MPGR HUB

Docs

How MPGR HUB actually works — the Agent, wallet and confirmation model, onchain utilities, games and rewards on Base.

Written against the running product. Anything not shipped is labelled PLANNED / FUTURE.

Overview

MPGR HUB is a Base-native application built around MoneyPaiger ($MPGR). It combines four things in one place: an AI agent that researches and prepares onchain actions, a play-and-progress layer (MPGR Run, XP, seasons, leaderboard), live onchain utility (staking, token lock, reward vault claims), and a tokenized-stock / agentic-payments surface — all on Base mainnet.

Live vs planned

This page documents the product as it exists today. Items that are designed but not shipped are marked PLANNED or FUTURE and linked to the roadmap. No future item is described as live.

The four product areas

  • Agent — Home (/) is the MPGR Agent. There is no separate Agent tab.
  • Play — Games and MPGR Run.
  • Earn — Rewards, Staking, Token Lock, Leaderboard.
  • Trade — swap and tokenized-stock preparation on Base, always prepare → confirm → sign.

The positioning is Play. Trade. Earn. With AI. Architectural detail lives in the Whitepaper; product intent lives in About.

Getting started

MPGR Agent

The Agent is the centre of MPGR HUB. It lives on Home (/ redirects to it from /agent). The screen is a single workspace: a status bar, suggested prompts, the conversation thread, a composer, and a live Base market tape whose Prepare swap action drops the same prompt into the chat.

What the Agent can do today

  • Research $MPGR, Base markets and Coinbase B20 tokenized stocks through read-only tools.
  • Summarise your portfolio context — XP, level, streak, holder tier, Premium status, season progress, staking, token lock, referral count and claimable rewards.
  • Prepare a Base transfer (native ETH or any Base ERC-20, to an address or a Basename).
  • Prepare a Base swap via the Coinbase CDP Trade API, with a 0x fallback.
  • Prepare a B20 tokenized-stock order through an Aerodrome Slipstream USDC pool.
  • Prepare an x402 payment against a discovered paid resource.
  • Offer smart actions that deep-link into Rewards, Games, Staking, Token Lock, Profile, Leaderboard and Premium.

What the Agent cannot do

  • It cannot sign, broadcast, approve, pay or move funds by itself. There is no autonomous execution path and no custody.
  • It cannot invent a recipient, amount or destination — every value-moving field is re-validated server-side before a proposal is ever shown.
  • It cannot claim a transaction succeeded until deterministic application code has confirmed it.

Model output is untrusted

Replies are generated by a network model (Gemini by default) or by the on-device deterministic engine. Model text is treated as untrusted data; tool arguments are validated; write actions are gated by deterministic code, not by the model.

Full detail: Agent workflow · Whitepaper → MPGR Agent

Agent workflow

The Agent loop is: understand → research → reason → plan → confirm → execute → verify. The order is enforced by application structure — the model suggests, deterministic code decides.

StageWhat happens
UnderstandThe message is matched against a closed list of intents (portfolio, XP, holder tier, premium, rewards, staking, locked tokens, season, referral, research, market overview, navigation). An unmatched message falls back to research/help — it never becomes an action.
ResearchRead-only tools fetch facts: Base RPC reads, MPGR token / staking / token-lock / reward-vault clients, /api/market/price data, the B20 catalog, x402 resource discovery. Tools return where a fact came from and when it was read.
ReasonA configured AI provider composes the reply. Policy sits in the system channel; client context is explicitly labelled untrusted so it cannot override it. Providers are tried in order (Gemini → NVIDIA NIM → OpenAI) and fall back to a deterministic engine that never invents live values.
PlanDeterministic code decides which action is allowed and builds a structured proposal. Write-capable paths are limited to prepare-mode tools: no tool in the registry executes a wallet write.
ConfirmA confirmation modal shows the exact effect — amount, asset, destination or route, provider, slippage, and deterministic risk facts. Nothing is sent until you confirm.
ExecuteYour connected wallet signs. For swaps the app submits the transaction (and, where the provider requires it, an ERC-20 approval first); for x402 it signs an EIP-3009 TransferWithAuthorization.
VerifyThe app waits for the receipt and checks its status before reporting success. A failed or reverted transaction is reported as failed — never as done.

