Skip to content
Ebb

Docs · one page, one source of truth

The pilot book

Everything Ebb does, how to use it, and how to check it. Every number on this page comes from the same constants file the contracts and API are built from.

01Overview

Ebb is a fee-to-AI-credit token on Robinhood Chain. Hold $EBB and the fees from every trade pay for your AI. Every 30 minutes (a tide) the fees collected in the vault, called the Basin, are split pro-rata among eligible holders as credit. Each grant lands in its own tidepool and lives for seven days. Credit you spend pays for model usage through an OpenAI-compatible API. Credit you leave is drawn into the Trench: it buys $EBB on the market and burns it.

What makes it checkable rather than trusted:

  • The Basin (EbbVault) is an immutable contract: no owner, no proxy, no delegatecall, no selfdestruct.
  • Each tide’s grants are committed on-chain as a Merkle root. Anyone can verify their own grant.
  • Reserves are read from the chain on every request and shown as an equation.
  • API keys are random, issued after a nonce-bound Sign-In with Ethereum, and stored only as SHA-256.
  • Contracts, API and this site are open source, built from one constants file.
  • A sandbox runs the whole stack against a simulated chain, so you can try it without funds.

02Quickstart

  1. 1 · Sign in with your wallet

    Open the console, connect an injected wallet and sign one message. It is an EIP-4361 (SIWE) message with a single-use nonce and an expiry. No transaction, no gas, no approval.

  2. 2 · Create a key

    Under Keys, create a key with a label. You can set a spend cap or make it a sub-key of another key for an agent or a teammate. The full key is shown once; we only keep its hash.

  3. 3 · Point your tools at the gateway

    Any OpenAI-compatible client works. Change the base URL and the key.

    curl
    curl https://api.ebbtide.xyz/v1/chat/completions \  -H "Authorization: Bearer $EBB_KEY" \  -H "Content-Type: application/json" \  -d '{"model":"<model id from /v1/models>","messages":[{"role":"user","content":"Hello"}]}'
    python · openai
    from openai import OpenAIclient = OpenAI(base_url="https://api.ebbtide.xyz/v1", api_key=os.environ["EBB_KEY"])reply = client.chat.completions.create(    model="<model id>",    messages=[{"role": "user", "content": "Hello"}],)
    typescript · openai
    import OpenAI from "openai";const client = new OpenAI({ baseURL: "https://api.ebbtide.xyz/v1", apiKey: process.env.EBB_KEY });const stream = await client.chat.completions.create({  model: "<model id>",  messages: [{ role: "user", content: "Hello" }],  stream: true,});

    Every response carries x-ebb-balance (credit before the call), x-ebb-cost and x-ebb-request-id headers.

03How credits work

A tide is 1,800 seconds and turns on :00 and :30 UTC. The tide number is tide(t) = floor((t − GENESIS) / 1800), where GENESIS is an immutable of the vault.

Who gets a grant

When a tide ends, the allocator integrates every wallet's $EBB balance over the tide: its time-weighted average balance (TWAB). A wallet is eligible if its TWAB is at least 100,000 $EBB (0.01% of supply) and it is not excluded (the Pons bonding curve, the Uniswap v4 pool, the vault, the treasury, the burn address, known exchanges).

grant formula · micro-USD, floored
grant(w) = floor( booked(tide) × twab(w) / Σ twab(eligible) )

Amounts are integer micro-dollars (1 USD = 1,000,000). Rounding dust stays in the tide and burns at expiry. The allocator never guesses: if the indexer is behind the end of the tide, it waits.

Spending

A request first reserves its maximum possible cost (estimated prompt tokens × input price + max_tokens × output price) from your tidepools, oldest first. When it finishes, the real cost is computed from the provider's usage and the rest is refunded to the same pools. If the provider fails, everything is refunded. Prices are the upstream list prices with no markup.

Expiry

A tidepool lives 336 tides (7 days, 604,800 seconds) from the start of its tide. After that it can no longer be spent, and whatever is left in the tide on-chain can be burned by anyone.

propertyrule
transferableNo. Credit belongs to the wallet the grant was committed to.
redeemableNo. It buys model usage, never ETH, USDG or anything else.
orderOldest pool first, always.
revivableNo. An expired pool is already in the Trench.

