Start here

↑ ↓ to choose · Enter to open · Esc to close

ANYROUTE NETWORK · WE’RE GAUGING INTEREST

Private AI needs
private hardware.
Yours counts.

The AnyRoute Network is coming: confidential hardware, owned by anyone, serving private AI and paid per token served. Hosting isn’t open yet. Join the waitlist and check your hardware now.

NETWORK STATISTICS
No data yet

Network hosts

No data yet

Hosts with proven hardware

No data yet

Models on admitted hosts

No data yet

Waitlist interest

No data yet

Public-lane tokens · 7 days

No data yet

Public-lane tokens · 30 days

No data yetUSDG

Total indexed bonds

No data yetUSDG

Active indexed bonds

No data yet. Network statistics appear when available.

Attested hosts require fresh successful attestation and admission evidence. Capacity counts distinct eligible models, not throughput. Token ranges cover retained public-lane records in 100,000-token buckets; this is not differential privacy. Private-lane host totals are unavailable: existing DP counters at /api/v1/stats cover the router as a whole. Waitlist entries express interest, not admission. Definitions and limits.

THE PLAN

Your hardware proves what it runs.

No KYC. No contracts. The machine would prove itself. This describes the proposed program; hosting and payouts are not available.

  1. STEP 1

    Join with one command

    When onboarding opens, an installer would connect your machine.

  2. STEP 2

    Prove the hardware

    Attestation would check the enclave and the measured software before traffic is accepted.

  3. STEP 3

    Serve private traffic

    The enclave would run the model. AnyRoute’s router still reads requests in memory.

  4. STEP 4

    Paid per token served

    The plan is USDG payouts for tokens served, claimable on-chain.

CURRENT SERVING

There’s already a foundation.

AnyRoute’s attested lane already serves 23 open models inside hardware enclaves, with a signed receipt for each call. See the serving protocol and current status.

Public host measurements and Sigstore records let you inspect what is measured. Receipt roots and anchors make served work checkable where anchoring is switched on. Verify a provider and its evidence.

A one-command installer exists in the open-source repository. It does not admit outside hosts to a network today. Tor onion access with blind tokens separates token issuance from spending; those protections depend on the transport and lane you use. Read the conditions and limits.

AnyRoute’s router still reads requests in memory; the enclave runs the model. Receipts store hashes, token counts and cost, not prompt text. See the full inventory of what we keep.

Bonds

Host bonds are indexed live from HostBond on Robinhood Chain at 0x2921d34fd86d3323a5369a270a82814a74250518. The minimum is 5,000 USDG. Read the indexed state at GET /api/v1/network/bonds or on Hosts.

Payouts, fee buy-and-burn and slashing are not switched on at anyroute.tech yet. No payouts are being made. A bond is a work deposit; it promises no payment. Read the bond rules and limits.

Bring the hardware. Or the demand.

  • Confidential GPU owners and fleet operators: NVIDIA H100, H200 or B200-class servers with GPU confidential-computing support on Intel TDX or AMD SEV-SNP hosts.
  • Confidential cloud users: rented TDX or SEV-SNP machines with spare capacity. Renting solely to host may not cover your costs.
  • Small-server owners: TDX or SEV-SNP CPU servers for small models.
  • Relay operators and witnesses: record your interest in supporting the proposed network.
  • Developers and agents: tell us you need more private inference capacity.
READ-ONLY · NO NETWORK CALLS

What can your machine do?

Download the checker, compare its SHA-256 with the value below, inspect it, then run it. It checks guest devices, host support hints and NVIDIA confidential-computing queries. It changes nothing and sends nothing. Kernel log permissions can limit the answer; sudo may reveal more, but the checker never asks for root.

curl -fsSLO https://anyroute.tech/network/check.sh && sha256sum check.sh && sh check.sh

The command prints the digest before running. Compare the downloaded file before running it; you can perform the three steps separately.

check.sh SHA-256
1ff1050a82f9a21d0ed4f6ab4b66c79f3c078bab66154c80a2bbed1de317c71e

Read or download check.sh

This is a hint. Real eligibility is proven by attestation when hosting opens. A capability mention or an enabled GPU mode is not proof of an eligible machine. Paste the summary into the form only if you choose.

