# Ocean Enterprise docs

Data Sovereignty for the Data Economy: Next Generation Data and AI Ecosystems

<table data-card-size="large" data-view="cards"><thead><tr><th data-type="content-ref"></th><th></th><th data-hidden data-type="files"></th><th data-hidden data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><a href="/pages/Jc5h7zoUBk0GCEMDX2iw">/pages/Jc5h7zoUBk0GCEMDX2iw</a></td><td>Learn how Ocean Enterprise transforms data sharing and monetization with its powerful Web3 open source tools.</td><td></td><td></td><td><a href="/pages/Jc5h7zoUBk0GCEMDX2iw">/pages/Jc5h7zoUBk0GCEMDX2iw</a></td><td><a href="/files/l6s58Mi46x5l9JaE6vhT">/files/l6s58Mi46x5l9JaE6vhT</a></td></tr><tr><td><a href="/pages/CNW3jAgaGhyptn1Vnb1u">/pages/CNW3jAgaGhyptn1Vnb1u</a></td><td>Follow the step-by-step instructions to unleash the power of Ocean Enterprise technologies!</td><td></td><td></td><td><a href="/pages/CNW3jAgaGhyptn1Vnb1u">/pages/CNW3jAgaGhyptn1Vnb1u</a></td><td><a href="/files/PNAKEuTKivpOWGBrUgYd">/files/PNAKEuTKivpOWGBrUgYd</a></td></tr><tr><td><a href="/pages/oNCMd9wlcaqGPVQZCPrs">/pages/oNCMd9wlcaqGPVQZCPrs</a></td><td>Find APIs, libraries, and other tools to build awesome dApps or integrate with the Ocean Enterprise ecosystem.</td><td></td><td></td><td><a href="/pages/oNCMd9wlcaqGPVQZCPrs">/pages/oNCMd9wlcaqGPVQZCPrs</a></td><td><a href="/files/pk2Mi8axKnGq3fnjf99w">/files/pk2Mi8axKnGq3fnjf99w</a></td></tr><tr><td><a href="/pages/998U26LMUg8EUmECksXS">/pages/998U26LMUg8EUmECksXS</a></td><td>For software architects and developers - deploy your own components in Ocean Enterprise ecosystem.</td><td></td><td></td><td><a href="/pages/998U26LMUg8EUmECksXS">/pages/998U26LMUg8EUmECksXS</a></td><td><a href="/files/GUlC1r4gHSKXYKPpuQ9E">/files/GUlC1r4gHSKXYKPpuQ9E</a></td></tr></tbody></table>


# Introduction

Growing demand for AI products and data sovereignty **is fuelling a proliferation of institutional AI and data ecosystems.**&#x20;

Since the initial release of Ocean Protocol there has been strong interest from the business and enterprise community in Ocean Protocol’s next generation data and AI ecosystem technology. &#x20;

Now, thanks to Ocean Enterprise, businesses can leverage a fully compliant, stable and secure version of Ocean Protocol that includes a wide range of specially developed enterprise ready features ready for immediate deployment at scale.&#x20;

### Quick Links

* [What is Ocean Enterprise?](/discover/what-is-ocean)
* [What can you do with Ocean Enterprise?](/discover/benefits)
* [Licensing Information](/discover/licensing)
* [FAQ](broken://pages/3Y6sOofwqndzkjpx5dym), [Glossary](broken://pages/R2OLx4Fnk7DPAqs49qjw)

***

*Next:* *Why Ocean?*

*Back:* [*Docs main*](/)


# What is Ocean Enterprise?

### What is Ocean Enterprise?

Ocean Enterprise is a free open-source enterprise-ready data ecosystem software solution that enables companies and public institutions to securely manage and monetize proprietary AI & data products and services in a trusted and compliant environment.\
\
Domain agnostic and collectively governed by an independent non-profit association, Ocean Enterprise is shaping a new transparent era of the data economy and is already being used by leading data-driven businesses in aerospace, agriculture, manufacturing, mobility, smart cities and more.

