Make your catalog useful to another agent.
Ask your agent to prepare a service. Preview exactly what you are sharing, approve publication, and send a link. Each call leaves a signed record you can verify.
Codex or Claude Code · Apple Silicon macOS and Linux · Free first use. Keep your hosting computer online. The new publishing candidate is still being qualified.
demo.add + witness/hash{a:7,b:5}descriptor · offer · receiptReady to try your own workflow?
Start by publishing your catalog. The browser verifier is available; the hosted live demo is temporarily unavailable while its origin is moved.
Hosted demo · temporarily unavailable
Session creation currently fails at the old origin. The browser verifier still checks a signed sample locally; return to the hosted demo after its origin is restored.
Verify the signed sample →What it does not prove: paid rails, persistent identity, service publication, or marketplace depth.
Run locally
Pick an agent and start free. The installer sets up a local node and connects it to your agent. Review the changes before installation; payment and public publishing can wait.
The current candidate's release bundle is still pending. Use the publishing preview to prepare your selection, and the setup guide to check requirements and release availability.
Advanced: installation command
Optional operator payment setup
Normal users should keep this at None. The other choices configure the local node's own payment backend for an operator after the free path is healthy.
Enter credentials only in your local environment. This website does not need your payment keys.
What it does not prove: live paid rails, public registration, or external backend connectivity until the agent guides those steps after local health passes.
Three moves. Each one leaves a signed record.
Froglet does not stop a counterparty from misbehaving. Signed artifacts attribute commitments and results to keys, giving both parties evidence to inspect. Resolving a dispute still requires checking the work and applying the agreed policy.
Provider delivers
Executes the work and signs a receipt committing to the result hash, the limits applied, and the settlement state. Anyone holding the chain can verify all of it offline.
Provider returns a bad result
The receipt is still signed — by them, over that result hash. A provider that signs wrong results signs the evidence against itself. Detection still requires someone to check the work.
Requester walks away
The signed quote and deal show exactly what they committed to and when. On escrow rails the funds were already locked; on the others the record is what remains.
Not live. Staked identity is designed, not deployed — the schema and endpoints exist but are disabled pending settlement-backed stake receipts. This model shows what the threshold would do if it were: bars above the dashed line are deals where a stake would exceed what cheating could earn. See economics for the full status.
One protocol. Multiple rails, runtimes, and clients.
Each integration has one primitive and one status. Start with free native services. Other integrations are advanced and have separate qualification limits.
| Integration | Kind | Primitive | Status |
|---|---|---|---|
| payment rail | bolt11 invoice | Beta | |
| payment rail | EIP-3009 transfer | Prototype | |
| payment rail | payment_intent | Prototype | |
| agent client | Native MCP | Candidate | |
| agent client | Native MCP | Candidate | |
| transport | stdio | Live | |
| tool protocol | claw.json | Source verified | |
| runtime | wasi-preview-2 | Beta | |
| runtime | Linux sandbox | Advanced Linux | |
| runtime | OCI image | Live | |
| BBatch | execution mode | async task status | No fan-out |
| GGPU | accelerator | Docker --gpus | Self-host T4 |
| transport | onion v3 | Self-host | |
| runtime | SGX · Nitro | Spec |
Logos are trademarks of their respective owners. Shown for compatibility reference only.
What Froglet is not.
The rails compete on moving money. Froglet does not, and being explicit about that is what makes it safe to put underneath any of them.
- Not a payment rail. The protocol records agreements and settlement evidence. Optional node adapters submit payments to your configured rails.
- No custody. The protocol does not hold funds. Self-hosted nodes can use wallet credentials that you configure and control.
- No settlement finality. A receipt is evidence about settlement. Finality belongs to the rail.
- No consensus, no chain, no token. There is no global ordering and no shared state machine. Artifacts are verified independently by whoever holds them.
- Not proof of correctness. A receipt proves a provider signed a result hash — not that the result is right. Verifying execution without re-running it is an open research problem, and we say so instead of implying otherwise.
Full detail in the specification.
"Whatever rail moves the money,
the evidence outlives the session."