The same loop applies to transfers, swaps, B20 orders and x402 payments. See Whitepaper → research, planning, confirmation, execution, verification.

Wallet connection & confirmations

MPGR HUB is Base mainnet only (chain ID 8453). Connect with RainbowKit — Coinbase Wallet, WalletConnect or an injected wallet — or through the Farcaster Mini App connector. If you are on another network the header shows a Wrong network button that opens the chain switcher.

Session, not just signature

Reading is open. Protected writes require a signed session: the app issues a nonce, you sign a SIWE message, and the server issues an HMAC session cookie. A wallet address sent by a browser is never treated as authentication on its own, and server-side write handlers take the wallet from the session rather than from request JSON.

The confirmation step

  • Every value-moving action opens a confirmation surface before anything is signed.
  • It shows amount, asset, destination (or route), provider, network, slippage and any deterministic risk facts the code computed.
  • Tokenized-stock and swap proposals are bound to the session wallet — a quote cannot be replayed for a different taker.
  • Cancelling a confirmation signs nothing. Nothing is broadcast in the background.

Troubleshooting: Support → Wallet

Security model

These rules are enforced in code, not only described in policy.

  • No keys in the client. Private keys, API secrets and CDP credentials are server-only. No secret is exposed under a NEXT_PUBLIC_ name.
  • A wallet address is not authentication. Privileged writes require a signed nonce and session.
  • Browser values are a cache, not proof. XP, score, referral, rank and reward claims sent from the browser are never trusted for ranking or payouts; ranking comes from the server ledger.
  • The model never executes a wallet write. The path is always parse → deterministic tool → validate → simulate → show exact effect → confirm → wallet signs.
  • Read and write tools are separate. Write-capable tools declare a risk level and require confirmation. Coinbase AgentKit runs in prepare-only mode on Base, and its automatic signing / payment actions are denied server-side.
  • One typed registry. Chain ID, contract addresses, decimals and ABIs live in a single typed source (lib/chain/base.ts and the per-domain configs).
  • Integer / bigint token math. No floating-point accounting for token amounts.
  • Validated API boundaries. Request shape, size, numeric range, origin and authorization are checked at every route, with rate limits and a daily AI token budget. Provider, RPC, Redis and stack-trace errors are never returned raw to the client.
  • Fail-closed game settlement. Financial game rewards stay disabled unless the operator gates are explicitly on.

Still open

An independent smart-contract audit and a full anti-cheat certification for MPGR Run have not been completed. See Roadmap → Security and Whitepaper → Risks.

Report vulnerabilities privately through a GitHub Security Advisory — never as a public issue.

Approval & execution boundaries

MPGR HUB has no autonomous spending authority. There is no standing delegation, no auto-approval, and no agent-held balance. The boundaries below are the real, enforced limits.

BoundaryEnforced valueWhere
User confirmationRequired for every value-moving action — no exceptions, no allowlist that bypasses itConfirmation modals; prepare-only tool mode
SlippageDefault 100 bps (1%); accepted range 1–500 bps (0.01%–5%)lib/trade/trade-config.ts
Quote freshnessA quote older than 30 seconds is re-quoted before signing; a worse minimum-output abortslib/trade/trade-config.ts, lib/trade/trade-execution.ts
Taker bindingSwap and B20 quotes are bound to the authenticated session walletTrade / B20 quote routes
Liquidity gateNo reported liquidity → nothing is signedlib/trade/trade-risk.ts
Balance gateInsufficient balance is a critical risk fact and blocks the proposallib/trade/trade-risk.ts, lib/trade/transfer-risk.ts
x402 scopeBase mainnet only (eip155:8453), exact scheme only, known-asset EIP-712 domain requiredlib/x402/x402-config.ts
Chain scopeBase mainnet (8453) only; unsupported chain IDs are rejected by every toollib/architecture/tools/tool-helpers.ts
Prompt & output budgetSystem ≤ 12,000 chars, user ≤ 8,000 chars, body ≤ 16 KiB, output ≤ 700 tokenslib/architecture/ai/server-policy.ts
Request limitsPer-IP and per-wallet rate limits on AI, XP, referral, x402 and trade routes, plus a daily AI token budgetlib/api/request-guard.ts
Staking minimum100 MPGR minimum per stake (contract constant)contracts/MPGRStaking.sol
Token lock penalty10% on-chain early-unlock penalty (contract constant, not a UI decision)contracts · lib/token-lock/token-lock-config.ts

