Compute Supply protocol v0.1

Constrained compute.
Public commitments.
Portable trust.

Compute Supply turns provider credentials into repository-bound resources that maintainers can trust before they create an account—and safely use without ever seeing a sponsor’s key.

01

The repository is the recipient.

A pledge points to an immutable provider and owner/repository identity. It can exist before any maintainer joins.

02

Backing is continuously verified.

A limit snapshot is evidence, not escrow. The protocol rechecks the provider and exposes freshness, expiry, and failures.

03

Credentials remain isolated.

Secrets are envelope-encrypted. Maintainers use a Compute Supply gateway token constrained by repository, amount, model policy, and time.

04

Revocation has a memory.

Before claim, sponsors can cancel freely. After activation, revocation creates a permanent public event and a 12-month reputation penalty.

Grant lifecycle

One legible state machine.

01Pledged

A sponsor names a repository, amount, provider, constraints, and expiry.

02Backed

The provider key reports enough remaining limit and passes an independent check.

03Claimed

A GitHub identity proves maintain or admin control of the named repository.

04Active

The maintainer receives a scoped gateway token and usage receipts begin.

05Fulfilled

The committed amount is consumed or released after the declared outcome.

What “backed” guarantees

Specific claims,
not vibes.

  • Key-scoped limitThe provider reports a finite remaining spend limit at the recorded check time.
  • Credential possessionThe gateway successfully authenticates with the credential backing this grant.
  • Constraint enforcementThe gateway rejects spend beyond the repository, amount, model, and expiry policy.
  • Public failure semanticsMissed checks, revocation, exhaustion, and expiry change the public state immediately.

Honest limitations

A provider key is not a bank escrow.

The sponsor can still disable a key or spend the parent account elsewhere. Compute Supply does not pretend otherwise. It makes the promise inspectable, detects broken backing quickly, rate-limits exposure, and prices sponsor reliability into how much the network trusts future pledges.

Verification cadence60 seconds active
Default historyPermanent event log
Reputation windowTrailing 12 months