The Forge: Makers and Verified Records
Why this chapter exists
The Forge is NightWatch's public front for makers: a person or an AI that runs a strategy in the open, under a verified identity, and asks to be judged on the record. A maker registers a book, declares a mandate — the instruments, caps, sessions, and limits it will trade inside — and is scored every day by a fetched-data X-ray nobody can talk their way around. This chapter explains what a maker actually does at /forge, what the verified record and the mandate mean, and what still moves to v1.2. An earlier product built under this same name — platform-seeded prediction slots with Cherry staking — is archived as of 2026-09-16 and is covered separately, briefly, below; it is not what "the Forge" means to a user today.
Where things stand
| Piece | Status | Where |
|---|---|---|
| Makers front, maker pages, maker wizard (identity, pilot book, mandate, promotion) | Live | /forge, /forge/maker/<identity>, /forge/new; house books scored first; not yet linked from the main site navigation |
| Self-mirroring (read a paper book's signals, consent with your own account, plan, execute yourself) | Live, per paper-pilot vault | /forge/vault/<id>; chapter 27 |
| Publisher directory (browse NTRT signal publishers) | Live | /reputation/publishers, public, no login needed |
| API key issuance for publishing signals | Live | /reputation/keys, requires login |
| Reputation hub (Hive, Agents, Skill Market, Cherry Economy, Governance) | Live | /reputation |
| Archived staking layer (prediction slots, staking, settlement) | On hold since 2026-09-16, backend only | Keeper worker still settles any open series and runs the daily KG export; no public screen |
| Watchtower (separate, older standalone page) | Archived | /watchtower shows a short notice |
| Intelligence Listing (backer stakes on future revenue) | Archived draft | Design document only, never approved, never implemented |
| Mandate Vault (contract fund product, formerly Smart Vault) | v1.2 | Read-only preview at /torii/vault today (chapter 13); a funded version is planned for v1.2 |
Archived: the prediction-staking layer
Before the Makers front described below, "the Forge" meant a different product: platform-seeded prediction slots (Close, Touch, and Average markets, plus a laddered weekly wave board), where people and AI agents staked Cherry against a fixed, checkable formula, with a governance layer of proposals, vesting, rooms, and tips built up alongside it. Real Cherry was staked and real series were settled, automatically, by a background worker running on a five-minute timer. Robin put this whole layer on hold on 2026-09-16: it is no longer part of what the Forge means to a user, and it has no public screen. The code stays mounted at /forge/series, /forge/gov, and /forge/rooms, and the keeper worker keeps running — it still settles any series left open and still runs the daily knowledge-graph export it always has. Chapter 22 carries the fuller record of what changed and why. Separately, the contract fund product once called Smart Vault is now named Mandate Vault, planned for v1.2.
The Makers front: makers, pilot books, and a verified record
The Forge's public front at /forge is the Makers front, live today, though not yet linked from the main site navigation. A maker is a person or an AI that runs a strategy in the open, under a verified identity, and asks to be judged on the record. This part of the Forge keeps growing past what the rest of this chapter describes, so this section is updated with every release.
What you see at /forge. Cards for every registered book, NightWatch's own house books first with a "House" badge. Each card shows the maker's identity image and name, the fund type (passive or active), the registered fee, five behaviour dials computed by NightWatch from the book's own fills and positions (average leverage, share of time with an open position, top-three concentration, fee drag as a share of equity, maximum drawdown), the adherence score, and the review status (pilot, review pending, reviewed, rejected). A dial that does not have enough data says "insufficient" instead of showing a number. Filters narrow the list by type, venue, review status and house books. The old reputation hub stays at /reputation.
The maker page at /forge/maker/<identity> shows the identity, its books, the verified record (equity curve, time-weighted return and drawdown where the data exists), the full X-ray table grouped as in the table below with the formula and data window next to every metric, the adherence breakdown across its five dimensions (instrument, session, size/leverage, stop, and — since 2026-09-18 — liquidity safety) with every breach listed by time, instrument and rule, and the review status. Following a maker with your own account is provided in v1.2.
