Aether (AETH)

MCP serverAI & models

Testnet wallet for AI agents on Aether: pay, get paid and buy from paid APIs, with spending caps.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use Aether (AETH) to find services

Install Aether (AETH)

The server’s own address, for the clients that take one directly. Or connect ahel once and every client you use reads it from one address, with the account kept on ahel rather than in each client’s config.

  • Claude Code

    claude mcp add --transport http --scope user aether-aeth 'https://explorer.157-245-252-221.sslip.io/mcp'

    Run it once in your project, then open /mcp to approve any sign-in the server asks for.

  • Claude Desktop

    https://explorer.157-245-252-221.sslip.io/mcp

    Add a custom connector in Settings, paste this address, and approve the sign-in.

  • Cursor

    cursor://anysphere.cursor-deeplink/mcp/install?name=aether-aeth&config=eyJ1cmwiOiJodHRwczovL2V4cGxvcmVyLjE1Ny0yNDUtMjUyLTIyMS5zc2xpcC5pby9tY3AifQ==

    Open the link and Cursor adds the server at that address.

  • ChatGPT

    https://explorer.157-245-252-221.sslip.io/mcp

    In Settings, enable Developer mode, create an MCP app, and paste this address. Your plan and workspace must allow custom apps.

  • Codex

    codex mcp add aether-aeth --url 'https://explorer.157-245-252-221.sslip.io/mcp'

    Run it once, then sign in with codex mcp login aether-aeth if the server asks for an account.

From the project's README

As published by whoyoujoshin/aether in README.md.

Aether is a sovereign, staking-free proof-of-work blockchain built on Cosmos SDK and CometBFT. Validators are selected by real, tracked native mining work — not bonded capital — and account transactions require ML-DSA-44 (Dilithium2 / FIPS 204) signatures from genesis.

Technical design: see the full Technical Whitepaper.

Warning: no independent security audit. This is early-stage software. Do not use it with funds you cannot afford to lose. See Known Issues and Technical Debt and the security review materials in this repo for an honest account of what has and has not been independently reviewed.

Design history, live-verification notes, and locked architectural decisions are tracked in the project wiki.

AI agents: start here

Agents use the same accounts and transactions as people: there is no AI-only lane. Testnet only: use disposable keys, never anything of value.

One page from nothing to a first payment: docs/START.md (the explorer serves it too, at /start.md). A key, test funds, a balance and a send, copy-paste for an MCP agent, TypeScript or Python. What won't change under you: API stability.

go install github.com/whoyoujoshin/aether/cmd/agentmcp@latest   # Go 1.25+
agentmcp init   # new key, testnet funds, and the MCP config for Claude / Cursor / any MCP client

No Go? agentmcp is in every platform's archive on the releases page. @latest is the newest tested release; @main has unreleased changes.

That gives the agent a spend-capped wallet as MCP tools: balance, send, invoice and wait-for-payment, paying for HTTP 402 APIs, and the service directory (full list and guarantees in AI agent wallet).

Chain IDaether-testnet-1 · denom uaeth (1 AETH = 10⁶ uaeth) · addresses aether1...
RPC / gRPChttps://rpc.157-245-252-221.sslip.io / grpc.157-245-252-221.sslip.io:443 (TLS; plain 157.245.252.221:26657/:9090 still work)
Faucetcurl -X POST https://faucet.157-245-252-221.sslip.io/request -H 'Content-Type: application/json' -d '{"address":"aether1..."}'
Explorerhttps://explorer.157-245-252-221.sslip.io/agents · balance: /api/address?addr=aether1... · this card as JSON: /api/agents · every endpoint: /api/openapi.json · for LLMs: /llms.txt · start page: /start.md

Let an agent spend from your account with a chain-enforced cap instead of holding funds: agent permissions. Sell to agents: paid APIs. See one agent pay another for a tool call, live, in docs/AGENT_DEMO.md. A prompt to check an agent is set up (the address is a test counterparty run by the project):

Using the aether-wallet tools: get your address and balance. If you have under 1 AETH, call request_testnet_funds and wait until your balance shows it. Then send 0.001 AETH to aether1cdugwhxk9cktjsemm6yjrd6xtfsq9wkjvnef03ml4u6ltuv7edcs0eyjds with idempotencyKey "aether-smoke-1", wait for the transaction to confirm, and report its hash and https://explorer.157-245-252-221.sslip.io/tx/.