### Tech: Data NFTs and Datatokens

Ocean Enterprise enables decentralized access control via token-gating using Data NFTs (for assigning IP) and Datatokens (for consuming data services). \
\
Key principles:

* Publish data services as a data NFT (ERC721)
* Access the datasets and data services if you hold datatokens (ERC20)
* Consuming data services = spending datatokens

Crypto wallets, exchanges, and DAOs become *data* wallets, exchanges, and DAOs.

### Tech:  Compute-to-Data (C2D)

Ocean Enterprise enables you to buy & sell private data, while preserving privacy

* Private data is valuable: using it can improve research and business outcomes. But concerns over privacy and control make it hard to access.
* Compute-to-Data (C2D) grants access run compute against the data, *on the same premises of the data*. Only the results are visible to the consumer. The data never leaves the premises. Decentralized blockchain technology does the handshaking.
* C2D enables people to sell private data while preserving privacy, as an opportunity for companies to monetize their data assets.
* C2D can also be used for data sharing in science or technology contexts, with lower liability risk, because the data doesn't move.
* Data can be on Azure or AWS, Filecoin or Arweave, REST APIs or smart contract feeds. Data may be raw AI training data, feature vectors, trained models, even AI model predictions, or non-AI data.

<div align="center"><figure><img src="/files/OZ9NArTGFO9n97Et5miY" alt=""><figcaption><p>Compute-to-Data flow</p></figcaption></figure></div>

### Ecosystem, News & Updates

Ocean Enterprise Collective emerged out of the Ocean Protocol [ecosystem](https://oceanprotocol.com/explore/ecosystem), a vibrant and forward-thinking community of data scientists and AI enthusiasts actively building and shaping the future of AI & data. \
\
Keep up to date on all the latest Ocean Enterprise developments and news by following Ocean Enterprise on [LinkedIn](https://www.linkedin.com/company/ocean-enterprise-collective) and [Medium](https://medium.com/ocean-enterprise-collective) to.  Or, track Ocean Enterprise progress directly on [GitHub](https://github.com/OceanProtocolEnterprise).

***

*Next:* [*What can you do with Ocean?*](/discover/benefits)

*Back:* [*Why Ocean?*](broken://pages/EF1FkqJ9GSKnM8iRAjrc)


# What can you do with Ocean Enterprise?

Ocean Enterprise essentially provides enterprises with a comprehensive platform to build data marketplaces, enable secure data sharing, and create new revenue streams from their data assets while maintaining compliance and security standards.

**Core Capabilities:**

* **Data Monetization & Sharing**: Create secure, controlled environments for businesses to share and monetize their data assets
* **Compute-to-Data (C2D)**: Enable data processing without exposing the underlying data, maintaining privacy and security
* **Advanced Pricing Models**: Implement sophisticated pricing mechanisms for data assets and services
* **IP Licensing**: Advanced intellectual property licensing capabilities for data and algorithms

<details>

<summary>Build Your Token-gated AI dApp</summary>

Monetize by making your dApp token-gated. Users no longer have to use credit cards or manage OAuth credentials. Rather, they buy & spend ERC20 datatokens to access your dApp content.

Go further yet: rather than storing user profile data on your centralized server -- which exposes you to liability -- have it on-chain encrypted by the user's wallet, and just-in-time decrypt for the app.

</details>

<details>

<summary>Build Your Token-gated REST API</summary>

Focus on the backend: make a Web3-native REST API. Like the token-gated dApps, consumers of the REST API buy access with crypto, not credit cards.

</details>

***

*Next:* [Ocean Enterprise Collective e.V](/discover/ocean-enterprise-collective-e.v.)