WAITLIST

Tell us what you’d bring.

No names required. Contact details are optional. This form works on this site’s onion address using the same relative API path, with no third-party requests.

Describe hardware only. Please don’t paste prompts or other sensitive information. We keep a minute-specific keyed digest for rate limits; the owner can read your submitted fields. What we keep.

We keep only what you type here, to count interest and contact you if you asked us to. We don't store your IP address. We delete the list when the program launches or is cancelled.

Delete a sign-up
HOST REGISTRATION

When hosting opens

Hosting isn’t open yet. These commands are for when host registration opens; they do not admit a host while registration is closed.

Run the approved build. The published host policy (/api/v1/network/policy) admits one build today: Intel TDX in a dstack confidential VM (for example Phala Cloud) running the pinned sidecar, llama.cpp and Qwen2.5 0.5B. The exact recipe is open source: deploy/network/approved/tdx-qwen2.5-0.5b. Other builds, including ones made with the general installer deploy/seal/install.sh, are refused with the reason until the policy lists them.

phala deploy -n my-anyroute-host -c docker-compose.yml -t tdx.small --wait

Then download join.mjs, compare its SHA-256 below and inspect it before running. Requires Node 22 or later. Replace the capitalized values with your host settings and model ids. Keep the operator private key and sidecar API key in separate files readable only by you. The sidecar must already hold the SHA-256 of the same API key in its auth.keys configuration.

node join.mjs --key-file /path/to/operator.key --api-key-file /path/to/sidecar.key --name HOST_NAME --endpoint https://SIDECAR --payout-address 0xPAYOUT_ADDRESS --models MODEL_ID

Use a dedicated operator wallet, not a wallet holding funds. The command signs wallet-auth messages, submits your host details, then supplies the sidecar credential to the router. It sends no transactions. --dry-run prints canonical signup and credential bodies without reading keys or sending requests; api_key is shown as <redacted> and the signup-assigned provider id as <provider_id>. --status PROVIDER_ID polls status five times; --help lists options.

Omit the API key source to register first, then use node join.mjs --credential-only PROVIDER_ID --key-file /path/to/operator.key --api-key-file /path/to/sidecar.key. --api-key-env NAME selects an environment variable instead. The trimmed API key must contain 16–500 characters; POSIX files must not be group or world readable. The router stores the credential encrypted and can decrypt it to call your sidecar.

join.mjs SHA-256
8fa1b8e07ee0927643b9f365586a33c553f66ff3272de8e51f5b02fed2cbd6db

Your signup details go to the router, including your operator wallet, endpoint, payout address, model ids and any contact you supply. AnyRoute’s router still reads inference requests in memory.

A few straight answers.

Do I need to do KYC?

The planned program has no KYC and no contracts. Your machine would prove itself through hardware attestation. When payouts exist, payout addresses would be screened against the public sanctions list.

What hardware do I need?

For GPU models: an NVIDIA H100, H200 or B200-class GPU that supports confidential-computing mode, on an Intel TDX or AMD SEV-SNP host. For small models, a TDX or SEV-SNP CPU server may be enough. The checker gives hints; attestation would establish eligibility.

How would I get paid?

Paid per token served, in USDG, claimable on-chain. This is a plan, not a live program. No amounts are promised. The form lets you record a payout preference.

Can I see the prompts my machine serves?

The planned design processes prompts inside the enclave, with attestation of the measured code intended to protect that memory from the host operator. This depends on the hardware, measured software and its policy. AnyRoute’s router still reads requests in memory; the enclave runs the model.

When does it launch?

There’s no date yet. We’re checking interest first, and your sign-up helps decide when host onboarding opens. Until then, outside hosts can’t join.

Can I join without leaving contact details?

Yes. Contact is optional. Keep your entry id and delete code to remove your entry at any time. We delete the list when the program launches or is cancelled.