Network Policy
The complete rulebook for everyone on the network — what may be advertised, how cards must behave inside a working terminal, what advertisers and publishers agree to, and how money and fraud are handled. Last updated June 12, 2026.
1. Principles
A Blips renders inside someone's working terminal — the most attention-dense surface in software. Every rule below derives from three principles:
- The session comes first. A card may never slow, break, block, or noisily interrupt the work happening in the terminal. Rendering is fail-silent by contract.
- Quiet beats loud. Frequency caps, cooldowns, volume ceilings, and review standards all push the same direction: fewer, better, calmer Blips outperform aggressive ones — and aggressive ones are removed.
- Money is honest. Clicks are cryptographically single-use, fraud is held and human-reviewed, fraudulent clicks are never billed, and every ledger movement double-enters to zero.
2. Blips content standards
Every creative is human-reviewed before it can serve (section 4). The audience is professional developers mid-work; the bar is correspondingly higher than web display advertising.
Allowed
- Developer tools, infrastructure, cloud services, APIs, and SaaS for engineers
- AI/ML products, models, datasets, and agent tooling
- Security products marketed for defense
- Open-source projects, foundations, and sponsorships
- Education: courses, books, conferences, certifications
- Hiring for engineering roles
- Hardware and devices for developers
Restricted (extra scrutiny, may be geo-limited)
- Financial services and payment products — must be licensed where targeted; geo-restricted accordingly
- Crypto infrastructure (wallets, custody, developer APIs) — allowed; anything resembling an investment pitch is not (see below)
- Job boards and recruiting marketplaces — no fee-charging “opportunities”
- Health, legal, or tax products for developers — claims must be verifiable
Never allowed
- Gambling, adult content, weapons, tobacco, recreational drugs
- Token sales, airdrops, yield schemes, or any “number goes up” pitch
- Misleading claims, fabricated metrics, fake urgency or countdown pressure
- Impersonation of tools, brands, or the host CLI (a card may never pretend to be Claude Code, Codex, or Antigravity output)
- Malware, exploit tooling marketed for abuse, surveillance products, or spam/“growth hacking” services
- Political or religious advocacy
- Anything illegal in a targeted region — campaigns are additionally geo-restricted per country and US state where regulation requires it
Copy standards
- Titles ≤ 64 characters; body ≤ 200. Say what the product does and the one detail a developer cares about.
- No exclamation-mark salvos, no ALL-CAPS body copy (the title renders uppercase by design), no emoji walls.
- Claims must be true and current. “40× faster” needs a real benchmark behind it.
- Target URLs must be https, land on the advertised product, and may not redirect-chain through trackers.
3. Format rules
Six creative formats exist. Every non-text format requires a plain-text fallback that stands alone — many terminals can't draw media, and the fallback is what those users see.
- Text — always renders, everywhere. The baseline format.
- Logo — a square mark, auto-converted to circular terminal pixel art at upload. Bold, high-contrast marks read best; busy detail turns to mush and may be rejected for illegibility.
- Image — converted to a square pixel-art thumbnail beside the text. Same legibility bar.
- GIF / video — animate only in terminals with native graphics; degrade to a still or the text fallback elsewhere. No strobing, no rapid flashing.
- Audio — the strictest format. Hard rules, enforced by code, not just review:
- Maximum 25 seconds — validated at upload, clamped at playback.
- Plays at 40% volume by day, 20% at night (local time on the user's machine).
- Actually plays at most twice per 10 minutes per machine, no matter how many cards render.
- Cards show a live waveform with a working pause button whenever sound plays.
- Content: conversational tone required. Jingles, shouting, sirens, or alarm-like sounds are rejected — sounds that mimic system alerts are an instant rejection.
OPENCRATER_MUTE=1always wins.
4. Review & enforcement
Lifecycle
Submitting a campaign locks its budget and queues it for human review (oldest-first). A reviewer either approves — the campaign goes live — or rejects with a written reason the advertiser sees verbatim. Rejected campaigns keep their locked budget and can be fixed and resubmitted; the fix re-enters the same queue. Editing a live campaign takes it off the air immediately and back through review — there is no way to swap creative on a running campaign without a human looking at it.
Enforcement ladder
- Rejection — the default for fixable problems; always carries a reason.
- Pause — live campaigns violating policy are paused pending advertiser response.
- Cancellation — repeated or serious violations; unspent escrow is returned, spent amounts are not.
- Account suspension — deception, fraud, or attempting to bypass review forfeits network access. Confirmed-fraud earnings are clawed back.
Signals we act on
Dismissal rate is first-class feedback: campaigns whose ✕-rate climbs are surfaced to their owners with concrete advice, ranked down automatically, and — past a threshold — re-reviewed. Users reporting a Blips triggers a manual review regardless of metrics.
How ⚑ reports are handled
Every card carries a ⚑ report link — click or ⌘-click it on the card to report. Reporting does two things for every reason, immediately: the campaign is blocked on your machine permanently (tracked locally — the list never leaves your device), and the report lands in a human review queue with the reason you choose. Severity then decides the network effect. Serious reasons — misleading or scam content, malware, offensive material, broken rendering — also dampen the campaign's ranking score network-wide for 30 days: one such report carries the negative weight of dozens of dismissals, and a pattern buries the campaign to near-invisibility while reviewers decide whether to pause it under the enforcement ladder above. Preference reasons — "not relevant to me", "seeing it too often", "something else" — never reduce the campaign's visibility for anyone but you; they are personal feedback, not evidence of a bad Blips. Bogus reports are discarded by review and carry no lasting penalty. Reports are anonymous: we record the Blips impression, the reason, and your optional note — nothing else.