PLANNED — configurable agent limits

User-configurable agent spend caps, per-action allowance limits and scheduled / recurring agent automations are not implemented. They are tracked under Roadmap → autonomous agent permissions. Today the only limit that matters is that you approve each action individually.

Supported protocols & actions

The Agent’s tool registry is explicit. Read tools return facts; prepare tools build a proposal that requires your confirmation; there is no execute-mode tool.

Read tools (no confirmation needed)

  • Wallet & portfolio — wallet_analyzer, token_analyzer, portfolio_analyzer, wallet_balances, base_research
  • Market — market_intelligence, trade_get_price, get_tape, get_pair, get_stock_holdings
  • Tokenized stocks — tokenized_stock_research, verify_b20_contract
  • Yield — yield_opportunities, yield_estimator, yield_comparison (normalised from live MPGR staking on-chain data)
  • x402 & AgentKit — x402_discover_resource, describe_x402_tape, agentkit_wallet_details, agentkit_discover_x402_services, agentkit_onchain_policy
  • Account — get_premium

Prepare tools (always require confirmation)

  • trade_prepare_swap — Base swap proposal (medium risk)
  • prepare_swap — tape-driven swap proposal (medium risk)
  • tokenized_stock_prepare_order — B20 order (medium risk)
  • transfer_prepare_send — Base transfer (high risk)
  • x402_prepare_payment — x402 payment (medium risk)

Infrastructure actually wired

LayerWhat MPGR HUB uses
ChainBase mainnet (8453) — the only configured chain; public RPC with fallbacks
SwapsCoinbase CDP Trade API (EVM swaps), 0x Swap API allowance-holder fallback, Permit2 signature append
Tokenized stocksCoinbase B20 catalog; single-hop Aerodrome Slipstream USDC pools (tick spacing 10)
Paymentsx402 — exact scheme, USDC on Base, EIP-3009 TransferWithAuthorization
Agent frameworkCoinbase AgentKit in prepare-only mode on base-mainnet (read actions only)
NamingBasename resolution for transfer recipients (server-side, never guessed)
AuthSIWE nonce + verify + HMAC session cookie; logout clears the session
DataUpstash Redis / Vercel KV for sessions, XP ledger, referrals, leaderboard and game allocation
ContractsMPGR token, MPGRStaking, MPGRTokenLock (V1), MPGRRewardVault — see below

Contract actions your wallet may be asked to sign

  • MPGR token — approve (0xB2000000000000000000008d204203177a78AF01)
  • MPGRStaking — stake, unstake, claimRewards, exit (0x1690C7b6d312284e30434d93498e56eE09fFa12c)
  • MPGRTokenLock — createLock, withdraw, earlyUnlock (0x0cb910b19b9d0ab772375a0b2e49b84ccdd51550)
  • MPGRRewardVault — claim, claimMultiple (0xbe4B0e8692670229129562a50A62f5173E30937C)

Admin-only contract functions (setAPR, pause, depositRewards, recoverERC20 and similar) are not reachable from the app or the Agent.

Research, market & portfolio

Research is fact retrieval, not opinion generation. The Agent answers from read-only tools and clearly states when live data is unavailable rather than filling the gap.

