<!-- markdown mirror of https://mintid.net/en/blog/first-live-network — generated at build time -->

> MintID stood up its first live network — a single-validator chain and the verifier service, deployed behind TLS from a reproducible bring-up package — and drove the first end-to-end test through it: proof-backed reads, live ten-second challenges, a fixed-slot decision record and a complete MCP session. Protocol-code defects found: zero. Alongside it, what the v2.0 re-freeze leaves fixed in the tokenomics — the hard cap, the ratified bands, the price-independent launch gate, the protocol cuts and the post-emission plan — now reads as closed policy, not promise.

Blog · milestone

# The first live network: running, not written

MintID stood up its first live network — a single-validator chain and the verifier service, deployed behind TLS from a reproducible bring-up package — and drove the first end-to-end test through it: proof-backed reads, live ten-second challenges, a fixed-slot decision record and a complete MCP session. Protocol-code defects found: zero. Alongside it, what the v2.0 re-freeze leaves fixed in the tokenomics — the hard cap, the ratified bands, the price-independent launch gate, the protocol cuts and the post-emission plan — now reads as closed policy, not promise.

by Marc Miró i Rierola·published 2026-08-02·updated 2026-08-02·11 min read

Two things happened on the same day, and they belong in the same post. The first: we stood up the first **live network** of the protocol — a single-validator chain and the verifier service, deployed behind TLS on our own infrastructure, and drove the first end-to-end test through it. The second: after the v2.0 re-freeze that answered [our own audit](/en/blog/we-audited-ourselves), the tokenomics stopped being a set of drafts and became a register of **closed questions** — each with a normative source you can hold us to. One is evidence that the design runs; the other is the design, frozen. Here are both.

## What we stood up

Let us be precise about what this is, because the wording matters. This is an **internal testnet**: a single-validator `idchaind` node plus the Verifier SDK running in its service mode, deployed behind TLS on infrastructure we operate, for our own testing. It is not a network anyone can join — there are no third-party validator accounts, no join kit, and we have not published its endpoints. It is stopped and rebuilt at our discretion.

The part we consider an achievement is not that it is up — it is that it is **reproducible**. The whole network comes from a bring-up package: tear it down, rebuild it from zero, and you get the same network in minutes. For a protocol whose whole posture is “the corpus is the source of truth”, the deployment being a derived artifact — not a hand-tended pet — is the property worth having first.

## The first end-to-end test

The first test passed everything the current stage can prove. The chain finalizes continuously. And the readings that matter were not taken on trust:

*   **Reads that prove themselves.** The verifier’s on-chain registration and its exact HTTPS origin were not just _claimed_ by an RPC answer — they were read from outside through the light-client-verified ics23 proof path, the same fail-closed path the SDK uses in production. An RPC answer that cannot prove itself against a verified app hash simply does not count.
*   **Live challenges, correctly bound.** Ten-second presentation challenges were issued live, bound to the registered verifier identity, the exact audience origin and a finalized chain height — and they expired on schedule. One honest note on their anatomy: the challenge design carries a signature field, and on the testnet it is present and empty — production challenge signing is HSM territory and arrives with Epic F3.
*   **A rejection that leaves almost nothing behind.** A deliberately invalid presentation was rejected with a reason code from the closed vocabulary — and the only thing the verifier retained was the fixed-slot decision record: outcome, reason, session, a 32-byte context digest, a timestamp. No proof bytes, no attributes, nothing to correlate.
*   **The agent surface, driven end to end.** We ran a complete live session through the verifier’s [MCP server](/en/blog/verification-is-a-tool-call) — the same three tools any agent framework would call — and the contract boundary held: a rejection is a successful tool result with a reason code; only transport failures are errors.

Defects found in protocol code: **zero**. Everything that broke during bring-up was deployment tooling, fixed on the spot. And the honest caveat stands, in its exact form: the full verification pipeline is live end to end, but the proof engine itself ships with Epic F3 and until then **fails closed by design** — every presentation is refused, so the deepest cryptographic paths are not yet exercisable, by design and visibly so in the build’s own version pin.

A network you can only trust because every answer proves itself — that property is now running, not written.

## How the v2.0 tokenomics work

The other half of this post is slower-moving and will matter longer. The v2.0 re-freeze — six architecture decision records, ratified on 2 August 2026 — leaves the tokenomics as a register of closed questions. Closed as in _policy_: each item below has normative text in the frozen corpus, and changing any of them has a procedure, not a mood. The pattern to notice across all of them: the **mechanism is committed, the bands are ratified, the points are commissioned** — to an independent simulation, never to us.

Fixed

What the policy says

The money supply

A hard cap of 108,000,000, immutable. Emission is strictly decreasing and there is no re-mint, ever. Burns count against circulating supply but never reopen mint headroom — a chain that has burned a lot is further from the cap, not closer — so the system can be net deflationary in any epoch where burns exceed emission.

The genesis split

Ratified bands: 15% development and team (native on-chain vesting over four years, one-year cliff, plus a twelve-month lock-up), 20–25% public tranche, and at least 60% reserved exclusively for validator emission. The final points inside those bands are set by the independent economic simulation — never by us. Insider genesis accounts do not delegate, do not vote, and do not count toward the launch-gate arithmetic.

