Daimon

anatomy of a walk · onchain agent payments

What walk

Every agent pays for its own work across three rails — Sui for its identity, Solana for its money, OpenRouter for its model. Today that runs on Sui testnet and Solana devnet, and every payment is on chain.

The flow

Spawning an agent happens once, from any of four doors. After that no one presses anything: the supervisor runs the agent's loop every 120 seconds until the operator pauses or retires it — or nobody looks at it for 15 minutes and it pauses itself.

spawn · oncedaimon.runtelegram /spawn/accountPOST /api/v1/agentssupervisorcreate the agentPOST /admin/create-agent→ agent id + owner tokensuiagent objectdaimon::agent::newsolanaits own keypaira fresh wallet, per agentsolana1 USDC dripfrom the operator treasurythe loop · every 120 s · no human in itissuer + suimint keyfirst tick onlyset_active_key → Suix402 · solanaself-chargeonly if key < $0.0625+$1.00 to the keyproxy · openrouterusethe agent's modeldebit per callproxy · openrouterreflectreasons over its replya second paid callsuiattestWalkRecorded event1 in 10 paid callsnext tickbeside the loop: wallet under $0.0625 → the treasury tops it up 1 USDC (checked every 60 s)15 min without anyone viewing it → the agent pauses itself

The operations — create, charge, use, reflect — also exist as four Nexus DAG vertices published on Sui. Today the supervisor runs them back to back itself; Talus DAG-execute as the live orchestrator is a later step. The breakdown below is what each one does on its rail.

Vertex by vertex

01create_api_key
issuer + Suigas only
On the agent's first tick, daimon-issuer mints a key bound to its agent_id with balance = 0, and the agent binds it on chain with set_active_key. No money moves — only Sui gas for that one call.Proves: the agent has an onchain identity that holds its own credentials, separate from the operator.
02charge_api_key
Solana1 USDC
Only when the key drops below $0.0625. The agent builds an x402 (v1, exact) payment signed by its own Solana keypair and hands it to the issuer, which settles it through the facilitator at x402.org/facilitator. The SPL USDC transfer moves agent_wallet → issuer_wallet on Solana devnet, and the issuer credits the key $1.00.Proves: agent pays with onchain money it controls. Tx hash is explorer-clickable in the ledger.
03use_api_key
OpenRouter~$0.0125
The harness presents the issued key to daimon-x402-proxy. Proxy validates the key on the issuer, debits the agent's per-call price (12500 micro USDC for paid models by default), and forwards the prompt to the agent's model on OpenRouter. A second paid call follows: the agent reflects on its own reply.Proves: agent consumes the API access it just paid for, end-to-end, in one walk.

What this proves

  • 01
    Agent has its own onchain identity — daimon::agent::new mints a shared agent object on Sui holding the agent's identity, its active key, and its walk history. The operator holds the object's owner capability and signs its Sui transactions; the money the agent spends is its own.
  • 02
    Agent owns its API access — The issued key is bound to agent_id. It cannot be reused by another agent or reissued without going through the agent's onchain identity.
  • 03
    Agent pays with onchain money — The charge is a real SPL USDC transfer on Solana, signed by the agent's own keypair, settled by Coinbase's CDP facilitator. No operator pocket money. No credit card on file.
  • 04
    Agent consumes the paid-for access — The LLM call goes through a proxy that debits the key per call, at the agent's own price. Usage is gated by paid credit, not by an operator-held API key.
  • 05
    The full loop is auditable + reproducible — Solana has every payment tx. Sui has the agent object, its active key, and a WalkRecorded event for one in ten paid calls. The live ledger links each to its explorer.

Where this sits

The original demo spec called for a four-operation skill the agent uses on its API access: create / charge / schedule / cancel. The live walk implements the first two end-to-end:

  • create_api_key — mint a key, gas only.
  • charge_api_key — pay USDC via x402 to add credit.
  • schedule_refill / cancel_schedule — v0.5, deferred. The recursive harness already self-charges on a threshold, which is the same guard rotated inline.

Stripe and Coinbase are shipping rails for agents to pay. The missing counterparty is the agent itself — a persistent, self-funded, onchain entity that does the paying. Daimon is that counterparty.

USDC has a chain problem

Daimon's agent identity, policy, and ledger live as Move objects on Sui. The x402 payment rails are on Solana — that's where Coinbase's CDP facilitator settles SPL USDC transfers. So the agent has to spend on Solana what it (eventually) earns or holds on Sui. The catch: USDsui (Sui Move coin) and SPL USDC (Solana SPL account) are not the same token. Circle issues both under the same logo, but they live on different chains and settle on different rails.

Circle's CCTP is the canonical burn-and-mint bridge, and Solana ↔ Sui works over it today in one hop (~25 s, ~$0.006). But Sui only supports CCTP V1, V1 deprecation begins 2026-10-31, and Sui V2 has no date — so an automated bridge built now would be thrown away within months.

today · livesolana · operatortreasurysolana usdcfunds every agentsolana · the agentagent wallet1 USDC at spawntopped up when lowx402self-chargethe agent signs$1 per chargeissuerapi key creditwhat the agent spendsper callplan · sui side · buy it, don't bridge itsui · operatorsui usdc treasurybought on suinever bridgedsui · the agentagent sui accountfunded by the key thatsigns its sui txsno CCTP code on the money path:V1 deprecation begins 2026-10-31,and Sui has no CCTP V2 date yet

So agents don't bridge. Today every agent's Solana wallet is funded from the operator treasury — 1 USDC at spawn, and a top-up whenever it runs low — and nothing crosses chains inside a tick. The plan for Sui-side balances has the same shape: buy USDC on Sui into one operator-held treasury, and fund agents from it with the key that already signs their Sui transactions. No new code on the money path.

Honest limitations

  • Talus leader is centralized today. Permissionless leader fleet is on Talus's roadmap.
  • LLM inference is signed-HTTP only (transport integrity, not attested compute). Sui Nautilus TEE wrap is the v1 path.
  • Sui records a sample of the work — one WalkRecorded event per ten paid calls — not every call. Every payment is on Solana.
  • Networks are Sui testnet and Solana devnet until mainnet.
  • Schedule + cancel operations and per-agent runtime via DePIN are v0.5+ scope.

One sentence

walk = a Sui agent paying, with Solana USDC it signs for itself, for the OpenRouter calls it makes — every payment on chain.