PayPerQ
ppq registers as a workspace model source. Select PayPerQ in the composer
model picker (or run /ai source ppq) after importing an account. When PPQ is
selected, the plugin builds and starts its vendored proxy in the background
without blocking bot startup. PPQ model loading and inference wait for the
proxy. Inactive workspaces do not build or start a proxy. It rebuilds after
source, lockfile, or Node version changes. No manual build command is needed.
Activation drains current runs, verifies both Tinfoil and Nitro attestations,
and switches OpenCode to PPQ-only models via the loopback proxy.
/ai source core restores the normal source and shuts down the PPQ proxy after
the transition.
The proxy protects each request between AppWeaver and PPQ's attested enclave.
For ordinary models, the upstream model provider still receives plaintext from
the Nitro enclave. For private/* models, inference runs in the verified
Tinfoil enclave. PPQ still observes billing and routing metadata required to
provide the service.
Before each PPQ inference task, the plugin authenticates the selected runtime
API key against POST https://api.ppq.ai/credits/balance, validates the
{ "balance": number } response, and requires a positive USD balance. An
invalid key, zero balance, failed request, or unexpected response blocks the
task before a paid request is submitted. The Funding tab requests a Lightning
invoice for a chosen satoshi amount and uses core's interactive payment modal
for explicit approval. Each request creates a fresh invoice. PPQ invoice and
payment-attempt history is not stored locally. If a payment might have started,
check PPQ account activity before choosing to pay another invoice.
Overview and Funding request the current PPQ budget in USD when opened; use
Refresh balance to check again after a top-up. An unavailable balance is
shown separately from a verified zero balance, and is not cached locally.
The composer context indicator reads session token usage from the active model
source. PPQ calculates the percentage using its validated catalog's context
window for the selected model. When PPQ streaming reports zero tokens despite
a completed turn, the indicator instead shows an ≈ estimate from available
session text; it omits system instructions, attachments, and some tool content.
It remains unknown until the session has an assistant message.
If the automatic build fails, check that Node.js 20+ and npm are installed;
npm ci inside plugins/ppq/vendor/ppq-private-mode/ can also be run manually
to see upstream build diagnostics. The generated dist/, node_modules/,
and build marker are local, Git-ignored artifacts.
The selected workspace keeps its own encrypted account and key records and
validated model cache under <workspace>/.appweaver/ppq/db.sqlite. credit_id
and API keys use core's versioned NIP-44 v2 encrypted-secret envelope. The
database contains no NWC URI. The AppWeaver identity key is required to read
previously stored credentials. Losing or replacing that identity key makes the
stored PPQ credentials unrecoverable; import the original credentials again or
create a new PPQ account.
Available commands
/ppqor/ppq status: see the current workspace, selected account and model./ppq accounts,/ppq keys: inspect safe account/key summaries, import via the password-masked web forms, create a PPQ account in the Accounts view, and select the current account/key. While PPQ is active, selection waits for running tasks to drain and rotates the attested proxy on its loopback port./ppq models: use a validated cached catalog immediately; refresh if stale./ppq refresh: request a fresh public catalog fromhttps://api.ppq.ai/v1/models./ppq select-account <id>,/ppq select-key <id>: select stored credentials by the IDs shown in the authenticated UI./ppq select-model <id>,/ppq favorite <id>,/ppq unfavorite <id>: update model selection and favorites by PPQ model ID./ppq settings: set recent-model limit and future push/DM notification settings./ppq funding: request an approved Lightning top-up in the authenticated web UI. Closing the payment modal does not block a future request.
Credential import is local only. It is not a claim that PPQ has authenticated the account or key. Do not send credentials through DM or command arguments; use the authenticated web form. Account creation calls PPQ and stores its returned credit ID and API key encrypted. Funding uses the selected account's key.
The catalog schema was checked against PPQ's public response on 2026-09-23:
it contained 381 chat models, including private/*, with auto and autoclaw
using -1 sentinel prices. Those dynamically priced entries are cached but
marked unavailable for model selection. All models are stored in API order,
and the bounded validated metadata is retained for later details UX.
The eight cached private/* IDs match the vendored proxy's private-model map.
OpenCode sends ppq/private/<model> to the loopback proxy, which routes the
private/* model through its attested Tinfoil path; ordinary models use the
Nitro path. End-to-end private inference with a funded account is still to be
verified.
The account-creation response and Lightning invoice/settlement shapes need
verification with a disposable PPQ account; unknown responses fail closed.
Remote key operations and funding incidents are still pending. See the
PPQ design and implementation plan for
that sequence. These limitations block remote catalog publication, but not the
local v0.1.0 release used to complete clean-install and funded-flow
verification.