Robinhood Chain

Private inference your agent can prove.

envolvr is an OpenAI-compatible inference API that runs inside hardware-attested enclaves. Every response comes with a signed receipt, and every receipt is anchored on Robinhood Chain. Your agent can prove what ran, where, and what it paid, and anyone can check the proof without trusting envolvr.

Overview

Quickstart

With the envolvr command from @envolvr/sdk (Node 20 or later), from an empty wallet to a verified receipt:

npm install -g @envolvr/sdk            # or run each command as npx @envolvr/sdk …
export ENVOLVR_PRIVATE_KEY=0x…          # a wallet with USDG and a little ETH for gas on Robinhood Chain

envolvr signin --save                   # sign a message, get an API key
envolvr deposit 10                      # credited, net of the deposit fee, within seconds
envolvr chat "Reply with the single word: sealed"
envolvr verify --last                   # run again once the 10-minute slot has closed

verify reads the saved receipt back and prints what it proves:

✓ receipt signature by the attested key
✓ receipt names the attested keyset
✓ request commitment matches the bytes sent
✓ response commitment matches the bytes received
✓ provider enclave verified before forwarding
✓ cited provider session checks out
✓ keyset bound into the TDX quote
✓ workload measured and linked to public source
✓ production dstack OS image
· TDX quote chains to Intel (checked live by verify-gateway)
✓ billing                     0.00001135 USD for 19+17 tokens, billed $0.000012
✓ charged to this key         yes
✓ anchor                      batch 2, leaf 0 of 2, 2026-09-25T11:40:01.000Z, tx 0xe379…bb98

verdict: VERIFIED

envolvr verify-gateway checks the live gateway: the TDX quote to Intel's root, the measured compose and source commit, the production OS, and that your TLS connection ends at the attested key.

In code

// npm install @envolvr/sdk
import { Envolvr, privateKeySigner, signIn, depositUsdg, MAINNET, toMicros } from '@envolvr/sdk';

const wallet = privateKeySigner(process.env.KEY, { rpcUrl: MAINNET.rpcUrl, chainId: MAINNET.chainId });
const { apiKey } = await signIn(wallet);                      // shown once: store it
await depositUsdg({ signer: wallet, amountMicros: toMicros('10') });

const envolvr = new Envolvr({ apiKey, receiptDir: './receipts' });
const { response, saved } = await envolvr.chat({
  model: 'z-ai/glm-5.3',
  messages: [{ role: 'user', content: 'Summarize the position risk.' }],
});
// later, once the slot has closed:
const proof = await envolvr.verify(saved.dir);                // signature, billing, payer, anchor

Any wallet works: implement Signer (address, signMessage, and sendTransaction for deposits) around viem, ethers or a hardware wallet. The client saves each receipt with the exact request and response bytes, the provider session it cites, and the attestation report of the keyset that signed it, so it can be verified later, offline.

With the OpenAI SDK

import OpenAI from 'openai';
const client = new OpenAI({ baseURL: 'https://api.envolvr.xyz/v1', apiKey: process.env.ENVOLVR_API_KEY });
const res = await client.chat.completions.create({ model: 'z-ai/glm-5.3', messages: [...] }).withResponse();
const receiptId = res.response.headers.get('x-receipt-id');   // fetch it within the hour

To have every request go over a verified channel, run the local verifying proxy and point the client at it. It verifies the gateway before it starts, pins the attested TLS key, and checks every receipt:

npx private-ai-proxy serve https://api.envolvr.xyz --require-production-os
# base URL: http://127.0.0.1:4180/v1

Account and funding

In a browser, the account app does all of this with your wallet: deposit, create and revoke API keys, see usage and deposits, and close the account. Agents use the endpoints below, or the SDK.

Sign in

GET https://auth.envolvr.xyz/auth/nonce?wallet=0x… returns a message; sign it with EIP-191 personal_sign and send {wallet, nonce, issuedAt, signature} to POST /auth/key. The API key is shown once. Each sign-in issues a new key; earlier keys keep working until you revoke them.

Manage keys

A management session lists, labels and revokes keys and shows usage and deposits. GET /auth/session/nonce?wallet=0x… returns a message to sign; POST /auth/session with {wallet, nonce, issuedAt, signature} returns a session token, valid for 12 hours. It manages the account and cannot call models, and an API key cannot manage the account.

Deposit USDG

Approve the credit vault for USDG, then call deposit(amount) from your wallet, or depositFor(account, amount) to fund another wallet. The balance is credited within seconds of the deposit being mined, net of the deposit fee. Deposit from a wallet you control, and use the vault's functions: a plain USDG transfer to the vault is not credited.

Automatic top-up

With the SDK, an agent can keep itself funded: when its balance falls below a threshold, the client deposits a set amount from a wallet you choose, waits until it is credited, and retries a request refused for insufficient credit once. A daily cap limits the deposits.

new Envolvr({ apiKey, autoTopUp: { signer: wallet, below: '5', amount: '20', maxPerDay: '100' } })

Balance

GET https://auth.envolvr.xyz/account with Authorization: Bearer <API key> returns your balance, in micro-USD.

Close your account

Your balance is yours to take back. Closing needs the wallet, not just a key: GET /account/close/nonce?wallet=0x…&refundTo=0x… returns a message to sign, and POST /account/close with {wallet, refundTo, nonce, issuedAt, signature} revokes every API key of the account and refunds the balance to refundTo, by default the wallet itself. The refund is paid from the credit vault shortly after. Deposit fees are not refunded. With the CLI: envolvr close --yes.