Current status

AreaStatus
Core PoW (Scrypt), difficulty retarget, height-based reward decay and tail emissionBuilt, tested, live-verified
Epoch Top-K validator selection (no staking module)Built, tested, live-verified
Validator bonding, equivocation slashing, escrow releaseBuilt, tested, live-verified
Downtime / liveness detection (distinct from equivocation)Built, tested, live-verified
Ancestor validationBuilt, tested, live-verified
AuxPoW (LTC/DOGE-family merged mining)Built and tested; verified live only with synthetic proofs. Real pool work needs the chain changes and bridge in docs/MERGED-MINING-PLAN.md
Post-quantum account signatures (ML-DSA-44), mandatory from genesisBuilt, tested, live-verified
Governance (deposit, tenure-weighted voting, treasury execution)Built, tested, live-verified
uaeth / aether bech32 prefixBuilt, migrated, live-verified
Wallet library and CLIBuilt, tested, live-verified
Testnet faucet and block explorerBuilt, live, deployed with seed node
Public testnetLive — see below
Native IBC (core, ICS-20 transfer, ICS-27 interchain accounts)Built, tested, live-verified — activated at block 122,000; full client/connection/channel/transfer round trip relayed with Aether's own ML-DSA relayer, locally and on the live testnet
Account abstraction (session keys, guardian thresholds)Built, tested, live-verified — activated at block 122,000
Escrow between accounts (x/escrow: release, refund, arbiter, deadline)Live since block 161,000 (docs/ESCROW.md)
Ligase: someone on another chain funds, releases and withdraws Aether escrows with IBC transfers carrying an instruction; such instructions can never move AETHLive since block 161,000; proven on a two-chain devnet (docs/LIGASE.md)
Helicase: the block proposer relays IBC packets, acknowledgements and timeouts onto Aether, unsigned and proof-checked, so no relayer signs on Aether; cmd/outbound relays the other way with the other chain's own keysLive since block 161,000; both directions proven unattended on a two-chain devnet (docs/HELICASE.md)
Independent professional security auditNot yet performed

See Known Issues and Technical Debt and Roadmap.

Why staking-free, and why post-quantum?

Aether has no x/staking module. The active validator set is the Top-K miners by epoch native work. AuxPoW can earn rewards and retarget difficulty but does not count toward Top-K standing.

Every account transaction must use ML-DSA-44 from genesis (no classical fallback), enforced by PostQuantumDecorator. CometBFT consensus keys remain ed25519. Details: docs/WHITEPAPER.md and the wiki decision records.

Public testnet

Chain IDaether-testnet-1
Seeddfa6aae4b7bfd5b0eb1e22fabbae3e83a475b938@157.245.252.221:26656
RPChttps://rpc.157-245-252-221.sslip.io (plain http://157.245.252.221:26657 still works)
gRPCgrpc.157-245-252-221.sslip.io:443, TLS (plain 157.245.252.221:9090 still works)
Faucethttps://faucet.157-245-252-221.sslip.io/request — POST JSON {"address":"aether1..."}; several at once: Faucet
Explorerhttps://explorer.157-245-252-221.sslip.io
Genesistestnet/genesis.json

Connecting a node

aetherd init <your-moniker> --chain-id aether-testnet-1

Replace config/genesis.json with testnet/genesis.json, set in config/config.toml:

seeds = "dfa6aae4b7bfd5b0eb1e22fabbae3e83a475b938@157.245.252.221:26656"

Then:

aetherd start

To expose RPC/gRPC publicly (defaults bind localhost only), before start:

# config/config.toml, [rpc]
laddr = "tcp://0.0.0.0:26657"
# config/app.toml, [grpc]
address = "0.0.0.0:9090"

This is an early-stage public network — not audited, subject to resets. Use only disposable test funds.

Historical note: for roughly the first ~10 hours, timeout_commit remained near CometBFT’s ~5s default instead of the intended ~60s, so height grew faster than wall-clock age (~7,000 blocks in that window). Fixed live; not a consensus/security failure — disclosed for operators interpreting height vs age.

Quick start (single-node devnet)

# Build
go build ./...
go install -mod=mod ./cmd/aetherd

# Initialize (once, or after full reset)
aetherd init mynode --chain-id aether-testnet-1

# Start (foreground)
aetherd start

Second terminal:

aetherd query pow difficulty
aetherd query pow block-reward
aetherd query pow active-validators
aetherd query pow current-epoch
aetherd query governance params
aetherd query governance proposals

# ML-DSA-44 key (no special flags)
aetherd keys add mywallet --keyring-backend test

# Mine a valid native PoW nonce against live state
go run ./cmd/powminer --miner <your-bech32-address>
# then run the aetherd tx pow submit command it prints
# (--fees 40uaeth if your node runs with --minimum-gas-prices=0.0001uaeth)

Keys: each account is one ML-DSA-44 keypair — no HD multi-account derivation from a mnemonic.
Addresses / denom: aether1... bech32; uaeth base unit (1 aeth = 1_000_000 uaeth).

