Anonymous RPC

anon-rpc makes it easy for wallets and applications to anonymize their RPC requests. Just provide an Ethereum address at run-time and get an anonymized fetch function — anon-rpc plumbs the requests to a sandboxed worker running the network's hash-pinned client code.

harness on npm · example address live on mainnet
Start here

Integration Guides

Why

Centralized RPC providers see too much

Wallets need to read the Ethereum state, and these reads are currently concentrated in a few large RPC providers. This makes users vulnerable to censorship and surveillance.

With anon-rpc, requests can be:

  • unlinked from your IP address,
  • connected through domainless P2P nodes (KPS),
  • switched to a better network at any time.
How it works

Pinned code in a box

An on-chain specifier contract (e.g.) pins the anon network's client code by keccak256. Any bytes matching the hash are acceptable, from anywhere.

1

Pin the worker on-chain

A specifier contract publishes workerHash() and advisory workerResolvers(). The hash is the trust; the URLs are merely suggestions for where to fetch.

2

Verify, then execute

The harness fetches the bundle, accepts it only if its keccak256 matches the pinned hash, and runs it in a Web Worker inside a null-origin sandboxed iframe.

3

Restricted capabilities

The network's client code is sandboxed away from your wallet and its keys, cookies, etc. Instead it uses a messaging channel to accept fetch calls, connect via KPS, provide logs, and access its scoped storage.

What you get

Isolation you can verify

🔏

Hash-pinned identity

The anon-client is content-addressed via an on-chain specifier. No resolver, CDN, or mirror is trusted — only bytes matching the hash execute.

🧱

Null-origin sandbox

The worker runs in a Web Worker inside a sandboxed, null-origin iframe: no DOM, no cookies, no wallet keys, no host identity.

📡

KPS transport built in

Key-pinned streams to any peer by certificate hash — WebRTC in the browser, QUIC natively — so the worker never needs CA-blessed network access.

📬

Ordered call discipline

Inbound fetch calls queue with backpressure: ordered, never dropped, delivered one at a time on the worker's terms.

🗄️

Scoped storage

Async binary storage namespaced to the specifier address. A worker can persist state; it can't read anyone else's.

🔁

Updatable, freezable

The specifier owner can ship new worker versions on-chain — or renounce ownership and freeze the pinned hash forever.

Resources

Adopters, spec, harness