  • Market tape — the live Base market tape on Home, with a pair sheet for detail (right drawer on desktop, bottom sheet on mobile).
  • $MPGR market data — served from /api/market/mpgr; the tool reports DATA_UNAVAILABLE instead of fabricating a price.
  • Tokenized-stock research — the official Coinbase B20 catalog, plus contract verification for a supplied Base address.
  • Portfolio summary — MPGR balance, staked and locked amounts, claimable rewards, XP and level, streak, holder tier, Premium status, season progress and referral count.
  • Wallet analysis — ETH balance, MPGR balance and recent MPGR transfer history for any Base address.

Scope note

There is no general multi-chain portfolio indexer and no external market-data vendor beyond the MPGR market endpoint. Cross-chain portfolio aggregation and third-party price feeds are not implemented — see Roadmap → research and portfolio intelligence.

Trading & swap execution

Trading is prepare → confirm → sign. The Agent (or the tape) builds a quote; nothing is submitted until you confirm in your wallet.

  • Assets — ETH / WETH / USDC / MPGR and ordinary Base ERC-20 tokens by contract address.
  • Routing — Coinbase CDP Trade API first; 0x Swap API is used when CDP will not route the pair.
  • Slippage — 1% default, 1–500 bps accepted.
  • Freshness — a quote older than 30 seconds is refreshed, and a worse minimum-output aborts the execution.
  • Approvals — where the provider requires it, an ERC-20 approval is submitted and its receipt confirmed before the swap transaction is sent.
  • Risk facts — unverified token, no liquidity, incomplete simulation and insufficient balance are surfaced as deterministic warnings before signing.

Coinbase B20 tokenized stocks do not use this path — see Tokenized stocks.

Troubleshooting: Support → Trading & swaps

Tokenized stocks (B20)

Coinbase B20 tokenized stocks are supported as research and secondary-market trading only.

  • The catalog shipped in the app is the official Coinbase B20 list: AAPLc, AMZNc, COINc, CRCLc, GOOGLc, INTCc, METAc, MSFTc, MSTRc, NVDAc, SNDKc, SPCXc, TSLAc.
  • A buy or sell is a single-hop swap through the Aerodrome Slipstream USDC pool for that asset on Base — not through CDP or 0x.
  • Primary mint and redeem are Authorized Participant only. MPGR HUB implements no retail mint API and is not a broker-dealer or authorized participant.
  • You can verify any Base address against the official B20 list with the Agent.

Not investment advice

Tokenized equity exposure carries market, liquidity and smart-contract risk. MPGR HUB provides technology services and does not provide financial, investment or trading advice.

See also Whitepaper → trading and execution architecture.

x402 / agentic payments

x402 is the payment path for agentic / machine-to-machine commerce. MPGR HUB implements it as a discover → register → confirm → sign → submit flow. There is no silent payment.

  • Discover — the Agent fetches a resource and reads its 402 Payment Required requirements.
  • Register — the server re-fetches the resource unauthenticated, applies SSRF and allowlist checks, and stores the server-observed terms. Terms are never taken from the client.
  • Confirm — you review amount, asset, recipient and resource in the payment modal.
  • Sign — your wallet produces an EIP-3009 TransferWithAuthorization signature. No token approval and no transfer is sent by the signature alone.
  • Submit — the signed payment is submitted against the stored registration, bound to the exact terms you approved.

Scope limits

  • Base mainnet only — eip155:8453 (and the base / base-mainnet aliases).
  • Exact scheme only.
  • USDC on Base is a known asset; an unknown asset without a supplied EIP-712 domain is rejected.
  • AgentKit’s automatic payment actions are denied server-side — the Agent can never pay on its own.

Roadmap: Roadmap → x402 & agentic payments

MPGR Run

MPGR Run is the flagship game and the only playable title today: a one-tap endless runner built on the official MPGR character art, playable at /games/mpgr-run.

  • Server-issued sessions. A run starts against a server session with heartbeats, so a client cannot simply declare a score.
  • Authoritative verification. The server replays the issued seed and the submitted input trace tick-for-tick and recomputes the score, with drift-tolerant timing checks.
  • XP. A completed run awards 8 XP, capped at 10 XP-earning runs per day. Runs beyond the cap still count toward campaign and eligibility logic.
  • Weekly stats. Verified runs feed the weekly game panel and are bound to the authenticated wallet.