The launch gate

Denominated in measurable, price-independent units: bonded stake as a share of the max supply, the number of independent validator operators, a Nakamoto-coefficient floor, and an estimated attack cost in fiat under a published, price-independent methodology. The concrete thresholds are outputs of the simulation, frozen with the genesis parameters. No threshold depends on a market price.

Validator bootstrap

Professional operators are recruited through service contracts — fiat or stablecoin, twelve to twenty-four months, paid from the operating budget — an instrument an operator can actually sign. Discretionary retroactive grants remain a possibility, not the recruitment mechanism.

The flows that scale

The two flows that grow with the agent population — per-agent mint/lease and consented disclosure — carry normative, non-zero protocol cuts, each with a defined burned share. They may not ship parameterless. Here too: bands before points — the cut and burn-split bands are ratified pre-genesis and published in the Title II white paper; points only ever move inside bands, under governance and versioning discipline.

The security budget after emission

When the reward pool is exhausted, the validator budget is the fee market: transaction fees plus the unburned share of the protocol cuts. The simulation must model it under published scenarios, and if it falls short the published successor options are, in order: point adjustments within bands, activation of protocol state rent redirected to validators, then supplementary shared security — never a post-cap mint. And the reward pool has exactly one use: validator emission. No other drain exists or can be created.

The registry’s microeconomics

The minimum bond is sized against a published deterrence target in fiat: it must exceed the modelled gain of the cheapest slashable violation, under the same price-independent methodology as the gate, reviewed annually. Bond exhaustion auto-suspends deterministically, and the adjudicator never keeps unclaimed remediation — its only two exits are a late claim or a burn. The fee module is now required, not conditional: fee routing, burn accounting and the collection of the protocol cuts.

Who sets the numbers

The economic simulation is an external engagement under a published statement of work with thirteen deliverables — allocation points within bands, gate thresholds and methodology, cut and burn points, the post-emission fee-market model, the minimum bond, issuer break-evens, x402 scenarios. Internal tooling may assist it, never substitute for it. And if the review objects to any frozen value, genesis does not proceed on the objected value: a dedicated unfreeze, a review with the finding on record, and a re-freeze before the genesis file is built.

Read the table top to bottom and a shape emerges. The supply cannot inflate — the cap is immutable and burns never reopen it. The insiders cannot dominate — their tranche is the smallest band, vested and locked, and their genesis accounts neither vote nor delegate nor count toward the launch gate. The launch cannot be gamed by a market price — every gate unit is price-independent by construction. The revenue scales with the thing the protocol is for — agents — and part of every scaled flow burns. The end of emission has a written plan whose options never include printing more tokens. And every number a reader could distrust is assigned to a named, external owner with a published band it must land inside.

The full picture — bands, vesting, gate, cuts, the post-emission plan — lives on the [tokenomics page](/en/tokenomics), which now derives from this same frozen register.

## What did not change

One thing refused to move through all of this, and saying otherwise would be false: the **consensus firewall**. Verification is free by construction, presentations never touch the chain, and off-chain service revenue never influences consensus rewards. The testnet exercised exactly that separation live — the chain finalized while the verifier decided, and neither needed the other’s economics — and the v2.0 corpus keeps it normative. It is the property everything else in the design leans on, and it is the one we will keep repeating.

Everything a reader can hold us to is now written, frozen and marked; everything numeric that remains open has a named, independent owner and a published band it must land inside. And as of this week, the part that is written also runs.

Can I join the testnet or run a validator on it?

No — and we are deliberate about the wording. This is an internal testnet: a single-validator deployment we operate on our own infrastructure for our own testing. There are no third-party validator accounts, no join kit, and no published endpoints yet — publishing them is a decision we have not taken. It is also stopped and rebuilt at our discretion, so there is no availability to promise. A package for third parties is future work, and it will be announced as such when it is decided.

Are zero-knowledge proofs being verified on this network?

No. The full verification pipeline is live end to end — registration, proof-backed reads, challenges, decision records, the MCP surface — but the proof engine itself ships with Epic F3 and until then fails closed by design: every presentation is refused with a proof-invalid reason code. That is a guarantee, not a defect — the system’s default answer is no until the audited engine exists, and the build’s own version pin says so visibly.

Does a live network mean a token is for sale?

No. Nothing is for sale: no token sale, no pre-sale, no whitelist, no price, no date. The project has committed, as ratified policy, to exactly one route by which an offer could ever exist — the complete EU MiCA Title II process: crypto-asset white paper, notification to the regulator, public offer, and only then admission to trading. This post is an engineering and governance record, not an invitation.

So what numbers are actually decided?

The structure is decided; the points are commissioned. Decided and frozen: the 108,000,000 hard cap, the 15% / 20–25% / at-least-60% genesis bands with their vesting and lock-up, the price-independent units of the launch gate, the existence and burned share of the protocol cuts, the single-use reward pool, and the deterrence-based minimum bond. Commissioned to the independent economic simulation, constrained to those bands: every final point, threshold and fee. No number moves outside a published band, and no band point comes from us.

## The design is frozen. Now it runs.

The tokenomics page carries the full v2.0 register — bands, gate, cuts and the post-emission plan — and the protocol page explains the pipeline the first test just exercised end to end.

[Tokenomics v2.0](/en/tokenomics)[The protocol](/en/protocol)

---
Source: https://mintid.net/en/blog/first-live-network · The first live network: running, not written — MintID blog
