dev.cocore.compute.provider
Schema Diff
+61 -1
Compatibility Analysis
Breaking Changes Detected
6 breaking changes, 14 non-breaking changes.
Breaking Changes (6)
- RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.attestationFault", src: "dev.cocore.compute.provider:body.attestationFault", tgt: "dev.cocore.compute.provider:body.attestationFault.code", kind: "prop", name: Some("code") }
- RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.attestationFault", src: "dev.cocore.compute.provider:body.attestationFault", tgt: "dev.cocore.compute.provider:body.attestationFault.at", kind: "prop", name: Some("at") }
- RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.attestationFault", src: "dev.cocore.compute.provider:body.attestationFault", tgt: "dev.cocore.compute.provider:body.attestationFault.message", kind: "prop", name: Some("message") }
- RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.advisorFault", src: "dev.cocore.compute.provider:body.advisorFault", tgt: "dev.cocore.compute.provider:body.advisorFault.message", kind: "prop", name: Some("message") }
- RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.advisorFault", src: "dev.cocore.compute.provider:body.advisorFault", tgt: "dev.cocore.compute.provider:body.advisorFault.observedAt", kind: "prop", name: Some("observedAt") }
- RequiredEdgeAdded RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.advisorFault", src: "dev.cocore.compute.provider:body.advisorFault", tgt: "dev.cocore.compute.provider:body.advisorFault.code", kind: "prop", name: Some("code") }
Non-Breaking Changes (14)
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault.code" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault.message" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault.observedAt" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault.at" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault.code" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault.message" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.shareLocation" }
- AddedVertex AddedVertex { vertex_id: "dev.cocore.compute.provider:body.toolCalls" }
- AddedEdge AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.advisorFault", kind: "prop", name: Some("advisorFault") }
- AddedEdge AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.attestationFault", kind: "prop", name: Some("attestationFault") }
- AddedEdge AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.shareLocation", kind: "prop", name: Some("shareLocation") }
- AddedEdge AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.toolCalls", kind: "prop", name: Some("toolCalls") }
Migration Guidance
Added Elements
AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault.code" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault.message" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.advisorFault.observedAt" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault.at" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault.code" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.attestationFault.message" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.shareLocation" }AddedVertex { vertex_id: "dev.cocore.compute.provider:body.toolCalls" }
Additional Notes
- Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.advisorFault", src: "dev.cocore.compute.provider:body.advisorFault", tgt: "dev.cocore.compute.provider:body.advisorFault.message", kind: "prop", name: Some("message") }
- Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.advisorFault", src: "dev.cocore.compute.provider:body.advisorFault", tgt: "dev.cocore.compute.provider:body.advisorFault.observedAt", kind: "prop", name: Some("observedAt") }
- Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.advisorFault", src: "dev.cocore.compute.provider:body.advisorFault", tgt: "dev.cocore.compute.provider:body.advisorFault.code", kind: "prop", name: Some("code") }
- Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.attestationFault", src: "dev.cocore.compute.provider:body.attestationFault", tgt: "dev.cocore.compute.provider:body.attestationFault.code", kind: "prop", name: Some("code") }
- Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.attestationFault", src: "dev.cocore.compute.provider:body.attestationFault", tgt: "dev.cocore.compute.provider:body.attestationFault.at", kind: "prop", name: Some("at") }
- Breaking: RequiredEdgeAdded { vertex_id: "dev.cocore.compute.provider:body.attestationFault", src: "dev.cocore.compute.provider:body.attestationFault", tgt: "dev.cocore.compute.provider:body.attestationFault.message", kind: "prop", name: Some("message") }
- Non-breaking: AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.advisorFault", kind: "prop", name: Some("advisorFault") }
- Non-breaking: AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.attestationFault", kind: "prop", name: Some("attestationFault") }
- Non-breaking: AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.shareLocation", kind: "prop", name: Some("shareLocation") }
- Non-breaking: AddedEdge { src: "dev.cocore.compute.provider:body", tgt: "dev.cocore.compute.provider:body.toolCalls", kind: "prop", name: Some("toolCalls") }
1
1
{
2
2
"id": "dev.cocore.compute.provider",
3
3
"defs": {
4
4
"main": {
5
5
"key": "tid",
6
6
"type": "record",
7
7
"record": {
8
8
"type": "object",
9
9
"required": [
10
10
"machineLabel",
11
11
"chip",
12
12
"ramGB",
13
13
"supportedModels",
14
14
"priceList",
15
15
"encryptionPubKey",
16
16
"attestationPubKey",
17
17
"trustLevel",
18
18
"createdAt"
19
19
],
20
20
"properties": {
21
21
"os": {
22
22
"type": "string",
23
23
"maxLength": 64,
24
24
"description": "Operating system + version, e.g. 'macOS 14.5.1'. Helpful for capability-based matchmaking (e.g. CoreML / MLX feature support)."