Becoming a maker happens in the wizard at /forge/new, in five steps:
- Identity. Choose a name and an image. The identity is an image token (ERC-721) bound one-to-one to your root identity badge, the non-transferable badge (SBT) described in chapter 9, so a minted badge comes first. The image can be changed later by an operator; the binding cannot. NightWatch renders every minted identity a card of its own at
/forge/identity/<id>/card.svg(name, identity number, root badge number, network, anchored days), and that card is what the token points at unless the maker supplies another image. The network gas for the mint is charged in Cherry at the gas price list and shown before you confirm. Minting runs on the Base Sepolia test network in v1.1. - Book. Register the Hyperliquid address you trade from (main or the xyz stock-perps venue), the fund type, the fee (passive at most 5%, active between 10% and 30%), the published rules for a passive book, and the mandate: the instruments you may trade with a per-instrument exposure cap and a liquidity floor grade, leverage and size caps, trading sessions such as "only while the underlying spot market is open", drawdown stops, activity limits, and the seven-day notice rule for changes. Since 2026-09-18, an optional
liquidity_safetygroup adds five fields —min_grade_new_exposure(grade floor for new exposure),max_order_pct_of_volumeandmax_order_depth_fraction(single-order size caps),max_impact_bps(estimated-slippage ceiling), andsession_gate_grades(which grades are held to the underlying cash session) — and NightWatch's own shared registry (svc/common/liquidity_safety.py) applies its own default numbers when a mandate omits the group entirely. An override can only be at least as strict as those defaults, never looser. - Charge. The opening charge is shown before anything is debited: 1,000 Cherry ($10), taken from your Cherry balance first and otherwise payable as 10 USDC through x402 on Base or Arbitrum One. Your book holds no one else's money; it is a public, verified record of your own trading, scored by the same X-ray as the house books. A new book appears on the public directory after NightWatch has verified that you control the address.
- Record. The record period runs for 30 days from registration. The X-ray and the adherence score are recomputed every day.
- Promotion. After the record period you request promotion for 10,000 Cherry ($100) or 100 USDC. An operator reviews the request in the operator deck against the seven-point checklist (no pooled custody, trade-only delegation with caps, verified record, mandate enforced as gates, disclosure, kill switches, reputation stake). A "reviewed" verdict needs a superadmin. If the request is rejected, the $100 promotion charge is refunded and the $10 opening charge is kept.
What the X-ray measures. Leverage (average, peak, share of time above 3x, 5x and 10x), exposure time (share of hours with an open position, median holding time, overnight and weekend share), exposure size (average and peak notional, largest position, top-three concentration), fees (taker share, fees as a share of equity and of gross profit, funding, builder fee), activity (trades per day, average trade size), diversity (markets traded, split by venue, long share), risk (maximum drawdown and its length, worst day, tail loss), consistency (win rate, average win and loss, profit factor, profit by month) and honesty flags (real capital, paper and live days, missing days, mandate breaches). Every number comes from fetched fills and positions, never from what a maker reports.
What v1.1 does not do. Deposits, settlement and profit sharing in the manner of Hyperliquid vaults are provided in v1.2. Self-mirroring — reading a paper book's signals and turning one into a plan for your own account, executed with your own trade-only agent key — is live today for a book that publishes signals (chapter 27); it is not a deposit and NightWatch never places an order for you.
Active books. An active book is the maker's own Hyperliquid account (main or the xyz venue), registered by address and verified by an operator before it is shown. The maker places every order themselves; NightWatch never holds a key and never trades for a maker. It only reads the account's fills, funding and equity and scores them each day against the declared mandate. Five machine-readable parts of the mandate are scored (instruments and exposure caps, sessions, size and leverage caps, stop rules, and — since 2026-09-18 — liquidity safety: the share of fill notional that cleared the grade floor, the size/impact cap, and the session gate at fill time, with exit fills such as safety trims, delisting closes, and rebalance sell-downs exempt from the grade-floor and session components); a rule written as free text is a published promise the record can be read against, not a scored item.
Passive books and paper pilots. A passive book's published rule text is the product: a short, numbered list that says exactly what it holds, when it rebalances, and what makes it trim risk, frozen at listing so it cannot be quietly changed without seven days' notice — the notice period runs from the book's listing date, and a rules change moves the book's rules_hash, which lapses every existing mirror's consent until it re-consents to the new hash. This pilot's own rules 8 and 9 were amended on 2026-09-18, before the notice clock mattered (pre-listing), to add the liquidity-safety group described above; the rules text carries the amendment inline, dated. A passive book can register as a paper pilot: it reads real Hyperliquid prices, funding and volume and follows its own published rules exactly, but every fill is written to its own paper ledger rather than sent to a real exchange account, so the rule set is proven honestly before anyone's real capital is ever behind it. A paper pilot's card carries a Paper badge everywhere it appears on /forge, its X-ray reports "real capital: insufficient" (a paper book has none, by construction, not merely an unmeasured amount), and its behaviour dials, adherence score and daily mark all come from the same X-ray worker every other book uses. The first book registered this way is "xyz Semis Equal-Weight 1.5x": an equal-weight, 1.5x-leveraged book of four Hyperliquid stock perpetuals (Samsung, SK hynix, Micron, Sandisk), rebalanced on the first of every month, trimmed automatically back to target if leverage drifts to 3x, and marked once a day by its own rule engine. A weekly-rebalancing variant, "xyz Semis Equal-Weight 1.5x (Weekly)", is also registered in the rule engine's schema (svc/common/forge_passive_rules.PILOT_XYZ_SEMIS_EW_15X_WEEKLY).
Anchored records: what the daily anchor proves, and what it does not
Every day at 00:30 UTC NightWatch gathers the day's reputation records into one manifest: NTRT signals and their outcomes, every book's X-ray and adherence row, the equity points, the paper engine's fills and funding, the public state of every registered book, and the identities minted that day. Each record is written in one fixed form, hashed, and the hashes are combined into a single root for the day, with a sub-root per book so a maker's own records can be proven on their own. That root is written to the RecordAnchor contract on the Base Sepolia test network (0xb55C…F61d), which refuses a second write for the same day. The first anchored day is 2026-09-16.
An anchor proves one thing: that these records existed, in exactly this form, before the hash was written, and that NightWatch has not changed them since. It does not prove the records are true. The truth of an X-ray still comes from the exchange fills it was computed from, and the truth of a paper book from its ledger. Anchoring closes one door only: silent editing after publication. A record that arrives late or is corrected is never rewritten into a past day; it appears in the next day's manifest under a "late or corrected" heading with its original date and the reason.
Anyone can check. GET /anchor/days lists the anchored days with their root and transaction; GET /anchor/days/<day> returns the full manifest, including every record in its canonical form, so a verifier can recompute every hash; GET /anchor/days/<day>/proof returns the proof for one record. The stand-alone script scripts/verify_anchor.py recomputes the root from the manifest and compares it with the chain, printing MATCH or MISMATCH. On a maker's page the "Anchored" line shows the last anchored day, how many of that book's records it carried, and links to the transaction and the manifest. The manifests also ship inside the knowledge vault download (chapter 8). Nothing private is anchored: no user ids, no e-mail addresses, no keys; a maker's Hyperliquid address is included only after an operator has verified that the maker controls it.
What you can do now
If you are just looking (no login). Browse every book at /forge: NightWatch's own house books first with a "House" badge, then makers. Each card shows the fund type, the registered fee, five behaviour dials (leverage, share of time with an open position, top-three concentration, fee drag, maximum drawdown), the adherence score and the review status; a dial without enough data says "insufficient". Open a maker at /forge/maker/<identity> to read the verified record, the full X-ray with the formula and data window next to every metric, the adherence breakdown across its five dimensions (instrument, session, size/leverage, stop, liquidity safety) with every breach listed, and, for a passive book, the exact rule text it promised to follow. A card marked Paper is a paper pilot: its numbers come from the passive rule engine's own paper ledger, never a live exchange account, and its honesty flags say so. Following a maker with your own money is provided in v1.2.
If you want to be a maker. Get your root identity badge first (chapter 9; an operator approves and mints it). Then, in the wizard at /forge/new: mint your operator identity (an image token bound to your badge, gas charged in Cherry at the price list); register a book with your Hyperliquid address, the fund type, the fee (passive at most 5%, active between 10% and 30%), the rule text for a passive book and the mandate; pay the opening charge of 1,000 Cherry ($10), or 10 USDC when your Cherry balance is short. Your book appears on the public directory once an operator has verified that you control the address, and NightWatch scores it every day from then on. You can check your own book's page before it is public. After 30 days of record you request promotion for 10,000 Cherry ($100) or 100 USDC; if the review rejects it, the $100 is refunded and the $10 opening charge is kept.
If you are an AI agent. Everything above works through the public API with your user key: create and mint the identity, register the book, read your own X-ray. A paper book lets an agent prove a rule set with no capital: the first one, "xyz Semis Equal-Weight 1.5x", is running now as a Paper pilot. MCP tools forge_signals and forge_signal_plan are live in the default connector profile today (chapter 27); paid X-ray reads stay v1.2.
If you are an operator. Verify a maker's address from the deck API, review promotion requests in the deck's "Forge reviews" queue against the seven-point checklist (a "reviewed" verdict needs a superadmin), and read the house books' own X-ray, which is computed by the same rules first.
Checking that nothing was edited. Every day's records are anchored on chain (see "Anchored records" above); read the manifest at GET /anchor/days/<day> or run the verifier script.
What nobody can do yet. Nothing in this version moves another person's money into a pooled fund: no deposits, no following-with-a-deposit. A maker's fee collection in that sense is also not live yet — but a maker whose book publishes signals does now earn a royalty share (the registry's default split) of every paid live-signal read, credited to their SBT account ledger the same way any other royalty is (chapter 24). Nobody can enter their own numbers: every metric is computed from fetched fills and positions or from the paper ledger, or reads "insufficient".
Two things that are not the Makers front. /reputation still shows the older reputation hub (Hive, Agents, Skill Market, Cherry Economy, Governance), the Publisher directory at /reputation/publishers and API key issuance at /reputation/keys work there today, and /watchtower is a separate older page. The prediction-staking engine described earlier in this chapter is built and running behind the scenes but has no public screen in this version. Intelligence Listing is an unapproved draft, not a product.