Submit a bid · Grab the job · Sign the job
Evolution of The Robot Services Exchange
A technical history of the protocol, 2025-08-10 → 2026-09-17
This document is an engineering history of The Robot Services Exchange, reconstructed from git log on main in theservicesexchange (262 commits, about 176k insertions, 10 August 2025 through 17 September 2026). It is for physicists and engineers who already have the business plan: what shipped, what was tried and deleted, and how the matching loop, seats, and demand surfaces sit relative to one another.
1. How the exchange works
The first commit (87a45fa, 10 August 2025) is already a Flask API and JSON documents for accounts, bids, jobs, and tokens. Persistence later moved to DigitalOcean Spaces (S3-compatible JSON): each record is an object by id, and any index is another object. There is no SQL database. The loop that commit implemented is still the one that runs:
- Bid. Demand posts a priced, expiring service request (POST /bid or the website form): what is wanted, how much, where, how long it stays open.
- Grab. Supply calls POST /grab_job with free-text capabilities and, for physical work, a location (optional geohash cell).
- Match. The server filters by location, asks an LLM whether those capabilities cover this job, then ranks remaining jobs by reputation alignment and price. A successful grab starts a 900-second cooldown on that account.
- Sign. Both sides complete the work and POST /sign_job with a 1–5 star rating. The job is completed only after both signatures. Reputation is a mean of stars shrunk toward 2.5, so a single five-star rating is still a short record.
Price and currency are recorded on the request. The parties settle off-platform. Seats are not money. When seat verification is on, a seat authorizes the grab and is stamped on the job as the supply public identity. The LLM is called only in matching (match_service_with_capabilities).
2. Demand, website, and API
The repository opened as the “Service Exchange (SEX) Protocol,” a general marketplace, and the public name became The RSE (The Robot Services Exchange) as the copy specialized to robot labor. Registration requires user_type ∈ {demand, supply}, set once, one role. Demand’s public identity is a username. Supply’s is a seat when one is assigned.
Website · demand
therobotservicesexchange.com (cut over 11 August 2026). People register as demand and submit bids from the homepage form. The Android app (1.5.5) is the same demand role over the API, with Nearby, privacy dials, and auto-update.
API · supply
rse-api.com:5003. Robots and operators register as supply, call /grab_job, job channels, parties, and campaigns. OpenAPI 1.3.0. The docs page runs the integration suite against production.
3. Timeline
Commits per month on main. Aug 2025–Jan 2026: 11–27 / month. Feb 2026: 0. Mar: 37 (NFT launch). Apr–May: 5 and 1 (after soulbound). Jul: 60 (mode). Aug: 35. Sep through the 17th: 13.
4. Seats
A seat is a number, an owner, and a private 12-word phrase. Seats are not money. All seats are identical. The price of a seat is $0. A demand account or a supply account calls POST /seats/issue and receives the next seat. Mickey Shaughnessy remains the registrar: he assigns, transfers, and revokes. Transfer keeps the phrase and updates the owner. With SEAT_VERIFICATION_ENABLED on, physical and hybrid grabs present the seat number, the owner name, and a daily hash of the phrase; remote software grabs skip the seat. Production cooldown is 900 seconds per account. Three books were used:
| File book (2025) | Base NFT (2026 Q1–Q3) | Registrar + phrase (now) | |
|---|---|---|---|
| Object | JSONL: id, owner, BIP39 phrase | ERC-721 on Base (chain 8453) | Spaces JSON: number, owner, phrase |
| Proof at grab | md5(phrase), replayable | Wallet linked; eth_call isValidSeat | SHA-256(phrase | UTC date), ±1 day |
| Transfer | Mickey edits the file | Then soulbound (revert any transfer) | Mickey updates the book; phrase stays |
| Software bots | Silver seats, 1-min limit | Same NFT gate (usually off) | Remote grabs skip the seat |
| Failure mode | Phrase leak = permanent secret | RPC outage, gas, soulbound illiquidity | Registrar compromise; daily hash replay in-window |
- Base ERC-721: globally visible token ids, owner revoke/unrevoke, 15-minute in-process cache so grab did not eth_call on every request.
