> For the complete documentation index, see [llms.txt](https://docs.redacted.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.redacted.money/node-network/running-a-node.md).

# Running a Node

Redacted's relayer nodes are run by independent operators. The nodes approve deposits and choose what to check, and they decide by vote whether a waiting deposit is sent back and how strict screening is. Fees, bonds and code are set by token holders after the token relaunch, and by the DAO until then (see [Who decides what](/protocol/system-overview.md#who-decides-what)). This page is for anyone considering running a node, and it covers how to join, what you commit to and what you earn. For how the network works as a whole, see [How the node network works](/node-network/node-network.md).

{% hint style="info" %}
**Coming soon.** Node registration opens with an upcoming update. Values marked as set at launch are published with the release.
{% endhint %}

## Joining

Governance admits operators, the DAO until the token relaunch. To apply, reach out through the official channels at [redacted.money](https://www.redacted.money). Governance can open admission, and from then on anyone who posts the minimum bond can register without applying. Opening is one-way. The network has 21 active places at launch, and governance can raise that number with notice, up to 100. A registered node without a place waits on standby (see [Node rotation](/node-network/node-rotation.md)).

## The bond

* You lock the bond when you register, which is 100 RUNE at launch, held apart from users' money. [The bond](/node-network/node-network.md#the-bond) explains how it works.
* Token holders (the DAO until the relaunch) can change the minimum with at least a day's on-chain notice, by at most ten times up or down per change. After the token's relaunch they can move the bond to the protocol token, with notice and a grace period in which RUNE bonds keep counting.
* A node whose bond falls below the minimum, after a slash or a raised minimum, pauses until it tops up.
* You can unbond at any time. Your node stops relaying at once, and your bond comes back after the unbonding period of about 14 days (fixed once set). It stays slashable until you claim it, so the rules apply until the bond is back in your hands.

## What you commit to

These are the node rules. They keep the network trustworthy, because token holders (the DAO until the relaunch) can answer a breach with removal and slashing. They cover how a node behaves, while what a node checks is up to the nodes, who decide by vote how strict to be.

1. Run the official node package unmodified. It can check addresses through the Ozone instance you trust. Don't pass a fallback off as a regular check, since the package marks a deposit approval made on a fallback, and while strict screening is on, fallbacks are refused.
2. Serve every user under the same published rules, with no private deals and no sign-ups, and don't refuse a free exit for being free.
3. Keep an append-only record of your checks and decisions as evidence, and don't keep users' network addresses.
4. Send heartbeats only while you actually serve requests.
5. Run one node per operator. Running several nodes to collect several stipend shares is misconduct.
6. Vote on the brakes in good faith. Pause or cap deposits only for a concrete reason and publish it, and reject a waiting deposit only for a concrete reason and name it, for example that the Ozone instance you trust lists where the money came from. The official package can cast that vote by itself.
7. Submit every action you accept promptly. It is bound to your node, so while you hold it, nobody else can place it.
8. Don't trade on, ahead of or around an action you carry, before or after submitting it, and use its contents only to relay it exactly as signed.
9. Confirm as the account's own money only what came from the Reserve, what its own positions paid back in the share the account put in, and payments straight from another account's Reserve. In a mixed return, confirm the own part and leave the rest to wait like a deposit. When in doubt, decline to confirm, and the return then waits like a deposit. A false confirmation lets outside money skip the wait and is misconduct.

Every relay, every deposit approval and every own-funds confirmation is public on-chain, with the node that made it, so a breach can be proved after the fact.

## Rewards

Rewards pay for work and risk, which means carrying actions and staying live with your bond at stake. They go to active nodes, so a node on standby earns nothing until it holds a place.

Every action your node carries earns a share of that action's protocol fee, credited by the contract in the same transaction. The user pays exactly the fee in their proof either way, and the contract only splits it. Token holders set the share (the DAO until the relaunch) with at least a day's notice. Free actions earn no share and still have to be served.

