Skip to content
Tenzro
Documentation menu
Consensus and ledger

Iroh data plane

The content-addressed QUIC data plane Tenzro Network 1 nodes use to move model weights, gradients, datasets, agent memory and media.

Tenzro Network 1 separates control from data. The peer-to-peer mesh (see Networking) carries small, reliable broadcasts: blocks, transactions, announcements. It is the wrong tool for shipping multi-gigabyte model weights, large training gradients or rendered video. Those move over the data plane, built on iroh: every payload is content-addressed by its BLAKE3 hash, sent over a single QUIC connection, and verified against that hash as it arrives.

A receiver never has to trust the sender. If the bytes do not hash to the address it asked for, it rejects them.

Tenzro URIs

Applications never see iroh directly. Payloads are named with tenzro:// URIs, and the node resolves them over whichever path is available:

URIPayload
tenzro://blob/<hash>Any content-addressed blob
tenzro://model/<id>@<hash>Model weights at a pinned hash
tenzro://gradient/<run>/<round>/<hash>A training gradient
tenzro://shard/<model>/<expert>An expert shard of a distributed model
tenzro://memory/<did>/<id>An archived agent memory
tenzro://receipt/<kind>/<hash>A settlement or inference receipt

A receiver does not need to know whether the bytes came over iroh or inline in a JSON-RPC response.

Using it

The CLI talks to your local node:

bash
# Show this node's endpoint id and the protocols it serves
tenzro iroh info

# Publish a file and get its tenzro:// URI
tenzro iroh publish --file ./adapter.safetensors

# Fetch by URI
tenzro iroh fetch --uri tenzro://blob/<hash> --out ./adapter.safetensors

The same operations are available over JSON-RPC as tenzro_iroh_publishBlob, tenzro_iroh_fetchBlob and tenzro_iroh_resolveTenzroUri, and tenzro_irohInfo reports the endpoint.

What runs over it

Model weights. When a node needs weights it asks connected peers first, then other origins, and verifies the result against the model's hash wherever it came from. Weights are stored across several origins, so no single host is a point of failure, and a node that fetches weights publishes them to its own store so later fetchers can pull from it. See Model provenance.

Distributed models. Mixture-of-experts models are split into per-expert blobs. Nodes each hold a subset, and the router sends expert batches to holders over their iroh endpoints. See Distributed MoE.

Training. Trainers publish gradients once; synchronising nodes pull them by hash. Dataset shards for public runs are addressed by hash too, and shards for confidential runs travel encrypted, with the signed manifest broadcast to participants. See Tenzro Train.

Data availability. Large receipts for settlement channels, inference and agent messages are stored as blobs, with only their hash kept on-chain. The hash is the locator and the integrity check.

Agent memory. When an agent archives a memory, the full record moves to the blob store and the agent keeps a pointer, so large memories stay queryable without bloating the hot tier. See Agent memory.

Storage and media. Content-addressed storage and generated images and video use the same store. See Decentralized storage.

A2A and MCP. Agent-to-agent and MCP sessions can run over the node's iroh endpoint as well as over HTTP, with the same handlers behind both.

Discovery

Each node's iroh endpoint has an endpoint id. The node publishes a signed address record for that id to a Pkarr relay, and its DID document lists the endpoint as a service, so a peer can go from a DID to a connectable endpoint and back.

Configuration

The endpoint is always on. These settings tune it:

toml
[iroh]
bind_addr = "0.0.0.0:9001"            # UDP; open this port in your firewall
external_addrs = ["203.0.113.10:9001"] # a routable address to publish; leave empty behind NAT
enable_docs = true                     # collaborative documents over the blob store

On the command line, --external-iroh-addr sets the published address and --pkarr-relay-url chooses the relay the node publishes to. Behind a NAT, leave the external address empty: iroh traverses NAT on its own and falls back to a relay when a direct path is not possible.