25
25
},
26
26
"chip": {
27
27
"type": "string",
28
28
"maxLength": 64,
29
29
"description": "Hardware identifier, e.g. 'Apple M3 Max'."
30
30
},
31
31
"tier": {
32
32
"ref": "dev.cocore.compute.defs#tier",
33
33
"type": "ref",
34
34
"description": "The highest confidentiality tier this machine can serve, advertised so requesters and matchmakers can pre-filter. ADVISORY: a requester demanding `attested-confidential` MUST still verify the per-job attestation + session handshake and fail closed; this field only avoids routing confidential jobs to machines that cannot serve them. A machine earns `attested-confidential` here only when it runs the measured native engine under a hardware-attested posture. This is the AGENT-published ACHIEVED tier, derived from evidence (never self-declared); see `desiredTier` for the owner's intent. Optional / additive; absent equivalent to `best-effort`."
35
35
},
36
36
"ramGB": {
37
37
"type": "integer",
38
38
"minimum": 1
39
39
},
40
40
"active": {
41
41
"type": "boolean",
42
42
"default": true,
43
43
"description": "Soft delete: false means the machine is retired and should not be matched."
44
44
},
45
45
"eCores": {
46
46
"type": "integer",
47
47
"minimum": 0,
48
48
"description": "Apple Silicon efficiency-core count, when applicable."
49
49
},
50
50
"pCores": {
51
51
"type": "integer",
52
52
"minimum": 0,
53
53
"description": "Apple Silicon performance-core count, when applicable."
54
54
},
55
55
"region": {
56
56
"type": "string",
57
57
"maxLength": 2,
58
58
"minLength": 2,
59
-
"description": "Coarse, opt-in country of this machine as an ISO 3166-1 alpha-2 code (e.g. 'US'). AGENT-published and ADVISORY: a self-asserted claim derived from a best-effort public-IP geolocation at serve start, NOT a proof of location — a VPN or proxy moves it, and Apple exposes no signed-location primitive — so a verifier MUST treat it as unverified and MUST NOT gate anything security-relevant on it (same trust posture as `tier`). Present only when the machine's owner has opted into location sharing from the tray; the agent re-resolves it on every serve (refresh-on-serve) and OMITS it when sharing is off, so opting out drops the value on the next re-publish. Optional / additive; absent ≡ location not shared. A future revision may add finer fields (e.g. integer-rounded lat/lon) additively if needed."
59
+
"description": "Coarse, opt-in country of this machine as an ISO 3166-1 alpha-2 code (e.g. 'US'). AGENT-published and ADVISORY: a self-asserted claim derived from a best-effort public-IP geolocation at serve start, NOT a proof of location — a VPN or proxy moves it, and Apple exposes no signed-location primitive — so a verifier MUST treat it as unverified and MUST NOT gate anything security-relevant on it (same trust posture as `tier`). Present only when the machine's owner has opted into location sharing by setting `shareLocation` (from the console); the agent re-resolves it on every serve (refresh-on-serve) and OMITS it when sharing is off, so opting out drops the value on the next re-publish. Optional / additive; absent ≡ location not shared. A future revision may add finer fields (e.g. integer-rounded lat/lon) additively if needed."
60
60
},
61
61
"proBono": {
62
62
"ref": "#proBonoPolicy",
63
63
"type": "ref",
64
64
"description": "The owner's pro-bono election for this machine: it serves matching jobs for free — no tokens metered, no exchange cut taken. Owner-written INTENT (set from the console / tray), like `desiredModels`/`active`: the agent reconciles toward it (it serves a matching job pro bono by writing a receipt with `proBono: true`, `price.amount: 0`, and `tokens: { in: 0, out: 0 }`) but NEVER authors it, so it must PRESERVE whatever it finds on every re-publish. Absent ≡ off: the machine meters and bills every job exactly as before. Pro bono is purely ADDITIVE — a requester that does not match the policy is still served as a normal paid job, so opting in never costs the machine paid work. This is the carve-out for explicitly unlimited usage: a matched requester is never metered or charged, and a requester with no balance is admissible against a machine offering them pro bono. Optional / additive; pre-2026-06 agents ignore it."