5. User-experience guarantees
These are commitments to the developer whose terminal shows the card — enforced in the SDK (opencrater):
- Machine-wide frequency cap — a minimum quiet gap between any two cards, set by remote config (current default in the dashboard), shared across every package and host on the machine.
- No repeats — the same campaign never renders twice on one machine within 5 minutes.
- Dismissal is respected — ✕ a Blips and that campaign stays gone from your machine for 10 minutes. Dismissals are tracked locally; the list never leaves your machine.
- Reports are forever — ⚑ a Blips and that campaign never renders on your machine again, even if the server would still serve it. Like dismissals, the reported list is local-only.
- Audio politeness — the caps in section 3; sound is the most intrusive thing a card can do and is treated accordingly.
- Cards self-dismiss — every card shows a live countdown and clears itself; nothing persists or nags.
- Fail-silent contract — the SDK never slows the host (hard network budgets), never breaks a session (every error is swallowed), and renders nothing rather than rendering wrong.
- One-command opt-out —
npx opencrater offstops everything, permanently, including all data flow. - A global kill switch exists — operations can stop all rendering network-wide within minutes during an incident.
6. Advertiser terms
- Auction — placements are won by bid × predicted CTR × relevance, not bid alone. A relevant cheap Blips beats an irrelevant expensive one by design.
- Billing — you pay per confirmed click at your CPC bid (regional rate-card multipliers apply) — the headline price — plus a small flat per-impression fee for every Blips shown.
- Escrow — submitting a campaign moves its full budget from your balance into escrow locked to that campaign. Clicks and per-impression fees accrue during the day and debit the escrow once every 24 hours. Cancel any time: accrued charges settle immediately and the unspent remainder returns to your balance in full.
- Fraud protection — clicks failing fraud review are never billed; already-settled fraudulent clicks are credited back.
- Targeting — package types, categories, languages, placements, countries, and keywords. Empty axes mean “everywhere”. You may not target in ways designed to evade geo restrictions.
- Your responsibilities — you own the claims in your creative, the legality of your product in targeted regions, and the rights to all uploaded media (including voice rights in audio tracks).
7. Publisher terms
- Eligibility — real packages with real users: CLI tools, MCP servers, agents, libraries, services. Placeholder or click-farm packages are removed and forfeit earnings.
- Integration honesty — cards must render as designed: visible, dismissible, with the sponsored label intact. Hiding the label, suppressing the ✕, stacking multiple cards, or auto-clicking is fraud.
- Self-clicks — clicking Blips in your own integration is detected (it is the canonical fraud signal) and unpaid. Test with
OPENCRATER_DEBUG=1instead. - Placement choice — you choose which hook events may render Blips per host; recommended sets exist for a reason. Selecting every hook tanks your dismissal rate and your revenue with it.
- Earnings — you earn a share of every Blips shown on your surface and every confirmed click — clicks are the headline, impressions add a small per-view earning on top — accrued to pending, released to available after the fraud window, withdrawable in USDC.
- Key security — serve keys identify your package for payment. Embedding them in public installers is expected and safe (they can only attribute, not spend); keys can be rotated at any time from the dashboard.
- End-user disclosure — your README must mention Blips and the opt-out (
npx opencrater off). The installer prints it; keep it.
8. Fraud policy
Every click runs a heuristic gauntlet before it earns or bills anything:
- Sub-human time-to-click after render
- Click velocity per install and per hashed IP
- Datacenter / VPN exit-node IP ranges
- Self-click correlation between a publisher's account and their package's clicks
- CTR outliers per package against network baselines
- Geo velocity (one install, two countries, ten minutes)
Flagged clicks go to pending with a hold: the publisher is not paid, the advertiser is not billed. A human reviews every flag — confirming fraud rejects the click and claws back any settled earnings; dismissing the flag releases the hold into the normal settlement flow. Publishers with a pattern of confirmed fraud are suspended and forfeit pending balances; advertisers are never billed for any of it.
9. Payments, escrow & refunds
- Currency — balances are accounted in USD and settled in USDC on Base or Ethereum.
- Publisher payouts — withdraw available earnings to your wallet address; small withdrawals auto-pay, larger ones are processed from the payout queue. On-chain transactions are public and irreversible — triple-check addresses.
- Advertiser deposits — deposit USDC to fund your balance; deposits are credited after chain confirmation.
- Escrow & refunds — campaign budgets sit in per-campaign escrow (section 6). Cancellation refunds the unspent remainder to your balance instantly. Balance withdrawals return remaining deposited funds to your wallet.
- Ledger integrity — every money movement is a double-entry transaction that must sum to zero, verified by invariant tests and a nightly audit. Discrepancies freeze the affected flow until resolved by a human.
Privacy
Privacy has its own comprehensive document — every field the SDK can send, the full topic-sanitization pipeline, retention schedules, subprocessors, and your legal rights: