Tenzro Network 1
The full stack for the Machine Economy.
- Participants
- Humans
- Agents
- Machines
- Services
- Rails
- Settlement
- Consensus
- Hardware
- TPM 2.0
- Secure Enclave
- Passkeys
- TEEs
- GPUs
What changed, and why we rebuilt.
A stolen key is spent at machine speed
Agents now hold spending authority and act without a person in the loop. Keys have to live in hardware, and spending has to carry limits the network enforces.Signatures recorded today can be forged later
Long-lived agent credentials, bridges and payments cannot wait for the day quantum computers arrive. Finality has to be quantum-safe now.Trust in AI needs evidence
Who served this model, which weights, under which policy, certified by whom. Relying parties need to pick the issuers they trust and check the rest themselves.
Tenzro DAG Consensus (TDC)
Our post-quantum consensus protocol. Every validator proposes in parallel each round, so no single leader limits the network.
- A DAG design: every validator proposes in parallel each round, so throughput is not bound to one leader.
- Post-quantum from the wire up. Validators talk over channels keyed by X25519 and ML-KEM-768, with a handshake signed by each validator's hardware key using ML-DSA-65 and P-256.
- Finality certificates are signed with ML-DSA-65. Light clients, bridges and new nodes can carry them and check them, and they can be used to slash a validator that signs two conflicting checkpoints.
- Certificates are compressed with STARK proofs.
- Consensus uses no signature scheme that a quantum computer can break.
Keys that live in hardware
Every key is rooted in a TPM, a Secure Enclave or a passkey. There are no key files and no seed phrases.
- Every key is rooted in a TPM 2.0, a Secure Enclave or a passkey.
- Any TPM 2.0 machine can run a validator. Signing keys are derived from the hardware on demand, used in memory and wiped.
- Votes are signed with an in-memory session key that the hardware certifies once per epoch, so the hardware is never on the hot path.
- People sign in with passkeys. Their identity is derived from the passkey itself, and every passkey operation carries a post-quantum ML-DSA-65 signature alongside P-256.
- Add more devices, or guardians, so losing one device never means losing the account.
Trust and provenance
Certification and ratings for models and operators, issued by anyone. You choose which issuers you trust and check the rest yourself.
- Any party can certify or rate a model or an operator. Relying parties choose the issuers they trust.
- Operators publish signed policies, and are slashed only for provable breaches of their own policy.
- Model weights are stored across multiple origins and verified by hash.
- Compliance tiers come from trust credentials, not a central registry.
- Trusted execution environments provide evidence that a workload ran untouched, verified against each hardware vendor's attestation chain.
The Machine Economy
A compute price index in consensus, SLA-attested rentals and metered, per-use settlement, paid in TNZO or stablecoins.
- A compute price index committed to consensus, built from metered usage.
- Compute claims, and SLA attestation, with rental billing on the chain's verdict.
- Metered settlement by default: agents pay per use.
- Stablecoin payments on Bridge.xyz wallets, x402 and MPP, including gas paid in stablecoins through the same rails.
- An ACP buyer side, so agents can purchase through agent-commerce flows.
Inference for any model
Prefix and state reuse for every architecture class, behind OpenAI-compatible APIs for chat, embeddings, images, audio and video.
- Prefix and state reuse for every architecture class: dense, sliding-window, hybrid recurrent and state-space, mixture-of-experts, multimodal and media models.
- OpenAI-compatible APIs for chat, embeddings, images, audio and video.
- Requests route to providers you can filter by trust, price and location.
Training for agents
Decentralised training with a chat fine-tuning objective for agent trajectories. Every round can be replayed from its seed.
- Decentralised training across operators and clusters.
- A chat fine-tuning objective built for agent trajectories.
- Every training round can be replayed from its seed, so contributions can be checked.
Closed by default
Open, owner and admin methods are separate. Anything that moves money or changes state needs a signature from the account that pays.
- The RPC surface is split into open, owner and admin methods.
- Anything that moves money or changes state requires a signature from the account that pays.
- Hosted functions and skills run deny-by-default, and databases are isolated per tenant.
Every participant, one network.
Operators
Validators, RPC, AI, compute, storage, security and training providers.Learn moreDevelopers
Build AI applications on open models, identity and payments.Learn moreAgents and machines
Hold their own identities and wallets, within limits people set.Learn morePartners
Integration, technical support and go-to-market partners.Learn more
Join Tenzro Network 1.
- OperatorRun a nodePut a GPU, a homelab or a data centre on the network and get paid in TNZO for the work it serves.Apply
- DeveloperBuild on the networkOpen models, OpenAI-compatible APIs, identity and payments in one stack, priced by an open market.Apply
- ResearcherTrain and experimentRun training across distributed clusters, with every round replayable from its seed.Apply
- PartnerPartner with TenzroIntegration, technical support and go-to-market partners who bring operators and builders onto the network.Apply