Models and providers

GET https://api.envolvr.xyz/v1/models lists every model with its per-token prices and routes. At launch:

ModelProviderInput / output per 1M tokens
z-ai/glm-5.3Phala (RedPill)$1.40 / $4.40
z-ai/glm-5.3-flashNEAR AI, enclave-signed$0.15 / $0.50
qwen/qwen3.8-27bChutes, end-to-end encrypted; Phala (RedPill) or NEAR AI on request$0.24 / $2.20 (RedPill: $0.24 / $2.50, NEAR: $0.44 / $3.30)
qwen/qwen3.6-35b-a3bNEAR AI, enclave-signed$0.17 / $1.10
deepseek/deepseek-v4-flashChutes, end-to-end encrypted$0.44 / $1.32
deepseek/deepseek-v3.2Chutes, end-to-end encrypted$1.00 / $1.00
moonshotai/kimi-k2.6Chutes, end-to-end encrypted$0.50 / $2.85

Choose providers per request with an OpenRouter-style block: "provider": {"only": ["near-ai"]}, or {"order": ["redpill", "near-ai"], "allow_fallbacks": true}. Provider names are redpill, near-ai and chutes. A route marked opt-in in /v1/models is used only when you name it.

Chutes runs on Bittensor's open GPU network, where independent operators run the machines. envolvr verifies each machine on its own (Intel TDX quote, NVIDIA GPU attestation) and encrypts every request end to end to that machine's attested key, so neither Chutes nor the operator sees your prompt. Hardware limits are set out in the protocol spec.

API reference

EndpointWhat
POST api/v1/chat/completionsOpenAI chat completions, streaming or not. Header x-receipt-id names the receipt; usage.cost is the cost in USD.
GET api/v1/modelsModels, prices, routes.
GET api/v1/aci/receipts/{id}The signed receipt, with the same API key. Kept for an hour.
GET api/v1/aci/sessions/{id}The attested provider session a receipt cites.
GET api/v1/aci/attestation?nonce=The gateway's attestation report for a fresh 64-hex nonce.
GET auth/auth/nonce, POST auth/auth/keyWallet sign-in.
GET auth/accountBalance (API key or session).
GET auth/auth/session/nonce, POST auth/auth/session, POST auth/auth/session/endA wallet-signed management session.
GET/POST auth/account/keys, POST auth/account/keys/revokeList, create and revoke API keys (session).
GET auth/account/usage, GET auth/account/depositsRequests with their cost, and deposits with their fee (session).
GET auth/pricingThe current deposit fee.
GET auth/receipts/{digest}/proofA receipt's inclusion proof on Robinhood Chain (public).

api is https://api.envolvr.xyz, auth is https://auth.envolvr.xyz. Both terminate TLS inside the attested VM.

Receipts

A receipt is a JSON document signed with an Ed25519 key that lives only inside the gateway's enclave and is listed in its attested keyset. Its event log records, in order:

EventRecords
request.receivedSHA-256 of the exact request bytes: a commitment you can later open to an auditor.
route.selectedThe provider route that served it.
upstream.verifiedThe attested provider session: TEE, GPU and OS claims, checked before forwarding.
upstream.response_attestedNEAR routes, non-streamed: the model enclave's own signature over this request and response.
billing.chargedToken counts, per-token rates, the exact cost, the amount billed, and a payer commitment.
response.returnedSHA-256 of the exact response bytes you received.

The payer commitment is sha256("billing.payer.v1:" + hex(sha256(api_key)) + ":" + receipt_id). It names no account and links no two receipts; you prove a receipt was charged to you by disclosing your key's hash, never the key.

Fetch receipts within the hour: the gateway keeps them for an hour. The SDK and the verifying proxy do it for you.

Verify

The gateway

npx private-ai-proxy verify https://api.envolvr.xyz --require-production-os

Checks the TDX quote to Intel's root, that the keyset and your nonce are bound into it, that the measured compose links to the public source commit, the production OS image, and that your TLS connection ends at the attested key. Pin a compose hash with --accept-compose.

A receipt

npx private-ai-proxy audit --report attestation.json --receipt receipt.json \
  --request-body request.json --response-body response.json --session session.json --require-production-os

Checks the signature against the attested keyset and the request and response bytes against the receipt's commitments. envolvr verify runs this for you on a saved receipt.

The anchor

The digest is SHA-256 of the receipt's JCS (RFC 8785) bytes. Get its proof from https://auth.envolvr.xyz/receipts/{digest}/proof and ask the contract directly:

cast call <ReceiptAnchor> \
  'verifyReceipt(bytes32,uint256,bytes32,bytes32[])(bool)' \
  0x86b99987cd8f8ebddc2dd0efa61ed52b5db594430f12446db424da0d9c4b831f <batchIndex> <digest> '[<proof>]' \
  --rpc-url https://rpc.mainnet.chain.robinhood.com

Receipts are anchored in fixed 10-minute slots (UTC): a slot's receipts become one Merkle root, anchored seconds after the slot ends by a key that only the attested gateway VM can derive. The chain sees the slot, never when in it your request ran.

Pricing

Network and contracts

Robinhood Chain (chain id 4663)
RPChttps://rpc.mainnet.chain.robinhood.com
Explorerhttps://robinhoodchain.blockscout.com
USDGPublished at launch
CreditVaultPublished at launch
NVLRPublished at launch
ReceiptAnchorPublished at launch
Gateway provider id0x86b99987cd8f8ebddc2dd0efa61ed52b5db594430f12446db424da0d9c4b831f

Source: envolvr/envolvr (contracts, control plane, SDK, deployment compose) and envolvr/private-ai-gateway (the gateway).

Good to know