# Addresses

> NeuroChain address format and types — free key-derived .human wallets and paid .node, .app, .vault and .agent names — with naming rules, prices and how ownership is proven.

Source: https://docs.nro.world/learn/addresses

Every NeuroChain address has the form `neuro:<name>.<type>`. The suffix says what the address is.

| Suffix | What it is | How you get it | Cost |
|--------|-----------|----------------|------|
| `.human` | Your wallet | Derived from your seed words | Free |
| `.node` | Validator | Registered by a `.human` owner | `min_stake` (default 10 000 NRO), locked as the validator's stake |
| `.app` | Smart contract address | Assigned on deploy, or a readable name registered by a `.human` owner | Deploy: the deploy fee only. Readable name: `min_stake` (default 10 000 NRO), burned |
| `.vault` | Multi-signature treasury | Registered by a `.human` owner | `min_stake` (default 10 000 NRO), burned |
| `.agent` | Smart account for AI agents (session keys, sponsored gas) | Registered by a `.human` owner | By name length, see [prices](#name-prices) |

`min_stake` is a governance parameter; read its current value from the governance parameters API rather than assuming the default.

## Your wallet address: `.human`

A `.human` address is computed from your public key, so nobody can register it and nobody else can own it.

![Address derivation: seed words are normalized, hashed with SHA3-256 under the NC_KDF_v3 label to a 32-byte seed, which generates an ML-DSA-65 keypair; the address is the first 15 hex characters of SHA3-256 of the public key](/diagrams/address-derivation.svg)

1. The seed words are lower-cased and joined with single spaces.
2. `seed = SHA3-256("NC_KDF_v3|" + words)` — 32 bytes.
3. The seed generates an **ML-DSA-65** keypair (Dilithium3, FIPS 204).
4. `address = "neuro:" + first 15 hex characters of SHA3-256(public key) + ".human"`.

The same keypair both defines the address and signs every transaction. Your password only encrypts the seed in the browser's keystore; it plays no part in the address or the key.

**Ownership proof.** To accept a signed operation for a `.human` address, the node recomputes the address from the public key sent with it. If they do not match, the operation is rejected — no registry, no "first key wins".

### Custom `.human` names

A wallet can also register a readable name such as `neuro:alice.human`. The name is recorded on chain as owned by your key-derived wallet; transfers still settle on the key-derived address. Price depends on length — see [below](#name-prices).

## Paid names: `.node`, `.app`, `.vault`, `.agent`

A paid name has no key of its own. It is controlled by the key of the `.human` wallet that owns it. When the owner rotates keys through an [identity](/ai/identity), control follows.

| Type | What registration does |
|------|------------------------|
| `.node` | Debits `min_stake` from the owner and records it as the validator's **stake** (unbonding applies). Default commission 10%. Only `.node` addresses are consensus validators. |
| `.app` | Debits `min_stake` and **burns** it, reserving a readable contract name. (A deployed contract always gets an address of its own — see below.) |
| `.vault` | Debits `min_stake`, burns it, and creates a vault with the owner as its first member and a threshold of 2 signatures. |
| `.agent` | Debits the length-based fee and records an agent smart account. Not a validator, holds no stake. |

### Contract addresses from deploy

Every deploy creates its contract at `neuro:<10 hex>.app`, where the hex is the first 5 bytes of `SHA3-256(owner ‖ nonce)` (nonce as 8 big-endian bytes). The address is computed the same way on every validator, so it is known before the deploy is final. See [Deploy contracts](/build/deploy).

Transferring a paid name to another owner costs a flat **100 uNRO** (`NFT_TRANSFER_FEE`). The current value is also returned by `GET /api/v1/gas/estimate` as `nft_transfer_fee`.

### Name prices

Custom `.human` names and `.agent` addresses are priced by length — shorter is rarer, so it costs more.

| Name length | Price |
|-------------|-------|
| 1 character | 100 000 NRO |
| 2 characters | 50 000 NRO |
| 3 characters | 10 000 NRO |
| 4 characters | 5 000 NRO |
| 5 characters | 2 000 NRO |
| 6 or more | 500 NRO |

## Naming rules

These apply to every registered name:

- ASCII letters, digits and hyphens only.
- 1 to 32 characters.
- No hyphen at the start or the end.
- The full address must start with `neuro:`.
- Uniqueness is by **full address**: `neuro:foo.node`, `neuro:foo.app` and `neuro:foo.agent` can all exist and belong to different owners. A custom `.human` name may not take a name already used by a `.node`.

## System addresses

Addresses under `neuro:system.*` are reserved by the protocol. They are targets of signed operations (`neuro:system.stake`, `neuro:system.node`, `neuro:system.name`, `neuro:system.deploy`, …) rather than accounts anyone owns.

## See also

- [Identity](/ai/identity) — rotating and recovering the keys behind an address.
- [Gas & fees](./gas) — what each operation costs.
