The Anyroute Network is live. $ANYR
Private inference should not depend on a handful of opaque providers. More private capacity needs to be operated by more independent hosts, with every server proving what it is running.
The Network opens that supply layer.
Eligible operators can run a SEAL host on confidential GPU or TDX infrastructure, connect it to Anyroute, and serve private inference through the network.
What is included:
• One-command host setup and a readiness check
• Hardware attestation before a host can serve private traffic
• Model-weight and server configuration verification
• Attested routing, health checks, and automatic failover
• Signed receipts for every response
• Public, attested, and unlinkable privacy lanes
• Per-lane status, SLOs, and incident feeds
• Token-based USDG settlement for capacity served
• Host bonding, dispute windows, and slashing rules for bad actors
• A public network page to check whether your infrastructure qualifies
For users, it means more verified private capacity and less dependence on a single endpoint.
For operators, it means private hardware can become part of a verifiable inference network.
The goal is not just more GPUs.
It is private inference with a record: what model ran, where it ran, what was verified, and what happened on every call.
Check your server:
https://t.co/oBkbbFgtOs
Build:
https://t.co/IS37BUmIDW
Next phase of our build.
Introducing the Anyroute Agent Economy. $ANYR
Agents are starting to hold wallets, pay for services, trade, negotiate, and act for people, teams, and treasuries.
The problem is that most of them are being given money before they are given rules.
An agent should not have unlimited access because it has a private key. It should work inside clear limits set by its owner: what it can spend, where it can spend it, which assets and venues it can use, when it needs approval, and when it needs to stop.
That is what we are building.
Private agent accounts with hard budgets and scoped permissions. Mandates that define what an agent is allowed to do. Private payments that do not turn every service call into a public history. Escrowed agreements for agents doing work for each other.
Trading is part of it too, but this is bigger than agentic trading.
Before an agent swaps, transfers, opens a position, or moves capital, the action can be checked against its policy, simulated, and compared against multiple price sources. If a price looks wrong, liquidity is thin, or limits are hit, it does not execute.
Every action leaves a receipt.
The owner stays in control. The agent gets room to work. The public does not need to see everything.
Not an agent with a wallet and a hope.
An agent economy with rules.
SEAL is fully shipped. $ANYR
Anyroute SEAL is private, verifiable infrastructure for open and uncensored models.
It is built around four parts:
S: Sidecar
The model runs behind an attested Sidecar. The hardware proves the environment, the model weights are measured, keys are created inside the enclave, and every response can be tied back to that record.
E: Encrypted transport
Your request is encrypted to the enclave. A relay separates your IP from the request path, so the operator handling the model does not need to know who sent it.
A: Anonymous credits
Payment and prompting are separated. Blind credits let a request be paid for without attaching the payer’s identity to the prompt or the receipt.
L: Ledger of receipts
Every response returns a signed receipt. It records the model, route, attestation, policy, and hashes of the request and response, not the content itself. Streams are hash-chained, so altered or cut output can be detected. Receipt records are anchored on-chain for verification.
SEAL also makes policy visible. If filtering is enabled, the policy is measured inside the enclave and named in the receipt. No hidden changes after the fact.
Builders can use it with OpenAI-compatible model servers, Claude Code, Codex, the OpenAI Agents SDK, Saved Routes, Batch Studio, and private RAG.
The point is not to ask users to trust a privacy policy.
The point is to show what ran, where the request went, what was retained, who could see what, and give the user a receipt they can verify themselves.
A lot shipped this week. $ANYR
SDKs in TS, Python + Go. Ollama support. Telemetry, rerank and versioned presets.
Encrypted chat. Private characters. Anonymous teams. Skills scanned before installation. Uptime by privacy lane.
Building the private layer for models and agents. Next phase incoming.
Agents Economy.
Agents should not install blind.
The Anyroute Skills Hub hashes and scans every skill for data theft, prompt injection, and hidden code before installation.
It caught all 14 malicious skills in our test set. Paid skills send 90% to their author.
Scanned, not guaranteed.
