Skip to main content

Compute

Covenant Compute rents GPUs by the second. You pay in USDC for the time a session runs, and whatever you held back for it and did not use comes back when it closes. Operators earn USDC for the same seconds and stake CVNT to take work. It runs on Solana mainnet.

How a session settles

  1. You open a lease with a rate, in micro-USDC per second, and a window. The ceiling, rate times window, moves from your balance into an escrow vault on Solana.
  2. While the machine runs, the session's meter lives in a MagicBlock ephemeral rollup (a short-lived Solana execution environment that writes back to mainnet). The coordinator ticks it with the elapsed time every five seconds, at no cost per tick.
  3. When you close the lease, the meter commits to Solana in one write and the vault pays the operator ceil(rate × elapsed_ms / 1000). The rest of the ceiling returns to your balance.

Elapsed time runs from the moment an operator accepts the lease. A lease no operator accepts, or whose machine never comes up, is refunded in full. A window can be at most 24 hours.

The first mainnet session held an NVIDIA L40S for 192,561 ms at 334 micro-USDC a second: 64,316 micro-USDC to the operator, 35,884 back to the renter.

Endpoints and addresses

WhatValue
Coordinator APIhttps://compute-api.opencovenant.org
Coordinator key3Z27s9cCPNWYg7y86PhGwHpEMV4crrY5vAwTwzQNbjjh
Settlement program3dTtXH7rah8YyWTsAfSg6qC3iqrJXWGEhAx57uUHXZff
Ephemeral rolluphttps://eu.magicblock.app, validator MEUGGrYPxKk17hCr7wpT6s8dtNokZj5U2L57vjYMS8e
PaymentsUSDC, EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
Operator stakeCVNT, 2mNVZ6aEjrGwiUVCfz7XGWpiXuWzgBDoznwE579upump

GET /federation/capacity on the coordinator lists what can be rented right now and at what price.

Install

The tools build from source with a Rust toolchain:

git clone --depth 1 --branch compute-v0.1.0 https://github.com/open-covenant/covenant
cd covenant/agent-os
cargo install --locked --path crates/covenant-compute-buyer
cargo install --locked --path crates/covenant-compute-node
cargo install --locked --path crates/covenant-compute-lease-signer --bin covenant-compute-stake

covenant-compute-buyer installs the covenant-compute command. Operators also need covenant-compute-node and covenant-compute-stake.

Rent a GPU

export COVENANT_COMPUTE_COORDINATOR_URL=https://compute-api.opencovenant.org
covenant-compute whoami      # your buyer key, kept in ~/.covenant-compute-mcp
covenant-compute balance     # funds, and where to send a top-up

To fund your balance, send USDC to the deposit address that balance prints, with the memo compute-buyer:<your buyer key>, then claim the transfer:

covenant-compute deposit <transaction-signature>

Open a lease and connect to it:

covenant-compute capacity
covenant-compute lease open --minutes 10 --rate 334 --ssh-key ~/.ssh/id_ed25519.pub
covenant-compute lease view <job-id>
covenant-compute lease close <job-id>

lease openwaits up to four minutes for the machine and prints its SSH address. The rate must meet an operator's ask, which capacity shows per lease hour. The whole ceiling must also fit under your per-call spend cap, COVENANT_COMPUTE_MAX_PRICE_MICRO_USDC, which defaults to $1: at 334 micro-USDC a second that is just under 50 minutes. Raise it for longer windows.

After a lease closes, covenant-compute verify <job-id> reads the payout back from Solana through your own RPC (--rpc-url). covenant-compute withdraw <micro-usdc> <wallet> moves unspent balance out; each withdrawal can move up to $100.

Run a node

A node is a machine, or a broker for one, that registers with the coordinator and serves leases or jobs. It is paid in USDC from each session's escrow, one payout per job.

covenant-compute-node setup     # coordinator URL and key, payout address, backend
covenant-compute-node           # register and serve
covenant-compute-node status    # why it is or is not winning work

The node README lists the executors a node can serve with and their settings.

Stake

The coordinator matches a node only while at least 1,000,000 CVNT is staked for its identity in the settlement program. The stake belongs to the wallet that signs it, and only that wallet can withdraw it, once its lock ends.

covenant-compute-stake stake <node> 1000000 --lock-days 30 --keypair <wallet.json> --rpc <mainnet RPC>
covenant-compute-stake status <node>
covenant-compute-stake unstake <node> --keypair <wallet.json>

The program requires a lock of at least seven days. The coordinator counts a stake while it stays locked for at least one more day plus the dispute window, two days today, so a node stops matching shortly before its stake unlocks. To stay matched, stake again from another wallet before then: positions are kept per node and wallet.

Slashing

A fault the coordinator proves itself costs 50,000 CVNT of the node's stake, sent to the protocol treasury. Two kinds of fault count: a known-answer test job answered wrong, and the losing side of a check where the same job is run again on other nodes. A buyer's dispute is recorded against the node's reputation and never moves stake. Leases are not tested this way, so a node that only serves leases is not slashed by these checks.

A node slashed below 1,000,000 CVNT stops matching until it is staked back up.