Atlas
nothing armed
spent today $0.00

Explore mini apps on The Graph — this data came from a standardized subgraph or a Substreams package The Graph

16 here · 5 autonomous · 5 monitor · 6 read onlyRegistry

aave-guard

unpublished

Autonomous · Aave borrow-load guard — Arbitrum

Watch how hard the Aave market I am exposed to on Arbitrum is being borrowed against. When it runs hot, swap out of ETH to de-risk. Show me what you're doing.

Runs1,204
Sources
Spent$0.00
arbitrum
cap $500.00

copy-trader-arb

unpublished

Autonomous · Liquidity follower — Arbitrum DEX pools

gas-rebate-claimer

unpublished

Autonomous · Rebate claimer — Optimism

perp-deleverage

unpublished

Autonomous · Perp deleverage guard — Arbitrum

yield-rotator

unpublished

Autonomous · Yield rotator — stables, weekly

bridge-outflow-watch

unpublished

Monitor · Bridge liquidity drain watch

funding-divergence

unpublished

Monitor · Perp book skew — Arbitrum and Optimism

health-factor-watch

unpublished

Monitor · Lending leverage watch — Arbitrum and Optimism

stale-oracle-watch

unpublished

Monitor · Read health watch — Optimism lending

whale-alert-arb

unpublished

Monitor · Volume milestones — Arbitrum DEXs

bridge-flows

unpublished

Read only · Bridge flows into Arbitrum, 24h

dex-volume-arb

unpublished

Read only · Top DEXs by volume — Arbitrum, 7d

nft-volume-eth

unpublished

Read only · NFT marketplace volume — Ethereum, 30d

perp-oi-board

unpublished

Read only · Perp open interest by market — Arbitrum

tvl-crosschain

unpublished

Read only · Cross-protocol TVL — Arbitrum vs Optimism vs Base

yield-leaderboard

unpublished

Read only · Best stablecoin vaults by net APY

click the wheel to turn it · click a card to open

Depth is agencyRead onlyMonitorAutonomous
Marksarmed — would act if a trigger firedlive — a Substreams run is open right now

You didn't build this interface. You asked for it.

three prompts · three interfaces

The composer reads the shape of what came back, not words in the prompt. A bounded ratio becomes a gauge. A ranked categorical becomes a leaderboard. Ask the same subject a different question and you get a different interface — and when the question asks for action, the frame that carries it stands up and shows its policy.

Which Arbitrum lending markets are closest to liquidation?

Health factor

1.2213
critical
threshold 1.15

the same gauge — what changed is what it may do about it

policy enforced at signer$150.00 / tx

Policy

active
per tx cap
$150.00
lifetime cap
$500.00
allowlist
2 targets
expires
spent against lifetime cap
$25.00 / $500.00
confirm requiredkill switchwallet at publish
  • 0x794a61358D…5b4814aD
  • 0x68b3465833…8665Fc45

Enforced at the signer, not suggested to the model.

Journal

6 events$120.04 spent
  1. 09:14:02STREAMsubstream aave-v3-arbitrum: 412 events, 1 position touched
  2. 09:14:02TRIGGERhealthFactor 1.28 < 1.35 — guard fired
  3. 09:14:02POLICYrepay 120 USDC → aave-v3 pool: within per-tx cap, target allowlisted
  4. 09:14:04ACTIONrepay 120 USDC to Aave v30x4f2c9a…123456$120.04
  5. 09:14:05QUERYrefetch position — healthFactor 1.28 → 1.46
  6. 09:31:44ERRORsource radiant-arbitrum unreachable — skipped, 27 of 31 live
1 line moved value
total $120.04
Streams from the action journal.

Every query, trigger, policy decision and signature.

Halt this app

not tripped
stops triggers and blocks signing immediately
local halt → then server event `halt_agent`

a demonstration — the measured runs are below

The Graph — this data came from a standardized subgraph or a Substreams packageThe Graph had everything it needed to be crypto’s consumer layer.

More chains, more protocols, real time, decentralized — and it only ever shipped for developers. Every consumer surface built on it was made by hand, one dashboard at a time, so only the questions worth a developer’s week ever got an interface.

Atlas generates the interface per question. An app exists the moment you ask for it, including for the long tail nobody would ever build by hand.

schema families
9
verified deployments
86
networks
4

The resolver picks a schema family, never a subgraph id — which is why a question nobody anticipated still resolves. arbitrum-one · optimism · base · mainnet.

You can see what a thing is allowed to do by looking at it.

analytics · monitoring · autonomous

Analytics sits flush in the surface. Monitoring lifts, on a live-blue rim. Autonomous stands proud, orange, with a shadow under it.

The tier is not decoration. An autonomous app always renders its policy strip, its kill switch and its trade log — and the renderer enforces that on screen rather than trusting the document to include them. A skin that hid which apps can spend would be a bug, not a theme.

Analytics

read only

Sits flush in the surface. Reads, renders, and can do nothing else.

Monitoring

watches

Lifts, on a live-blue rim. Evaluates its triggers and tells you — it still cannot spend.

Autonomous

holds a wallet

Stands proud, orange, with a shadow under it. Signs — inside a policy it cannot talk its way past.

It sends a name. It never sends code.

