thefux 667f9bf6bb test: money-path audit — 8 RED tests for live fund-loss vulnerabilities
Comprehensive audit of all money-moving code paths on current main.
Found 8 live vulnerabilities where users, providers, or node runners
can lose funds, plus 1 false-green in the existing emergency refund
test suite.

Live vulnerabilities (all RED — tests assert correct/safe behaviour):

V-E1  send_refund() swallows DB failure after minting a refund token
      base.py ~line 3625 — except Exception: pass
V-E2  Emergency refund (chat) — same except: pass
      base.py ~line 3992 (existing test is a false green — 500-char
      window too short)
V-E3  Emergency refund (responses API) — identical pattern
      base.py ~line 4972
V-E4  Balance refund endpoint swallows DB failure
      balance.py ~line 628
V-E5  credit_balance() swallows 'in' transaction DB failure
      wallet.py ~line 1715
V-E6  EHBP refund token — except: pass after store
      ehbp.py ~line 762
V-E7  EHBP 'in' transaction — except: pass after store
      ehbp.py ~line 1028
V-E8  Admin withdraw returns token even when DB store fails
      admin.py ~line 475

V-E9  Window regression guard (GREEN) — documents the false-green in
      the existing test_emergency_refund_no_try_except_pass

Test results: 8 failed, 1 passed.
2026-08-06 20:58:06 +00:00
2026-08-05 00:49:17 +02:00
2026-08-05 00:49:17 +02:00
2026-07-24 01:10:57 +02:00
2025-10-22 12:18:00 +08:00
2026-08-04 01:32:25 +02:00
2025-11-23 21:51:16 +00:00
2025-10-27 12:38:55 +08:00
2025-06-09 23:46:19 +02:00
2025-08-12 15:02:22 -03:00
2026-07-07 17:22:48 +02:00
2025-04-08 21:42:32 +08:00
2026-01-24 17:55:45 +08:00
2025-08-01 22:31:18 -03:00

Routstr Payment Proxy

License Stars Issues Release

Routstr is a decentralized protocol for permissionless, private, and censorship-resistant AI inference. It combines Nostr for discovery and Cashu for private Bitcoin micropayments.

This repo contains Routstr Core: a FastAPI-based reverse proxy that sits in front of OpenAI-compatible APIs and handles pay-per-request billing.

Start Here

Basic Usage

If you are a user/developer, you just point an OpenAI-compatible SDK at a Routstr node and pay with a Cashu token.

OpenAI SDK

from openai import OpenAI

client = OpenAI(
    base_url="https://api.routstr.com/v1",
    api_key="cashuBo2FteCJodHRwczovL21...",
)

response = client.chat.completions.create(
    model="gpt-5-nano",
    messages=[{"role": "user", "content": "hello"}],
)

print(response.choices[0].message.content)

cURL

curl https://api.routstr.com/v1/chat/completions \
  -H "Content-Type: application/json" \
  -H "x-cashu: cashuBo2FteCJodHRwczovL21..." \
  -d '{
    "model": "gpt-5-nano",
    "messages": [{"role": "user", "content": "hello"}]
  }'

Quick Start (Docker)

If you are a node runner, start a Routstr Core instance using Docker Compose:

  1. Prepare your .env:

    # Optional: encrypts node secrets at rest. If unset, the node generates a key
    # on first start, writes it to routstr_secret.key, and prints it once — back
    # up that file. Set it explicitly to manage the key yourself (recommended in
    # production).
    ROUTSTR_SECRET_KEY=<generated-key>
    NAME="My AI Node"
    DESCRIPTION="Fast access to models"
    RECEIVE_LN_ADDRESS=yourname@wallet.com
    

    Your Nostr identity (nsec) is not set in .env — configure it from the admin UI after first start, where it's stored encrypted in the database. (NSEC in .env is still read once as a legacy seed for existing deployments.)

    If you don't set one, a key is generated and printed on first start — save it somewhere safe (losing it makes previously encrypted secrets unreadable). To supply your own, generate it once and keep it stable:

    uv run python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
    
  2. Start the services:

    docker compose up -d
    
  3. Get your admin password: On first start the node generates an admin password and logs it once with the /admin URL. Read it from the logs:

    docker compose logs routstr | grep -i admin
    

    (Lost it? Reset with docker compose exec routstr /.venv/bin/python scripts/reset_admin_password.py --regenerate.)

  4. Configure: Open http://localhost:8000/admin/ to connect your AI providers and set pricing.

For full instructions, see the Provider Quick Start Guide.

Development

make setup
cp .env.example .env
fastapi run routstr
S
Description
Routstr is a decentralized protocol for permissionless, private, and censorship-resistant AI inference.
Readme GPL-3.0
10 MiB
Languages
Python 68.8%
TypeScript 29%
HTML 1.5%
Makefile 0.3%
Shell 0.2%
Other 0.1%