*Back:* [*What is Ocean?*](/discover/what-is-ocean)


# Ocean Enterprise Collective e.V.

### Ocean Enterprise Collective e.V.

Ocean Enterprise is designed, developed maintained and governed by the Ocean Enterprise Collective e.V. (OEC): a non-profit association registered in Germany that was founded by companies representing a wide range of countries and industries including agriculture, energy, health, human resources, manufacturing and public sector.\
\
Whether startup, enterprise, or government entity, we welcome you to become a member of the OEC and join a pioneering community of passionate business leaders shaping the future of data sharing, AI compliance, and next generation digital ecosystems.\
\
OEC membership opens the door to cutting-edge technologies, high-value partnerships, and new business opportunities in the new data economy.\
\
Learn more about [OEC membership opportunities and benefits](https://www.oceanenterprise.io/member-benefits).  <br>


# Governance

This section serves as a guide to the policies, procedures, and standards that drive the development and maintenance of Ocean Enterprise software by Ocean Enterprise Collective e.V. and its community.

The section includes details on version numbering and releases, operational decision making, strategic decision making, contributions, quality assurance and code of conduct.&#x20;

Quick links to pages in this section:

* [Version Numbering & Releases](https://docs.oceanenterprise.io/~/revisions/x26BXC6KT8zMWxX3gyfl/discover/governance/version-numbering-and-releases)
* [Operational Decision Making](https://docs.oceanenterprise.io/~/revisions/x26BXC6KT8zMWxX3gyfl/discover/governance/operational-decision-making)
* [Strategic Decision Making](https://docs.oceanenterprise.io/~/revisions/x26BXC6KT8zMWxX3gyfl/discover/governance/strategic-decision-making)
* [Contributions & Quality Assurance](https://docs.oceanenterprise.io/~/revisions/x26BXC6KT8zMWxX3gyfl/discover/governance/contributions-and-quality-assurance)
* [Code of Conduct](https://docs.oceanenterprise.io/~/revisions/x26BXC6KT8zMWxX3gyfl/discover/governance/code-of-conduct)


# Version Numbering & Releases

This page includes the standardised versioning system and release process used by OEC to ensure updates to the code base don't unexpectedly break existing workflows.

## 1. Version Numbering Strategy

#### Semantic Versioning

Versions of OE software are named and numbered according to MAJOR.MINOR.PATCH format (e.g., 2.3.1):

* MAJOR: Breaking changes, incompatible API modifications
* MINOR: New features, backward-compatible additions
* PATCH: Bug fixes, security patches

## 2. Release Cadence&#x20;

#### Feature-Based Releases

* A new release will occur when specific features are complete, typically about every 6 months

## 3. Release Preparation Process

#### Phase 1: Planning&#x20;

* Typically 3-4 months prioir to release
* Roadmap review: Maintainer meeting to finalize features for release
* Issue triage: Label and milestone assignment
* Communication: Announce upcoming release and feature freeze date
* Documentation planning: Identify docs needing updates

#### Phase 2: Development Window

* Active development: Contributors work on milestoned features
* Regular check-ins: Progress updates in public channels, typically weekly
* Pull request reviews: Prioritize release-targeted PRs
* Testing infrastructure: Ensure Continuous Iteration (CI) / Continuous Delivery (CD) pipelines are healthy

#### Phase 3: Feature Freeze

* typically 1 month before scheduled release
* Code freeze: No new features, only bug fixes
* Beta release: Deploy beta version for community testing
* Bug bash: Organized testing period with contributor participation
* Translation updates: Coordinate with localization teams
* Documentation completion: Finalize release notes, changelog, upgrade guides

#### Phase 4: Release Candidate

* Release Candidate deployment: Publish release candidate (RC)
* Final testing: Regression testing, security audit
* Sign-off process: Maintainer approval required
* Announcement draft: Prepare blog posts, social media content

#### Phase 5: Release Day

* Tag creation: Create git tag with version number
* Build artifacts: Generate and sign release binaries/packages
* Distribution: Upload to package managers, registries, download sites
* Announcement: Publish release notes, blog post, social media
* Support preparation: Ensure maintainers are available for issues

#### Phase 6: Post-Release Activities

* Monitor issue tracker for critical bugs
* Prepare hotfix releases if needed
* Gather community feedback
* Update documentation based on user questions
* Retrospective meeting with contributors
* Document lessons learned
* Update release process based on feedback
* Begin planning next release cycle


# Operational Decision Making

This page covers guidelines used for routine decisions with respect to the code base.

