Private inference your agent can prove.
envolvr is an OpenAI-compatible inference API that runs inside hardware-attested enclaves. Every response comes with a signed receipt, and every receipt is anchored on Robinhood Chain. Your agent can prove what ran, where, and what it paid, and anyone can check the proof without trusting envolvr.
Overview
- Gateway
https://api.envolvr.xyzruns in an Intel TDX virtual machine whose code, configuration and keys are measured and published. It verifies the provider's GPU enclave before forwarding, and signs a receipt for every response. - Providers serve open-weight models in confidential GPU enclaves: Phala (through RedPill) and NEAR AI Cloud. On NEAR routes each non-streamed response is also signed by the model enclave that produced it.
- Accounts are wallets. Sign a message to get an API key; fund it with USDG.
- Receipts record the model, the attested provider session, commitments to the exact request and response, and what was billed. They are anchored on Robinhood Chain every 10 minutes.
Quickstart
With the envolvr command from @envolvr/sdk (Node 20 or later), from an empty wallet to a verified receipt:
npm install -g @envolvr/sdk # or run each command as npx @envolvr/sdk …
export ENVOLVR_PRIVATE_KEY=0x… # a wallet with USDG and a little ETH for gas on Robinhood Chain
envolvr signin --save # sign a message, get an API key
envolvr deposit 10 # credited, net of the deposit fee, within seconds
envolvr chat "Reply with the single word: sealed"
envolvr verify --last # run again once the 10-minute slot has closed
verify reads the saved receipt back and prints what it proves:
✓ receipt signature by the attested key
✓ receipt names the attested keyset
✓ request commitment matches the bytes sent
✓ response commitment matches the bytes received
✓ provider enclave verified before forwarding
✓ cited provider session checks out
✓ keyset bound into the TDX quote
✓ workload measured and linked to public source
✓ production dstack OS image
· TDX quote chains to Intel (checked live by verify-gateway)
✓ billing 0.00001135 USD for 19+17 tokens, billed $0.000012
✓ charged to this key yes
✓ anchor batch 2, leaf 0 of 2, 2026-09-25T11:40:01.000Z, tx 0xe379…bb98
verdict: VERIFIED
envolvr verify-gateway checks the live gateway: the TDX quote to Intel's root, the measured compose and source commit, the production OS, and that your TLS connection ends at the attested key.
In code
// npm install @envolvr/sdk
import { Envolvr, privateKeySigner, signIn, depositUsdg, MAINNET, toMicros } from '@envolvr/sdk';
const wallet = privateKeySigner(process.env.KEY, { rpcUrl: MAINNET.rpcUrl, chainId: MAINNET.chainId });
const { apiKey } = await signIn(wallet); // shown once: store it
await depositUsdg({ signer: wallet, amountMicros: toMicros('10') });
const envolvr = new Envolvr({ apiKey, receiptDir: './receipts' });
const { response, saved } = await envolvr.chat({
model: 'z-ai/glm-5.3',
messages: [{ role: 'user', content: 'Summarize the position risk.' }],
});
// later, once the slot has closed:
const proof = await envolvr.verify(saved.dir); // signature, billing, payer, anchor
Any wallet works: implement Signer (address, signMessage, and sendTransaction for deposits) around viem, ethers or a hardware wallet. The client saves each receipt with the exact request and response bytes, the provider session it cites, and the attestation report of the keyset that signed it, so it can be verified later, offline.
With the OpenAI SDK
import OpenAI from 'openai';
const client = new OpenAI({ baseURL: 'https://api.envolvr.xyz/v1', apiKey: process.env.ENVOLVR_API_KEY });
const res = await client.chat.completions.create({ model: 'z-ai/glm-5.3', messages: [...] }).withResponse();
const receiptId = res.response.headers.get('x-receipt-id'); // fetch it within the hour
To have every request go over a verified channel, run the local verifying proxy and point the client at it. It verifies the gateway before it starts, pins the attested TLS key, and checks every receipt:
npx private-ai-proxy serve https://api.envolvr.xyz --require-production-os
# base URL: http://127.0.0.1:4180/v1
Account and funding
In a browser, the account app does all of this with your wallet: deposit, create and revoke API keys, see usage and deposits, and close the account. Agents use the endpoints below, or the SDK.
