Developer documentation
Build on REAX
REAX is a Bittensor subnet in development. Miners serve fast, calibrated, finite-answer decision models that are Jev-compatible, and validators measure whether those models are served faithfully. These docs describe the design and the private reference implementation as they stand today.
Status · 30 September 2026
Pre-release. Nothing runs on testnet or mainnet. No REAX subnet is registered and there is no netuid. The only running system is a local loopback harness: three simulated miners, one validator, synthetic traffic, no chain. The design specification is provisional and changes often. These docs follow revision 0.6; newer working revisions are in review, and every rollout gate is closed. Source code is private; prospective operators can request access through reax.co/apply.
What REAX does
A REAX request carries a question with a finite candidate set: yes or no, one option out of several, or a level on an ordered scale. A miner answers with a complete probability distribution over that set, signed with its serving key. The network is built for decisions that must come back quickly and with calibrated probabilities, not for free-form text generation.
- Miners serve approved models only. The v1 model catalog is closed: each public
modelalias maps to a signed list of approved model manifests, and miners compete on faithful, available, verified-capacity serving of those models. They do not bring their own models. - Validators measure faithful serving: identity and quality fidelity to the reference manifest, availability, latency (capped at the reference) and verified serving capacity. These sit behind hard eligibility gates for tier, identity and integrity. Validators convert the result into miner weights.
- Chain emissions are an incentive mechanism. They are not customer billing and not a service guarantee. Customer charges and any operator settlement are fiat-accounted and kept separate from the score ledger.
Architecture
Customer requests never reach a miner directly. They enter through System1's API, are authenticated and projected by the REAX gateway, and are dispatched to an eligible miner in the right tier. Validators inject their probes through the same gateway, so a probe travels the same path as any other request.
Every miner calls its own co-located inference engine. The gateway strips caller identity and replaces the request ID and nonce with fresh per-dispatch values before anything reaches a miner. See the protocol reference for the exact envelopes.
Roles
| Role | Responsibility | Trust boundary |
|---|---|---|
| Miner (GDPR tier) | Serves admitted EU requests under contract and DPA | Sees plaintext while inferring; admitted through an off-chain process and a signed admission snapshot |
| Miner (permissionless) | Serves authorized synthetic traffic only | Assumed to be able to log, copy or retain payloads, so it never receives personal or GDPR-tier data |
| Validator | Private schedules, labelled items, identity items, verification, epoch scoring, weight submission | Receives no customer content and no organic metadata; injects probes only through the gateway; must be independent of other validators |
| Gateway / router | Authenticates callers; enforces tier, eligibility and capacity; projects payloads; dispatches; measures latency; records receipts | Customer API keys and chain keys never reach miners; never reads the emission score |
| Reference processor | Computes reference outputs p_ref on byte-identical payloads | Never stores payloads; must be admitted like a GDPR operator for any tier whose organic traffic it shadows |
| System1 (external owner) | Customer ingress, tenant policy, legal notices, billing | Owns the decision to send real traffic; REAX cannot override that gate |
| Subnet owner / trust root | Chain hyperparameters, signed trust root, policy, catalog and chain profile | Owner and coldkey are not yet decided; offline owner key signs issuer keys |
The chain provides hotkey registration, validator permits and stake-weighted consensus over weights. It does not inspect models, prove EU location, bind a company to a DPA, or judge whether answers are correct. Those are the jobs of admission, the gateway and validators.
Tiers
| GDPR tier | Permissionless tier | |
|---|---|---|
| Wire value | gdpr_eu | global_permissionless |
| Who can serve | EU-established legal operators processing data in admitted EU countries | Any chain-registered hotkey that passes conformance |
| How you get in | Off-chain KYB, contract and DPA, then a signed admission snapshot; chain registration is necessary but never sufficient | Chain registration plus a signed miner record and conformance |
| Traffic today | None outside the local harness | Synthetic only, and only in the local harness |
| Real traffic requires | A signed acceptance record from the System1 owner, legal review, DPA and subprocessor workflow, and the organic identity shadow enabled. None of these exist yet. | |
System1 currently routes both of its customer tiers only to verified EU capacity, and routing outside the EU is hard-disabled. The permissionless route therefore carries synthetic traffic only until the System1 production owner signs an acceptance record. No REAX setting can override that gate.
Current status
| Area | State | Detail |
|---|---|---|
| Design specification | Provisional | Docs follow revision 0.6; newer working revisions (0.7, 0.8) are in review. Not frozen; constants are provisional and several measurements (M1–M4) and simulations (S1–S4) have not run |
| Rollout gates G0–G6 | All closed | From spec freeze through mainnet; see the roadmap |
| Local harness | Runs locally | Loopback only: 3 simulated miners, 1 validator, synthetic traffic, mocked chain snapshot |
| Testnet | Not registered | No REAX subnet, no netuid; read-only chain checks exist |
| Mainnet | Not registered | Requires explicit approval of a stated cost and coldkey |
| Customer traffic | None | No System1 acceptance record exists |
| Images | Disabled | Disabled at the network miner pending isolated decode validation |
| Capacity measurement | Not built | Capacity is fixed at 1 in code; no weight to external miners on any non-local network until it exists |
| Organic identity shadow | Designed, off | Disabled by default; mandatory before real traffic |
| Source code | Private | Pre-release; access by request for prospective operators |