import type { ReactNode } from "react"; import type { Metadata } from "next"; import { specMetadata } from "@/lib/page-meta"; import { SiteShell } from "@/components/site-shell"; import { card, mono, pre, table, td, th } from "../openontology/ui"; export const metadata: Metadata = specMetadata( "/openswarm", "OpenSwarm is an open specification family for paid, encrypted, peer-to-peer distribution of files and media: BitTorrent plus payment plus encryption as extension messages, with audio, video, live streams and a replicated catalogue on top, and c0mpute.com nodes that seed, relay and index for money." ); const PROTOCOLS: Array<[name: string, line: string]> = [ ["ipfile", "Paid, encrypted file swarms as BitTorrent extension messages"], ["ippay", "Passes and vouchers over x402 and CoinPay: how a leecher pays and a seeder is paid"], ["ipdb", "A replicated, append-only catalogue of manifests and metadata, discoverable over the DHT"], ["ipaudio", "Audio releases and tracks on ipfile swarms: renditions, seek tables, gapless, royalties"], ["ipvideo", "Video on demand: CMAF renditions, segment index, subtitles, thumbnails, an HLS bridge"], ["iplive", "Live streams: segment fan-out over paid relays with backpressure"], ["ipname", "How a Moshpit name or a domain resolves to a publisher key and a catalogue"], ["pay2seed", "Client protocol for paid seeding: consent at upload, seed offers with escrowed budgets, the requester's market"], ["paid2seed", "Server protocol for paid seeding: leases, storage challenges and probes over the wire, GiB-month settlement, the seeder client"], ["pay2stream", "Client protocol for paid live streams: consent for channels, relay offers by the hour, tickets, watching on any HLS player"], ["paid2stream", "Server protocol for paid live streams: relay leases, presence proofs, gateways serving standard HLS with an M3U and EPG"] ]; const ROLES: Array<[role: string, work: string, paid: string]> = [ ["Storage", "Pin an ipfile swarm for a period and seed it", "Pin job plus vouchers per byte served"], ["Relay", "Fan out iplive segments to viewers", "Vouchers per byte served"], ["Transcode", "Produce ipaudio and ipvideo renditions as ipfile swarms", "Job price"], ["Index", "Replicate ipdb feeds, answer queries, serve a gateway", "Job price plus x402 per query"], ["Keeper", "Hold a content key and grant it to paying peers", "Share of each key grant"] ]; const DOCS: Array<[slug: string, title: string, blurb: string]> = [ ["openswarm", "Overview", "What the family defines, how the pieces stack, and what already exists."], ["opencreds", "OpenCreds", "Where the publisher seed should live."] ]; export default function OpenSwarmPage(): ReactNode { return (

LogicSRC standards surface

OpenSwarm

An open specification family for paid, encrypted, peer-to-peer distribution{" "} of files and media. It is an add-on to BitTorrent, not a new transport. A swarm carries ciphertext, the tracker and the DHT learn nothing about the content, every peer that serves a verified piece gets paid for it, and the same primitives carry files, audio, video, live streams and the catalogue that describes them.

It exists because BitTorrent solved distribution and never solved the two things that keep it from being a product: nobody is paid to seed, and nothing in it is private. Every Profullstack media property has rebuilt the same paid-access layer on top of a central HTTP proxy because the swarm could not carry the payment.

Status: 0.1 draft. No reference implementation yet. The full documents live in the repo under docs/openswarm/.

The family

Seven protocols over one core. Reuse is the default posture: a primitive is specified once.

{PROTOCOLS.map(([name, line]) => ( ))}
Protocol One line
{name} {line}
{`  +---------------------------------------------------------------+
  |  ipaudio      ipvideo      iplive         ipdb (catalogue)    |
  +---------------------------------------------------------------+
  |  ipfile: manifest, per-file key pair, encrypted pieces,       |
  |          key grants, credit window, vouchers per served piece |
  +-------------------------------+-------------------------------+
  |  ippay: passes and vouchers   |  ipname: Moshpit name -> key  |
  +-------------------------------+-------------------------------+
  |  BitTorrent wire (BEP 3) + extension protocol (BEP 10)        |
  |  DHT (BEP 5, 44, 46), trackers, WebRTC peers, webseeds,       |
  |  optional Moshpit MTP/1 tunnel                                |
  +---------------------------------------------------------------+`}

One swarm shape, one key model, one payment loop

The swarm carries ciphertext.

A hybrid BEP 52 torrent whose single file is AES-256-CTR ciphertext. The v1 infohash makes it reachable from WebTorrent in a browser, the v2 merkle tree makes every 16 KiB block verifiable, and the plaintext root in the signed manifest makes the decrypted result verifiable. A vanilla client can join and, if the publisher allows, download bytes it cannot read.

Adding a file mints a key pair for it.

Derived from one publisher seed by default, so there is one thing to back up. The public half is the file’s identity and the BEP 46 key under which the latest manifest is published; the private half signs the manifest and authorises key grants and payout changes. A separate random content key encrypts the bytes and is sealed to paying peers.

Seeders are paid per verified piece.

A leecher buys a pass over x402 in USDC. A seeder serves inside a bounded credit window. After verifying each batch the leecher signs a cumulative voucher. The seeder redeems the latest voucher at a hub, which splits it between publisher, seeder and itself. Nobody pays for bytes they did not verify, and nobody serves more than the window unpaid.

{`leecher                                   seeder
  |  hello                                  |
  |---------------------------------------->|
  |<------------------------------- hello   |
  |  pass                                   |
  |---------------------------------------->|   verifies hub signature, scope, cap
  |<----------------------------- unchoke   |
  |  request / piece ... (vanilla)          |
  |<=======================================>|   up to the credit window unpaid
  |<------------------------------ credit   |
  |  voucher (cumulative, signed)           |
  |---------------------------------------->|   unpaid resets
  |  key_req                                |
  |---------------------------------------->|
  |<------------------------------- grant   |   content key sealed to the leecher`}

How c0mpute.com nodes take part

A node already advertises roles and takes work through a gossipsub auction. OpenSwarm adds workload types to bid on and a per-byte income that needs no auction at all.

{ROLES.map(([role, work, paid]) => ( ))}
Role Work Paid by
{role} {work} {paid}

Using it (proposed CLI)

{`# One publisher identity, reused for every file
ip init

# Add a file: derives the file key pair, encrypts, builds the hybrid torrent,
# signs the manifest, starts seeding
ip file add ./interview.flac --per-gib 0.01 --key-price 0.50

# Publish an audio release that references it
ip audio publish ./release.json

# Fetch as a paying peer (buys a pass, gets the key, verifies, decrypts)
ip file get ed25519:0d87e09c7fea3ad6ba6c2f3e027ea47f5b245452899910948470906704c5295d --out ./interview.flac

# Ask the catalogue
ip db query --type ipaudio.track --where 'record.artist == "Ada"' --limit 20`}

What already exists

bittorrented.com runs the browser WebTorrent player, a hybrid seeder on wss trackers, and a DHT crawl. It speaks the vanilla wire this family extends.
x402-gateway and CoinPay sell passes with the x402 v2 offer and verify and settle the proof. ippay reuses that exchange unchanged.
c0mpute has the blake3 chunk store, erasure coding, hardware transcode, a gateway, and a live-stream design that already swarms segments.
moshpit-transport and the Moshpit registry provide the post-quantum tunnel and the name pins.
{DOCS.map(([slug, title, blurb]) => ( {title}

{blurb}

))}
); }