Skip to content

Gateway ​

The gateway is a Node.js (Fastify) service between users and the node. The web app, the SDKs and the MCP server all talk to it.

It doesDetails
Serves the REST APIMost paths proxy the node; a few are its own — see REST
Serves the WebSocket/ws — live blocks, transactions, AI events, balance subscriptions; see WebSocket
Routes by shardSends each transaction to the node serving the sender's shard
Watches the chainPolls the node, turns changes into events, raises contract activity alerts
Rate-limitsPer IP, globally and for AI endpoints
Hosts AI toolsContract audit proxy, contract generation (SmartForge), documentation assistant

The gateway never decides anything about chain state: signatures, balances and AI scores come from the node.

Run ​

bash
cd neurochain/gateway
npm install
NODE_RPC_URL=http://localhost:9933 node src/index.js
bash
curl -s http://localhost:3000/health
# {"status":"ok","network":"neurochain-mainnet-1","height":11,"peers":0,"round":0,"mempool":0}

It listens on port PORT (3000) on all interfaces.

Configuration ​

Connection ​

VariableDefaultMeaning
PORT3000Listening port
NODE_RPC_URLhttp://localhost:9933The node's RPC
NEUROCHAIN_SHARD_NODES—Shard routing, e.g. 0=http://n0:9933,1=http://n1:9934
SHARD_NODE_URLS—Same, positional (index = shard), used if the above is unset
NETWORK_IDneurochain-mainnet-1Network name reported in /health
CORS_ALLOWED_ORIGINS*Allowed browser origins — set your site's origin in production
TLS_CERT, TLS_KEY—PEM paths to serve HTTPS directly

Limits ​

VariableDefaultMeaning
GLOBAL_RL_MAX_RPS200Requests per second per IP
AI_RL_MAX_RPM10AI endpoint requests per minute per IP
WS_MAX_MSG_BYTES65 536Largest WebSocket message
WS_MAX_SUBS_PER_CLIENT50Balance subscriptions per connection
WS_RPC_MAX_RPS30RPC calls per second per connection

Chain watching ​

VariableDefaultMeaning
POLL_NODE_INTERVAL_MS2000How often the node is polled for new blocks
SENTINEL_CHECK_INTERVAL_MS30000Contract activity check
SENTINEL_SPIKE_LOW_THRESHOLD / _HIGH_THRESHOLD10 / 50Calls per interval that raise a medium / high alert
SENTINEL_LOW_SCORE_THRESHOLD60Alert when a contract below this security score starts being called
ALERT_COOLDOWN_MS60000Minimum gap between alerts for one contract
PROTOCOL_PARAMS_REFRESH_MS60000How often protocol parameters are re-read from the node

Faucet (test networks) ​

VariableDefaultMeaning
FAUCET_AMOUNT50 NROAmount per request
FAUCET_COOLDOWN_SECS86400Per address and IP
REDIS_URLredis://localhost:6379Optional — keeps the faucet cooldown across gateway restarts; without Redis it is kept in memory

AI tools ​

VariableDefaultMeaning
ANTHROPIC_API_KEY—Enables SmartForge contract generation with Claude; without it a built-in template generator is used
SMARTFORGE_MODEL, SMARTFORGE_MAX_TOKENS—Model and length for SmartForge
AI_EXPORT_TOKEN—If set, /api/v1/ai/export/* requires it
ASSISTANT_ENABLED0Documentation assistant (POST /api/v1/assistant/ask); rebuild its index with npm run assistant:index

The full list with every default is in the repository's .env.example.

Security notes ​

  • Keep the node's RPC private and expose only the gateway (behind a reverse proxy with TLS, or with TLS_CERT / TLS_KEY).
  • Set CORS_ALLOWED_ORIGINS to your own origins.
  • POST /api/v1/wallet/derive-address receives a recovery phrase; the node refuses it on mainnet, and it should never be reachable on a public gateway.
  • Some fields of /api/v1/network/status (tps_peak, block_time_ms, the crypto list, AI model figures) are fixed descriptive values, not measurements.

Tests ​

bash
cd neurochain/gateway
npm test            # HTTP API tests; the node must be running for the full set