ContextVM MCP over Nostr
01 / 13

Permissionless infrastructure for computation

ContextVM turns MCP into a sovereign network.

Not another AI tool. A transport layer that keeps MCP intact while removing the hosting assumptions of the old web stack.

No domains. No static IPs. No OAuth gatekeepers. Just keys, relays, and globally reachable services.

builders protocol hackers MCP practitioners freedom tech

02 — Stakes

Why this matters

AI capabilities are spreading. Infrastructure power is not.

Remote computation is becoming central to how apps, agents, and people work — but deployment still gravitates toward hosted platforms, managed auth, centralized billing, and platform-controlled reachability.

Hosted

Operational default

Most remote MCP patterns still assume cloud endpoints, DNS, TLS, and service operators.

Fragile

Access model

Reachability, identity, and monetization are often mediated by external infrastructure and gatekeepers.

Open?

Unfinished promise

MCP is useful — but the network layer still decides who can deploy, discover, and get paid.

03 — Problem

Traditional remote MCP

Remote MCP still inherits the old web stack.

Useful protocol. Familiar deployment story. Same infrastructure bottlenecks: domains, hosting, auth stacks, public endpoints, and centralized payment rails.

The protocol can be open while the deployment model stays closed.

Hidden requirements

  • Acquire and operate a public endpoint
  • Manage DNS, TLS, uptime, reverse proxies, and edge routing
  • Integrate OAuth, API keys, sessions, or account systems
  • Rely on external payment or marketplace infrastructure
  • Expose builders to policy, platform, and hosting constraints

04 — Thesis

Do not replace MCP

Free MCP by changing its transport assumptions.

ContextVM runs MCP over Nostr. The application model remains MCP. The transport becomes public-key addressed, relay-routed, optionally encrypted, and globally reachable without the normal hosting ceremony.

Keep MCP semantics Replace transport
A

MCP defines capabilities

Tools, resources, prompts, sampling, and request/response behavior remain familiar.

B

ContextVM defines transport

Messages ride through relays as Nostr events, signed by keys instead of tied to endpoints.

05 — Mechanism

Three-layer architecture

Three layers. Clear separation of concerns.

ContextVM is easiest to understand as a transport layer inserted under MCP and above the Nostr relay network.

MCP Application Layer Tools, resources, prompts, sampling, and client/server behavior.
↓
ContextVM Transport Layer Nostr event wrapping, public key identity, signing, verification, encryption, relay coordination.
↓
Nostr Relay Network Relay connectivity and message propagation across an open event network.

06 — Identity & security

Keys instead of accounts

Identity

Servers and clients are addressed by public keys, not by domain ownership or account records in a central database.

Integrity

Messages are signed and verifiable. Trust shifts toward cryptographic authorship and relay-observable events.

Privacy

Private interactions can use regular gift wraps via kind 1059 and ephemeral gift wraps via kind 21059, making encryption flexible instead of mandatory.

Reachability is public-key native. Privacy is layered on, not bolted on.

Why this matters

  • Public servers stay easy to discover
  • Private servers remain possible without bespoke account systems
  • The same identity primitive works for humans, apps, and LLM clients

07 — Discovery & communication

Event kinds and message flow

Core event roles

Kind Purpose
25910 Primary transport event for MCP messages, typically ephemeral
11316 Public server announcements for discovery
11317–11320 Capability and server metadata lists
1059/21059 Gift wrap envelope for encrypted payloads

Transport without lifecycle lock-in

1

JSON-RPC inside Nostr events

MCP messages ride as JSON-RPC payloads inside relay-routed events, so the transport stays machine-readable and schema-aware.

2

Stateful or stateless

Initialization can be used when helpful, but it is not required for stateless operation. The protocol does not force one lifecycle model.

3

Capabilities stay portable

Tools, resources, prompts, and notifications remain inspectable and composable across clients, UIs, and agents.

08 — Dual API

One service, many consumers

One service can speak to humans, apps, and LLMs at once.

MCP is fundamentally a JSON-RPC capability layer with structured schemas for tools, resources, prompts, inputs, and outputs. That makes the same service legible to software, renderable into human interfaces, and natively useful to LLMs that already understand MCP.

Human user Schemas can drive forms, interfaces, and guided UX instead of forcing people into raw protocol messages.
Application Structured JSON-RPC calls make services easy to integrate into workflows, bots, and product surfaces.
LLM / MCP client MCP-native agents can discover and call the same capabilities without translation into a second protocol.

09 — Ecosystem

Incremental adoption paths

SDK, gateway, proxy, CVMI — choose the layer you need.

TypeScript SDK

Build native ContextVM clients and servers with transports, signers, relay handlers, and payment integrations.

Gateway

Expose an existing MCP server to the ContextVM network without rewriting its application semantics.

Proxy

Connect standard MCP clients to remote ContextVM services by translating transport expectations.

CVMI

Use the CLI as the Swiss Army knife for serving, using, testing, and exploring the ecosystem.

10 — Use cases

What becomes practical

public

Open utility servers

Publish capabilities to the network and let any compatible client discover and use them.

private

Encrypted personal services

Run private agents, assistants, or device services addressed by keys and shielded by gift wrapping.

local-first

Garage deployment

Ship services from home labs, laptops, or community infrastructure without first becoming a cloud operator.

Community-owned infra

Co-ops, collectives, and small teams can expose capabilities globally without outsourcing the trust boundary to platform intermediaries.

Monetized services

With CEP-8, services can advertise pricing and negotiate settlement through PMIs, keeping payment rails extensible instead of hard-wired to a single network.

Trust and reputation engines

Projects like Relatr and Wotrlay show how relay-visible computation can shape reputation, moderation, and trust-aware routing.

Sovereign personal software

Blovm, Nutoff, and KeePass-CVM point to a world where storage, wallets, and secrets management remain user-controlled but globally reachable.

Composable public services

Geo servers, analytics tools, media metadata services, and experimental AI apps become reusable network primitives instead of siloed products.

11 — Comparison / proof

Traditional remote MCP vs ContextVM
Dimension Traditional remote MCP ContextVM
Addressing Domain, URL, public endpoint Public keys plus relay reachability
Deployment assumptions Cloud or managed hosting, edge config, TLS, uptime stack Any node that can sign, relay, and speak the protocol
Identity model Accounts, API keys, OAuth, custom auth Cryptographic identity with optional encrypted payloads
Discovery Directories, docs, manual endpoint sharing Relay-published announcements and capability events
Payments Usually separate, platform-specific, externally mediated PMI-based and payment-rail agnostic, with pricing and settlement negotiated at the protocol layer

12 — Tradeoffs & maturity

Credibility over hype

Running protocol, still expanding

ContextVM is already powering services in production. The spec is still being refined because the network is alive, not because the model is unproven.

Relay-native advantage

By building on Nostr, ContextVM inherits an existing open communication fabric instead of waiting for a new network to be invented from scratch.

Ecosystem headroom

Payments, discovery, encryption, client generation, UI generation, and new capability patterns still have room to grow — which is exactly why this layer matters now.

This is not a speculative idea. It is working infrastructure with room to become a much larger ecosystem.

13 — Closing

Memorable ending

Computation should be publishable like speech — not deployable only with permission.

ContextVM makes MCP portable, sovereign, and network-native by anchoring it in keys, relays, and open protocols.

no gates no permission slips globally reachable computation

ContextVM is the transport layer that lets open capability systems live on open network infrastructure.

1 / 13