For routine decisions to the code base that do NOT involve new version updates or breaking updates the following approach is taken:

#### Basic Decision Framework

* Consensus-seeking: Aim for agreement through discussion
* Voting mechanism: Fallback for disputed decisions (majority)
* Public transparency: Document decisions in issue trackers or mailing lists

#### Maintainer Roles

* Release Manager: Coordinates release process; rotates between maintainers.
* Core Maintainers: Vote on major decisions, approve final releases
* Area Maintainers: Responsible for specific components


# Strategic Decision Making

This page includes guidelines used for important strategic decisions with respect to the code base.

For important strategic decisions with respect to the code base such as feature inclusion (new version updates) and feature changes (breaking updates) a vote must be taken by existing OEC Association members.&#x20;

Only members in good standing are eligible to vote.&#x20;

Voting on these decisions is based on a contribution-weighted voting system, where voting power is proportional to the member's level of contribution to the OEC Association's activities, as measured by:

* Technical contributions to Ocean Enterprise development
* In-Kind contributions for work needed to complete pre defined deliverables
* Financial contributions beyond membership dues
* Material contributions including subscriptions to online collaboration and marketing tools

Contribution-weights are reassessed on a quarterly basis based on the contribution level of the previous quarter.&#x20;

The OEC Board acts as tie breaker. Contribution-weights are calculated according to the following structure:

<table><thead><tr><th align="center">Support Level</th><th width="127.93359375" align="center" valign="top">Raw Vote</th><th align="center">Weighted Vote</th></tr></thead><tbody><tr><td align="center">0</td><td align="center" valign="top">0</td><td align="center">0</td></tr><tr><td align="center">1</td><td align="center" valign="top">1</td><td align="center">1</td></tr><tr><td align="center">2</td><td align="center" valign="top">1</td><td align="center">2</td></tr><tr><td align="center">3</td><td align="center" valign="top">1</td><td align="center">5</td></tr></tbody></table>

<br>


# Contributions & Quality Assurance

Contributions to OEC repositories are warmly welcomed.

#### Contributions

It takes a lot of hard work to build an open source tech stack and contributions to OEC repositories are warmly welcomed within the Ocean Enterprise [ GitHub](https://github.com/OceanProtocolEnterprise) organization.

All Ocean Enterprise code (software) is licensed under an [GLP3.0 (GNU General Public License version 3)](https://www.gnu.org/licenses/gpl-3.0.en.html) a strong copyleft license that ensures software remains free and open source.

All contributions to the Ocean Enterprise code are also licensed under the GLP3.0 license.\
\
If you are a current member of the Ocean Enterprise Collective e.V then there is nothing extra for you to do: licensing is already handled.\
\
If you are not a current member of the Ocean Enterprise Collective e.V then you are considered to be an "external contributor".  All external contributors are welcome to open an issue in the Ocean Enterprise GitHub repositories specifying in detail the recommendation or bug they have found. Comments submitted by external contributors should clearly indicate if the comment relates to an improvement or a bug.  Please remember to be respectful in the comments, as outlined in the Contributor Code of Conduct ([LINK](https://docs.oceanenterprise.io/~/revisions/IKmS06jx6d2zQh2vmKN9/discover/governance/code-of-conduct)).

#### Quality Assurance

Because open-source projects rarely live in isolation, OEC takes Quality Assurance (QA) as well security and vulnerability management very seriously. Before code is release OEC performs various automated and manual testing.

