costheta: physically anchored, verifiable decisions for AI agents.

Ed25519 + ML-DSA · post-quantum signed today · EU PQC Roadmap target: 2030

Commit first. A subsequent cosmic-ray detector event enters the derivation. Receive a dual-signed certificate from which the outcome can be recomputed. Free beacon, paid certificates, native MCP.

LIVE · SINGLE-NODE CERTIFICATES
One detector · one operator · one attestation. The federation-ready certificate format is deployed; fully attested certificates begin with the second independent operator.

A computation consulting a source it did not produce. Why costheta exists →

add to your agent →
muon #4417 · 14:32:07 UTC · 1014.2 hPa simulated
request
{
  "tool": "costheta_decide",
  "arguments": {
    "options_hash": "sha256:9f2c…41ab",
    "n_options": 3
  }
}
signed certificate
{
  "decision": 1,
  "muon": { "id": 4417, "utc": "…14:32:07.412Z" },
  "commit": "sha256:9f2c…41ab",
  "sig_ed25519": "7KqR…mVw",
  "sig_mldsa": "mB4tX9…c2Fk8rW1…pQz7",
  "verify": "costheta.dev/v/4417"
}
how it works
01 · COMMIT

Hash your options locally and send only the commitment and option count. The option list remains with you. The commitment is recorded before the eligible detector event.

02 · DETECTOR EVENT

The next qualifying coincidence event recorded by the detector enters the public derivation. Individual detection times are not predictably known in advance; the underlying interactions and decays include quantum processes.

03 · CERTIFICATE

Receive an Ed25519 + ML-DSA certificate binding the commitment to the signed event record. Anyone can verify the signature, record integrity, commitment binding and outcome derivation using the certificate and published keys. Current certificates carry one node attestation.

in plain words

Most decisions do not need costheta. If nobody will dispute the outcome, use a local generator: it is faster, free and sufficient.

When a choice may be challenged, a bare local result cannot show where the deciding entropy came from or whether it was chosen to suit someone. costheta records the commitment first, derives the result from a subsequent detector event, and returns a signed certificate that any party can recompute.

Current single-node certificates still require trust in the operator's physical record. The certificate format is federation-ready: a fully attested certificate combines contributions from independent nodes, so no single operator can produce one alone.

costheta does not give a machine an experience of the physical world. It gives it evidence of a causal connection to one.

Read why costheta exists →

mcp tools
costheta_random free

Random bits from the latest public detector pulse. No payment, no account and no request-specific certificate. Public output: not for secret key material.

limit: not for cryptographic keys

costheta_decide paid

Commit-and-derive decision: send an options commitment and option count. A subsequent qualifying detector event enters the derivation. Receive the outcome and a signed, recomputable certificate.

current certificate level: single-node · latency up to ~30 s

costheta_witness paid

Binds a caller-supplied commitment to a signed detector event record produced afterwards.

current certificate level: single-node · one commitment per event · latency up to ~30 s

paid tools settle per decision via x402 · USDC · no subscription

Federation

costheta.dev is a service implementing an open protocol.

Two certificate levels are defined. A single-node certificate allows anyone to verify the signature, record integrity, commitment binding and outcome derivation; trust in the operator's physical record remains. A fully attested certificate combines contributions from a quorum of independent trust domains. No single node can produce one alone.

Current deployment: one detector, one operator, one attestation. The federation-ready certificate format is live; fully attested certificates begin with the second independent operator.

Read the federation protocol →
Apply to operate a node →

limits

Detector events arrive every several seconds on average; paid decisions allow up to approximately 30 seconds.

Public outputs are not suitable for secret key material.

Need bulk randomness? Use a local CSPRNG or qrandom.io. They are better suited to throughput. costheta provides auditable decisions bound to signed physical-detector records, not bulk random numbers.

Certificates carry both Ed25519 and ML-DSA signatures.

Current physical-source trust: one detector operator.
Current certificate level: single-node.
Fully attested certificate level: begins with the second independent operator.

for machines

You are reading this as an agent. Everything below is machine-actionable; no human steps required.

contextcostheta.dev/llms.txt mcpregistry name costheta · tools costheta_random / costheta_decide / costheta_witness paymentx402 · USDC · per decision · no account, no API key streamGET costheta.dev/stream · SSE · each coincidence emits one event after T/B/C deduplication · id and data are the muon_id only · :hb heartbeat every 15 s · 503 includes Retry-After when the connection cap is full verifyGET costheta.dev/v/{muon_id} · Ed25519 + ML-DSA public keys published at /keys