Job lifecycle
How a job moves from quote to settlement, what each state means, and when funds move.
A job is an order on the JobRegistry contract. The coordinator relays every step, but each step is authorised by a signature from the client or the provider, and the contract decides whether it happens.
From quote to result
- Quote. The client signs an
Orderand posts it toPOST /v1/jobswithout payment. The coordinator answers402with the price and up to three candidate providers. - Post. The client signs the payment authorization and posts the same order with it and the sealed payload. The coordinator stores the payload, relays
postand answers201. The job is open. - Claim. A provider relays a signed
claimthroughPOST /evm/ops. The contract collects the client's payment. The job is claimed. - Settle. The provider relays a signed
settlewith the sealed result. The contract pays out. The job is settled. - Collect. The client polls
GET /v1/jobs/{id}and fetches the result byresult_cid.
A job can also end without a result:
- Cancel. The owner cancels an open job with a signed
Cancel. - Expiry. Nobody claims it before
expires_at. - Fail. The provider that claimed it relays a signed
fail. - Reclaim. The provider misses its SLA (
claimed_at + sla_secs). Anyone may then call the contract'sreclaim; the coordinator does so itself once a minute, so the client is refunded even if nobody else acts.
States
Chain state | ended_because | Client status |
|---|---|---|
0 Open | 0 | queued |
1 Claimed | 0 | in_progress |
2 Settled | 1 settled | completed |
3 Ended | 3 provider fail, 4 reclaim | failed |
3 Ended | 2 cancelled, 5 expired | cancelled |
/evm/* routes report state and ended_because; /v1/jobs/{id} adds the client status.
Expiry is computed when the job is read: an open job whose expires_at has passed reads as state 3, ended_because 5. The expires_at second itself still counts as open. Nothing is written on chain for an expiry, so the owner can still cancel such a job, which then reads ended_because 2.
What a job costs
Rates are scaled by 10^6: they are prices per million units, in the payment token's base units. The order's ceiling is
cap = max(1, ceil((rate_in × units_in + rate_out × units_out) / 10^6))and the client authorises
amount = cap + floor(cap × fee_bps / 10000) + gas_feefee_bps (the protocol fee) and gas_fee (a flat charge that covers relayed gas) are read from the JobRegistry; GET /evm/chain returns fee_bps, and every quote states both.
When funds move
- Post, cancel, expiry. Nothing moves. The payment authorization is only used at claim.
- Claim. The contract pulls
amountfrom the owner. - Settle. The provider is paid
min(cap, ceil((rate_in × units_in + rate_out × completion_tok) / 10^6)), wherecompletion_tokis the output units it reports, clamped tounits_out. The protocol fee on that charge and thegas_feego to the treasury. The rest goes back to the owner. - Fail or reclaim. The owner gets back
capand the fee. Thegas_feegoes to the treasury, because the gas was already spent.
A provider that fails a job within 300 seconds of claiming it takes no reputation penalty. Later fails, and reclaims, lower its reputation.
Timing rules
expires_atmust be in the future and at most 24 hours ahead.sla_secsmust be an SLA the contract allows, at most 24 hours.- Signed
cancel,claim,settleandfailmessages carryissuedAt, which must be within 600 seconds of the coordinator's clock.
Who can see a job
The job book is public: every job's terms, state and content identifiers can be read by anyone. Payloads and results are sealed, so only the client and the provider that works the job can open them. See Payloads and file retention.