Binary home defaults to ~/.aether.

Wallet

go run ./cmd/wallet create mywallet --keyring-backend test
go run ./cmd/wallet balance mywallet --grpc localhost:9090
go run ./cmd/wallet send mywallet <recipient> 1000000uaeth --keyring-backend test --grpc localhost:9090 --chain-id aether-testnet-1

balance and send accept a bech32 address or keyring account name.

Faucet

go run ./cmd/faucet --from faucet --chain-id aether-testnet-1 --keyring-backend test
curl -X POST http://localhost:8080/request \
  -H 'Content-Type: application/json' \
  -d '{"address":"aether1..."}'

Requires a funded key named faucet in the configured keyring.

It's built for bots as well as people:

  • POST /request/batch with {"addresses":["aether1...", ...]} funds up to --batch-max (10) addresses in one transaction and lists any it skipped.
  • GET /status?address=aether1... says whether a request would be funded now, and when if not. GET / describes the faucet and its limits.
  • Each address is funded once per --cooldown-minutes (60), and each caller (client IP) funds at most --caller-limit (20) addresses per --caller-window-minutes (60). Behind a reverse proxy, list it in --trusted-proxies (default: localhost) so X-Forwarded-For names the real caller; the header is ignored from anyone else.
  • Every answer has a stable code (sent, pending, address_cooldown, caller_limit, invalid_address, batch_too_large, invalid_request, send_failed) and the caller's quota in RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset; a 429 also has Retry-After. A failed send gives back both the cooldown and the quota.
  • --gas-price (e.g. 0.0001uaeth) pays fees for a node with --minimum-gas-prices.
  • Where requests come from. Each drip is tagged by source and kept in --drip-log (JSON lines, default <keyring dir>/faucet-drips.jsonl), so the explorer's Faucet page can show who's creating wallets:
    • web: a browser that solved a small proof of work. GET /challenge?address= returns a challenge and bits; the page finds a nonce where sha256(challenge + ":" + nonce) starts with that many zero bits (--pow-bits, 18 by default, about a second) and sends {"address", "pow":{"challenge","nonce"}}.
    • agent: a request signed with a self-registered agent key. Register an ed25519 public key once with POST /agents {"name":"my-bot","public_key":"<base64>"} to get an agent_id, then send X-Aether-Agent: <agent_id>, X-Aether-Agent-Timestamp: <unix seconds> and X-Aether-Agent-Signature: base64(ed25519(timestamp + "\n" + body)). Agents get their own quota (--agent-limit, 100 per window) instead of their IP's; registry in --agent-registry.
    • api: neither, on the per-IP limit as before.
  • A drip to an address the chain had no account for counts as a new wallet (single requests answer "new_wallet": true). GET /stats sums drips, wallets funded and created, sources over 30 days, new wallets per day and the top agents; GET /drips?limit= lists the newest. "strand":"ibc" answers ibc_unavailable until the Osmosis channel opens.

Block explorer

go run ./cmd/explorer --grpc localhost:9090 --rpc http://localhost:26657 --port 8081

Open http://localhost:8081.

The helix. Add --ibc-rpc <the RPC of the chain on the other end of Aether's transfer channel>, and optionally --ibc-name to name it. The Overview and Blocks pages then draw both chains as the two strands of a helix. Aether's blocks run along one strand and the other chain's along the second. Each IBC packet between them is a rung, labelled in flight, received, acknowledged or timed out. A Both / Aether / other-chain switch sits in the top bar. /api/helix serves the data, read live from both chains' RPCs. Without --ibc-rpc, the Overview still draws Aether's strand live. The second strand is a faint ghost labelled "no IBC chain connected", and the rest of both pages stays as it was.

To redeploy the live explorer from main, run bash scripts/deploy-explorer.sh as root on the server that hosts it. It builds while the old version keeps serving, keeps backups, restarts aether-explorer and rolls back if the new one doesn't answer.

The Faucet page talks to the faucet through the explorer: run it with --faucet-api http://127.0.0.1:8080 (the faucet must trust the explorer's address in --trusted-proxies, localhost by default). The Validators globe shows what --node-locations publishes; see docs/EXPLORER-LOCATIONS.md.