Financial game rewards are OFF by default

Competitive financial payouts for MPGR Run require two independent operator gates (GAME_REWARDS_ENABLED and GAME_AUTHORITATIVE_VERIFICATION_ENABLED) and both default to false — the pipeline is fail-closed. The economics behind it (a 7,000,000 MPGR lifetime games budget and a 35,000 MPGR weekly pool cap, with eligibility, weighting, per-player share caps and settlement reconciliation) are implemented but not enabled. XP and season progression run regardless.

Other titles (Clicker, Memory Challenge, Space Shooter, 2048 Daily, Pet Raising, Speed Run, Roguelike RPG, AI Battle Arena) exist in the game registry as coming soon and are not presented as playable. See Roadmap → gaming ecosystem.

Rewards & claims

/rewards is the Reward Hub: a summary, reward categories, on-chain claims, claim history, achievements and the season preview.

How claiming works

Real MPGR claiming is on-chain, through the deployed MPGRRewardVault contract on Base (claim / claimMultiple). A vault reward is either allocated or claimed — there is no partial-progress concept. An older local/mock claim system was removed; the hub no longer invents claimable MPGR.

Reward categories

The hub groups rewards into daily, weekly, staking, quest, game, referral, season, AI, premium and airdrop. Category metadata covers the full program, but a category only shows real numbers when a live provider exists behind it:

CategoryStatus
StakingLIVE — real rewards from the deployed staking contract
GameGATED — pipeline implemented, financial payouts disabled by default
SeasonUI track — Season Pass progress is computed in-app
Daily / weekly / quest / referralProgram categories in the treasury plan; surfaced through the hub when an allocation exists
AI / premium / airdropFUTURE — no live per-wallet provider yet

All rewards are existing tokens from the community treasury — no new $MPGR is ever minted. See $MPGR → tokenomics and Whitepaper → rewards economy.

XP, levels & streaks

XP is earned from a fixed set of actions with fixed values. There are no arbitrary or variable grants.

ActionXP
Wallet connected (one-time)50
Daily check-in20
Profile completed (one-time)30
Shared on X15
Quest completed40
Referral success100
MPGR Run completed (max 10/day)8
  • XP drives your level on a progressive curve and your daily check-in streak.
  • The authoritative XP total is the server-owned ledger (/api/xp), not the browser. XP shown in the app before the server value syncs is a cache and is never used for ranking.
  • Authenticated XP writes are rate-limited and the server rejects client-supplied XP totals.

Troubleshooting: Support → Rewards & games

Season points & Season Pass

Seasons run on UTC calendar months. Season points are derived from XP earned inside the current season window — there is no separate points currency.

  • /season — current season number, your season points, milestones (250 / 500 / 1000) and the countdown to season end.
  • /season-pass — a reward track over the same season: 20 levels at 150 season points per level, with a free track and a Premium track (every 5th level is a milestone) plus missions.
  • Premium-track eligibility comes from your Premium tier, which is derived from active token locks.

Where season-pass state lives

Season points come from the XP engine, but Season Pass claim state is stored per wallet per season in browser storage. It resets naturally when a new season starts. It is not an on-chain balance.

Achievements

Achievements are computed from your XP record and your MPGR Run stats. They are unlocked by meeting a target and then claimed once.

  • Account — First Check-in, 7 Day Streak, 30 Day Streak, 100 XP, Level 5, Level 10, Community Builder, Top Referrer.
  • MPGR Run — First Run, 1,000m Club, 5,000m Club, 10,000m Club, Flawless Run, Coin Collector, MPGR Runner.
  • Some cosmetic entries are flagged coming soon and stay locked until their feature ships.

Achievements are visible on Rewards, Games and Profile.

Leaderboard

The global leaderboard at /leaderboard is sourced from the server-side ranking built on the XP ledger in Redis — not from a client-reported score. It shows the global top plus your own row, with your wallet highlighted as you and never presented as the whole board.

Ranking updates as authenticated XP is awarded. Browser-side scores are ignored for ranking purposes.