Sign in
GET https://auth.envolvr.xyz/auth/nonce?wallet=0x… returns a message; sign it with EIP-191 personal_sign and send {wallet, nonce, issuedAt, signature} to POST /auth/key. The API key is shown once. Each sign-in issues a new key; earlier keys keep working until you revoke them.
Manage keys
A management session lists, labels and revokes keys and shows usage and deposits. GET /auth/session/nonce?wallet=0x… returns a message to sign; POST /auth/session with {wallet, nonce, issuedAt, signature} returns a session token, valid for 12 hours. It manages the account and cannot call models, and an API key cannot manage the account.
Deposit USDG
Approve the credit vault for USDG, then call deposit(amount) from your wallet, or depositFor(account, amount) to fund another wallet. The balance is credited within seconds of the deposit being mined, net of the deposit fee. Deposit from a wallet you control, and use the vault's functions: a plain USDG transfer to the vault is not credited.
Automatic top-up
With the SDK, an agent can keep itself funded: when its balance falls below a threshold, the client deposits a set amount from a wallet you choose, waits until it is credited, and retries a request refused for insufficient credit once. A daily cap limits the deposits.
new Envolvr({ apiKey, autoTopUp: { signer: wallet, below: '5', amount: '20', maxPerDay: '100' } })
Balance
GET https://auth.envolvr.xyz/account with Authorization: Bearer <API key> returns your balance, in micro-USD.
Close your account
Your balance is yours to take back. Closing needs the wallet, not just a key: GET /account/close/nonce?wallet=0x…&refundTo=0x… returns a message to sign, and POST /account/close with {wallet, refundTo, nonce, issuedAt, signature} revokes every API key of the account and refunds the balance to refundTo, by default the wallet itself. The refund is paid from the credit vault shortly after. Deposit fees are not refunded. With the CLI: envolvr close --yes.
Models and providers
GET https://api.envolvr.xyz/v1/models lists every model with its per-token prices and routes. At launch:
| Model | Provider | Input / output per 1M tokens |
|---|---|---|
z-ai/glm-5.3 | Phala (RedPill) | $1.40 / $4.40 |
z-ai/glm-5.3-flash | NEAR AI, enclave-signed | $0.15 / $0.50 |
qwen/qwen3.8-27b | Chutes, end-to-end encrypted; Phala (RedPill) or NEAR AI on request | $0.24 / $2.20 (RedPill: $0.24 / $2.50, NEAR: $0.44 / $3.30) |
qwen/qwen3.6-35b-a3b | NEAR AI, enclave-signed | $0.17 / $1.10 |
deepseek/deepseek-v4-flash | Chutes, end-to-end encrypted | $0.44 / $1.32 |
deepseek/deepseek-v3.2 | Chutes, end-to-end encrypted | $1.00 / $1.00 |
moonshotai/kimi-k2.6 | Chutes, end-to-end encrypted | $0.50 / $2.85 |
Choose providers per request with an OpenRouter-style block: "provider": {"only": ["near-ai"]}, or {"order": ["redpill", "near-ai"], "allow_fallbacks": true}. Provider names are redpill, near-ai and chutes. A route marked opt-in in /v1/models is used only when you name it.
Chutes runs on Bittensor's open GPU network, where independent operators run the machines. envolvr verifies each machine on its own (Intel TDX quote, NVIDIA GPU attestation) and encrypts every request end to end to that machine's attested key, so neither Chutes nor the operator sees your prompt. Hardware limits are set out in the protocol spec.
API reference
| Endpoint | What |
|---|---|
POST api/v1/chat/completions | OpenAI chat completions, streaming or not. Header x-receipt-id names the receipt; usage.cost is the cost in USD. |
GET api/v1/models | Models, prices, routes. |
GET api/v1/aci/receipts/{id} | The signed receipt, with the same API key. Kept for an hour. |
GET api/v1/aci/sessions/{id} | The attested provider session a receipt cites. |
GET api/v1/aci/attestation?nonce= | The gateway's attestation report for a fresh 64-hex nonce. |
GET auth/auth/nonce, POST auth/auth/key | Wallet sign-in. |
GET auth/account | Balance (API key or session). |
GET auth/auth/session/nonce, POST auth/auth/session, POST auth/auth/session/end | A wallet-signed management session. |
GET/POST auth/account/keys, POST auth/account/keys/revoke | List, create and revoke API keys (session). |
GET auth/account/usage, GET auth/account/deposits | Requests with their cost, and deposits with their fee (session). |
GET auth/pricing | The current deposit fee. |
GET auth/receipts/{digest}/proof | A receipt's inclusion proof on Robinhood Chain (public). |
api is https://api.envolvr.xyz, auth is https://auth.envolvr.xyz. Both terminate TLS inside the attested VM.
