Submit a bid · Grab the job · Sign the job

Evolution of The Robot Services Exchange

A technical history of the protocol, 2025-08-10 → 2026-09-17

This document is an engineering history of The Robot Services Exchange, reconstructed from git log on main in theservicesexchange (262 commits, about 176k insertions, 10 August 2025 through 17 September 2026). It is for physicists and engineers who already have the business plan: what shipped, what was tried and deleted, and how the matching loop, seats, and demand surfaces sit relative to one another.

The RSE robot mascot — white and blue bust with visor eyes
262
commits on main
13 mo
Aug 2025 → Sep 2026
11k
founding seats issued

1. How the exchange works

The first commit (87a45fa, 10 August 2025) is already a Flask API and JSON documents for accounts, bids, jobs, and tokens. Persistence later moved to DigitalOcean Spaces (S3-compatible JSON): each record is an object by id, and any index is another object. There is no SQL database. The loop that commit implemented is still the one that runs:

  1. Bid. Demand posts a priced, expiring service request (POST /bid or the website form): what is wanted, how much, where, how long it stays open.
  2. Grab. Supply calls POST /grab_job with free-text capabilities and, for physical work, a location (optional geohash cell).
  3. Match. The server filters by location, asks an LLM whether those capabilities cover this job, then ranks remaining jobs by reputation alignment and price. A successful grab starts a 900-second cooldown on that account.
  4. Sign. Both sides complete the work and POST /sign_job with a 1–5 star rating. The job is completed only after both signatures. Reputation is a mean of stars shrunk toward 2.5, so a single five-star rating is still a short record.

Price and currency are recorded on the request. The parties settle off-platform. Seats are not money. When seat verification is on, a seat authorizes the grab and is stamped on the job as the supply public identity. The LLM is called only in matching (match_service_with_capabilities).

2. Demand, website, and API

The repository opened as the “Service Exchange (SEX) Protocol,” a general marketplace, and the public name became The RSE (The Robot Services Exchange) as the copy specialized to robot labor. Registration requires user_type ∈ {demand, supply}, set once, one role. Demand’s public identity is a username. Supply’s is a seat when one is assigned.

Website · demand

therobotservicesexchange.com (cut over 11 August 2026). People register as demand and submit bids from the homepage form. The Android app (1.5.5) is the same demand role over the API, with Nearby, privacy dials, and auto-update.

API · supply

rse-api.com:5003. Robots and operators register as supply, call /grab_job, job channels, parties, and campaigns. OpenAPI 1.3.0. The docs page runs the integration suite against production.

3. Timeline

Commits per month on main. Aug 2025–Jan 2026: 11–27 / month. Feb 2026: 0. Mar: 37 (NFT launch). Apr–May: 5 and 1 (after soulbound). Jul: 60 (mode). Aug: 35. Sep through the 17th: 13.

commits / month A25 S O N D J26 F M A M J J A S 60 · Jul 2026
2025-08-10
Genesis. Flask API, Anthropic Haiku matcher, local JSON. Bid, grab, dual-sign.
2025-08-26
File seats. seats.dat: id, owner, 12-word phrase. Grab sent md5(phrase). Golden (physical); Silver (software, 1-minute limit).
2025-10-03
OpenRouter. Matching model is an HTTP endpoint with free and paid fallbacks.
2025-12-03
Roles. user_type required at register. Homepage is a bid form.
2026-03-18
Base NFT. ERC-721 RSESeat (chain 8453). /set_wallet; grab checks seat_active.
2026-04-23
Soulbound. On-chain transfers revert. Title moves only through the contract owner.
2026-07-10
Cooperation. Job parties, campaigns, agent tokens, activity log, job channels, taxi reference client (geohash whitelist).
2026-07–08
Surfaces. Demand Android app (now 1.5.5), Nearby + DP, catalog, Garage, hiring / investors. The SPA and Hyperion Fund pages were later removed.
2026-09-10
Matching v3. Integer 0–10, threshold 7. Disjoint domain lexicons score 0 with no LLM call.
2026-09-14
Registrar. Wallets and NFT code deleted (~82k lines, mostly lockfile and artifacts). Mickey Shaughnessy keeps the book. Seats transferable.
2026-09-17
Phrase proof. Seat = number, owner, phrase. Daily SHA-256 at grab. Remote software skips the seat. 1–1000 Dr. Aftab; 1001–11000 Amanda Jean. Gate off.