An optional stipend is possible as well. Token holders (the DAO until the relaunch) can fund a stipend and set its size per epoch of about a day, split equally among the nodes active in that epoch, and a node counts once per epoch whatever its volume. Whether there is a stipend, and its size, is set at launch.

Credited rewards are yours. They are paid to the operator address, also after you leave, and misconduct is answered through the bond. Once governance switches staking on, holders can stake behind your node and share its rewards (see [Staking behind a node](#staking-behind-a-node)).

Honest work pays best, because relaying your own actions always costs more than it returns and volume never buys stipend. Each extra stipend share needs another full bond, locked and slashable, admission by governance and one of the limited active places. Every action is also bound to its node by the proof, so no node can take over another's action or its reward.

## Staking behind a node

Holders stake the bond currency (the token after the relaunch) behind a node whose operator opened staking. As an operator, you open staking on your node and set your commission. Stake counts toward the node's bond, and the operator holds at least 10% of the minimum itself. Rewards are split by stake, and the operator keeps a commission on the stakers' part. Stakers claim any time. A slash takes from the operator and the stakers in proportion, unbonding stake included, and unbonding takes the same period as a node bond, about 14 days. Governance switches staking on after the relaunch. A node needs its bond to be active, so where holders stake helps decide which nodes run. See [Staking behind a node](/node-network/node-network.md#staking-behind-a-node) for the full picture.

## Staying live

* The official package sends a heartbeat by itself, by default at least every eight hours, and only while the node can serve. Heartbeats are what keep your node ready for an active place.
* A node that is bonded and ready but has no active place waits on standby. It keeps sending heartbeats and does not relay or approve deposits, and a daily rotation gives a place to the ready standby nodes with the most stake first (see [Node rotation](/node-network/node-rotation.md)). A standby node that sends heartbeats is not evicted.
* A node that neither relays nor sends a heartbeat for 14 days can be evicted by anyone. It moves into unbonding without a penalty.
* If no node at all is active for 7 days, the emergency exit opens and deposits stop until a node is live again.
* As an active operator you vote on the brakes, which are the deposit pause, the deposit cap, pausing new private accounts, strict screening and incident mode.
* Your node also votes on waiting deposits. It sends each vote from one of its relayer accounts, so your operator key stays off the server. See [New money waits briefly](/node-network/node-network.md#new-money-waits-briefly).

## Removal and slashing

Token holders (the DAO until the relaunch) can remove a node, which stops it at once and for good, and slash any part of its remaining stake. The reason goes on-chain and should cite the rule and the evidence, such as transaction hashes and the node's own records. Slashed amounts go to the protocol's fee collector. Registering, relaying, casting node votes and sending a deposit back stay with the operators. A slash never takes more than a node's stake or its credited rewards.

### What happens in a slash

A slash applies at once, and its reason is published on-chain. It takes from your bond and, once staking is on, from the stake behind your node, both the active stake and the stake that is unbonding, in proportion. Rewards you have already earned stay claimable. Unbonding takes about 14 days, and a bond or stake that is unbonding can still be slashed until it is claimed. Staking is off at launch, so at first a slash can only take from your bond. See [What happens in a slash](/node-network/node-network.md#what-happens-in-a-slash) for the full picture.

## What you need

* A Linux server with a public HTTPS endpoint, running the official node package from a reviewed release.
* An operator key that holds the bond, kept off the server, signer accounts on the server that submit actions (up to 16 per node), and a separate key that signs deposit approvals and own-funds confirmations.
* Your own THORNode with a complete transaction index and your own Midgard in sync, on servers you control, because whoever runs them sees which Spending accounts your node traces. A public THORChain RPC from another provider serves as a second source the node uses to confirm what it reads.
* The signing keys of the Ozone instance you trust, to verify its answers and lists. Ozone is the reference screener, built by Redacted's core contributors, and it works only from public data. The public instance publishes its keys, and because Ozone is published as open source with the launch, you can run your own instance instead. Each node chooses which instance it trusts, and the node network can decide to use or add other sources.

[Run a node, step by step](/node-network/run-a-node-guide.md) walks through the setup from the server to the first claim, and the full operator guide is published with the node package.