AI agent wallet (MCP)

An MCP server exposing wallet operations as tool calls, so an AI agent can pay and get paid directly instead of only a human clicking through a UI.

Quick start (testnet):

go install github.com/whoyoujoshin/aether/cmd/agentmcp@latest   # or, in a clone: go install ./cmd/agentmcp
agentmcp init

init creates the agent's account (showing its recovery phrase once), asks the testnet faucet for funds, waits until they arrive and prints the exact claude mcp add ... command and the JSON config block for Claude Desktop and other MCP clients. Run it again to reuse the same account. --faucet <url> points it at another faucet, --no-faucet skips funding; it takes the same --grpc, --rpc, --chain-id and --keyring-dir flags as the server (on aether-testnet-1, --grpc and --rpc default to the public node). Once running, the agent can top itself up with the request_testnet_funds tool (testnet only; FAUCET_RATE_LIMITED means wait).

Claude Desktop without Go: download aether-wallet.mcpb from the latest release and open it. Claude Desktop asks for the spending limits and a keyring folder; the agent creates its account on first use and funds it with request_testnet_funds. The same bundle runs on Windows, macOS (Intel and Apple Silicon) and Linux. Its MCP Registry name is io.github.whoyoujoshin/aether-wallet.

To run the server by hand:

go run ./cmd/agentmcp --grpc localhost:9090 --rpc http://localhost:26657 --chain-id aether-testnet-1 \
    --per-tx-limit 1000000 --daily-limit 5000000 \
    [--granter <your-address> [--fee-granter <your-address>]]

Public read-only URL (no local package). --http serves Streamable HTTP at /mcp and GET /healthz. It is a different server from the wallet above: it never opens the keyring and does not register tools that spend, sign, create a key, or call the faucet. get_balance, get_miner_status and get_account_authenticators require an address. get_transaction_status looks a hash up. find_services is the service directory. Stdio, with the full wallet, stays the default when --http is omitted.

go run ./cmd/agentmcp --http 127.0.0.1:8090 \
    --grpc grpc.157-245-252-221.sslip.io:443 --chain-id aether-testnet-1

That listens on http://127.0.0.1:8090/mcp. Bind it to loopback. The explorer SPA serves index.html with HTTP 200 for unknown paths, so Caddy has to proxy /mcp to this process before that fallthrough — the snippet is commented in scripts/tls/Caddyfile and is not applied. The registry entry stays io.github.whoyoujoshin/aether-wallet; agentmcp server-json --remote <url> can add a remotes URL later, and omits it when the flag is empty. Neither the Caddy route nor a registry publish is done yet.

Built for how agents actually fail:

  • No double payments on retry. send_aeth requires an idempotencyKey; a retry with the same key re-sends the identical signed transaction (its sequence number is signed in, so the chain can include it at most once) and returns its status.
  • Knows when a payment is final. send_aeth returns pending once the node accepts it; wait_for_transaction waits until it's confirmed or failed in a block.
  • Can get paid. create_invoice returns a unique memo and the current height; wait_for_payment(memo, minAmount, sinceHeight) waits for a confirmed incoming payment that matches. It reads every incoming payment since that height, page by page, so a busy agent can't miss one. Memos are sender-controlled, so tools label them as untrusted data.
  • Can buy from paid APIs. fetch_paid(url, maxAmount, idempotencyKey) requests a URL; if the server answers HTTP 402 (see Paid APIs), it pays at most maxAmount, waits for the payment to confirm and returns the response. Retrying with the same key resumes the same payment, never a second one. For many requests to one service, add pullAllowance (e.g. "1 AETH"): if the service offers aether-pull, the agent grants it an on-chain allowance of that much (payable only to it, for 7 days, revocable, and approved by the owner like a payment of that size when it's over the approval threshold), then pays each request instantly by signature; the service collects what the agent owes later, so nothing is deposited with it. Or add prepay (e.g. "1 AETH"): the agent deposits that once and then pays each request instantly by signature — milliseconds instead of a block. list_prepaid_balances shows what's left where, and withdraw_prepaid(service) takes it back, from services that offer withdrawals.
  • Can find services, and tell good ones from bad. find_services(query, maxPrice) lists paid APIs from the on-chain service directory with each one's reputation: recent payments and payers, ratings from paying accounts, ratings from accounts you trust (the owner, the agent itself, --trust <addresses>), and the agent's own history with it. orderBy: "trusted" puts what can't be faked first. rate_service(url, score) rates one it has bought from; announce_service lists one the agent runs.
  • Hires other agents through escrow (once x/escrow is active: see docs/ESCROW.md). create_escrow locks AETH for a payee until this agent or an arbiter releases it, the payee or arbiter refunds it, or its deadline settles it the way onExpiry says; it counts against the same limits and owner approvals as send_aeth, takes an idempotency key, and isn't available in grant mode (the chain caps grant spending only for plain sends). release_escrow, refund_escrow, get_escrow (open, or how and by whom it was settled, including at the deadline) and list_escrows cover the rest; the payee checks get_escrow before starting work.
  • Knows where it stands as a miner. get_miner_status answers in one call, as of one block: whether the address has a registered consensus key, its work this epoch, its rank among eligible miners against the Top-K size, blocks and estimated seconds until the epoch's last block picks the next validator set, whether it's a validator now, and its escrowed rewards — no log scraping. The explorer serves the same at /api/miner?addr=.
  • Keeps receipts. When a seller signs receipts, fetch_paid checks each one against exactly what was sent and received and returns it; list_purchases is the log of what the agent bought, with each receipt — proof anyone can check against the seller's address.
  • Answers to its owner. With --approval-threshold "0.5 AETH" --approver <owner-address>, bigger payments wait (nothing signed or sent) until the owner runs agentmcp approve <id>, which signs the decision with the owner's key — so the agent can't approve itself even if it can write files on the machine. agentmcp approvals lists what's waiting. With --notify-webhook <url> (and --notify-secret to HMAC-sign each alert), every payment, approval request and refusal is POSTed there.
  • Wakes on new blocks. Waiting tools subscribe to the node's new-block events over --rpc instead of polling, falling back to polling if the feed is down.
  • No unit mistakes. Amounts must carry a unit ("1.5 AETH" or "1500000uaeth"); a bare number is refused rather than guessed at, and every result states amounts in both units and names the asset.
  • Pays in USDC too, when the owner allows it. With --usdc-channel <Aether's channel to Noble>, the agent knows USDC: Noble's uusdc over exactly that channel, never a lookalike that arrived another way. Spending it stays off until the owner sets its own caps, --usdc-per-tx-limit "5 USDC" --usdc-daily-limit "20 USDC" (and optionally --usdc-approval-threshold), separate from AETH's since there's no price to add them up with. Then send_aeth, create_escrow, create_invoice and wait_for_payment take "5 USDC" or "5000000uusdc", get_balance and get_spending_status list each asset, and an owner's approval is bound to the asset it was for. Without the caps, a USDC payment fails with ASSET_NOT_ENABLED. fetch_paid pays services priced in USDC (with maxAmount in USDC, and prepay or pullAllowance in USDC too: a USDC allowance is a send limit in USDC only), withdraw_prepaid returns a USDC balance, and find_services shows each service's asset.
  • Errors a bot can act on. Every failure is {"error":{"code","retryable","message"}} with a stable code (DAILY_LIMIT_EXCEEDED with retryAfterSeconds, INSUFFICIENT_FUNDS, GRANT_LIMIT_EXCEEDED, NODE_UNREACHABLE, ...); a failed transaction carries an errorCode too.

Two modes:

  • Hot wallet (default): pays from a dedicated agent account (created on first use), capped per transaction and per rolling 24h by the server itself — not by the chain. Fund it with only a small, disposable balance.
  • Grant (--granter): pays from your account under an x/authz grant you gave the agent (below), so the chain enforces the spend limit, expiry and allowed recipients, and you can revoke it at any time. The agent account needs no balance of its own. The server's caps still apply on top. Available from the activation height.

Read cmd/agentmcp/main.go's package doc comment before deploying either.

Client libraries (TypeScript, Python)

For agents and services that aren't MCP clients, clients/ts (@aether-chain/client) and clients/python (aether_client) implement the same things natively — no Go, no aetherd:

Shortened here. Read the whole README on GitHub.

Tools it offers (5)

What this server listed when ahel dialed its public endpoint in Oct 2026, with no key and no account of yours. The names are the server’s own.

  • find_services
  • get_account_authenticators
  • get_balance
  • get_miner_status
  • get_transaction_status

Signals

Last commit
Oct 2026
Advanced
Delivery
aether-wallet MCP server → your ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
io-github-whoyoujoshin-aether-wallet
Source
github.com/whoyoujoshin/aether
Hosted endpoint
https://explorer.157-245-252-221.sslip.io/mcp