Almanak KeeperHub
01 / Hero

Almanak decides.KeeperHub lands it.No strategycode changes.

Every Almanak strategy, unmodified, dry-runs, signs and broadcasts through KeeperHub: one idempotency key per intent, a verified receipt back, no private key on the machine.

Scroll
02 / Live proof

Every number on this pageis read from a file a real run wrote,and a runner rewrites those filesevery six hours.

Next runner tick
…
Proof as of
loading the latest run…
03 / The problem

A clean execution layer,and one way to execute.

Almanak is an open-source DeFi strategy framework whose execution layer was built for pluggable backends. None ever shipped: what runs today is a local key, the public mempool, and a retry that can pay twice.
03 / The problem · 1 of 3

The private key lives on the strategy machine

Whoever reaches the box can sign anything the strategy could.

With KeeperHub: no key on the machine. The org wallet signs in Turnkey's enclave, behind KeeperHub's caps.
03 / The problem · 2 of 3

The public mempool is the only submitter

The private relay is a stub, the simulator is off on live networks. Nothing dry-runs the bundle before it goes out.

With KeeperHub: the exact calldata is dry-run first; a revert stops the tick before anything is signed.
03 / The problem · 3 of 3

No idempotency: a retry can pay twice

A retry after a nonce error minted twice, in Almanak's own repository.

With KeeperHub: one idempotency key per intent. 50 of 50 retries replayed, 10 of 10 crashed processes resumed, zero double broadcasts.
04 / How a tick runs

Six steps, two gatesthe strategy does not control.

Almanak's policy refuses before anything is compiled; KeeperHub's dry run and caps refuse before anything is signed.

    05 / The guard

    An exit decision can be staleby the time it executes.

    Between a decision and its broadcast the position can change. So the redeem is never a bare write: two shapes, both KeeperHub's.

    check-and-execute direct execution

    KeeperHub reads balanceOf(wallet) right before the write and redeems only if it still covers the decision. /exit on the phone.

    a workflow with a Condition node KeeperHub's engine

    The same decision in KeeperHub's builder: a balance node, a Condition, the Morpho redeem behind the true branch. /guard on the phone.

    On production, 22 September: the stale decision stopped at the Condition in 3.7 s; the live one redeemed and verified in 8.4 s.

    1 2 ≥ Exit decision shares = 5000000 KeeperHub reads the balance observed 5000000 Condition held ≥ decided true false Redeem, verified 90eswt00kn44cw2szpl80 Stopped, nothing broadcast qez8b9fhipm7c4zcqa6sg live decision: the balance covers it, the redeem runs
    06 / Proof

    The result.

    Every figure is a KeeperHub execution record or a receipt on Base Sepolia; scripts/benchmark.py reproduces the table.

    MeasureResult
    Live

    The latest lifecycle, run by a GitHub runnerwith nobody present.

    Every six hours a runner ticks the strategy through KeeperHub, exits through the guarded redeem, checks eleven API behaviours against production, and republishes this site.

    07 / Demo

    Four minutes, from a strategy tickto the operator's phone.

    The demo video is being uploaded. In the meantime, the console has every execution it shows.
    08 / Judged on what goes wrong

    Seven failure modes,on purpose.

    Each one is a script anyone can run; the verdicts are what they recorded.

    09 / Authority

    Who can act,and through which gate.

    1 2 3 4 Almanak strategyor its agent: proposes Almanak policylimits, allowlists KeeperHub dry runsimulate: true KeeperHub capsdaily native, 100 USD stablecoin Turnkey enclave signsone idempotency key per intent refused: nothing compiled would revert: nothing signed over the cap: nothing signed allowed

    What a stolen API key can and cannot do: SECURITY.md.

    10 / Surfaces

    Three ways to use it,one truth.

    CLI

    run --once runs any strategy through KeeperHub; exit and exit-guard are the two guarded exits; verify asks KeeperHub for its verdict on any hash.

    MCP server

    For any agent. Read and dry-run by default; --write adds the real tick and the exits. Three Claude sessions, recorded unedited.

    Telegram bot

    Status, executions, verify, a dry run, a confirmed tick, both guarded exits, every failure demo. It is what the video shows.

    All three read the same receipts and drive the same code. Two more surfaces are KeeperHub's own: the compounder and the guarded exit are workflows generated from the strategy config, run by KeeperHub's engine with no Almanak process.

    11 / Upstream

    What this project fixedin KeeperHub, it now uses.

    Four gaps met while building, each filed, accepted and built to the maintainers' spec; then three of their own backlog issues. Two are merged and live on production; the runner's next tick used them without a change here. The other five are in review.

    2 merged, live on production5 in review1 proposed to Almanak
    ChangeIssuePull requestState
    Raw calldata on POST /api/execute/contract-call: send the bytes a framework compiled, KeeperHub decodes them losslessly#2426#2449merged
    Simulate a sequence of calls against the state the earlier ones produce (eth_simulateV1, with a state-override fallback)#2427#2452merged
    The acting wallet on sponsored executions (executedCall.from)#2428#2450in review
    Workflow preflight simulates consecutive write nodes against the state the earlier ones produced#2519#2531in review
    An approve with no upstream allowance check gets a hint that does not claim redundancy (maintainer-filed)#2367#2533in review
    The EVM chain runbook, and a seed that fails instead of warning on a chain with no explorer (maintainer-filed)#2497#2532in review
    math/aggregate no longer truncates a fraction next to a wei amount; fixed point through the post-operation (maintainer-filed)#2496#2534in review
    Almanak: a pluggable execution backend for the gateway, with a diff that applies to their mainalmanak-co/sdk#3diff in the issueopen

    Three defects in the merged simulator's fallback path were found by other contributors within two days (#2517, #2541, #2542); the path this runner uses is not affected.

    12 / Verify it yourself

    Nothing here asksto be believed.

    pip install 'almanak-keeperhub[mcp]'
    export KEEPERHUB_API_KEY=kh_...        # your own KeeperHub key
    
    almanak-keeperhub verify <hash or execution id>
    # KeeperHub's verdict, the receipt, and who acted, decoded from the events
    
    almanak-keeperhub api-features --chain base_sepolia
    # which of the two merged upstream features production has today

    Or without an account

    tests/e2e/rehearsal.sh --testnet runs the whole lifecycle on an Anvil fork against a stand-in that speaks the merged API. Every console row links to the explorer; every execution id resolves in the KeeperHub app.

    Source, tests, the proof workflow, the roadmap: github.com/Prashant-thakur77/almanak-keeperhub.

    13 / Start here

    Open the console.Every row is a receipt.

    Open the console Release v1.1.0 The deck