04Fees

$EBB trades on Pons v2. It starts on a bonding curve priced in ETH (1.68 ETH phantom reserve) and graduates when 4.2 ETH has been collected into a Uniswap v4 pool (Pons Meme hook, pool fee 0, liquidity locked forever).

Traders pay 3% on every buy and sell, on the curve and after graduation alike: Pons' 1% base fee plus a 2% $EBB creator tax. The base fee splits 30% to Pons and 70% to the creator; the creator gets all of the tax. The creator is the Basin, so 2.7% of volume reaches the Basin, paid in ETH, and Pons keeps 0.3%.

per $100,000 volumeamount
Traders pay (3%)$3,000
Pons keeps (0.3%)$300
Reaches the Basin (2.7%)$2,700
Credit pool (70%)$1,890
Treasury (30%)$810
If holders spend 15%: becomes AI$283.50
If holders spend 15%: buys and burns $EBB$1,606.50

How the fees reach the Basin

Pons does not push fees. They sit on the curve (before graduation) or on the Pons hook (after) until they are swept into Pons' fee escrow, and only the recipient can claim them. harvest(), which anyone can call, sweeps the curve, claims from the escrow, swaps the ETH to USDG on the Uniswap V3 WETH/USDG pool within 3% of its 30-minute TWAP, then splits it in the same transaction: 70% to the current tide's credit pool, 30% to the treasury. After graduation, fees reach the escrow when Pons' sweep operator sweeps the hook.

Who receives them

The founder launches $EBB through the Pons UI. Right after launch the creator fee recipient is transferred on-chain to the Basin. From then on only the Basin holds that right, and it has no function to use it, so nobody we control can redirect the fees. Fees from the first minutes, before the transfer, are forwarded to the Basin by the founder. Pons' owner can still propose a change (see Risks).

Play with the numbers in the Tide tables.

05EbbVault, the Basin

No owner. No upgrade. No selfdestruct, no delegatecall. Every address and constant is immutable. The operator key can only commit grant roots and pay the fixed settlement address; a guardian can freeze the operator, one way, forever.

functionwhowhat it does
harvest()anyoneSweeps the Pons curve and claims from Pons’ fee escrow (fees are not pushed), swaps all ETH to USDG on the V3 WETH/USDG pool within 3% of its 30-min TWAP, sends 30% to treasury, books 70% to the current tide.
commitGrants(tide, root, total, wallets)operatorOnce per ended tide. Stores the Merkle root of grants; total ≤ booked.
verifyGrant(tide, wallet, amount, proof)viewTrue if the leaf is in that tide’s root.
withdrawForUsage(tide, amount, usageRoot)operatorPays the fixed settlement address for credit already used. withdrawn + amount ≤ granted. Not after expiry, not when frozen.
burnExpired(tide, maxAmount)anyoneAfter tide start + 7 days: swaps min(remaining, max) to $EBB and burns it. Caller earns 0.25%, capped at $2.
freezeOperator()guardianOne-way. Afterwards nothing can be withdrawn for usage; everything left burns.
currentEpoch() · epochStart(e) · epochs(e) · remaining(e) · totalOpen()viewRead the Basin’s state per tide.

Grant leaves follow the OpenZeppelin StandardMerkleTree layout: keccak256(bytes.concat(keccak256(abi.encode(tide, wallet, amount)))).

Address on Robinhood Chain testnet: 0x2d7aA8AB158F46c2EA8FA344D05b60B216Bec293

06Burns

Every burn takes one path through the vault's immutable swap adapter: USDG → ETH, then ETH → $EBB on the Pons curve (before graduation) or the Uniswap v4 pool (after), bounded at 97% of a 30-minute TWAP quote, then token.burn(amount). If the token had no burn function the vault would send to 0x…dEaD; $EBB has one. Total supply drops by exactly the amount burned, which an invariant test checks.

burnExpired takes a maxAmount so thin pools can be burned in slices without moving the price beyond the bound. Our keeper calls it every ten minutes for every expired tide with a remainder. If it stops, anyone can call it and keep the tip.

07Logbook and Soundings

The Logbook has one entry per tide: booked, granted, wallets, used, withdrawn, still open, the grant root and its transaction, and the burn when it happens. It is available as JSON and CSV, and the console can verify your own grant against the on-chain root.