#### Automated Testing

* Comprehensive test suite running on CI
* Code coverage requirements (e.g., >80%)
* Performance regression tests
* Security scanning (dependency checks, SAST tools)

#### Manual Testing&#x20;

* Installation/upgrade procedures
* Critical user workflows
* Platform-specific testing (OS, browsers, etc.)
* Accessibility compliance
* Documentation accuracy


# Code of Conduct

This page includes the principles outlining expected behaviour within the community and frameworks for conflict resolution.

As contributors and maintainers of this project, and in the interest of fostering an open and welcoming community, we pledge to respect all people who contribute to the project.

We are committed to making participation in this project a harassment-free experience for everyone, regardless of level of experience, gender, gender identity and expression, sexual orientation, disability, personal appearance, body size, race, ethnicity, age, religion, nationality, or species.

Examples of unacceptable behavior by participants include:

* The use of sexualized language or imagery
* Personal attacks
* Trolling or insulting/derogatory comments
* Public or private harassment
* Publishing other's private information, such as physical or electronic addresses, without explicit permission
* Deliberate intimidation
* Other unethical or unprofessional conduct

Project maintainers have the right and responsibility to remove, edit, or reject comments, commits, code, wiki edits, issues, and other contributions that are not aligned to this Code of Conduct, or to ban temporarily or permanently any contributor for other behaviours that they deem inappropriate, threatening, offensive, or harmful.

By adopting this Code of Conduct, project maintainers commit themselves to fairly and consistently applying these principles to every aspect of managing this project. Project maintainers who do not follow or enforce the Code of Conduct may be permanently removed from the project team.

This Code of Conduct applies both within project spaces and in public spaces when an individual is representing the project or its community.

Instances of abusive, harassing, or otherwise unacceptable behavior directed at yourself or another community member may be reported by contacting a project maintainer at <info@oceanenterprise.io>. All complaints will be reviewed and investigated and will result in a response that is appropriate to the circumstances. Maintainers are obligated to maintain confidentiality with regard to the reporter of an incident.

This Code of Conduct is adapted from the[ Contributor Covenant](http://contributor-covenant.org/), version 1.3.0, available at[ contributor-covenant.org/version/1/3/0/](http://contributor-covenant.org/version/1/3/0/)

<br>


# Licensing

## PREAMBLE

A. This repository is a dual-licensed software, available under commercial and open-source license terms.

B. These open-source license terms (“OS License Terms”) solely apply to the use of the Software in conjunction with smart contracts provided by OEC e.V. The latest version of the addresses of the smart contracts provided by OEC e.V. can be found on the website of OEC e.V. under \[[https://docs.oceanenterprise.io/developers/networks](/developers/networks)].

C. The commercial license terms (“Commercial License Terms”) apply to the use of the Software in conjunction with smart contracts provided by parties other than OEC e.V.

## OPEN-SOURCE LICENSE (GPLv3)

1. OWNERSHIP AND DELIVERY OF THE SOFTWARE&#x20;

1.1 OEC e.V. is the sole and exclusive owner of all rights of use in the Software and any associated documentation and manuals.

1.2 The use of the Software shall be subject to these OS License Terms and to the standard open-source license terms referred to herein.

1.3 The Software is made available in source code and object code form, along with any associated documentation and manuals.

2. LICENSE 2.1 The Software is provided free of charge, under the GNU General Public License 3 (available here and attached as Schedule 1 (“GNU General Public License 3 Terms”), with the rights and obligations set forth in therein.

2.2 The use of the Software under the OS License Terms is subject to the following conditions: 2.2.1 All access to and use, including, but not limited to, propagation and conveying, of the Software shall be in accordance with these OS License Terms and the GNU General Public License 3 Terms.

2.2.2. Unless otherwise provided herein, OEC e.V.’s role hereunder is that of “Licensor” under the GNU General Public License 3 Terms, and the rights and obligations stipulated for the “Licensor” under the GNU General Public License 3 Terms shall apply to OEC e.V. mutatis mutandis.

