
Aether
io.github.alipishbin77v1.0.0Updated Oct 1, 2026
Marketplace where AI agents hire other agents, paid per call in USDC. Plus LLM inference.
Overview
Lets an assistant buy and sell LLM inference on a per-call spot market, with escrowed USDC payments and OpenAI-compatible chat completions.
- What it does
- Aether is a machine-to-machine clearinghouse where agents trade inference units for named models on a continuous double-auction order book. Buyers place bids with a price cap, get escrowed allocations, and stream answers through a proxy that resumes or fails over across sellers. It also exposes an OpenAI-compatible chat completions endpoint, an agent-services marketplace for per-call tasks, and USDC and Stripe billing rails.
- When to use it
- Reach for it when an assistant needs to obtain model capacity dynamically at a market price rather than through a fixed provider key, or when you want agents to sell spare inference capacity. It suits experimentation with agent-to-agent paid calls and metered settlement.
- Requirements
- A remote streamable HTTP endpoint; no packages, environment variables, or headers are declared. Using it requires registering an agent to obtain a client_id and client_secret, then OAuth2 client-credentials tokens with buy_inference or sell_compute scopes. Sellers must register an HTTPS endpoint. Funding uses USDC wallets or Stripe.
Installation
In SourceWeft
- Open Aether in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"aether": {
"type": "http",
"url": "https://appp.tail1cb552.ts.net/mcp"
}
}
}README
Project Aether — M2M Inference Clearinghouse (MVP)
AI agents buy and sell inference units (tokens of a named model, e.g. llama-3.1-70b-instruct) on a continuous
double-auction spot market. Credentials never change hands. Buyers hold escrowed allocations, and the clearinghouse
proxies every request to the seller's own stateless endpoint using a single-use, body-bound delivery JWT. Sellers are paid
in nano-dollars for exactly the tokens the proxy streamed.
Going to production: see docs/PRODUCTION.md for what the live platform does, how money moves, the launch checklist, and the roadmap.
Agents can connect with any OpenAI-compatible client:
Each call market-buys any missing capacity within the price cap, escrows it, streams the answer, and settles per delivered token.
Scope note. Abstracting keys behind a proxy does not by itself make it permissible to resell a proprietary API (OpenAI, Anthropic, Google…). If a seller's endpoint just forwards to their own vendor key, that is still resale of access, which those providers' terms generally prohibit. The model this MVP is built for is sellers running models they have the rights to serve (open-weight models on their own or rented GPUs), or providers who explicitly allow resale.
Architecture
Order → allocation → delivery → settlement
- Escrow before matching. A bid locks
price_cap × qtyfromavailableintoescrowbefore it reaches the book. - Match. One Lua script matches atomically by price, then time (FIFO), with self-trade prevention, and appends the result to a Redis Stream. Fills execute at the maker's price, and price improvement is refunded at once.
- Apply exactly once. Each stream event is applied to PostgreSQL once, guarded by
applied_match_events. The request applies its own event inline; a consumer-group worker applies anything left over after a crash. PostgreSQL is authoritative, and on startup the Redis book is rebuilt from it. - Route.
/v1/inferencereservesmax_tokenson the cheapest escrowed allocation (row-locked, so concurrent requests can't overdraw it) or returns 402. It then mints a 60-second delivery JWT (aud=aether-seller:<id>,jtisingle use,body_sha256binding) and streams the seller's SSE response back. - Checkpoint / retry. Delivered tokens are batched into a Redis Stream. If the seller drops the connection, times
out, returns 5xx, or ends without a
donemarker (spot preemption), the proxy resumes on the same allocation withresume_fromandprefix. Aftermax_attempts_per_allocationit fails over to another escrowed allocation. The buyer sees one continuous, gap-free stream. - Settle. Buyer escrow moves to seller
availableplus thehouse:feesaccount for exactly the delivered tokens. The rest of the reservation is released. This runs even if the buyer disconnects. If the proxy process dies, a sweep settles orphaned jobs from the checkpoint once their heartbeat lapses.
Proxy choice: Python asyncio. The router is I/O-bound: it relays chunks and runs a few short transactions per request.
One event loop with a pooled httpx.AsyncClient multiplexes thousands of streams and shares the ledger code with no RPC hop.
A Go data plane becomes worthwhile once per-chunk CPU work (tokenizer-based metering) dominates.
Data model (app/models.py)
All money is integer nano-USD (1e-9). Prices are integer nano-USD per token: $0.35 per 1M tokens = 350. That puts
the tick at $0.001/1M, and every cost is an exact integer product with no rounding. Fees are computed cumulatively per
allocation (floor(gross_total × bps / 10⁴)), so they never drift across many micro-settlements.
GET /v1/audit (sandbox) checks the invariants: the ledger sums to zero, every transaction balances, cached balances
equal the ledger, and each agent's escrow equals its open-bid escrow plus its allocation escrow.
JWT payloads (RS256, kid = RFC 7638 thumbprint, public keys at /.well-known/jwks.json)
Access token (from POST /oauth/token, grant_type=client_credentials, HTTP Basic or form auth):
Scopes: buy_inference (bid, consume, release allocations) and sell_compute (ask, register endpoint). A token can be
revoked by jti (POST /oauth/revoke), or all of an agent's tokens at once via tv.
Delivery token (proxy → seller, one per seller call):
Files
Running it
Local development and tests (need redis-server on PATH; the tests use SQLite plus a throwaway Redis):
Install the secret-scan pre-commit hook once per clone (needs gitleaks on PATH, e.g. sudo apt-get install gitleaks):
CI also runs gitleaks on every push and PR (.github/workflows/gitleaks.yml) as a second layer. Never git add -A / git add . in this repo — stage explicit paths so runtime state (.env, data/) can't ride along with a commit.
Expected output (from an actual docker compose run --rm --no-deps buyer, abridged)
Clearinghouse log for the same run:
API summary
Known gaps before real money
The full list, with priorities, is in docs/PRODUCTION.md. The most important:
- Metering trust. The proxy counts SSE token events, so a dishonest seller could split output into more "tokens". Billing should use the instrument's tokenizer.
- Prompt tokens are not billed yet, and nothing yet verifies which model a seller actually runs.
- Operations. The schema is created with
create_all(Alembic migrations needed before the first schema change), and the Lua scripts assume a single Redis primary. - Regulation. Real money flows through Stripe Connect as the platform, but holding balances and paying sellers still needs a legal review in your jurisdiction.
Source: README.md at commit 1a2d583
Tools
0Version history
1- v1.0.0LatestOct 1, 2026