Staking

Staking runs against the deployed MPGRStaking contract on Base at 0x1690C7b6d312284e30434d93498e56eE09fFa12c. The UI is at /staking.

  • Single-sided — stake MPGR, earn MPGR.
  • No lock term — rewards accrue continuously and can be staked, claimed or unstaked at any time.
  • Minimum stake — 100 MPGR (contract constant).
  • Reward schedule — the contract declares a 730-day rewards duration and a 25,000,000 MPGR reward pool, with APR bounded between 1% and 100%.
  • Actions — approve, stake, unstake, claim rewards and exit (claim plus full unstake). Each is a wallet-signed transaction with a confirmation step.
  • Live APR, total staked, your stake, accrued rewards and pool state are read from the contract with short cache TTLs and background refresh.

See Whitepaper → staking and Roadmap → staking.

Token lock

Token lock runs against the deployed, immutable MPGRTokenLock V1 contract at 0x0cb910b19b9d0ab772375a0b2e49b84ccdd51550. The UI is at /app/token-lock.

  • Duration presets — 30, 90, 180 or 365 days.
  • Early unlock — allowed at any time, but the contract applies a fixed 10% penalty (90% returned to you, 10% to the penalty recipient). The split is computed and executed on-chain; the app only previews it.
  • What it powers — locked MPGR feeds your Premium tier and Holder Score.
  • Actions — approve, create lock, withdraw (after maturity) and early unlock, each wallet-signed after confirmation.

See Whitepaper → token lock.

Holder tier & Premium

Two independent reputation systems read the same on-chain positions.

Holder tier

Derived from your Total Holder Score — live wallet balance + active staked + active locked. It is not a purchase and falls away automatically if the score drops. It grants a badge, frame, governance voting weight and community reputation.

TierMin scoreVote multiplier
Bronze1,0001×
Silver10,0001.25×
Gold50,0001.5×
Platinum150,0002×
Diamond500,0003×

Premium

Derived only from MPGR currently active in Token Lock. Premium owns the XP and rewards multipliers (1.5× XP, 1.25× rewards on every tier); Holder tier never touches multipliers.

TierMin locked MPGR
Silver10,000
Gold50,000
Diamond100,000

No paid subscription

There is no paid Premium subscription in the product. Premium is a function of what you have locked on-chain, and it lapses if you release enough locked MPGR.

Referrals

Referrals are authenticated and server-recorded.

  • A referral link (?ref=) is captured when a visitor arrives, and attributed only once that wallet holds a valid signed session.
  • The referred wallet is always the authenticated session wallet — a client can only ever supply the referrer, never the referred identity.
  • A successful referral awards 100 XP.
  • Self-referral is rejected and recorded as abuse; re-pointing an already-attributed wallet at a different referrer is rejected and logged.
  • The referral endpoint is rate-limited (20 requests per 60 seconds) and requires authentication.

Hardening in progress

Referral sybil resistance is still being hardened — see Roadmap → quests, referrals & leaderboards.

Your referral link and count are on Profile.

Campaigns & quests

/campaigns hosts temporary, operator-launched events. Campaigns are config-driven: a definition file plus a registry entry is all a new campaign needs — no page or engine changes.

  • Each campaign owns its own points ledger and leaderboard, separate from global XP and Season Points.
  • Joining and scoring require an authenticated wallet session.
  • Points are computed server-side from the campaign config and adapter validation; clients submit only an action id, an idempotency event id and an optional bounded number.
  • Adapter types exist for game, trading, agent and social activity, with a generic fallback for future event types.

Current registry

The registry currently ships example campaign definitions (MPGR Run weekly, a trading competition and an agent competition) used to exercise the system. Treat the specific pools and dates as illustrative until an operator announces a live campaign.

Quests in the wider sense (community and on-chain missions) are part of the treasury program and are surfaced through the Reward Hub when an allocation exists. Deep quest automation is planned.

Base ecosystem integration

MPGR HUB is Base-native by design. There is no multi-chain runtime today, and no bridge or cross-chain execution path.

