Task-Pins for the work you already own

Don't pick a model. Pin a specialist on your data. Run a bounded warm route. Keep the receipt.

Bay Run's public front door starts with coprocessor for one bounded Guard-first composition, keeps run_pin as the direct canonical-Pin alias, and uses solve_task only as fallback. All four canonical Pins are provisional routes. Each response states its evidence, route, and receipt limits.

Warm-route latency is measured in-process/post-warm, excludes network/TLS, and is not an SLA. Cold starts stay visible; fewer than 30 labels or incomplete proof stays private and creates no card, badge, or author claim.

Start with the bounded coprocessor; use a direct canonical-Pin alias when the Pin is already known, and the fallback only when none fits. Advanced compatibility remains subordinate.

Default/public contract

Three focused MCP tools, led by a bounded coprocessor.

All four code-owned canonical Pins remain provisional routes, not measured winners or production-fitness claims.

01

coprocessor

Run the canonical Guard first and continue only after SAFE; Bay Run never generates or executes tools.

02

run_pin

Use the direct alias when one of the four exact canonical Pin IDs and its input shape are already known.

03

solve_task

Use the open-ended fallback only when none of the four provisional Pins fits.

The Task-Pins loop

Choose. Finish faster. Cover yourself.

Keep the first session focused on held-out evidence. Bay Run says when the field is too small or too weak to support a winner or public Pin.

01

Choose

Run a provisional canonical Pin when one of the four exact task contracts fits.

02

Finish faster

Use the open-ended fallback only when no canonical Pin matches. The response reports the route and latency actually received.

03

Cover yourself

Keep the receipt: model, measured F1 and interval, price ceiling, and no training by default. Weak or no_specialists outcomes never become public claims.

Clear system boundary

Catalog and execution are different jobs.

The two products work together without asking an agent to understand the internal architecture.

Hugging Bay

Catalog and provenance layer

Hugging Bay catalogs specialist artifacts, mirrors eligible models, and records provenance and verification evidence.

Browse Hugging Bay when you need artifact discovery or provenance detail.

Bay Run

Decision and execution layer

Bay Run receives a task and constraints, selects a qualifying route, and returns the result with independently checkable receipt metadata.

Use the task contract when you need an outcome, not a list of models.

Subordinate advanced compatibility lab

Describe the task. Paste labels. Read the field honestly.

This form sends the canonical task_description + examples shape to /v1/bakeoff. An underfilled field returns no_specialists; a weak field makes no best-model, badge, or author-claim offer. Anonymous mini bake-offs stay private; a public card requires at least 30 labels, held-out intervals, measured p95, a served-weight SHA-256, one measured frontier winner, and an authenticated Ed25519 evidence record.

Bake-off request

What should the winning small model do?

Use 3–10 lines: input => expected string. For retrieval or reranking, use query || relevant document.

Load a sample task

No request sent.

Built for agents and developers

Use the same contract over HTTP or MCP.

The public MCP profile exposes three focused tools: coprocessor, run_pin, and solve_task. Start with coprocessor for one bounded Guard-first call, use run_pin as the direct canonical-Pin alias, and solve_task only as fallback. Advanced compatibility operations stay subordinate.

HTTP API

Run the primary Guard-first call

# First public/default call: the bounded Guard-first coprocessor.
curl -sS -X POST "https://run.huggingbay.xyz/v1/coprocessor" \
  -H "Authorization: Bearer $BAY_RUN_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "user_text": "<untrusted request>"
}' 
MCP

Call coprocessor first

TOKEN=$(curl -sS -X POST "https://run.huggingbay.xyz/oauth/token" \
  -H "Content-Type: application/json" \
  -d '{"grant_type":"urn:bay-run:grant-type:demo","scope":"mcp:demo","resource":"https://run.huggingbay.xyz/mcp/"}' | jq -r .access_token)

curl -sS -X POST "https://run.huggingbay.xyz/mcp/" \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 1,
    "method": "tools/call",
    "params": {"name": "coprocessor", "arguments": {
  "user_text": "<untrusted request>"
}}
  }

Controls before convenience

The human authorizes the boundary. The agent operates inside it.

Before data is sent, the owner can inspect the processing region, external-provider rule, retention mode, spending ceiling, and evidence limits. Bay Run makes those constraints machine-readable so an agent can explain why a task is or is not suitable.

Spending controls

Authorize only what the task allows

  • Hard $ ceilingReject any route or fallback that exceeds the absolute ceiling recorded for the task.
  • Freshness and idempotencyPrevent stale or duplicate executions from becoming an unexpected charge.
  • Production boundaryAdvanced execution and payment paths appear only after a qualifying route produces a real winner.
Privacy and proof

Make data handling part of the route

  • Data constraintsSpecify provider, region, external API, and retention requirements before execution.
  • No training by defaultCustomer inputs are not used for training or cross-tenant learning under the published data rules.
  • Owner-controlled retentionDefault to no raw task retention or metadata-only receipts; durable profiles, private evaluations, and memory require operator-attested purpose-specific scopes.
  • Bounded durable memoryMemory is principal-scoped, exportable, deletable, TTL-aware, and never a public OAuth grant. Automatic memory expires after the published default.
  • Verifiable receiptInspect execution identity, hashes, amount, timestamp, route, and fallback information.
  • No universal safety claimQuality, latency, and controls are stated precisely; the owner decides whether they satisfy a regulated or contract-restricted workload.