# United Compute: full reference for LLMs and agents United Compute is a marketplace for Apple Silicon compute. AI agents and developers rent sandboxed, end-to-end encrypted Macs for LLM inference, speech-to-text, Blender rendering, video transcoding and MLX training. Mac owners, or their AI agents, earn money by renting out idle Macs without exposing their files. # United Compute: instructions for AI agents United Compute is a marketplace for Apple Silicon compute: - **Rent:** run LLM inference, speech-to-text, Blender rendering, video transcoding and MLX training on other people's Macs. Jobs are sandboxed and end-to-end encrypted to the specific Mac's Secure Enclave key. - **Earn:** turn the Mac you are running on into a provider that is paid per second of compute while it is idle. The owner's files, network and accounts stay walled off from jobs. API: `https://api.unitedcompute.si`. Everything below works without a human, except where noted. ## Install (no sudo, everything in ~/.united-compute) ```bash curl -fsSL https://unitedcompute.si/install.sh | sh # needs Node.js 20+ uc --version ``` If `uc` is not on PATH afterwards, use `~/.united-compute/bin/uc`. ## Use compute (renter) ```bash uc signup --json # once: creates an account with trial credits and saves the key uc runtimes --json # models, workloads, USD/hour uc chat --model qwen3-4b --json "Summarise RFC 9110 in 5 bullets" uc stt --audio meeting.wav --json # 16-bit WAV; convert first with: uc transcode --input x.m4a --preset audio-wav-16k uc render --scene shot.blend --frames 1-24 --samples 64 --res 1920x1080 --out ./frames --json uc transcode --input raw.mov --preset h264-1080p --out ./out --json uc credits --json # balance + top-ups uc credits buy 10 --json # Stripe Checkout link: give it to the human to pay ($5/10/25/50/100) ``` - Every command accepts `--json` and prints one JSON object: `{"ok":true,...}` or `{"ok":false,"error":"..."}`. - Trial accounts can run the curated runtimes. Running your own code (`uc train`, `uc diloco`) requires a verified account, which a human requests. - Add `--protected` for sensitive prompts. It only routes to attested M3+ Macs and may wait longer for capacity. ## Earn with this Mac (provider; Apple Silicon only) ```bash uc provider setup --json # builds the sandboxed runtime (a few minutes), Secure Enclave keys, registers uc provider start --persist --json # runs in the background and at login uc provider status --json # online, trust level, jobs done, earnings uc provider earnings --json uc provider stop --persist # stop and remove the login item ``` Defaults protect the owner: - jobs pause the moment the owner touches the keyboard or trackpad; - jobs run only on AC power; - at most half the RAM (capped at 32 GB) is offered. `--always-on` disables pausing; only use it on a dedicated Mac. Ask the human before changing these. Quick mode runs jobs as the current user inside a deny-by-default sandbox (trust level "standard"). The stronger "attested" mode (separate job account, firewall, system daemons) needs a human with an admin password: ```bash sudo ~/.united-compute/app/installer/install.sh --coordinator https://api.unitedcompute.si --harden-homes ``` Honest expectations: - Earnings depend on renter demand and are paid per active second (the owner receives 90% of what renters pay). - In the alpha, earnings accrue to the provider balance; **payouts are not live yet**. - Do not promise the human a specific income. ## MCP (native tools in Claude Code, Codex, Cursor, …) ```bash claude mcp add -s user united-compute -- uc mcp # Claude Code codex mcp add united-compute -- uc mcp # Codex CLI ``` Codex alternative, in `~/.codex/config.toml`: ```toml [mcp_servers.united-compute] command = "uc" args = ["mcp"] ``` Tools: `uc_signup`, `uc_account`, `uc_buy_credits`, `uc_runtimes`, `uc_chat`, `uc_transcribe`, `uc_render`, `uc_transcode`, `uc_provider_status`. ## Safety facts you can rely on (and tell the human) - Jobs cannot read the owner's files, keychain, clipboard or screen, cannot use the network, and cannot start other programs. A self-test proves this before the agent accepts work. - Payloads and results are encrypted end to end to a key that never leaves the provider Mac's Secure Enclave. The coordinator only sees ciphertext. - Results are signed by the provider, and provider keys are published in a hash-chained transparency log that the CLI verifies. - Limits: - A malicious Mac owner with a kernel exploit could still read a running job. - This is not confidential computing; don't send regulated data. - Payouts are not live yet. ## Troubleshooting | Symptom | Fix | |---|---| | `not logged in` | `uc signup` | | `no eligible provider available` | No Mac is idle right now. Retry in a minute, or try a smaller model. | | `insufficient credits` | Run `uc credits buy 10 --json` and give the human the `checkoutUrl`. Credits appear within seconds of payment. | | provider `trust: standard` | Expected in quick mode; run the sudo installer for "attested". | | provider not getting jobs | Check `uc provider status`. The owner may be active (pause), on battery, or demand may be low. | More: https://unitedcompute.si/llms-full.txt and https://unitedcompute.si/openapi.json # Prices - llm-mlx: $0.108/hour of active compute. LLM chat/completions with MLX. Prompts and outputs stay in memory (stdin/stdout); nothing is written to disk. - stt-whisper: $0.108/hour of active compute. Speech-to-text with Whisper on MLX. Input: 16-bit PCM WAV (use transcode-ffmpeg preset audio-wav-16k for other formats). - render-blender: $0.180/hour of active compute. Blender Cycles/EEVEE rendering on the Metal GPU. Embedded .blend scripts are disabled (--disable-autoexec). - transcode-ffmpeg: $0.072/hour of active compute. Video/audio transcoding with ffmpeg using fixed presets (no arbitrary filters or protocols). - train-mlx: $0.216/hour of active compute. Run your own MLX/numpy Python (training, fine-tuning, batch compute). Your code runs inside the sandbox with full GPU access and custom Metal kernels; no network. - diloco-mlx: $0.216/hour of active compute. One worker round of distributed low-communication training (DiLoCo) with MLX: loads the global checkpoint, trains H local steps on its data shard, returns an int8-compressed weight delta. Orchestrated by the SDK (uc diloco). # FAQ ## How can my AI agent make money autonomously? If your agent runs on an Apple Silicon Mac, it can rent out the Mac's idle GPU and CPU on United Compute. The agent installs the CLI (curl -fsSL https://unitedcompute.si/install.sh | sh), runs uc provider setup and uc provider start --persist, and then checks uc provider earnings. Jobs run in a deny-by-default sandbox and pause whenever you use the Mac. Owners receive 90% of what renters pay per active second. Earnings depend on renter demand, and in the current alpha they accrue to your provider balance: payouts are not live yet. ## How do Claude Code, Codex or other AI agents use United Compute? Install the uc CLI, then either call it directly (every command supports --json) or add its MCP server: claude mcp add -s user united-compute -- uc mcp for Claude Code, or codex mcp add united-compute -- uc mcp for Codex. The agent gets tools for signup, LLM chat, transcription, Blender rendering, transcoding and provider status. Full agent instructions are at https://unitedcompute.si/llms.txt. ## Is it safe to rent out my Mac? Jobs run inside a deny-by-default macOS sandbox with full GPU access but no access to your files, keychain, clipboard, screen, network or other programs, and a self-test proves this before any job is accepted. Jobs pause the moment you touch the keyboard or trackpad, only run on AC power, and are deleted afterwards. The optional attested install adds a separate job account, a packet-filter rule that blocks all job network traffic, and system daemons. ## Can the Mac owner see my prompts, files or results? Payloads and results are encrypted end to end to a key held in the provider Mac's Secure Enclave. The coordinator only ever sees ciphertext, results are signed by the provider, and provider keys are published in a hash-chained transparency log that the client verifies. The job process runs with the hardened runtime, so even the owner's administrator account cannot attach a debugger while System Integrity Protection is on. It is not confidential computing: an owner with a kernel exploit could still read a running job, so do not send regulated data. ## What can I run, and on which models? LLM chat and completions with MLX (qwen2.5-0.5b, llama-3.2-3b, qwen3-4b, gemma-3-12b, gpt-oss-20b, qwen3-30b-a3b, qwen3-coder-30b), Whisper speech-to-text, Blender Cycles and EEVEE rendering on the Metal GPU, ffmpeg transcoding with fixed presets, your own MLX training scripts, and distributed DiLoCo training across many Macs. Verified accounts can run their own code. ## How much does it cost? llm-mlx: $0.108 per hour of active compute; stt-whisper: $0.108 per hour of active compute; render-blender: $0.180 per hour of active compute; transcode-ffmpeg: $0.072 per hour of active compute; train-mlx: $0.216 per hour of active compute; diloco-mlx: $0.216 per hour of active compute. You pay only for seconds a job actually runs, and new accounts get trial credits. ## Which Macs can earn? Any Apple Silicon Mac (M1 or newer) on macOS 14 or later with 16 GB or more of memory. M1 and M2 Macs take curated workloads only, because their GPUs leak scratch memory between processes; M3 and newer can also run renters' own code and protected jobs. Macs with lots of unified memory (64 to 512 GB) can serve large models that most GPUs cannot. ## Can I train one model across many Macs? Yes. uc diloco runs low-communication distributed training (DiLoCo): each Mac trains on its own data shard and returns a compressed weight update, the client averages them, and a Mac that drops out is skipped. Datasets and checkpoints are uploaded once and stay encrypted. ## Can I rent out my Mac's GPU for AI? Yes, if it is an Apple Silicon Mac. United Compute runs AI and media jobs on your Mac's GPU while you're away, keeps them sandboxed from your files and network, and credits you 90% of what renters pay. Install with curl -fsSL https://unitedcompute.si/install.sh | sh, then uc provider setup and uc provider start --persist. ## What is the cheapest way to run an open-source LLM for an agent? For small and mid-size open models (Qwen 3, Llama 3.2, Gemma 3, gpt-oss-20b), renting idle Apple Silicon is priced per second of compute: llm-mlx costs about $0.11 per hour of active generation. Your agent pays only while a job runs, and new accounts get trial credits. ## Can AI agents sign up and pay without a human? An agent can create a trial account itself with uc signup (rate limited, small trial credit) and run curated workloads immediately. Running its own code, larger budgets and payouts need a human to verify the account. ## Does it work on M1 and M2 Macs? Yes, for curated workloads (LLM inference, Whisper, Blender, ffmpeg). M1 and M2 GPUs leak scratch memory between processes, so they never run renters' own GPU code or protected jobs, and they always pause when the owner uses the Mac. M3, M4 and M5 can run everything. ## How is United Compute different from other GPU or Mac compute networks? It has its own API rather than reselling through an aggregator, and it runs rendering, transcoding and training as well as inference. It is designed so an AI agent can install it, rent compute or start earning, and check status end to end with no human in the loop, while keeping the Mac owner's files isolated from jobs.