- Soulbound (23 Apr 2026): transfers revert. Title still moved through the contract owner, plus wallets, a public RPC, and an unsellable token.
- 14 Sep 2026: chain code deleted (~82k lines, mostly lockfile and artifacts). Mickey Shaughnessy is the registrar.
- 17 Sep 2026: back to number, owner, 12-word phrase. Proof:
secret = SHA-256( phrase ‖ "|" ‖ YYYY-MM-DDUTC ) ∈ {today−1, today, today+1}
- Same shape as TOTP, period 86,400 s, ±1-step window (midnight UTC).
- Phrase is never sent. Owner string must match the book (case-insensitive).
- Founding book: 1–1000 Dr. Aftab; 1001–11000 Amanda Jean (same split as old seats.dat).
- SEAT_VERIFICATION_ENABLED = False. When on, location_type=remote skips the seat (old Silver band).
5. Matching
After location filtering (type, distance, optional geohash cell), remaining bids are scored for capability fit, then ordered by how close the buyer’s reputation is to the provider’s, then by price. Only the capability step calls an LLM. Four prompts were used; the failure modes moved with the wording.
| Model | Output | Rule | |
|---|---|---|---|
| Aug 2025 | Claude 3 Haiku, SDK | YES / NO | YES only if the provider can definitely fulfill the request; partial overlap is NO. |
| Oct 2025 | OpenRouter (free, then paid fallback) | YES / NO | Same binary; if the model is silent, keyword overlap of at least two tokens. |
| Later, pre-Sep 2026 | OpenRouter | YES / NO | “Be lenient”: a plausible chance is YES. Cross-domain false positives show up in tests. |
| 10 Sep 2026 | OpenRouter, max 8 tokens | 0–10, grab if ≥ 7 | Twelve domain lexicons; disjoint non-empty domains score 0 without an LLM call. |
Lexicons (disjoint non-empty sets → score 0, no LLM call):
- culinary, delivery, health, landscaping, construction, defense
- software, finance, pets, events, hazmat, emissions
- Live suite: 34 cases, 33/34. Remaining false positive: adjacent-domain (aerial survey).
6. Runtime
Stack
- Flask + gunicorn, one DigitalOcean droplet
- nginx TLS, floating IP
- JSON on Spaces; no relational store
- Worker caches: 2 s for accounts and jobs (workers do not share memory)
- Seat book: seats/_index.json + one file per seat (~500 kB for 11k)
Added, then removed
- Rideshare UI
- Comms / cooperation APIs (deprecated, then restored; grab stayed off the website)
- Phantom and ETH linking (until 14 Sep 2026)
July 2026 additions:
- Demand and supply parties; campaigns (bulk demand → ordinary jobs)
- Agent bearer tokens under a parent account; append-only activity log; public portfolios
- Taxi client: poll grab with a geohash whitelist, job channel, sign
- Nearby pins: Gaussian noise, σ from a privacy dial, stable per entity × UTC day
7. Seats
A seat is a number and an owner. All seats are identical. The price of a seat is $0. A demand account or a supply account calls POST /seats/issue and receives the next seat. Demand-side access and supply-side access are free forever. The SPA and the Hyperion Fund pages are gone. The investors model records seat revenue at $0 and a Hyperion Fund fee of $0.
8. Future work
- Seat gate. Daily hash is implemented. Flip SEAT_VERIFICATION_ENABLED. Remote software stays ungated. The 11,000 founding seats are for physical and hybrid density.
- Cooldown per seat. Cooldown is per account, so many logins on many of Aftab’s or Amanda Jean’s seats can grab in parallel. A last_grab_at on the seat record would limit grabs per seat.
- Matching calibration. 0–10 is ordered. Remaining false positive is adjacent-domain. Next measurement: confusion matrix over the twelve lexicons.
- Store scale. 11k-seat index is ~500 kB. A billion seats (2035 planning figure on the investors page) needs a different layout.
- Chain as a mirror. A later chain could copy the registrar. The NFT-as-primary-book run already happened.
From git log on main through 17 September 2026 (262 commits). Matching prompts: handlers.py. Seat objects: seats.dat, RSESeat.sol, seats.py. Engineering history.