4. Seats

A seat is a number, an owner, and a private 12-word phrase. Seats are not money. All seats are identical. The price of a seat is $0. A demand account or a supply account calls POST /seats/issue and receives the next seat. Mickey Shaughnessy remains the registrar: he assigns, transfers, and revokes. Transfer keeps the phrase and updates the owner. With SEAT_VERIFICATION_ENABLED on, physical and hybrid grabs present the seat number, the owner name, and a daily hash of the phrase; remote software grabs skip the seat. Production cooldown is 900 seconds per account. Three books were used:

File book (2025)Base NFT (2026 Q1–Q3)Registrar + phrase (now)
Object JSONL: id, owner, BIP39 phrase ERC-721 on Base (chain 8453) Spaces JSON: number, owner, phrase
Proof at grab md5(phrase), replayable Wallet linked; eth_call isValidSeat SHA-256(phrase | UTC date), ±1 day
Transfer Mickey edits the file Then soulbound (revert any transfer) Mickey updates the book; phrase stays
Software bots Silver seats, 1-min limit Same NFT gate (usually off) Remote grabs skip the seat
Failure mode Phrase leak = permanent secret RPC outage, gas, soulbound illiquidity Registrar compromise; daily hash replay in-window

secret = SHA-256( phrase ‖ "|" ‖ YYYY-MM-DDUTC )  ∈ {today−1, today, today+1}

5. Matching

After location filtering (type, distance, optional geohash cell), remaining bids are scored for capability fit, then ordered by how close the buyer’s reputation is to the provider’s, then by price. Only the capability step calls an LLM. Four prompts were used; the failure modes moved with the wording.

ModelOutputRule
Aug 2025 Claude 3 Haiku, SDK YES / NO YES only if the provider can definitely fulfill the request; partial overlap is NO.
Oct 2025 OpenRouter (free, then paid fallback) YES / NO Same binary; if the model is silent, keyword overlap of at least two tokens.
Later, pre-Sep 2026 OpenRouter YES / NO “Be lenient”: a plausible chance is YES. Cross-domain false positives show up in tests.
10 Sep 2026 OpenRouter, max 8 tokens 0–10, grab if ≥ 7 Twelve domain lexicons; disjoint non-empty domains score 0 without an LLM call.
You score whether a provider can perform THIS exact job. Reply with one integer 0-10. 0-3: different domain (chef vs construction vs UAV/defense vs nursing vs lawn). 7-10: clearly has the skills or equipment for this job. Do not score 7+ across domains. Score:

Lexicons (disjoint non-empty sets → score 0, no LLM call):

6. Runtime

Stack

  • Flask + gunicorn, one DigitalOcean droplet
  • nginx TLS, floating IP
  • JSON on Spaces; no relational store
  • Worker caches: 2 s for accounts and jobs (workers do not share memory)
  • Seat book: seats/_index.json + one file per seat (~500 kB for 11k)

Added, then removed

  • Rideshare UI
  • Comms / cooperation APIs (deprecated, then restored; grab stayed off the website)
  • Phantom and ETH linking (until 14 Sep 2026)

July 2026 additions:

7. Seats

A seat is a number and an owner. All seats are identical. The price of a seat is $0. A demand account or a supply account calls POST /seats/issue and receives the next seat. Demand-side access and supply-side access are free forever. The SPA and the Hyperion Fund pages are gone. The investors model records seat revenue at $0 and a Hyperion Fund fee of $0.

8. Future work

From git log on main through 17 September 2026 (262 commits). Matching prompts: handlers.py. Seat objects: seats.dat, RSESeat.sol, seats.py. Engineering history.