Permissionless infrastructure for computation
ContextVM turns MCP into a sovereign network.
Not another AI tool. A transport layer that keeps MCP intact while removing the hosting assumptions of the old web stack.
No domains. No static IPs. No OAuth gatekeepers. Just keys, relays, and globally reachable services.
02 — Stakes
AI capabilities are spreading. Infrastructure power is not.
Remote computation is becoming central to how apps, agents, and people work — but deployment still gravitates toward hosted platforms, managed auth, centralized billing, and platform-controlled reachability.
Operational default
Most remote MCP patterns still assume cloud endpoints, DNS, TLS, and service operators.
Access model
Reachability, identity, and monetization are often mediated by external infrastructure and gatekeepers.
Unfinished promise
MCP is useful — but the network layer still decides who can deploy, discover, and get paid.
03 — Problem
Remote MCP still inherits the old web stack.
Useful protocol. Familiar deployment story. Same infrastructure bottlenecks: domains, hosting, auth stacks, public endpoints, and centralized payment rails.
The protocol can be open while the deployment model stays closed.
Hidden requirements
- Acquire and operate a public endpoint
- Manage DNS, TLS, uptime, reverse proxies, and edge routing
- Integrate OAuth, API keys, sessions, or account systems
- Rely on external payment or marketplace infrastructure
- Expose builders to policy, platform, and hosting constraints
04 — Thesis
Free MCP by changing its transport assumptions.
ContextVM runs MCP over Nostr. The application model remains MCP. The transport becomes public-key addressed, relay-routed, optionally encrypted, and globally reachable without the normal hosting ceremony.
MCP defines capabilities
Tools, resources, prompts, sampling, and request/response behavior remain familiar.
ContextVM defines transport
Messages ride through relays as Nostr events, signed by keys instead of tied to endpoints.
05 — Mechanism
Three layers. Clear separation of concerns.
ContextVM is easiest to understand as a transport layer inserted under MCP and above the Nostr relay network.
06 — Identity & security
Identity
Servers and clients are addressed by public keys, not by domain ownership or account records in a central database.
Integrity
Messages are signed and verifiable. Trust shifts toward cryptographic authorship and relay-observable events.
Privacy
Private interactions can use regular gift wraps via kind 1059 and ephemeral gift wraps via kind 21059, making encryption flexible instead of mandatory.
Reachability is public-key native. Privacy is layered on, not bolted on.
Why this matters
- Public servers stay easy to discover
- Private servers remain possible without bespoke account systems
- The same identity primitive works for humans, apps, and LLM clients
07 — Discovery & communication
Core event roles
| Kind | Purpose |
|---|---|
| 25910 | Primary transport event for MCP messages, typically ephemeral |
| 11316 | Public server announcements for discovery |
| 11317–11320 | Capability and server metadata lists |
| 1059/21059 | Gift wrap envelope for encrypted payloads |
Transport without lifecycle lock-in
JSON-RPC inside Nostr events
MCP messages ride as JSON-RPC payloads inside relay-routed events, so the transport stays machine-readable and schema-aware.
Stateful or stateless
Initialization can be used when helpful, but it is not required for stateless operation. The protocol does not force one lifecycle model.
Capabilities stay portable
Tools, resources, prompts, and notifications remain inspectable and composable across clients, UIs, and agents.
08 — Dual API
One service can speak to humans, apps, and LLMs at once.
MCP is fundamentally a JSON-RPC capability layer with structured schemas for tools, resources, prompts, inputs, and outputs. That makes the same service legible to software, renderable into human interfaces, and natively useful to LLMs that already understand MCP.
09 — Ecosystem
SDK, gateway, proxy, CVMI — choose the layer you need.
TypeScript SDK
Build native ContextVM clients and servers with transports, signers, relay handlers, and payment integrations.
Gateway
Expose an existing MCP server to the ContextVM network without rewriting its application semantics.
Proxy
Connect standard MCP clients to remote ContextVM services by translating transport expectations.
CVMI
Use the CLI as the Swiss Army knife for serving, using, testing, and exploring the ecosystem.
10 — Use cases
public
Open utility servers
Publish capabilities to the network and let any compatible client discover and use them.
private
Encrypted personal services
Run private agents, assistants, or device services addressed by keys and shielded by gift wrapping.
local-first
Garage deployment
Ship services from home labs, laptops, or community infrastructure without first becoming a cloud operator.
Community-owned infra
Co-ops, collectives, and small teams can expose capabilities globally without outsourcing the trust boundary to platform intermediaries.
Monetized services
With CEP-8, services can advertise pricing and negotiate settlement through PMIs, keeping payment rails extensible instead of hard-wired to a single network.
Trust and reputation engines
Projects like Relatr and Wotrlay show how relay-visible computation can shape reputation, moderation, and trust-aware routing.
Sovereign personal software
Blovm, Nutoff, and KeePass-CVM point to a world where storage, wallets, and secrets management remain user-controlled but globally reachable.
Composable public services
Geo servers, analytics tools, media metadata services, and experimental AI apps become reusable network primitives instead of siloed products.
11 — Comparison / proof
| Dimension | Traditional remote MCP | ContextVM |
|---|---|---|
| Addressing | Domain, URL, public endpoint | Public keys plus relay reachability |
| Deployment assumptions | Cloud or managed hosting, edge config, TLS, uptime stack | Any node that can sign, relay, and speak the protocol |
| Identity model | Accounts, API keys, OAuth, custom auth | Cryptographic identity with optional encrypted payloads |
| Discovery | Directories, docs, manual endpoint sharing | Relay-published announcements and capability events |
| Payments | Usually separate, platform-specific, externally mediated | PMI-based and payment-rail agnostic, with pricing and settlement negotiated at the protocol layer |
12 — Tradeoffs & maturity
Running protocol, still expanding
ContextVM is already powering services in production. The spec is still being refined because the network is alive, not because the model is unproven.
Relay-native advantage
By building on Nostr, ContextVM inherits an existing open communication fabric instead of waiting for a new network to be invented from scratch.
Ecosystem headroom
Payments, discovery, encryption, client generation, UI generation, and new capability patterns still have room to grow — which is exactly why this layer matters now.
This is not a speculative idea. It is working infrastructure with room to become a much larger ecosystem.
13 — Closing
Computation should be publishable like speech — not deployable only with permission.
ContextVM makes MCP portable, sovereign, and network-native by anchoring it in keys, relays, and open protocols.
ContextVM is the transport layer that lets open capability systems live on open network infrastructure.