Join our community of builders on Discord!

Custody and Trust

The API decrypts your answers

On Lightchain AI, prompts and answers travel encrypted under a session key: only the consumer, the worker serving the session and the protocol's disputers can read them. In the Lightchain AI chat, that key is made and kept in your browser. The Developer API is a drop-in replacement for the OpenAI API, and OpenAI clients know nothing about session keys. So the API holds the session keys for your key's sessions and does the encryption and decryption on its servers. Plainly:
  • The operator of the API can read your prompts and answers. They reach it over TLS in plaintext, and it encrypts them for the worker and decrypts the answers for you.
  • The session keys are stored encrypted, under a key kept outside the database.
  • Workers and disputers see what they see with the chat: the conversation carried by each job they serve or check.
If your prompts must stay confidential from the API's operator, use the chat, or talk to the protocol directly with session keys you hold yourself, instead of the Developer API. The same trade-off limits verification: you can prove which on-chain job produced your answer, but not check the decrypted text against the encrypted answer committed on chain, because you do not hold the key.

What the API can spend

The API spends only through your wallet's delegate authorization on JobRegistry (see Payment):
  • On chain, the delegate can spend at most its allowance, and only on jobs. It cannot withdraw or move your balance.
  • Per key, the lifetime spend cap you set bounds what that key can spend within the allowance.
  • You can withdraw your balance, or revoke the delegate, at any time with a transaction of your own.
A per-call payment spends only what its payer signed for: one job, at most its maxAmount, before its deadline, settled once. An API key is a spending credential up to those bounds. Keep it server-side, give each app its own, cap it, and revoke it the moment it leaks.

What your wallet signs

Using the Developer API needs a wallet to sign only two kinds of things:
  • the sign-in message, to manage API keys, and
  • the depositAndAuthorize transaction, to fund the prepaid balance and authorize the API's delegate (and again to top up).
Withdrawing the balance or revoking the delegate are ordinary transactions too, sent only when you choose.