Almanak decides.KeeperHub lands it.No strategycode changes.
Every Almanak strategy, unmodified, dry-runs, signs and broadcasts through KeeperHub: one idempotency key per intent, a verified receipt back, no private key on the machine.
Every number on this pageis read from a file a real run wrote,and a runner rewrites those filesevery six hours.
A clean execution layer,and one way to execute.
The private key lives on the strategy machine
Whoever reaches the box can sign anything the strategy could.
The public mempool is the only submitter
The private relay is a stub, the simulator is off on live networks. Nothing dry-runs the bundle before it goes out.
No idempotency: a retry can pay twice
A retry after a nonce error minted twice, in Almanak's own repository.
Six steps, two gatesthe strategy does not control.
Almanak's policy refuses before anything is compiled; KeeperHub's dry run and caps refuse before anything is signed.
An exit decision can be staleby the time it executes.
Between a decision and its broadcast the position can change. So the redeem is never a bare write: two shapes, both KeeperHub's.
check-and-execute direct execution
KeeperHub reads balanceOf(wallet) right before the write and redeems only if it still covers the decision. /exit on the phone.
a workflow with a Condition node KeeperHub's engine
The same decision in KeeperHub's builder: a balance node, a Condition, the Morpho redeem behind the true branch. /guard on the phone.
On production, 22 September: the stale decision stopped at the Condition in 3.7 s; the live one redeemed and verified in 8.4 s.
The result.
Every figure is a KeeperHub execution record or a receipt on Base Sepolia; scripts/benchmark.py reproduces the table.
| Measure | Result |
|---|
The latest lifecycle, run by a GitHub runnerwith nobody present.
Every six hours a runner ticks the strategy through KeeperHub, exits through the guarded redeem, checks eleven API behaviours against production, and republishes this site.
Four minutes, from a strategy tickto the operator's phone.
Seven failure modes,on purpose.
Each one is a script anyone can run; the verdicts are what they recorded.
Who can act,and through which gate.
What a stolen API key can and cannot do: SECURITY.md.
Three ways to use it,one truth.
CLI
run --once runs any strategy through KeeperHub; exit and exit-guard are the two guarded exits; verify asks KeeperHub for its verdict on any hash.
MCP server
For any agent. Read and dry-run by default; --write adds the real tick and the exits. Three Claude sessions, recorded unedited.
Telegram bot
Status, executions, verify, a dry run, a confirmed tick, both guarded exits, every failure demo. It is what the video shows.
All three read the same receipts and drive the same code. Two more surfaces are KeeperHub's own: the compounder and the guarded exit are workflows generated from the strategy config, run by KeeperHub's engine with no Almanak process.
What this project fixedin KeeperHub, it now uses.
Four gaps met while building, each filed, accepted and built to the maintainers' spec; then three of their own backlog issues. Two are merged and live on production; the runner's next tick used them without a change here. The other five are in review.
| Change | Issue | Pull request | State |
|---|---|---|---|
Raw calldata on POST /api/execute/contract-call: send the bytes a framework compiled, KeeperHub decodes them losslessly | #2426 | #2449 | merged |
Simulate a sequence of calls against the state the earlier ones produce (eth_simulateV1, with a state-override fallback) | #2427 | #2452 | merged |
The acting wallet on sponsored executions (executedCall.from) | #2428 | #2450 | in review |
| Workflow preflight simulates consecutive write nodes against the state the earlier ones produced | #2519 | #2531 | in review |
| An approve with no upstream allowance check gets a hint that does not claim redundancy (maintainer-filed) | #2367 | #2533 | in review |
| The EVM chain runbook, and a seed that fails instead of warning on a chain with no explorer (maintainer-filed) | #2497 | #2532 | in review |
math/aggregate no longer truncates a fraction next to a wei amount; fixed point through the post-operation (maintainer-filed) | #2496 | #2534 | in review |
Almanak: a pluggable execution backend for the gateway, with a diff that applies to their main | almanak-co/sdk#3 | diff in the issue | open |
Three defects in the merged simulator's fallback path were found by other contributors within two days (#2517, #2541, #2542); the path this runner uses is not affected.
Nothing here asksto be believed.
pip install 'almanak-keeperhub[mcp]'
export KEEPERHUB_API_KEY=kh_... # your own KeeperHub key
almanak-keeperhub verify <hash or execution id>
# KeeperHub's verdict, the receipt, and who acted, decoded from the events
almanak-keeperhub api-features --chain base_sepolia
# which of the two merged upstream features production has today
Or without an account
tests/e2e/rehearsal.sh --testnet runs the whole lifecycle on an Anvil fork against a stand-in that speaks the merged API. Every console row links to the explorer; every execution id resolves in the KeeperHub app.
Source, tests, the proof workflow, the roadmap: github.com/Prashant-thakur77/almanak-keeperhub.