Shipped: https://t.co/9eXLTGXgK3
Ship the chat, not the frontend.
`@anyroute/chat-kit` is a white-label React kit for streaming, presets, and characters.
MIT. React 18+. No dependencies.
History is AES-256-GCM encrypted. The key stays with the user.
https://t.co/Dx855ByHmY
Bring your characters to Anyroute.
Import Tavern v2 or v3 cards, select `@character/<id>`, and use them from SillyTavern or any OpenAI-compatible app.
Your character memory stays sealed on your device. Attested models use the attested lane when available.
Shipped: https://t.co/8TgAvYd6nW
SDKs for every stack.
Anyroute now has official TypeScript, Python, and Go SDKs, alongside LangChain and LlamaIndex integrations.
Build with chat, batches, rerank, and presets. Every SDK can verify receipts offline.
Shipped: https://t.co/jiBs4KuvGZ
Uptime, by privacy lane.
Anyroute now has a public status page with SLOs for the public, attested, and unlinkable lanes.
Private lanes are measured only through privacy-preserving aggregates. Follow incidents through Atom or RSS.
Shipped: https://t.co/9Ggq4YYW6q
Teams should not need to hand over their identities to work together.
Anonymous orgs on Anyroute let members join with a passkey or wallet, no email required. A Safe can own the org.
Set roles for admins, devs, viewers, and agents. Every action lands in a hash-chained audit log you can verify offline.
Shipped: https://t.co/vql93Me0io
Sort by speed. Sort by cost.
Add `:nitro` to a model for the fastest available provider, or `:floor` for the lowest-cost option.
Anyroute also now supports a Cohere- and Jina-compatible rerank endpoint that returns grounded scores, not invented ones.
Shipped: https://t.co/uBrKe5bAok
Your traces, your collector.
Send OpenTelemetry GenAI spans to your own OTLP endpoint, Langfuse, or Helicone.
Prompt content is exported only when you opt in. Private-lane requests are never exported.
Shipped: https://t.co/wLDenCtM3N
The Anyroute Network is coming.
Private inference cannot depend on a small group of providers. More private capacity needs to be in more hands. $ANYR
Soon, operators with confidential GPUs and eligible TDX hosts will be able to run a SEAL host on Anyroute.
One command sets up the host.
Your hardware attests what it is running.
Private requests are routed to verified capacity.
Every response carries a signed receipt.
Hosts earn USDG for the tokens they serve.
The goal is simple: make private, verifiable inference available beyond a single provider or data centre.
The attested lane is already live with open models. The next step is opening supply.
Check whether your server qualifies:
https://t.co/oBkbbFfVYU
Build details:
https://t.co/IS37BUmaOo
Presets, with memory.
Presets keep a versioned configuration for your model, system prompt, and settings.
Use `@preset/name`, compare any two versions, roll back in one call, or pin an exact release with `@preset/name@3`.
Shipped: https://t.co/4Z1qvmfI4N
Your Ollama apps, every model.
Point `OLLAMA_HOST` to Anyroute, and tools like Open WebUI, Continue, and LangChain can access 376 models through the Ollama API.
Streaming stays native. Every call includes a signed receipt. The attested lane is available too.
Shipped: https://t.co/tQPdVpidH2
@RobinhoodApp Agents can now act. The next question is what rules sit between an agent and your money.
Budgets. Mandates. Simulation before signing. A real kill switch. Private payments and receipts.
That is the layer Anyroute is building next.
The Anyroute Network is coming.
Private inference cannot depend on a small group of providers. More private capacity needs to be in more hands. $ANYR
Soon, operators with confidential GPUs and eligible TDX hosts will be able to run a SEAL host on Anyroute.
One command sets up the host.
Your hardware attests what it is running.
Private requests are routed to verified capacity.
Every response carries a signed receipt.
Hosts earn USDG for the tokens they serve.
The goal is simple: make private, verifiable inference available beyond a single provider or data centre.
The attested lane is already live with open models. The next step is opening supply.
Check whether your server qualifies:
https://t.co/oBkbbFfVYU
Build details:
https://t.co/IS37BUmaOo