65
65
},
66
66
"serving": {
67
67
"type": "boolean",
68
68
"description": "Liveness flag. The agent sets this true while its serve loop is up, and publishes false on graceful shutdown (it receives SIGTERM when quit/paused/bounced or its schedule window closes), so consumers can show the machine as 'offline' the moment it stops serving rather than leaving it looking idle. Absence means unknown — treat as NOT offline for backward-compat with pre-2026-06 records that never set it. (An ungraceful stop — crash / power loss — can't publish false; a future lastSeenAt heartbeat will cover that case.)"
69
69
},
70
70
"cpuCores": {
71
71
"type": "integer",
72
72
"minimum": 1,
73
73
"description": "Total CPU core count (logical = physical for Apple Silicon)."
74
74
},
75
75
"gpuCores": {
76
76
"type": "integer",
77
77
"minimum": 0,
78
78
"description": "Reported GPU core count, when applicable."
79
79
},
80
80
"createdAt": {
81
81
"type": "string",
82
82
"format": "datetime"
83
83
},
84
84
"priceList": {
85
85
"type": "array",
86
86
"items": {
87
87
"ref": "dev.cocore.compute.defs#modelPrice",
88
88
"type": "ref"
89
89
},
90
90
"maxLength": 256,
91
91
"minLength": 1,
92
92
"description": "Per-model rates the provider advertises. INFORMATIONAL since 2026-05: the active `dev.cocore.compute.exchangePolicy.tokenRate` is canonical for any provider settling through that exchange — providers MUST price receipts at the exchange's tokenRate and SHOULD denormalize the same rate into every priceList entry so the on-PDS view is internally consistent. A future lexicon revision will introduce a per-receipt provider-set override (gated on the exchange's permission), at which point priceList becomes authoritative again. Held required for backward compat with pre-2026-05 readers."
93
93
},
94
+
"toolCalls": {
95
+
"type": "boolean",
96
+
"description": "The owner's opt-in to serving tool/function calls on this machine. Owner-written INTENT, set from a management UI (the console's per-machine settings), exactly like `desiredModels`/`desiredTier`/`proBono`/`shareLocation`: the agent reconciles toward it but NEVER authors it, so it must PRESERVE whatever it finds on every re-publish. When `true`, the agent starts each eligible engine with vLLM automatic tool-choice enabled and verifies real tool-call behavior with a forced-tool startup canary before advertising support (per-model, via the advisor `Register.toolCallModels`); a model that fails the canary is served exactly as before, just without tool calls. Eligibility is RESTRICTED to the curated 'top models' the provider knows a tool-call parser pairing for — models outside that set never attempt tool calling even when this is on, so turning it on can only ADD capability, never break existing serving. Absent ≡ off: no engine advertises tool calls and the machine behaves exactly as it does today. Optional / additive; pre-2026-07 agents ignore it.\nNote: an operator may still force the raw vLLM passthrough on any model via the `COCORE_ENABLE_TOOL_CALLS` env var; this field is the curated, UI-driven path that does not require a known global parser."
97
+
},
94
98
"trustLevel": {
95
99
"ref": "dev.cocore.compute.defs#trustLevel",
96
100
"type": "ref"
97
101
},
98
102
"desiredTier": {
99
103
"ref": "dev.cocore.compute.defs#tier",
100
104
"type": "ref",
101
105
"description": "The confidentiality tier the OWNER has opted this machine into, set from a management UI (the console / tray 'Upgrade security' action). Mirrors `desiredModels`: owner-written INTENT, the agent reconciles toward it (e.g. switches to the measured native engine and earns the hardware-attested posture). Setting `attested-confidential` NEVER fakes the achieved state — the agent only publishes the higher `tier`/`trustLevel` once it actually earns them, and a machine that can't (e.g. not a native build) stays best-effort with a surfaced reason. Absent / `best-effort` means the owner has not opted into confidential and the machine serves exactly as before — opting in is the only thing that changes anything. Owner-written, agent-preserved. Optional / additive; pre-0.9.19 agents ignore it."
102
106
},
103
107
"engineFault": {
104
108
"type": "object",
105
109
"required": [
106
110
"code",
107
111
"message",
108
112
"at"
109
113
],
110
114
"properties": {
111
115
"at": {
112
116
"type": "string",
113
117
"format": "datetime",
114
118
"description": "When the agent gave up and recorded the fault."
115
119
},
116
120
"code": {
117
121
"type": "string",
118
122
"maxLength": 64,
119
123
"description": "Machine-readable fault class: `model-load-failed` (the inference subprocess never became ready), `venv-missing` (the Python environment is absent or incomplete), or `no-home` (the agent could not locate its state directory)."
120
124
},
121
125
"models": {
122
126
"type": "array",
123
127
"items": {
124
128
"type": "string",
125
129
"maxLength": 256
126
130
},
127
131
"maxLength": 256,
128
132
"description": "The configured model identifiers that failed to load."
129
133
},
130
134
"message": {
131
135
"type": "string",
132
136
"maxLength": 600,
133
137
"description": "Human-readable, content-safe summary with remediation guidance. Never contains prompt or completion bytes (faults are recorded before any job is served)."
134
138
}
135
139
},
136
140
"description": "Present when the agent could not bring its configured inference engine online after exhausting its startup recovery attempts. The machine still appears (and may still serve the no-op `stub` engine), but it will NOT be routed real inference jobs because its `supportedModels` does not include the configured model. Consumers SHOULD surface this to the operator as a fault with remediation guidance. Absence means the engine loaded cleanly (the agent clears this field on every healthy serve). Additive / optional — pre-2026-06 readers ignore it."
137
141
},
142
+
"advisorFault": {
143
+
"type": "object",
144
+
"required": [
145
+
"code",
146
+
"message",
147
+
"observedAt"
148
+
],
149
+
"properties": {
150
+
"code": {
151
+
"type": "string",
152
+
"maxLength": 64,
153
+
"description": "Machine-readable fault class; see the field description for known values. Unknown codes MUST be treated as a generic advisor-unreachable fault."
154
+
},
155
+
"message": {
156
+
"type": "string",
157
+
"maxLength": 600,
158
+
"description": "Human-readable, content-safe summary with remediation guidance. Carries only the classified error kind — never raw error text, URLs, or credentials."
159
+
},
160
+
"observedAt": {
161
+
"type": "string",
162
+
"format": "datetime",
163
+
"description": "When the agent recorded the fault (RFC3339, UTC)."
164
+
}
165
+
},
166
+
"description": "Present when the agent cannot establish its WebSocket connection to its advisor (matchmaker) after repeated consecutive attempts. The machine may be perfectly healthy locally — engine loaded, records published, `serving: true` — yet completely absent from the network: no advisor registry entry, no jobs routed, and without this field the failure is invisible remotely (the record looks like a healthy idle machine, so operators misdiagnose it as an onboarding problem). Consumers SHOULD surface this as 'serving locally but cannot reach the network' with remediation guidance (VPN / firewall / WebSocket filtering). Known codes: `dns-failure`, `tls-failure`, `connect-timeout`, `connect-refused`, `upgrade-blocked` (plain HTTPS to the advisor works but the WebSocket upgrade cannot be established — a middlebox on the network is filtering WebSockets), `http-<status>` (the upgrade handshake got a non-101 HTTP answer), `closed-<code>` (the socket was closed with the given WebSocket close code), and `network-unreachable`; new codes may be added, and consumers MUST treat an unknown code as a generic advisor-unreachable fault. The agent publishes this through its record-write path over plain HTTPS — which is exactly the transport that still works in the failure this diagnoses — and clears the field on its next successful advisor registration, so presence reflects the current state, not a stale failure. Additive / optional — pre-2026-07 readers ignore it."
167
+
},
138
168
"machineLabel": {
139
169
"type": "string",
140
170
"maxLength": 128,
141
171
"description": "Human-readable name for this machine, e.g. 'MacBook Pro M3 Max #1'."
142
172
},
143
173
"provisioning": {
144
174
"type": "boolean",
145
175
"description": "True while the agent is still coming up — it publishes this record immediately on serve start (so the machine appears right away) but before its inference engine has finished loading. The agent re-publishes with this false (or absent) once the engine is ready and it has connected to its matchmaker. Consumers SHOULD show such a machine as 'provisioning' and SHOULD NOT route jobs to it. Absence is equivalent to false."
146
176
},
147
177
"regionSource": {
148
178
"type": "string",
149
179
"maxLength": 32,
150
180
"description": "How `region` was derived, e.g. 'ip-geo' (public-IP geolocation). Surfaces the provenance — and thus the trust ceiling — of the coarse location to consumers. Present iff `region` is present. Optional / additive."
151
181
},
152
182
"binaryVersion": {
153
183
"type": "string",
154
184
"maxLength": 64,
155
185
"description": "Version string of the agent binary that wrote this record (e.g. `0.3.4`). Stamped on every `cocore agent serve` startup, so the record reflects the freshest deploy. Operators / dashboards use this to spot machines that haven't been updated to a release with a known fix. Optional / additive — pre-2026-05 records won't carry it."
156
186
},
157
187
"desiredModels": {
158
188
"type": "array",
159
189
"items": {
160
190
"type": "string",
161
191
"maxLength": 256
162
192
},
163
193
"maxLength": 256,
164
194
"description": "Model identifiers the OWNER wants this machine to load, set from a management UI (e.g. the console's per-machine model picker). The agent reconciles toward it: on serve start it loads this set instead of its local default, and while running it restarts to reload when this set changes. Distinct from `supportedModels`, which is what actually loaded (a model that won't fit RAM stays in `desiredModels` but never appears in `supportedModels`). Owner-written, agent-preserved; absent means the agent uses its local config. Additive / optional — pre-2026-06 agents ignore it."
165
195
},
196
+
"shareLocation": {
197
+
"type": "boolean",
198
+
"description": "The owner's opt-in to publishing this machine's coarse country. Owner-written INTENT, set from a management UI (the console's per-machine settings), like `desiredModels`/`desiredTier`/`active`: the agent reconciles toward it but NEVER authors it, so it must PRESERVE whatever it finds on every re-publish. When `true`, the agent resolves this machine's country from a best-effort public-IP geolocation at serve start and stamps `region`/`regionSource`/`regionObservedAt`; when absent/`false` it omits those fields, so turning sharing off drops any previously-shared value on the next re-publish (opt-out clears the data). Absent ≡ not sharing. Optional / additive; pre-2026-06 agents ignore it."
199
+
},
166
200
"payoutsEnabled": {
167
201
"type": "boolean",
168
202
"description": "True iff the provider has completed payout onboarding with at least one exchange and that exchange has confirmed it can transfer funds to them. Matchmakers SHOULD filter paid jobs away from providers where this is false; self-loop jobs (requester == provider) and free-tier jobs are unaffected. Absence is equivalent to false. The exchange asserts this from its own side via the corresponding paymentAccount record; this field exists so consumers don't have to do a second lookup to know whether the provider can be paid."
169
203
},
170
204
"contactEndpoint": {
171
205
"type": "string",
172
206
"format": "uri",
173
207
"description": "URL of the advisor / matchmaking service this provider currently uses. Federable; may change without invalidating prior receipts."
174
208
},
175
209
"modelIdentifier": {
176
210
"type": "string",
177
211
"maxLength": 64,
178
212
"description": "Apple model code, e.g. 'Macmini9,1' or 'Mac15,3'. Stable across OS updates and useful for hardware-class matching."
179
213
},
180
214
"supportedModels": {
181
215
"type": "array",
182
216
"items": {
183
217
"type": "string",
184
218
"maxLength": 256
185
219
},
186
220
"maxLength": 256,
187
221
"minLength": 1,
188
222
"description": "Opaque model identifiers honored by this provider."
189
223
},
224
+
"attestationFault": {
225
+
"type": "object",
226
+
"required": [
227
+
"code",
228
+
"message",
229
+
"at"
230
+
],
231
+
"properties": {
232
+
"at": {
233
+
"type": "string",
234
+
"format": "datetime",
235
+
"description": "When the agent recorded the fault."
236
+
},
237
+
"code": {
238
+
"type": "string",
239
+
"maxLength": 64,
240
+
"description": "Machine-readable fault class: `attestation-publish-failed` (the record could not be written to the PDS) or `attestation-build-failed` (the signed record could not be assembled)."
