Skip to content
Tenzro
← All tutorials
Tutorial · Operate

Peer-first model fetch

Fetch model weights from whichever origin has them, peers first, and verify every file against the model's content-addressed manifest before it loads.

Intermediate10 min

Model weights on Tenzro Network 1 live in many places at once: on other Tenzro nodes, with storage providers, in the model creator's own release and on public model hubs. None of them has to be trusted. A model's identity is the hash of its manifest, so your node can take the bytes from whichever origin is fastest and check every file before loading it. This tutorial fetches a model peer-first, checks it, and makes your node an origin for the next fetcher.

Prerequisites

  • A running node (tenzro-node --roles ai --data-dir ./data).
  • The tenzro CLI pointed at it (the default is http://127.0.0.1:8545).

1. Check your node's data-plane endpoint

Every node runs a QUIC endpoint on the peer-to-peer data plane, used for blobs, model weights and expert shards.

bash
tenzro iroh info

Expected output shows the endpoint id and the protocols bound on it. Peers reach you directly when they can and through a relay when they cannot, so a machine behind NAT still takes part.

2. Fetch a model, peers first

bash
tenzro model download qwen3-4b --rpc http://127.0.0.1:8545

The node asks connected peers whether they already hold the model's blobs. If one does, the transfer runs peer to peer, and every chunk is verified against its BLAKE3 hash as it streams. If no peer holds it, the node falls back to the other origins.

Choose the origin explicitly when you need to:

bash
# verified network providers only
tenzro model download qwen3-4b --source network

# a public hub only
tenzro model download qwen3-4b --source huggingface

3. Verify against the hash record

Whatever the origin, the files must match the model's hash record before the node loads them. The record holds the BLAKE3 root of the manifest, the SHA-256 of every file and the per-file manifest. A mismatch refuses the load and names the file that failed.

bash
tenzro model get-hash qwen3-4b
tenzro model list-hashes

Because the root commits to every byte of every file, two nodes serving qwen3-4b with the same root are serving the same weights. Certifications and ratings for a model name this root, and when several independent observers report the same hashes from different origins, a caller can require that agreement before trusting the model. See Model provenance.

4. Become an origin

After a successful fetch, the node publishes the verified blobs into its local store. The next node that asks for the model can fetch it from you instead of a hub, and verifies your bytes exactly as you verified the first origin's. The network gets faster for a model the more it is used.

You can publish other artifacts the same way:

bash
tenzro iroh publish --file ./adapter.safetensors

5. Fetch by URI

Anything published this way is addressable by its hash, whichever origin supplied it:

bash
tenzro iroh fetch --uri tenzro://blob/<blake3-hex> --out ./adapter.safetensors

The same tenzro://blob/<hash> scheme is used for expert shards, training shards and receipts.

Next steps