Soundings is the reserve check. It reads the vault's USDG balance from the chain on every request and sets it against what the books say:

the soundings equation
usdg.balanceOf(EbbVault) = open credits + used, not yet settleddifference                = 0

08Depth tiers

Tiers are set by your current $EBB balance. They change rate limits and cosmetics, never the value of a credit or the size of a grant.

tierholdreq/minconcurrentadds
Shore0102Spends credit already held · Logbook, soundings and docs
Reef100,000608Tides every 30 minutes, pro-rata · Usage dashboard and ebb view
Shelf1,000,00012016Everything in Reef · Shelf badge on share cards
Abyss10,000,00024032Everything in Shelf · New models first · Name on the depth wall

09Token facts

factvalue
ContractSOON: published here and on @ebbtidexyz at launch
LaunchFair launch on Pons, 5 Oct 2026, 15:00 UTC
Testnet token (46630)0xB2744c634B30F43a69A292f2Bd6b09CE7c6aEe59
ChainRobinhood Chain, chain id 4663 (testnet 46630)
Supply1,000,000,000 $EBB, fixed, no mint
Decimals18
LaunchpadPons v2: bonding curve priced in ETH, graduates at 4.2 ETH into a Uniswap v4 pool, liquidity locked forever
AllocationFair launch, no team allocation; dev buy disclosed at launch
Trader fee3% on every trade: Pons 1% base fee + 2% creator tax
Reaches the Basin2.7% of volume, in ETH (Pons keeps 0.3%)
Creator fee recipientEbbVault (the Basin), verify it on-chain: 0x2d7aA8AB158F46c2EA8FA344D05b60B216Bec293
Grant floor100,000 $EBB (0.01% of supply)
Tide1,800 s; credit lives 336 tides (7 days)

Verify the address on this page, in the repository and on our X account before buying. Fake addresses are common in the first hour of any launch.

10API reference

Base URL https://api.ebbtide.xyz. Money fields are decimal strings with six places. Errors always look like { "error": { "type": "…", "message": "…" } }.

Public

endpointreturns
GET /v1/modelsModels with upstream name, context window, list price and minimum tier
GET /api/statsCurrent and next tide; granted, used, expired and burned over 24 h and all time
GET /api/tides/:nOne tide’s Logbook entry
GET /api/logbook?from=&limit=Logbook, newest first. Add format=csv for CSV
GET /api/soundingsvault_usdg (on-chain), open_credits, unsettled_used, difference, block, addresses
GET /api/grants/:addr/:tide{ amount, proof[] } for verifyGrant
GET /api/holders?limit=The depth wall: top holders by balance, with tier
GET /api/healthLiveness and mode

With an API key

endpointreturns
POST /v1/chat/completionsOpenAI-compatible, streaming supported. Headers x-ebb-balance, x-ebb-cost, x-ebb-request-id
GET /v1/keyBalance, tidepools [{ tide, remaining, expires_at }], tier and limits
GET /v1/usage?from=Your requests with tokens and cost

With a wallet session

endpointdoes
GET /api/auth/nonceA single-use nonce for the SIWE message
POST /api/auth/verify{ message, signature } → sets an httpOnly session cookie for 24 h
POST /api/auth/logoutEnds the session
GET /api/meAddress, tier, balance, credit, pools and keys
POST /api/keys{ label, spend_cap?, parent_id? } → { key }, shown once
POST /api/keys/:id/revokeRevokes a key and its sub-keys

Errors

statusmeaning
401Missing or unknown key, or no session
402insufficient_credit: your pools cannot cover the reserved maximum
429Rate or concurrency limit for your tier; honour retry-after
503Spending paused because settlement failed three times in a row
verify a grant yourself
# 1. fetch your proofcurl https://api.ebbtide.xyz/api/grants/0xYourWallet/1234# 2. call the vault (cast, from Foundry)cast call <EbbVault> "verifyGrant(uint256,address,uint256,bytes32[])(bool)" \  1234 0xYourWallet <amount> "[<proof...>]" --rpc-url https://robinhood-rpc.publicnode.com