LayerUsage in MPGR HUB
Base mainnetSole production chain, ID 8453
Coinbase Wallet / Base AppFirst-class connection path via RainbowKit
Coinbase CDP Trade APISwap quotes and swap transactions, BYO wallet
Coinbase B20 tokenized stocksResearch + Aerodrome Slipstream secondary market
USDC on BaseSettlement asset for swaps and x402 payments
Farcaster Mini AppIn-app distribution and auto-connect on the Base / Farcaster graph
BasenamesHuman-readable transfer recipients
VercelProduction host, GitHub-connected
BaseScanPublic verification of every contract and transaction

Naming Coinbase, Base, Aerodrome, 0x, Farcaster, Vercel or USDC describes public infrastructure MPGR HUB uses. It does not imply partnership, endorsement, brokerage access or authorized-participant status.

See Whitepaper → Base and Roadmap → Base expansion.

AI provider architecture

The Agent is a layered, replaceable provider stack. No single model is trusted with execution, and a network failure never produces a fabricated answer.

  • Providers — Gemini is the default, with NVIDIA NIM and OpenAI available; the chain falls back to a deterministic on-device engine that never invents live values. Anthropic and Ollama are declared but not implemented.
  • Routing — tasks are classified and routed to a provider order; the deterministic engine is always the last link.
  • Safety layers — guardrails, per-provider timeouts, a circuit breaker and diagnostics wrap every network provider.
  • Prompt policy — trusted policy sits in the system channel; client and tool context is explicitly labelled untrusted so it cannot override it.
  • Budgets — prompt/output limits (system 12,000 chars, user 8,000 chars, body 16 KiB, output 700 tokens), per-IP and per-wallet rate limits, and a daily AI token budget.
  • Onchain layer — Coinbase AgentKit runs in prepare-only mode on Base with a read-action allowlist; its signing and auto-payment actions are denied server-side.

See Whitepaper → AI agent infrastructure and Roadmap → AI provider layer.

Account & profile

MPGR HUB is wallet-based — there is no email and no password.

  • Session — SIWE sign-in creates an HMAC session cookie; sign-out from Profile clears it. A wallet address alone is never accepted as proof.
  • What Profile shows — wallet and address, XP/level, streak, holder tier, Premium status, Season Pass progress, your referral link and count, activity timeline, achievements, and links into staking, token lock and support.
  • What is stored — sessions, XP ledger rows, referral attributions, leaderboard ranking and game allocation state on the server; XP/Season Pass/achievement caches and local game state in the browser, always as a cache and never as proof.
  • Memory — you can clear the Agent conversation from the chat; do not paste secrets, seed phrases or private keys into the Agent.

See Privacy and Terms.

Frequently asked questions

Is MPGR HUB custodial?

No. The Agent prepares; your wallet signs. MPGR HUB never holds your keys, never holds a balance for you, and never broadcasts a transaction you have not confirmed.

Can the Agent spend without me?

No. There is no autonomous execution path, no standing allowance and no agent-held funds. The AgentKit actions that would sign or pay automatically are denied server-side.

Which network do I need?

Base mainnet (8453) only. If the header shows Wrong network, switch to Base and retry.

Is there a maximum supply?

Yes — 1,000,000,000 MPGR, fixed. No inflation, no future minting, no private sale, no VC allocation, no locked team allocation. Rewards come from the community treasury, not from new supply. See $MPGR tokenomics.

Are game rewards live?

XP and season progression are live. Competitive financial game payouts are disabled by default behind two operator gates and are not enabled in production today.

Is there a mobile app?

Not yet. The web app is responsive on phones and tablets, and a mobile wrapper is planned.

Is there governance?

Not as a DAO. Governance is planned; until then the fixed-supply, no-VC, no-team-unlock commitments are the standing constraints.

Has the code been audited?

An independent third-party smart-contract audit has not been completed. The repository ships unit, security and contract tests in CI, which is not the same thing. See Roadmap → security.

Support

For guided troubleshooting — wallet and connection issues, transaction and confirmation guidance, swap troubleshooting, rewards and game questions, and security reminders — see Support.

Community and official channels:

Related documentation: