDRESS=<your-solana-wallet-address>\nexport COMPUTE_AUTH_CHAIN=\"solana\""},{"language":"bash","snippet":"npm install -g @open-wallet-standard/core@0.5.0\nexport OWS_WALLET=\"compute-wallet\"\nexport COMPUTE_AUTH_MODE=\"ows\""},{"language":"bash","snippet":"python {baseDir}/scripts/create_api_key.py --label \"my-agent\""},{"language":"bash","snippet":"python {baseDir}/scripts/agent_pod.py catalog                              # pick tier/plan/model\npython {baseDir}/scripts/agent_pod.py templates                            # curated pods with a job (TGPod …)\npython {baseDir}/scripts/agent_pod.py deploy --ai-mode managed --tier pro \\\n    --plan <plan_id> --prepaid-hours 720 --telegram <bot_token> --use-credits\npython {baseDir}/scripts/agent_pod.py create-key <pod_id> --name my-integration   # → sk-sglpod-int-…\npython {baseDir}/scripts/agent_pod.py chat <pod_id> \"What's on my calendar?\" --key sk-sglpod-int-…"},{"language":"bash","snippet":"curl \"https://grid.x402compute.cc/v1/models?type=systemone\" \\\n  -H \"X-API-Key: $COMPUTE_API_KEY\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: x402-compute\nversion: 1.31.0\ndescription: |\n  This skill should be used when the user asks to \"provision GPU instance\",\n  \"integrate agent pods over an API\", \"create pods for my customers\",\n  \"pod webhooks\", \"pod events\",\n  \"spin up a cloud server\", \"list compute plans\", \"browse GPU pricing\",\n  \"deploy AI machine\", \"one-click GPU running an LLM\", \"deploy a private LLM endpoint\",\n  \"OpenRouter-ready endpoint\", \"agent deploy GPU\", \"spin up my own OpenAI-compatible endpoint\",\n  \"extend compute instance\", \"resize compute instance\", \"destroy server instance\", \"check instance status\",\n  \"list my instances\", \"top up compute credits\", \"check credit balance\",\n  \"run inference on the grid\", \"decentralized inference\", \"OpenAI-compatible API\",\n  \"multimodal embeddings\", \"EmbeddingGemma 2\", \"embed image\", \"embed audio\",\n  \"embed video\", \"mixed media vectors\", \"local embeddings\",\n  \"confidential / TEE inference\", \"list grid models\", \"check grid capacity\",\n  \"Laya\", \"System One\", \"Jev-compatible decisions\", \"typed decision model\",\n  \"private Laya\", \"serve Laya from the node app\",\n  \"run a node\", \"provide compute\", \"become a grid node\", \"node operator\", \"join the grid\",\n  \"stake to run a node\", \"serve a model on the grid\", \"earn from compute\",\n  \"deploy an always-on AI agent\", \"deploy a hosted OpenClaw agent\", \"spin up a ClawPod\",\n  \"agent pod\", \"hosted agent with its own wallet\", \"free agent trial\",\n  \"deploy a processor\", \"sell my code per call\", \"monetize an endpoint\",\n  \"publish a paid API\", \"connect a processor as an MCP tool\",\n  \"back up my agent\", \"agent backup\", \"restore my agent\", \"migrate my agent\",\n  \"agent vault\", \"snapshot my agent's memory\", \"move my agent to a new machine\",\n  or manage Singularity Cloud Network compute. Seven jobs: SGL Machines\n  (GPU/VPS provisioning across Vultr & DigitalOcean), AI Machines (one-click GPU\n  running an LLM — deploy a private OpenAI-compatible endpoint, or join the grid & earn),\n  SGL Grid (decentralized, confidential, OpenAI-compatible inference, multimodal embeddings,\n  plus Laya/System One typed decisions — consume it),\n  Provide Compute (run a TEE node on the grid to serve inference and earn USDC + SGL), and\n  Agent Pods (deploy an always-on hosted OpenClaw agent with its own crypto wallet, memory,\n  preinstalled x402 skills, and owner/platform customization for identity, instructions,\n  and self-check heartbeat prompts — managed or BYOK, tiers, free 24h trial), and\n  Processors (publish your own code as a paid endpoint — buyers pay you directly in USDC via\n  x402, you pay only for runtime; every processor is also a connectable MCP server, so agents,\n  harnesses and LangGraph nodes can call it with just a URL), and Agent Vault\n  (zero-knowledge encrypted backup, restore & migration for OpenClaw/Hermes agents —\n  snapshot an agent's memory and soul, store it encrypted, restore or migrate it to any\n  machine or pod). Pay with\n  USDC on Base, Solana or Arc, USDm on MegaETH, USDG on Robinhood Chain via x"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn73xndw522wt8y06avyd39a8h7ztbeh\",\n  \"slug\": \"x402-compute\",\n  \"version\": \"1.31.0\",\n  \"publishedAt\": 1791361180079\n}"},{"path":"references/agent-pods-api.md","content":"# Agent Pods API — `/pods/v1` (API-key surface)\n\nThe endpoints in `agent-pods.md` are the **dashboard's** surface: they expect a wallet\nsignature or a compute session, which is right for a human at a browser and awkward for a\nprogram. `/pods/v1` is the same product behind **one API key**, meant for building on top of\npods rather than clicking them.\n\nUse this reference when the caller holds an `x402c_…` key and no wallet. Use `agent-pods.md`\nwhen signing with OWS.\n\n- **Base:** `https://compute.x402layer.cc/pods/v1`\n- **Auth:** `X-API-Key: x402c_…` on every route\n- **Mint a key:** dashboard → Settings → API Keys\n\n---\n\n## Two rules that will cost you if you skip them\n\n**Create is idempotent and the header is required.** `POST /pods` refuses without\n`Idempotency-Key`, because the call provisions a machine and charges for it. Replaying the\nsame key returns the original response byte for byte instead of making a second pod; the same\nkey with a *different* body is a `409` with `details.code = idempotency_mismatch`, since that\nis a bug in the caller and swallowing it would hide it.\n\nUse an id you already have — an order number, a job id. A generated UUID protects a retry\ninside one process; only a stable id protects a retry after that process dies.\n\n**Delete is not instant.**\n\n| Response | Meaning |\n|---|---|\n| `200` `destroyed` | the machine is confirmed gone |\n| `202` `destroying` | accepted, provider would not delete yet, **may bill a few minutes more** |\n\nA provider refuses to remove a machine that is still installing. Treating `202` as done is how\na pod keeps billing after you thought you deleted it. Poll `GET /pods/{id}` until `destroyed`.\n\n---\n\n## Create, then talk to it\n\n```bash\nPOD=$(curl -s -X POST https://compute.x402layer.cc/pods/v1/pods \\\n  -H \"X-API-Key: $SGL_API_KEY\" \\\n  -H \"Idempotency-Key: order-4471\" \\\n  -H 'content-type: application/json' \\\n  -d '{\n    \"tier\": \"starter\",\n    \"name\": \"support agent\",\n    \"external_ref\": \"customer-42\",\n    \"agent_identity\": \"You are Atlas, Acme Cloud support.\",\n    \"agent_instructions\": \"Answer as Acme support. Be concise and cite the current integration step.\",\n    \"heartbeat_prompt\": \"Check open escalations and renew yourself if runway is low. Stay silent if clear.\",\n    \"agent_heartbeat_minutes\": 30\n  }' | jq -r .pod.id)\n\n# Booting takes a few minutes. status goes provisioning -> online.\ncurl -s \"https://compute.x402layer.cc/pods/v1/pods/$POD\" -H \"X-API-Key: $SGL_API_KEY\" | jq -r .pod.status\n```\n\n`external_ref` is **your** id. It comes back on every read and filters `GET /pods`, so you can\nfind a pod again from your own database without storing ours.\n\n### Customizing the agent\n\nPlatforms can customize a pod without taking over the managed runtime files:\n\n| Field | Create | PATCH | Meaning |\n|---|---:|---:|---|\n| `agent_identity` | yes | yes | Owner/platform identity text, max 8000 chars. Rendered into managed `AGENTS.md` and `IDENTITY.md`. |\n| `agent_instructions` | yes | yes | Owner/platform operatin"},{"path":"references/agent-pods.md","content":"# Agent Pods — deploy & drive an always-on hosted agent\n\nAn **Agent Pod** (\"ClawPod\", built on **OpenClaw**) is a persistent AI agent that runs 24/7 on\na dedicated CPU machine. It chats on **Telegram & Discord** (Slack / WhatsApp / Signal coming\nsoon) and from the dashboard, has its own **crypto wallet** (Coinbase CDP — EVM + Solana, keys in\na TEE), **persistent memory**, and ships with the `x402-compute` + `x402-layer` skills preinstalled\n(wired to your account with capped, revocable credentials) so it can buy confidential compute and\npay x402 endpoints itself. Owner/platform customization is supported through structured fields:\nidentity, instructions, and the quiet self-check heartbeat prompt.\n\nA pod **is a compute order** — the `pod.id` returned by deploy is the compute order id. Lifecycle\n(extend / destroy) reuses the Machines endpoints with that id as the instance id.\n\n- **API base:** `https://compute.x402layer.cc`\n- **Only `openclaw` is deployable today** (`agent_id: \"openclaw\"`, display name \"ClawPod\").\n  `hermes` (\"HermPod\") shows in the catalog marked *coming soon* and is rejected by deploy.\n\n## Auth model (important)\n\nPod endpoints split into two auth surfaces:\n\n| Surface | Endpoints | Auth |\n|---------|-----------|------|\n| **Owner** (manage the pod) | `POST /pods`, `GET/PATCH /pods/{id}`, `POST /pods/{id}/actions`, `GET/POST/DELETE /pods/{id}/api-keys*`, wallet, credentials | **Compute auth** — `X-API-Key: x402c_…`, a signed compute session, or an `X-Auth-*` wallet signature. Required even when paying with x402, because a pod is owned by your wallet. |\n| **Adapter** (talk to the agent) | `GET /pods/{id}/v1/models`, `POST /pods/{id}/v1/chat/completions` | **`Authorization: Bearer sk-sglpod-int-…`** — a pod-scoped integration key you mint via `POST /pods/{id}/api-keys`. NOT compute auth. |\n\nThe catalog (`GET /pods/catalog`) is public (no auth).