Receipts
A receipt is a JSON document signed with an Ed25519 key that lives only inside the gateway's enclave and is listed in its attested keyset. Its event log records, in order:
| Event | Records |
|---|---|
request.received | SHA-256 of the exact request bytes: a commitment you can later open to an auditor. |
route.selected | The provider route that served it. |
upstream.verified | The attested provider session: TEE, GPU and OS claims, checked before forwarding. |
upstream.response_attested | NEAR routes, non-streamed: the model enclave's own signature over this request and response. |
billing.charged | Token counts, per-token rates, the exact cost, the amount billed, and a payer commitment. |
response.returned | SHA-256 of the exact response bytes you received. |
The payer commitment is sha256("billing.payer.v1:" + hex(sha256(api_key)) + ":" + receipt_id). It names no account and links no two receipts; you prove a receipt was charged to you by disclosing your key's hash, never the key.
Fetch receipts within the hour: the gateway keeps them for an hour. The SDK and the verifying proxy do it for you.
Verify
The gateway
npx private-ai-proxy verify https://api.envolvr.xyz --require-production-os
Checks the TDX quote to Intel's root, that the keyset and your nonce are bound into it, that the measured compose links to the public source commit, the production OS image, and that your TLS connection ends at the attested key. Pin a compose hash with --accept-compose.
A receipt
npx private-ai-proxy audit --report attestation.json --receipt receipt.json \
--request-body request.json --response-body response.json --session session.json --require-production-os
Checks the signature against the attested keyset and the request and response bytes against the receipt's commitments. envolvr verify runs this for you on a saved receipt.
The anchor
The digest is SHA-256 of the receipt's JCS (RFC 8785) bytes. Get its proof from https://auth.envolvr.xyz/receipts/{digest}/proof and ask the contract directly:
cast call <ReceiptAnchor> \
'verifyReceipt(bytes32,uint256,bytes32,bytes32[])(bool)' \
0x86b99987cd8f8ebddc2dd0efa61ed52b5db594430f12446db424da0d9c4b831f <batchIndex> <digest> '[<proof>]' \
--rpc-url https://rpc.mainnet.chain.robinhood.com
Receipts are anchored in fixed 10-minute slots (UTC): a slot's receipts become one Merkle root, anchored seconds after the slot ends by a key that only the attested gateway VM can derive. The chain sees the slot, never when in it your request ran.
Pricing
- Tokens are priced at the providers' own list prices.
/v1/modelshas them; every response carries itsusage.cost. - Deposits: a fee of 5% is kept from each USDG deposit.
GET /pricingalways has the current rate. - Billing is the exact cost rounded up to the next micro-USD, and every receipt records the tokens, rates and amount, so any charge can be recomputed.
- If one request allows several providers, it is priced at the highest of their list prices.
Network and contracts
| Robinhood Chain (chain id 4663) | |
|---|---|
| RPC | https://rpc.mainnet.chain.robinhood.com |
| Explorer | https://robinhoodchain.blockscout.com |
| USDG | Published at launch |
| CreditVault | Published at launch |
| NVLR | Published at launch |
| ReceiptAnchor | Published at launch |
| Gateway provider id | 0x86b99987cd8f8ebddc2dd0efa61ed52b5db594430f12446db424da0d9c4b831f |
Source: envolvr/envolvr (contracts, control plane, SDK, deployment compose) and envolvr/private-ai-gateway (the gateway).
Good to know
- NVLR and its buyback and burn are explained on the token page.
- Receipts are kept at the gateway for an hour; anchoring proofs are kept for good.
- A proof is available within about 10 minutes, once the receipt's slot has closed.
- Every wallet is screened against sanctions lists at sign-in and on deposit.
- The gateway never logs prompts, responses, keys or wallets.