Run the escrow
Enable the escrow so a coordinator can accept open-bid orders, and rotate its key.
Only a coordinator that accepts open-bid orders needs the escrow. Designated orders are sealed straight to a provider and never touch it. With the default ESCROW_MODE=off, the escrow routes answer 403 escrow_unavailable. See Escrow and key release for what it guarantees.
Enable it
Set ESCROW_MODE=static and an operator key:
ESCROW_MODE=static
OPERATOR_KEY=0x<32-byte secp256k1 private key>The escrow key pair is derived from OPERATOR_KEY, so:
- every instance with the same
OPERATOR_KEYholds the same key, and any of them serves any release; - a restart loses nothing;
- nothing rotates on a timer.
Keep OPERATOR_KEY as secret as RELAYER_KEY: whoever holds it can open every open-bid payload sealed to its key. Use a dedicated key for it.
Check it:
curl -s "$VORQ/key" | jq{ "escrow_public_key": "<64 hex characters>", "evidence": { "type": "static-coordinator-v1", "report_data": "…", "debug": false, "release": 1 }, "issued_at": 1786000000 }Rotate the operator key
OPERATOR_KEY takes a comma-separated list. The first entry derives the key that GET /key announces; every entry still opens payloads sealed to its key. Rotate in two restarts:
OPERATOR_KEY=K_new,K_old. New orders are sealed toK_new; orders already sealed toK_oldstill release.OPERATOR_KEY=K_new, once every order sealed toK_oldhas settled or ended.
Wait at least 51 hours between the two steps: clients may cache the announced key for up to 3 hours, an order can stay open for up to 24 hours, and a claimed job can run for up to 24 hours. Dropping K_old sooner leaves providers unable to open jobs sealed to it; they can still fail those jobs and the client is refunded.
Development mode
ESCROW_MODE=mock mints random keys in memory, rotates them every ESCROW_ROTATE_INTERVAL_MS and can copy them between instances with POST /handover (PEER_URL, PEER_REQUIRED, PEER_SYNC_S). Its attestation evidence is forgeable by design. Use it only for development and CI, and never expose it to the internet. The node logs a warning at boot in this mode.
The mock-only variables are listed in Configuration.