get access sepolia research preview

Stake without giving us an identity.

A refundable bond on Sepolia buys your agent a budget of anonymous HTTPS tunnels through the canopy. The identity is made in this tab and stays with you. Only its public commitment goes on chain, and nodes only ever see a proof of membership.

network
Sepolia testnet
nodes announced
…
staked members
…

Your privacy is only as large as the staked set. The live count loads from this site's aggregate API.

What each party learns

This page
Generates and validates locally. No identity API exists.
Your wallet and its RPC
Sees your address, public commitment, bond, and timing.
The canopy
Later sees a valid anonymous membership proof, not which leaf made it.
The destination
Sees a Shade Tree node's IP, never yours.

Loading any website can expose your IP to its host. This static page never sends the commitment or recovery file to the ShadeNet server.

  1. 01 tier
  2. 02 identity
  3. 03 save
  4. 04 stake
  5. 05 finality
  6. 06 hand off

Choose a tier

A session is one visit to a node: it opens up to 6 HTTPS connections to different sites within 90 seconds and carries up to 40 MiB in both directions combined. Each tier gets that many new sessions per minute, canopy-wide. A search plus five result pages is about one session. The tier is part of the identity, so pick it first.

Tier

The bond is refundable collateral, not a fee: exit whenever you like and withdraw it after 24 hours. Sending two different requests from the same slot in one minute reveals your secret and lets anyone slash the bond. A valid slash pays 1/10 of the bond to whoever reports it and burns the rest. To change tier later, stake a new identity and exit the old one.

Create the identity

The secret comes from your operating system's randomness and never leaves this tab. Already have an identity file? Import it to check its status, exit, or withdraw; each new stake needs a new identity.

public commitment Create or import an identity to reveal its public commitment.

Save the file

The ShadeNet client reads this file directly. Whoever holds it can use the membership and authorise its exit, and nobody can recover it for you.

  • Keep it on an encrypted disk or in a secrets vault.
  • Never paste it into chat, email, or a ticket. The public commitment is the only thing to share.
  • Lose it and the bond stays locked for good.

Fund and stake

The wallet sends exactly the tier's bond to the pinned contract, plus gas. Its address is linked to the commitment forever, so use a wallet you don't mind linking, or let a sponsor stake for you.

contract 0xDEB2…4bBC

No wallet connected

No Sepolia ETH? Two ways in

Faucet drips are usually smaller than a bond, so funding can take a few tries. No ETH at all: copy your public commitment above and send it to a sponsor. The sponsor never sees the secret.

Member mode: the identity stays in this tab until you download it.

Hand it to your agent

The commands below fill in your identity file's name once you create one. They work the same for a file made by shadenet init.

Install the shadenet binary (it embeds Tor), put the file where it looks, and run the proxy. Every command after init reads the identity from that folder.

curl -fsSL --proto '=https' --proto-redir '=https' \
  https://raw.githubusercontent.com/dmarzzz/shade-tree-node/main/scripts/install.sh \
  | SHADENET_VERSION=v0.7.1 sh
mkdir -p ~/.config/shadenet && chmod 700 ~/.config/shadenet
mv ~/Downloads/shadenet-identity-XXXXXXXX.json ~/.config/shadenet/identity.json
chmod 600 ~/.config/shadenet/identity.json
shadenet init            # keeps that identity, writes the proxy token and config
shadenet status --wait   # returns once the stake is final
shadenet proxy           # leave this running
shadenet run --no-proxy api.openai.com -- your-agent

run gives only the child process the proxy settings. Keep your model API host on --no-proxy: it has its own network path and would waste tunnels.

Nodes admit the identity once its stake is final: shadenet status --wait returns then, and one request through the proxy returns a Tor exit address, not yours (shadenet run -- curl -s https://api.ipify.org).

Change tier or leave

Exit and withdraw are zero-knowledge proofs of the identity secret. Made here, they take a few seconds in this tab after a one-time 1.8 MB prover download; the secret never leaves the page. The connected wallet only pays gas, so it can be one unrelated to the funder.

  1. Import the identity file above and connect a wallet that only pays gas.
  2. Start the exit. The bond unlocks 24 hours later.
  3. Withdraw to a fresh address so the refund doesn't link back to the funder.

From a terminal instead: shadenet exit-member --identity identity.json --key-file gas.key, then after 24 hours shadenet withdraw-member --identity identity.json --recipient 0xFRESH --key-file gas.key. To change tier, stake a new identity at the new tier, then exit the old one; both bonds are locked for 24 hours.

Questions

What do Shade Tree nodes see?

The destination hostname, timing, and how many bytes flow, as any proxy would. They see a valid membership proof, not which member made it. Destinations see the node's IP, not yours.

Why wait for finality?

Nodes and the proxy both read the finalized member set, so a reorg can't admit or drop a member. On Sepolia that is usually 13 to 16 minutes after the stake confirms.

What if I lose the identity file?

Nobody can recover it for you. Without it you can't use the membership, exit, or withdraw, so the bond stays locked for good.

Can nodes limit me across the whole canopy?

The per-minute budget is canopy-wide, but nodes share spent proofs on a best-effort basis today. Double use across two nodes at the same moment may not be caught immediately; it is still slashable once seen.

Is there a free or paid path?

Operators can admit invited members from a private members file; ask one for their setup details. A paid path exists in the code but is not offered on this canopy.

Will these addresses and prices change?

Yes. This is a research preview. The contract, bonds, tiers and unbonding time can change at the next deployment, and this page is rebuilt from that deployment's record.

Is ShadeNet related to Shade Network or Shade Protocol?

No. ShadeNet is not affiliated with Shade Network, Shade Protocol or any other project with Shade in its name. It is one word, and it is this: proof-gated Tor egress for AI agents.

Honest boundary

Tier 1 buys 1 session per fixed 60-second epoch, capped at 40 MiB combined traffic each and 6 connections per session. Registration becomes usable after Sepolia finality. The wallet-to-commitment link is permanent; use a separately funded wallet or a sponsor if address-graph separation matters. Exit and withdraw are proof-authorised and return the testnet bond to a fresh recipient after 24 hours. The proof keys come from the published trusted-setup ceremony. Never use mainnet ETH or sensitive traffic.