11Security and anti-gaming

attemptwhy it fails
Buy before the tide turns, sell afterTWAB: five minutes of holding earns a sixth of the tide’s share.
Wash tradingA round trip costs 6% in fees and only a pro-rata slice returns to the trader.
Redirecting the feesThe creator fee recipient is the Basin, which has no function to change it. Nobody we control can move the fees.
Splitting a bagPro-rata maths gains nothing; the floor keeps dust out.
Replaying a signatureSIWE nonces are single-use with an expiry; keys are random, not derived.
Stolen databaseKeys are stored as SHA-256 hashes.
Compromised operatorPays only the fixed settlement address, bounded per tide by granted; the guardian can freeze it.
Stalled keeperharvest and burnExpired are permissionless, and burns pay a tip.
Indexer lag or reorgIndexer lags 3 blocks; the allocator waits rather than guesses.

Invariants

  1. I1 · USDG in the vault equals the sum of remaining over every tide
  2. I2 · withdrawn ≤ granted ≤ booked, per tide
  3. I3 · burnExpired reverts before tide start + 7 days
  4. I4 · a fully burned tide can never be withdrawn
  5. I5 · every harvest splits exactly 70 / 30
  6. I6 · swaps revert beyond 3% of the oracle quote
  7. I7 · total supply drops by exactly the amount burned
  8. I8 · USDG moves only to settlement, treasury, the burn path or the caller tip

12Treasury

The treasury receives 30% of every harvest and is published monthly in Soundings with a transaction link for every movement.

bucketsharefor
Operations35%servers, indexing, monitoring
Provider float20%prepaid balance, so credits never wait
Free demo15%the chat on the landing page, capped
Growth20%creators, dev communities, bounties
Reserve10%audits, incident fund

13Risks

  • Grants follow trading volume. If volume falls, grants fall with it. Nothing is promised.
  • Metering happens on our gateway. Withdrawals for usage are bounded, rooted and freezable, but usage figures are still reported by us.
  • Pons’ owner (a 2-of-3 Safe) can propose moving the creator fees away from the Basin, a community takeover. The proposal is public and can only execute after a 3-day delay; our keeper watches for CreatorFeeRecipientChangeProposed and we will announce it publicly.
  • Pons v2 is not yet audited. A bug in its curve, hook or fee escrow could stop or trap the fees.
  • After graduation, fees reach Pons’ escrow only when Pons’ sweep operator sweeps the hook. If it stops, inflow pauses until it resumes.
  • Fees from the first minutes, before the fee recipient moves to the Basin, depend on the founder forwarding them.
  • Model providers can change prices, limits or access.
  • Smart contracts can have bugs. At launch the vault is invariant- and fork-tested; an external audit is on the charted course.
  • $EBB is volatile, like every token.

14FAQ

Do I need to stake or lock anything?

No. Hold $EBB in your own wallet, sign one message for a key, and tides arrive on their own.

Is this cash or a yield?

No. Credit is access to model usage. It is not transferable, not redeemable and never a fixed amount.

What happens to credit I do not use?

After seven days it buys $EBB on the market and burns it. You still benefit through the smaller supply.

Which models can I use?

The ones listed at /v1/models, with their upstream names and list prices. Some arrive first for the Abyss tier.

Who triggers burns?

Our keeper, every ten minutes. And anyone else: burnExpired is permissionless and pays a tip.

Can I share a key?

Yes. It spends your credit. Use sub-keys with spend caps for agents and teammates, and revoke them any time.

Who can redirect the fees?

Nobody we control. The creator fee recipient is the Basin, which has no function to change it. Pons’ owner can propose a change, publicly, with a 3-day delay; we would announce it.

Where does the money sit?

In EbbVault, in USDG, booked per tide. It can only pay a provider for used credit or buy and burn $EBB.

Can I try it without buying?

Yes. The sandbox runs the full stack against a simulated chain and holders; signing in gives a dev wallet a seeded balance.

15Disclaimer

Ebb credits are a grant of access to AI model usage. They are not transferable, not redeemable for money or any digital asset, and not an investment return. Credit amounts depend on trading activity and are never fixed or promised. $EBB is a utility token for access within the product; it confers no ownership, profit share or claim on any person, entity or asset. Burns are a protocol mechanism, not a payment to holders. Nothing here is financial, investment, legal or tax advice. Smart contracts can contain bugs, providers can change price or access, and digital assets are volatile. Never risk what you cannot afford to lose.