241
+
},
242
+
"message": {
243
+
"type": "string",
244
+
"maxLength": 600,
245
+
"description": "Human-readable, content-safe summary with remediation guidance. Never contains prompt or completion bytes."
246
+
}
247
+
},
248
+
"description": "Present when the agent could not build or publish its `dev.cocore.compute.attestation` record. The machine still appears and may still answer inference, but it will NOT produce verifiable receipts (a receipt strong-refs an attestation; without a published one there is nothing to reference), so it stays effectively self-attested even when the hardware would support more. Consumers SHOULD surface this to the operator as a fault with remediation guidance — without it, a publish failure is invisible and the machine merely looks idle. Absence means the attestation published cleanly (the agent clears this field on every successful (re-)attestation). Additive / optional — pre-2026-06 readers ignore it."
249
+
},
190
250
"encryptionPubKey": {
191
251
"type": "string",
192
252
"maxLength": 128,
193
253
"description": "X25519 public key (base64) used to wrap requests to this provider."
194
254
},
195
255
"regionObservedAt": {
196
256
"type": "string",
197
257
"format": "datetime",
198
258
"description": "When `region` was observed during the current serve (RFC3339, UTC). Because the agent re-stamps on every serve, this doubles as a freshness signal for the coarse location. Present iff `region` is present. Optional / additive."
199
259
},
200
260
"acceptedExchanges": {
201
261
"type": "array",
202
262
"items": {
203
263
"type": "string",
204
264
"format": "did"
205
265
},
206
266
"maxLength": 64,
207
267
"description": "Exchange DIDs this provider will accept settlement from. Empty/absent means any exchange is acceptable."
208
268
},
209
269
"attestationPubKey": {
210
270
"type": "string",
211
271
"maxLength": 256,
212
272
"description": "P-256 public key (base64) bound to this machine's Secure Enclave. Used to verify attestation and receipt signatures. Doubles as the stable per-machine fingerprint: the SE keypair is generated once at first agent boot and survives reboots / re-pairs / OS updates, so two records with the same `attestationPubKey` describe the same physical machine. Agents reuse the rkey of any existing record with this same key (and delete duplicates) instead of creating a fresh provider record per `serve` invocation, so the on-PDS view stays one record per machine."
213
273
},
214
274
"memoryBandwidthGBs": {
215
275
"type": "integer",
216
276
"minimum": 0,
217
277
"description": "Reported memory bandwidth in GB/s, when applicable."
218
278
}
219
279
}
220
280
}
221
281
},
222
282
"proBonoPolicy": {
223
283
"type": "object",
224
284
"required": [
225
285
"mode"
226
286
],
227
287
"properties": {
228
288
"dids": {
229
289
"type": "array",
230
290
"items": {
231
291
"type": "string",
232
292
"format": "did"
233
293
},
234
294
"maxLength": 1024,
235
295
"description": "Requester DIDs this machine serves pro bono when `mode` is `direct` — the owner's explicit pro-bono relationships. Ignored when `mode` is `any` (everyone is already free). Empty/absent under `direct` means the machine currently serves no one pro bono (every job is paid), which is the safe default for a half-configured policy."
236
296
},
237
297
"mode": {
238
298
"type": "string",
239
299
"description": "`any`: serve every requester pro bono. `direct`: serve only the requesters in `dids` pro bono; all others are normal paid jobs.",
240
300
"knownValues": [
241
301
"any",
242
302
"direct"
243
303
]
244
304
}
245
305
},
246
306
"description": "How this machine holds itself out for pro-bono (free, unmetered, no-cut) work. `mode: any` opts the machine into pro bono for EVERY requester — held out for any pro-bono work. `mode: direct` restricts the carve-out to the requesters listed in `dids` — the owner's direct pro-bono relationships — and serves everyone else as a normal paid job. An absent policy (or an unknown `mode` a reader doesn't understand) means pro bono is off and the machine bills normally; readers MUST fail closed to paid rather than assume free."
247
307
}
248
308
},
249
309
"$type": "com.atproto.lexicon.schema",
250
310
"lexicon": 1,
251
311
"description": "A compute provider's public profile. One record per physical machine. The DID owning the record is the provider's billable identity; the same DID may own multiple provider records (one per machine)."
252
312
}