Whitepaper

How OffRouter lets an onchain agent think in private: where a request goes, who can see what along the way, how it is paid for, and how you can check all of it yourself.

The problem

An agent that manages money reasons out loud. Its prompts hold positions, counterparties, strategies and the questions it is unsure about. When that reasoning is sent to an ordinary inference API, three parties can read it: the company running the API, the company running the hardware, and anyone who later gets access to their logs.

The agent is also identified. A normal API account is tied to an email, a card and a billing history, so the reasoning is not only readable, it is attributable.

Onchain agents feel this most, because the rest of what they do is already public. Their transactions can be watched in real time. If their thinking can be read as well, there is nothing left that is theirs.

Design goals

OffRouter is built around four rules.

  • Private by default. Every model runs inside a hardware enclave. There is no cheaper, non-private tier to fall back to, and a model that cannot be served privately is not served.
  • Nothing to leak later. Prompts and outputs are never written to storage, never cached and never logged. The only record of a call is its token counts and its price.
  • A wallet is the only identity. No email, no card, no approval step. An agent that holds a stablecoin can make its first call with nothing else.
  • Check it, do not trust it. Each response carries a receipt signed inside the enclave, and a link to the hardware attestation that proves which key did the signing.

The request path

A call passes through two machines. The gateway prices it, takes payment and forwards it. The enclave runs the model. They are operated by different parties, and neither holds everything.

YouAgentSends an ordinary OpenAI-style request with a key, or with a signed payment.
request over TLS
StatelessOffRouter gatewayPrices the call, settles payment, forwards it. Keeps token counts only.
forwarded over TLS
SealedGPU enclaveRuns the model in memory that the host machine cannot read. Signs a receipt for the response.

The way back

AgentGets the completion, the exact charge, and three headers that point to the proof.
response and receipt id
OffRouter gatewayStreams the answer through, books the real token count, releases any unused hold.
completion and signed receipt
GPU enclaveReturns the answer with a receipt signed by a key that exists only inside it.
The enclave is a confidential virtual machine with a confidential GPU attached. Its memory is encrypted by the processor, so the company that owns the server, and anyone with access to it, sees only ciphertext.

The gateway holds no model and the enclave holds no billing. The gateway never learns anything from the enclave beyond the response it passes back, and the enclave never learns who paid.

Who sees what

Privacy claims are only useful when they say who is kept out of what. This is the full picture for one call.

PartyYour walletWhat you paidYour promptThe answer
Anyone watching the chainYesYesNoNo
Payment facilitatorYesYesNoNo
OffRouter gatewayYesYesIn memory, not storedIn memory, not stored
Enclave host operatorNoNoNoNo
The model, inside the enclaveNoNoYesYes
The two amber cells are the honest limit of the system today. They are covered under Limits and next steps.

What the gateway keeps after a call is a single row: the time, the model, how many tokens went in and out, the charge, and which key or wallet paid. That row is what your dashboard is built from. There is no column for content.

Paying without an account

Payment uses x402, an open standard built on the HTTP 402 status code. The buyer signs a stablecoin transfer for an exact amount, and never needs a gas token. OffRouter quotes the same price on Base, Robinhood Chain and Arc, each in its own dollar stablecoin.

There are two ways to pay. Both reach the same models at the same price.

Prepaid key, for anything built on an OpenAI SDK

Sign onceOne signature funds a key from your wallet.
per call
Hold the worst caseFull input plus the output budget is held against the balance.
serve
Run in the enclaveThe model answers.
settle
Charge the real countThe hold drops to the exact token cost. The rest returns to the key.

Pay per call, for agents that hold their own wallet

AskThe agent sends the request with no key.
402 with a price
Sign the ceilingIt signs a transfer for the most the call could cost.
settle first
Run in the enclaveServed only after the payment has settled.
refund
Return the unused partThe difference goes back to the paying wallet on the same network.
The ceiling is a provable upper bound, not an estimate. Input is bounded by the size of the request in bytes, since no tokenizer can produce more tokens than bytes, and output is bounded by the budget the caller sets.

Two properties follow from this design. A key can never spend more than it holds, even with many calls in flight, because the hold and the balance check are one atomic step. And a call is never served on credit: money settles before the model runs.

A prepaid key also leaves the smaller onchain trail. One deposit covers many calls, where pay per call writes a payment and often a refund for each one.

Verifying a response

You do not have to take any of this on trust. Every response names its own evidence in three headers, and the check needs no key and no cooperation from us.

Read the headersReceipt id, receipt URL and attestation URL arrive with the response.
fetch
Get the receiptHashes of the request and response, timestamps and a signature. No content.
fetch
Get the attestationA report signed by the hardware itself, stating what is running and which key it holds.
compare
Match the keyThe receipt must be signed by the key the attestation names.
The signing key is created inside the enclave and never leaves it. The gateway cannot produce a valid receipt, so it cannot quietly route your call anywhere else.

Limits and next steps

Three things are not private today, and we would rather say so than have you find out.

  • The gateway sees a request while forwarding it. It is held in memory for the length of the call and never stored, but it is readable there. The planned fix is for the agent to encrypt its request to the enclave's attested key, so the gateway forwards ciphertext it cannot open.
  • Payments are public. A deposit or a per-call payment is an onchain transfer from your wallet to ours. It shows that a wallet uses OffRouter and how much it spends, never what it asked. Prepaid keys keep that trail short.
  • The ledger links a wallet to its usage. We know which wallet paid for which calls, by token count and time. We are studying ways to break that link, so that even the gateway cannot connect a payment to a request.

What is already true does not depend on those steps: the machine that runs the model cannot be read by the people who own it, nothing you send is kept, and every answer comes with proof of where it was produced.

Get an API key