A2UI v0.9.1

The model emits a declarative document and a data model. No markup, no class names, no styles, no module path. Rendering is a map lookup:

lookupCatalog(name) ?? <UnknownComponent/>

There is no eval, no new Function, no dangerouslySetInnerHTML and no dynamic import keyed on model output anywhere in the renderer. A name outside the catalog renders a visible, inert placeholder — never nothing, never something executable. For a generated interface that can move money, that containment is the entire safety argument.

Press this. One attribute re-expresses the whole system in a different material — no component changes, no catalog changes, nothing round-trips to the agent. That the swap is possible at all is the proof the interface is data.

re-skins this page, the deck above it, and every mini app on it

Receipts

each figure labelled with what produced it

The registry

derived from SOURCE_REGISTRY at build time

96 entries, of which 86 are deployment ids confirmed by a network crawl. 9 of 11 schema families have a live deployment, across arbitrum-one, optimism, base, mainnet. Resolving a schema rather than a subgraph id is what makes an unanticipated question resolvable — via The Graph — this data came from a standardized subgraph or a Substreams packageThe Graph’s standardized subgraphs.

A fan-out run

recorded 2026-07-25 · not a live reading
18 sources queried → 13 healthy, 5 dead skipped by health check → 74 rows in 2.8s → $0.0014

That 28% dead rate is real, and it is why sources are health-checked at generation time and frozen into the app’s manifest rather than trusted at read time.

The registry is built by the pipeline

snapshot measured 2026-07-26

All 16 of 16 seed mini apps are produced by resolve → health-check → fan-out → compose, not written by hand. Re-measuring every one of them costs $0.0084 in total.

Substreams, verified both directions

scripts/substreams-verify.ts
breach:  blocks 487508073 → 487508075 in 1.5s
         487508074 → healthFactor 1.035 breaches "healthFactor < 1.15"
         → TRIGGER fired
control: blocks 487509578 → 487509580, healthy throughout, 0 firings

Against arb-one.streamingfast.io, one tick per block. The control run is the half that proves anything — a harness that can only report a firing has not shown that it stays quiet when it should.

A real transaction

scripts/substreams-verify.ts --real
Arbitrum block 487540654 → trigger fired → POLICY OK
  → session key signed → 0x5a44e9d5…9d78
  → Base Sepolia block 44604106, allowance 25 USDC read back on chain

View on Basescan. It is an approve, and it is described as one: granting the router an allowance is genuinely the first step of a swap, and it is not a swap.

Names

read from the deployed origin with no write key

ENS — this name is an ENS subname, and it is what resolves to the app atlas-apps.eth, registered and wrapped on Sepolia, issuing a subname per mini app. Records written per app:

addr
contenthash
agent-context
agent-endpoint[web]
agent-endpoint[mcp]
agent-registration
url · description · avatar

Identity and inference

0G Galileo · scripts/publish-under-parent.ts

Agentic ID token 10 on 0G — inference and the Agentic ID token live on 0G 0G Galileo (chain 16602), planned on 0G Compute with model 0gm-1.0-35b-a3b and attestation 0g://6f3651f2….

What isn't built

stated here rather than left ambiguous

x402 is implemented and has paid for nothing

The 402 challenge is parsed for real and answered with a real EIP-3009 signature at the published price. But X402_PRIVATE_KEY is unset, so no query has actually been paid for this way — every row on this board arrived over the API-key gateway.

One session key signs for every mini app

AGENT_SESSION_PRIVATE_KEYis process-wide. Register two different mini apps and both come back with the same address. “A wallet per app” is true of the manifest and not true of custody — a record says where a name points, and custody is not a property of a record.

Subgraph MCP is not wired

GRAPH_MCP_URL is an environment variable nothing in src/ calls. Schema resolution runs off the local registry plus a live health check, so discovery beyond that registry is a real gap. Distinct from our MCP server, which is served and listed below.

Three of the eight issued subnames point at manifest bytes that no longer exist

The names resolve. What they resolve to is gone.

The Substreams success path is unexercised inside the app

The free tier allows two concurrent streams and the account is at its quota, so POST /api/stream reaches the endpoint and is refused — a real failure of a real call, rendered as one. The subscription is verified end to end by scripts/substreams-verify.ts, and verified only as far as the endpoint’s answer in the product itself.

Reachable by an agent

read-only by design

Every published mini app writes this URL into its agent-endpoint[mcp] ENS record. Stateless Streamable HTTP, one JSON-RPC message per POST.

{ "mcpServers": { "atlas": { "type": "http", "url": "<origin>/api/mcp" } } }
ToolDoes
list_schemasList the standardized subgraph schema families this server can query, with how many health-checked deployments exist per network.
check_coverageAsk whether The Graph can answer a question at all: how many standardized subgraph deployments exist in the schema families the question plans to query, and whether any Substreams package is published for it.
plan_mini_appTurn a natural-language question about onchain activity into a query plan: which standardized schema families and networks answer it, the GraphQL to run, and the agency tier the question implies.
query_graphAnswer a question with live data: resolve the question to standardized schemas, health-check the deployments, query all healthy ones in parallel across networks, and return the merged rows.
build_mini_appThe whole pipeline: question to a renderable mini app.
resolve_mini_appResolve a published mini app by ENS name (e.g.

Nothing here signs or spends. /api/act owns the action loop and reads its policy server-side, because an MCP endpoint is a URL strangers point agents at.