Gloam

io.github.cryptoduke01v1.1.0更新於 Oct 6, 2026

Private stablecoin payments for people and AI agents, hosted or local with spending limits.

已驗證Streamable HTTP可網頁執行AI & MLFinanceSecurity & Monitoring

概覽

AI 產生的概覽

Gloam 讓助手在測試網上規劃,並在持有本機金鑰時執行隱私穩定幣支付與屏蔽餘額操作。

功能
Gloam 是隱私鏈上支付系統的代理介面。託管伺服器 gloam.trade/mcp 僅供讀取與規劃:回報網路與資產、金庫統計、付款請求連結、證明檢查、存款計畫與付款操作說明。本機 npm 伺服器還能簽署並提交隱私轉帳、提領與 x402 工具付款,並提供代理支出上限與支出報告。備註金鑰保存在加密儲存中,代理只看得到代號。
適用情境
當助手需要在支援的測試網上發起或規劃隱私穩定幣付款、為 HTTP 402 工具付費,或查詢屏蔽餘額與證明時,值得加入。只做唯讀檢視時用託管端點;只有助手確實需要在擁有者設定的上限內簽署並支出時,才安裝本機伺服器。
執行需求
使用 gloam.trade/mcp 遠端端點(無需安裝),或以 npx 執行本機 npm 套件。簽署需要密鑰 GLOAM_AGENT_PRIVATE_KEY,可選搭配 GLOAM_TEMPO_ACCOUNT 使用受鏈上上限約束的 Tempo 存取金鑰;備註儲存由密鑰 GLOAM_NOTE_KEY 加密。需要連線至支援的測試網。沒有代理金鑰時工具只能讀取與規劃。
安裝前請注意
代理金鑰 GLOAM_AGENT_PRIVATE_KEY 授權真實資金流動,應視為支出憑證,並依賴擁有者設定的單筆、每日、收款方與到期上限;沒有上限就不能支出。GLOAM_NOTE_KEY 保護加密的備註儲存。本機伺服器可以簽署並提交付款、提領與 x402 付款,會實際轉移資金。目前僅限測試網,主網在產品內被封鎖,可信設定仍是開發儀式。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Gloam,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "gloam": {
      "type": "http",
      "url": "https://www.gloam.trade/mcp"
    }
  }
}

README

Gloam

The privacy layer for onchain finance. Shielded balances, private payments, and verifiable disclosure that any app or agent can plug into.

gloam.trade · Testnet app · Verify a disclosure · Docs · Whitepaper · @gloamtrade

Robinhood Chain 46630 · Tempo 42431 · testnet only, real ZK proofs, no mock fills


Public chains put finance on public rails: every holding, every size, every move is visible. Robinhood Chain does it for tokenized stocks and crypto; Tempo does it for stablecoin payments. Gloam is the sealed chamber on top. Shield a balance, pay privately, and later prove exactly what you choose to a counterparty or auditor, and nothing else. It is not a dark theme on a public DEX; it is a private-execution primitive that other onchain apps and AI agents build on — live today on Robinhood Chain (flagship) and Tempo.

Three surfaces, one private core

The vault app is the reference implementation, not the whole product.

SurfaceWhat it isPackage
SDKDrop shielded balances, private sends, and selective disclosure into any onchain app or agent, on Robinhood Chain or Tempo. Unsigned intents + client proving.@gloamtrade/sdk
AgentsAn MCP server + a reference wrapper so an AI agent can shield, move value, and pay for tools privately over x402, under policy.@gloamtrade/mcp · examples/agent-shield
VaultThe live testnet app that proves the whole path works.app/
Partner APIApps add private payments with an API key, set their own fee (flat per private payment, a share of cash outs and deposits), and see attributed volume and would-be fees live in the partner portal. Testnet: nothing is charged; real fees need a fee output in the circuits, part of the mainnet ceremony./partners · /docs/partners · GloamApiClient

All three share one core: a Poseidon note scheme, a depth-20 incremental Merkle tree, circom witness builders, real Groth16 verification, and one canonical intent shape.

What works today (testnet, real ZK proofs)

PathStatusWhat you can do
ShieldLive, proof-gatedDeposit ETH, USDG (Paxos Global Dollar) + faucet stock tokens on Robinhood Chain, PathUSD and other stablecoins on Tempo; the hardened pool enforces shieldBound() so a deposit proves commitment == Poseidon(secret, amount, asset) (audit C1)
Private sendLiveSend inside the vault to a receive tag; an on-chain encrypted memo inbox (GloamPayMemo) for discovery, with the sender no longer revealed
Private payrollLiveUpload a CSV and pay a whole team at once in USDG (Robinhood Chain) or PathUSD (Tempo). Gloam-address payees are paid directly and notified on-chain; everyone else gets a claim link. Crash-safe resume, results export. Docs
Scheduled payrollLiveSave a pay list as a schedule (monthly, every two weeks, weekly or one time) with a cap per run and an end date. A "Payroll due" reminder runs it in one click. Runs happen in your browser because only you hold the keys; schedules are encrypted at rest
Payment requestsLiveShare a link or QR that opens Pay with your Gloam address, amount, asset and reference filled in. The details sit after the #, so they never reach a server and nothing about the request goes on-chain
Gloam relayLiveSubmits proven sends, cash outs and payment memos from a Gloam account so the user's wallet never appears. Dry-runs every payment against the pool first; cash-out recipients are bound in the proof, so the relay can only submit or refuse. SDK relayIntent, MCP GLOAM_USE_RELAY=1
Passkey lockLive, optionalProtect the private balance on a browser with a passkey (Face ID, Touch ID, security key). The WebAuthn PRF output wraps the key that encrypts notes at rest, so the app unlocks only with the passkey. Backups stay restorable without it. Browsers without PRF keep the device key. Docs
Sanctions screeningLiveChecked against a vendored snapshot of the OFAC sanctioned-address list (EVM): the depositing wallet in the app before signing and at /api/screen, and every cash-out address inside the relay before it submits. Public addresses only; a blocked wallet sees one neutral message. Refresh with node app/scripts/refresh-ofac-list.mjs; optional Chainalysis check via CHAINALYSIS_API_KEY
Issuer policies (Tempo)LiveDeposits and cash outs on Tempo also respect the stablecoin's TIP-403 transfer policy: the wallet must be allowed to send and the vault to receive on deposit, the vault to send and the recipient to receive on cash out. Read-only checks in the app, at /api/screen and in the relay, next to sanctions screening, with a warning when an issuer policy or pause would block the vault itself. Compliant privacy with no operator
Cash outLive, proof-gatedUnshield to a public balance with a real browser-generated Groth16 proof
Selective disclosureLiveProve you hold a specific shielded balance to a party you choose, revealing nothing else. Anyone verifies it at /verify, no wallet
Proof of fundsLive, new circuitProve you hold at least an amount across up to four private balances, without showing the balance. The proof names who it is for and when it expires; the verifier checks it in the browser against the live vault, including that the backing balances are still unspent. Docs
Proof of paymentLive, new circuitA receipt for a payment you received: show the amount, or only that it was at least some amount, anchored to the real payment in the vault
Private agent payments (x402)SDK + MCP liveAgents pay for tools over HTTP 402 with a private send. The payment note is sealed to the payee's receive tag, and the payee sweeps it into a fresh note before serving, so the payer cannot spend it back. settleGloamPayment in the SDK, gloam_fetch_paid / gloam_verify_payment in the MCP server
Agent spending limitsLive (MCP)The owner sets each agent's assets, per-payment and per-day caps, allowed recipients, tools and expiry. Every spend is checked and logged before it is proved or signed; no limits means no spending. Note secrets stay in an encrypted store inside the server and the agent only sees handles. Enforced by the MCP server, off-chain. gloam_get_limits, gloam_get_spending_report. Config
Hosted MCP serverLivePaste https://www.gloam.trade/mcp into Claude (Settings, Connectors, Add custom connector), ChatGPT, Cursor or any MCP client; nothing to install. Read and plan only: networks and assets, vault stats, payment request links, proof checks, deposit plans and MPP how-to. It never signs and refuses anything that looks like a key or note secret; for signing, the local server (npx -y @gloamtrade/mcp). Docs
Transparency pageLive/transparency shows what anyone can see about the vault on each network: what it holds, counts of deposits, private transfers, cash-outs and payment messages, and recent public activity, read straight from public nodes
Private tradeDisabled, by designsealedSwap is off until the H1 solvency accounting lands. Oracle-bound rates are built and tested; see below

Every private action is proof-gated on-chain. No mock fills, no theatrical privacy. If a path cannot be both private and solvent yet, it waits. See contracts/audit/H1-SWAP-SOLVENCY.md.

Selective disclosure: private by default, proven by choice

The answer to the "dark pool" objection. A holder mints a disclosure for one note; the recipient verifies, entirely in the browser, that the holder owns that exact balance in the vault, without learning their identity, their note secret, or any other holding. It reuses the shield circuit (no new trusted setup): the proof binds the commitment to (amount, asset), and the verifier confirms the commitment is a live note via pool.commitmentSeen. Generate at /app/disclose, verify at /verify.

Robinhood Chain native

Robinhood Chain is an Arbitrum Orbit L2 (Nitro, mainnet live since July 2026), ETH gas, Ethereum blob DA. Gloam targets what the chain actually ships:

  • Chainlink oracles from block zero. RH Chain prices tokenized equities on-chain via standard AggregatorV3 feeds. Gloam's OracleRates module binds sealed-trade rates to the live feed with L2 sequencer-uptime, staleness, and positivity guards, and a ratio-tolerance check that is also on-chain slippage protection. Built and tested (contracts/src/lib/OracleRates.sol); it activates when private trade re-enables.
  • Tokenized stocks are ERC-20s (18 decimals, ERC-8056 Total-Return value). Gloam shields the canonical set (TSLA, NVDA, AMZN, and more).
  • Groth16 runs native. bn254 pairing precompiles are present and the 96 KB code-size cap fits large verifier contracts, so shield / unshield / transfer proofs verify with no special infra.
  • First-class ERC-4337 opens the door to gasless private transactions.

Live on Tempo

The same private core now runs on Tempo, the payments-first stablecoin L1, as private stablecoin payments for people and agents. Tempo ships its own operator-run privacy (Zones); Gloam is the self-custodial, permissionless complement, with issuer-compatible selective disclosure. The sealed pool and verifiers are deployed on Tempo Moderato (42431), and the app's runtime network toggle switches the whole product between chains — shield PathUSD, send, and cash out, proof-gated end to end. Because Tempo blocks native msg.value and pays gas in stablecoins, Gloam shields ERC-20 stablecoins there instead of a native asset. Design and constraints: TEMPO_EXPANSION.md.

Trust, verified

Privacy earns the mainnet gate only when it is auditable and correct.

  • Self-audited, then re-verified. A Kensho pass found a critical funded drain, two highs, and a set of mediums in the sealed pool and client. Every critical and high is fixed and verified on-chain and in code (independent re-audit): the drainable pool drained and de-published, value-binding enforced at deposit (C1), the swap path disabled (H1), the re-open path closed (one-way verifier + two-step ownership). Full status: contracts/audit/REMEDIATION.md.
  • No middlemen. Redeployed 2026-09-29 on both networks with no admin withdraw: nobody, including the team, can move pooled funds, and after setup every verifier, rate or oracle change must be queued on-chain 3 days ahead (endSetup(), queueChange, 93/93 tests). Verify setupMode() == false on the pools listed below.
  • Selective disclosure, not a mixer. Prove balance or a payment to a counterparty or auditor without revealing everything. The right posture for a regulated-sponsor chain.
  • Fast vault sync, same privacy. The app loads the vault's public leaf list (every commitment, in order) from /api/vault-leaves in one request instead of walking the chain, rebuilds the Merkle tree in the browser, and uses it only if the root matches the pool's on-chain root; otherwise it reads the chain itself. The request names only the network and is the same for everyone, so the server never learns which notes are yours.
  • Honest gates. The trusted setup is a dev ceremony and mainnet needs a multi-party one; note secrets are encrypted at rest (AES-GCM under a device key, audit M-1), though the key is device-bound. These are disclosed, not hidden. Mainnet 4663 is blocked in-product.

Using the SDK

Deposit privately into the hardened pool in a few lines. The SDK mints the note and generates the shield proof; you sign the resolved call.

ts
import { buildShieldBoundIntent, artifactProver } from "@gloamtrade/sdk";import { parseEther } from "viem";
const intent = await buildShieldBoundIntent({  amountWei: parseEther("0.001"),  prover: artifactProver({ wasm: "shield.wasm", zkey: "shield_final.zkey" }),});
// intent.exec is the resolved shieldBound(asset, amount, commitment, proof) call.// Persist intent.note.secret to spend the balance later.await wallet.writeContract({ ...intent.exec, abi: shieldPoolAbi });

A complete runnable agent is in examples/agent-shield.

Architecture

gloam/  packages/sdk/          @gloamtrade/sdk  the private path as a reusable package  mcp/                   @gloamtrade/mcp  agent server (plan + signed execution)  examples/agent-shield/ reference wrapper: an agent shields via the SDK  app/                   Next.js reference app + docs → Vercel root: app  contracts/             Foundry · ShieldPoolPoseidon vault, verifiers, circuits, audit

Contracts — Robinhood Chain testnet 46630

RoleAddress
Sealed vault ShieldPoolPoseidon (no admin access to funds, 3-day timelock on rule changes)0x7240…d740
Pay memo GloamPayMemo0x689e…5DCE

Contracts — Tempo Moderato testnet 42431

RoleAddress
Sealed vault ShieldPoolPoseidon (no admin access to funds, 3-day timelock on rule changes)0x841D…d5eb
Dual-proof verifier DualProofVerifier0x82F4…03A2
Pay memo GloamPayMemo0x3ca8…b4E3

The pre-C1 RH pool 0x4F38… is drained and retired, never use it. Circuits (Groth16 + Poseidon + depth-20 Merkle membership): shield, transfer, unshield, sealedSwap. Details in contracts/ARCHITECTURE.md.

Local

bash
pnpm installpnpm --filter @gloamtrade/sdk build        # build the SDKcd contracts && forge test            # contracts (67 tests)pnpm --filter @gloamtrade/sdk test         # SDK core self-tests

Run the reference app from app/ (next dev), or open gloam.trade/app. The in-app network toggle switches between chains. Robinhood testnet ETH + stock tokens: faucet.testnet.chain.robinhood.com. Tempo test stablecoins (PathUSD and friends): the Tempo faucet (tempo_fundAddress).

Guardrails

  • Testnet only until a production ceremony + external audit. Mainnet 4663 blocked in-product.
  • Real privacy only. Never fake or mock a private success.
  • Selective disclosure over opacity. Verifiable, not just hidden.
  • Brand: Twilight, paper #F4F3EF, ink #121316, indigo #3B3766. Light, spacious, plain-language.

No private keys in-repo. Deploy with DEPLOYER_PK env only. Circuit zkeys are dev-ceremony artifacts. See SECURITY.md.

來源:README.md,提交 291f7da

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.1.0最新Oct 6, 2026