\n\n## 1. Catalog (public)\n\n```bash\ncurl -s https://compute.x402layer.cc/pods/catalog\n```\nReturns deployable agents, managed **tiers** (with each tier's model menu + RAM floor), supported\n**channels**, memory backends, and pricing. Read it first to pick a `tier`/`plan`/`model`.\n\n## 2. Deploy — `POST /pods` (owner / compute auth)\n\nTwo AI modes:\n\n- **`managed`** — we run the LLM and meter it from your platform **credits**. Pick a `tier`:\n  - `starter` — text chat.\n  - `pro` — adds vision + computer-use (runs a browser on the box → higher RAM floor).\n  - `max` — top reasoning + vision.\n  Each tier bundles a machine RAM floor + a curated model menu the agent can switch among at\n  runtime (`/model`). Managed pods include a small prepaid inference allowance.\n- **`byok`** — bring your own OpenAI-compatible key + any machine `plan`. You pay CPU + a small\n  service % only; your AI runs on your key.\n\n**Pay:** platform **credits** (`use_credits: true`) or **x402** (omit `use_credits` → the deploy\nanswers `402 Payment Required`; settle with the `X-Payment` header like any provision, and add\n`\"network\"` for a no"},{"path":"references/agent-vault.md","content":"# Agent Vault — encrypted agent backup & migration\n\nZero-knowledge encrypted backup, restore, and migration for AI agents\n(OpenClaw `~/.openclaw`, Hermes `~/.hermes`). Snapshot an agent's entire\nself — memory, soul/workspace, config, skills — and bring it back anywhere:\na new machine, a fresh Agent Pod, or the same box after a bad day.\n\n**Zero-knowledge, for real:** every backup is sealed on the machine it lives\non (scrypt key derivation + AES-256-GCM, AAD-bound to the snapshot identity).\nThe platform stores ciphertext it cannot read. That cuts both ways — **a lost\npassphrase is unrecoverable by anyone, including Singularity Layer.** Tell the\nuser to write it down before the first backup.\n\nDashboard: https://cloud.x402compute.cc/network/backups\nPlans (all paid from platform credits):\n  FREE      — 1 GB, 1 rolling snapshot (each new backup replaces the previous).\n  VAULT PRO — 10 GB, the last 10 snapshots OF EACH AGENT. $3/month or $30/year.\n  VAULT MAX — 50 GB, unlimited snapshots, full history. $5/month or $50/year.\nYearly is two months free. The FREE tier needs no call and no payment — every\nwallet starts there. Subscribe with\n`POST /backups/subscribe {\"plan\":\"pro\"|\"max\",\"interval\":\"month\"|\"year\"}`\n(credits), or add `\"pay\":\"x402\",\"network\":\"base\"|\"solana\"|\"robinhood\"|\"megaeth\"`\nto pay directly: the route answers 402 with an x402 challenge when a charge is\nrequired and credits are short, then activates on the retry carrying\n`X-Payment`. The challenge quotes the FULL plan price; proration means the real\ndebit can be lower and the remainder stays as credits. Cancels and scheduled\ndowngrades never produce a challenge. The payer must be the authenticated\nwallet, and a replayed `X-Payment` cannot double-charge. The dashboard route is\nAgent Vault → Upgrade.\n\nUpgrades charge now, PRORATED against the unused part of the period already\npaid for, and start a fresh period; downgrades and `\"plan\":\"free\"` (cancel)\ntake effect at the end of the period already paid for, and never charge. An\nx402 challenge is therefore only ever issued for an action that actually costs\nmoney. A failed renewal downgrades behavior only; stored\nbackups are never deleted. Per-snapshot cap: 2 GiB.\n\n## CLI (the normal path)\n\n```bash\nnpm i -g @singularity-layer/agentvault\n\nagentvault login              # browser wallet approval (device flow)\nagentvault login --api-key    # headless: paste a compute API key instead\nagentvault backup --all       # detect, encrypt, upload every local agent\nagentvault backup --path <dir> --name <n>   # UNIVERSAL: vault any directory (any harness)\nagentvault list               # agents + snapshot counts\nagentvault restore            # pick snapshot -> passphrase -> safe unpack\nagentvault restore --dest ~/x # restore into a specific directory\nagentvault passphrase set     # store passphrase in the OS keychain\nagentvault daemon install --frequency weekly   # automatic backups\n```\n\nNon-interactive (cron/agents): store the passphrase once with\n`agentvault pass"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2656,"uniquenessScore":36,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T06:47:25.959Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T06:47:25.959Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:35:33.890Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}