Skip to content
nara

Docs

How Nara works.

Plain answers: how an agent pays a person, who does what, what stays private, and what can go wrong.

Non-custodialper-job escrow
Livemainnet
01Overview

Cash for AI agents.

An AI agent has a wallet, but it can't open a PayPal, Zelle or bank account. Nara closes that gap. The agent pays in USDG on Robinhood Chain; a runner, an independent person with an account on that app, sends the money; an escrow contract holds the USDG until the payment is done.

The person paid gets an ordinary payment from the runner. They never see the agent or its owner. The recipient's details are sealed end to end for the one runner who takes the job.

It's non-custodial. Each job's USDG sits in the escrow contract, which can only pay the runner or refund the agent. Nara never holds the money and can't take it.

What works today

Oct 2026

  • Cash for agents

    SDK, MCP server, runners and the USDG escrow on Robinhood Chain mainnet

    Status: Live
  • Private account and @handles

    Stealth addresses on Robinhood Chain mainnet; runner earnings land here

    Status: Live
  • Exposure scanner

    Reads Robinhood Chain mainnet, read-only

    Status: Live
  • Agent console

    Plain-English plans in the app, you approve each; /agents is a demo

    Status: Live
  • Updates list

    Join with an email for launch news

    Status: Live
  • Status: Liveworks today
  • Status: Testnetworks on testnet, no real money
  • Status: Demoscripted preview
  • Status: Soonnot available yet
02How a payout worksStatus: Live

Five steps, one of them a person.

  1. 01

    The agent posts a job

    Rail, amount (up to $1,000), what kind of recipient detail it holds (an email, a phone, an IBAN…), a deadline and the highest runner fee it accepts. No recipient details yet. Runners see only the rail, the amount, the kind of detail, the fee cap and the deadline.

  2. 02

    A runner accepts

    A runner who pays on that rail takes it at a fee inside the agent's cap. The first valid acceptance wins. The runner publishes a fresh key for this job, a fresh address for the payout and a key to encrypt to.

  3. 03

    The agent seals the details and funds the escrow

    The agent's SDK checks the runner's signed acceptance, encrypts the recipient's details for that runner and locks amount + runner fee + Nara fee in USDG. An accepted job not funded within 15 minutes goes back to the board.

  4. 04

    The runner pays

    The runner decrypts the details, sends the money from their own account, uploads a sealed proof (a reference or a screenshot) and marks the job paid. A relayer submits that signature on-chain, so the runner needs no gas.

  5. 05

    It settles

    The agent can release the USDG early. Otherwise anyone can finalize the job 24 hours after it was marked paid, if there is no dispute: the runner receives amount + fee at their fresh address, Nara its fee.

A payout, state by state

  1. openagent posts↓ accept
  2. assignedrunner takes it↓ fund
  3. fundedUSDG locked↓ markPaid
  4. paid24 h window↓ finalize
  5. releasedrunner paid
  • funded or paid→release→released

    The agent can pay the runner early.

  • open→2 h, never funded→expired

    Nothing moved; the day's cap comes back.

  • assigned→15 min, not funded→open

    Back on the board for another runner.

  • funded→cancel or expire→refunded

    Runner backs out, or misses the deadline: full refund.

  • paid→dispute→disputed

    Agent only, inside the window.

  • disputed→resolve→released or refunded

    The arbiter rules on the evidence.

States as the API reports them. From funded on, the escrow contract is the source of truth.
03For developers

An SDK, an MCP server, no API keys.

The agent's address is its account. Every write to the API is signed by the agent's key: no sign-up, no email, no API key. A request carries x-nara-signer, x-nara-ts and x-nara-sig, a signature over the method, the path, a hash of the body and the time. Signatures older than five minutes, or seen before, are refused.

TypeScript SDK
nara-agent: createNaraAgent, then payFiat posts the job, waits for a runner, seals the details, funds the escrow and hands back a job you can wait() on, release() or dispute().
MCP server
nara-mcp, over stdio, with the key in NARA_AGENT_PRIVATE_KEY. Tools: nara_pay_fiat, nara_job_status, nara_release, nara_dispute, nara_balance, nara_rails.
Gas and USDG
The agent's address needs USDG for the payouts and a little ETH on Robinhood Chain for gas. The escrow accepts a signed permit, so funding is one transaction.
Status
The escrow is configured on Robinhood Chain mainnet.

The quickstart, the full API reference and your agent's jobs live in the developer hub.

04For runners

Runners are people with payment apps.

A runner picks the rails they can pay from, their limits and their fee, takes the jobs they want, sends the money from their own account and gets the amount back in USDG plus their fee. Start in the runner app.

Keys
Runner keys derive from the Nara keys you unlock with a wallet signature. Each job uses a fresh key, so a runner's jobs don't link on-chain.
Earnings
Each payout goes to a fresh one-time address only you can spend from, and shows up in your private balance in the app.
Reputation
A pseudonymous alias with a track record: jobs completed, on-time rate, disputes lost, a volume bucket. Never a name.
You front the money
You pay first and get reimbursed after the 24 h window. If the agent disputes and the arbiter rules against you, the agent is refunded. Keep your proof.
The apps' rules
You use your own accounts under each app's terms, limits included. Some apps restrict business use or payments on someone else's behalf: read their terms before you run.
Independent
Runners are independent people, not Nara staff. They pay from their own accounts and must follow those apps' terms and limits.
05The escrow

One contract, two ways out.

NaraCashEscrow holds USDG per job. Once funded, a job's USDG can go to exactly two places: the runner's address (amount + runner fee, with the Nara fee to the protocol), or back to the agent in full.

Funding
The agent funds a job with its terms: runner key, payout address, amount, both fees, deadline. Every check runs on-chain.
Fees
Nara fee: 1% of the amount, exactly (rounded down). Runner fee: at most 5%, and at most what the agent accepted.
Deadlines
The runner's deadline is set at funding, between 10 minutes and 48 hours.
What the owner can do
Change the arbiter, the treasury, the fees within their caps, the dispute window and the per-job cap, for new jobs only; pause new funding (every exit keeps working); recover tokens sent by mistake. No upgrades, and no access to escrowed USDG.
Blocked addresses
If the token refuses a payout (say its issuer froze the address), the job still settles and the amount waits as a claimable balance for that same address.
Source
Verified on Sourcify (exact match): anyone can read the code.
06Refunds and disputes

What happens when it goes wrong.

  • Not paid in time

    If the runner hasn't marked the job paid by its deadline, anyone can expire it: every USDG goes back to the agent.

  • The runner backs out

    Before paying, the runner can cancel with a signature: full refund to the agent.

  • Paid, but it didn't arrive

    The agent disputes before the 24 h window ends. Its SDK shares the recipient's details with the arbiter, sealed, so the arbiter sees exactly what the runner was asked to pay.

  • The arbiter decides

    Only on jobs the agent disputed, on the evidence: the sealed proof, the details, the timeline. It can send the escrowed USDG to the runner or back to the agent, nothing else.

07Who sees what

Sealed for one runner, invisible to the recipient.

The agent's SDK encrypts the recipient's details to the assigned runner's key (ECDH on secp256k1, HKDF-SHA256, AES-256-GCM). Our server stores the ciphertext and can't read it. Proofs are encrypted to the agent and sealed to the arbiter. Both are deleted 30 days after the job ends; the job record 180 days after (see the Privacy Policy).

  • The recipient's details · email, phone, IBAN

    Agent
    sees
    Runner
    sees1
    Payee
    sees
    Server
    never sees it2
    Chain
    never sees it
  • Who owns the agent · you

    Agent
    sees
    Runner
    never sees it
    Payee
    never sees it
    Server
    never sees it
    Chain
    never sees it3
  • The agent's address · 0x…

    Agent
    sees
    Runner
    sees
    Payee
    never sees it
    Server
    sees
    Chain
    sees
  • The runner's identity · their payment-app name

    Agent
    partly4
    Runner
    sees
    Payee
    sees
    Server
    never sees it
    Chain
    never sees it
  • Amounts and timing · dollars, USDG, when

    Agent
    sees
    Runner
    sees
    Payee
    partly5
    Server
    sees
    Chain
    sees
  • The proof of payment · reference, screenshot

    Agent
    sees
    Runner
    sees
    Payee
    never sees it
    Server
    never sees it6
    Chain
    never sees it
  1. 1The assigned runner only.
  2. 2Ciphertext only; if your agent disputes, the arbiter can open it.
  3. 3Unless you fund it from a wallet tied to you.
  4. 4Only if the proof shows it.
  5. 5The dollars they get.
  6. 6Ciphertext; the arbiter can open it, to decide disputes.

Notes travel sealed. The SDK's memo, the note the runner writes on the payment, is encrypted with the recipient's details. The raw API also takes an optional job label that our server stores in the clear and shows to the assigned runner: keep anything private out of it.

08The private accountStatus: Live

Where runner earnings land.

The Nara app is also a private account: pay and get paid by @handle or pay link, and every payment lands at a brand-new address only you can find and spend from. Runners' payouts arrive the same way.

  1. 01

    Sign once

    One message signed with your wallet derives your keys in your browser: one to spot payments, one to spend them. They're never sent to us or stored.

  2. 02

    Get paid at fresh addresses

    Each payment goes to a one-time address made from your public meta-address and fresh randomness, with a short public note your app can recognise.

  3. 03

    One balance

    Your app finds what's yours with your viewing key and shows one balance. On-chain, the addresses share no history.

Three payments, two views

Demo

Your view

in the app

  • @leo

    Concert tickets

    +$18.00
  • @maya

    Dinner, split 3 ways

    −$42.00
  • @ines

    Book club

    +$12.50

Public view

what a block explorer sees

  • 0x9c1e…44d0

    name hidden

    +18.00 USDG
  • 0xb24d…0c71

    name hidden

    −42.00 USDG
  • 0x6d02…a3f8

    name hidden

    +12.50 USDG
Amounts and times stay public, as on any blockchain. Names, and the links between your addresses, don't.
09Exposure scannerStatus: Live

See what anyone can already see.

Paste any Robinhood Chain address. The scanner reads public chain data only and shows what it gives away: holdings, counterparties, apps touched, first funding, active hours, and a score from 0 to 100. Try it.

Scan results
Cached on our server for up to 24 hours, then they expire.
Share links
A random ID, never the address. A shared card shows a coarse score and finding labels only.
Sign-up
None. No account, no wallet connection.
Exposure cardDemo

This wallet is

75/100 exposed

  • Exchange deposit
  • Linked wallets
  • Active hours

…/scan/s/k7Qm2x · random ID

Never on a shared card

  • Addressnot shown
  • Balancesnot shown
  • Counterpartiesnot shown

The link carries a random ID, so sharing your card doesn't tie you to your address.

10Agent consoleStatus: Live

Plain words in, a plan out.

The console demo shows an agent turning a request into a plan, step by step; its runs are simulated. In the app, the agent tab turns plain English into plans for your private account, and you approve each payment or move.

11Limits

What Nara can't hide.

  • The agent's address

    Funding the escrow is a public transaction. If you fund your agent from a wallet tied to you, that link is public too.

  • Amounts and timing

    USDG amounts and times are public on Robinhood Chain. The same amount at the same time can hint at a link.

  • The runner's name, to the recipient

    The person paid sees the runner's payment-app identity, as with any payment.

  • What the runner sees

    The assigned runner sees the recipient's details, the amount, any note and the agent's address.

  • The payment apps

    Each app sees the payment between the runner and the recipient, under its own privacy policy.

  • Our server

    It sees job records, runner profiles, IP addresses and timing, and stores ciphertexts it can't read. Sealed details and proofs go 30 days after a job ends, job records 180 days after, runner profiles 365 days after the runner's last activity.

12Risks

Risks, before you start.

  1. 01

    People in the loop

    Runners are independent people. They can be slow, make mistakes or act in bad faith; the escrow and disputes limit that risk, they don't remove it.

  2. 02

    The 24 h window

    Miss it and a job settles to the runner even if the money never arrived. Dispute within 24 hours of "paid".

  3. 03

    Reversible payments

    Payment apps can reverse, hold or limit payments and accounts. A runner can lose money that way.

  4. 04

    Final transactions

    On-chain transactions can't be reversed, by us or by anyone.

  5. 05

    Your keys

    An agent's key is its account and its money. Keep it out of logs and repos. A runner's keys come from a wallet signature: only sign the key message on this site.

  6. 06

    No insurance, no advice

    Balances aren't insured, and nothing here is financial advice.

13Acceptable use

What it's not for.

  • Illicit funds, money laundering or terrorist financing.
  • Fraud, scams, phishing or extortion.
  • Sanctions evasion, or paying sanctioned people, entities or regions.
  • Paying people who didn't agree to be paid.
  • Getting around a payment app's terms or limits.

Caps apply to every agent: $1,000 per job and $5,000 per day for now. The Terms of Use have the full rules.

14Non-affiliation

Who we're not.

Not a bank
Nara is not a bank. It doesn't take deposits, and balances aren't insured.
Not Robinhood
Nara is not affiliated with, endorsed by, or officially connected with Robinhood Markets, Inc. Robinhood Chain is a public blockchain; Nara is built on it.
Not the payment apps
Nara isn't affiliated with, endorsed by or partnered with PayPal, Zelle, Venmo, Cash App, Revolut, Wise or any app named here.
Names on this site
Company and product names are trademarks of their owners, used only to identify and compare.

Read the Terms of Use and the Privacy Policy. Both are drafts under legal review.

Give your agent a way to pay people.

Start with the SDK or the MCP server, or earn by running payouts.