2.2.3 The right to use the Software is limited to the use in conjunction with the use of smart contracts provided by OEC e.V. The latest version of the addresses of the smart contracts provided by OEC e.V. can be found on the website of OEC e.V. under \[<https://docs.oceanenterprise.io/developers/networks>].

2.2.4 Any use of the Software other than in conjunction with the use of smart contracts provided by OEC e.V. shall require a commercial license. OEC e.V. makes the SoftwareSofftware available for such use under the Commercial License Terms.

2.2.5 The right to use the Software under these OS License Terms is subject to the condition subsequent of any use of the Software inconsistent with these OS License Terms.

2.3 The user shall be authorized to modify the Software or portions of the Software and to copy and distribute the results of such modification under these OS License Terms and the GNU General Public License 3 Terms, provided that the user causes any subject matter containing the Software or portions of the Software, whether modified or not, to be licensed at no charge to any third party under these OS License Terms and the GNU General Public License 3 Terms.

2.4 The use and compatibility of the Software with other Open Source Licenses is permitted in accordance with the GNU General Public License 3 Terms. The use of the Software is especially compatible with the Apache 2.0 terms (available here). In all cases, any resulting work is licensed under the GNU General Public License 3 Terms.

2.5 The user is not allowed to grant sublicenses. Any recipient of the Software automatically receives a license from OEC e.V. to use, modify and propagate the Software, subject to these OS License Terms and the GNU General Public License 3 Terms.

2.6 Any use of the Software not expressly permitted herein shall require OEC e.V.’s prior consent. The user shall be liable for any unauthorized use of the Software without limitation.

2.7 Clause 2.6 shall not apply to the use of the Software for internal evaluation and testing in test environments (i.e. Ethereum Sepolia, Optimism Sepolia etc.).

3. LIMITATION OF LIABILITY 3.1 OEC e.V. shall be liable in accordance with applicable laws in the following cases: 3.1.1 injury to life, body or health of a person;

3.1.2 where damages, losses, costs or expenses are caused by intent or gross negligence; and

3.1.3 where liability cannot be limited under applicable law, such as the Product Liability Act in German law.

3.2 OEC e.V. shall not be liable in cases where damages, losses, costs or expenses are resulting from slight negligence except for breaches of essential contractual obligations, i.e., such obligations the violation of which endangers the purpose of these OS License Terms and on the fulfillment of which the user relies and may rely to a particular extent (cardinal obligations or Kardinalpflichten); such liability shall be limited to an amount reasonably foreseeable for the kind of relationship contemplated in these OS License Terms.

3.3 In case of a loss of data OEC e.V.’s liability hereunder shall be limited to the amount of typical recovery costs which would have arisen if proper and regular data backup measures had been carried out by the user. 3.4 Any other liability of OEC e.V. shall be excluded.

4. AUDIT OEC e.V. shall be authorized to appoint a qualified third party to conduct audits of the use of the Software at the user’s premises or otherwise, to verify compliance with these OS License Terms. Such audit may occur once every calendar year, with reasonable prior notice, and outside this interval if there is reasonable suspicion of the user’s non-compliance with these OS License Terms. The user shall provide to the auditor all physical and other access and any cooperation reasonably required by the auditor to carry out the audit.
5. EXPORT CONTROL The user shall comply with all applicable export control laws, rules and regulations, as amended from time to time, and shall indemnify and hold OEC e.V. harmless from any liability arising out of use of the Software in violation of these laws, rules or regulations.
6. MISCELLANEOUS 6.1 These OS License Term shall be governed by and construed in accordance with the laws of the Federal Republic of Germany, excluding the provisions of the United Nations Convention on Contracts for the International Sale of Goods dated 11.4.1980 (CISG).

6.2 For all disputes arising out of or in connection with these OS License Terms the courts of \[…] shall have exclusive jurisdiction.

6.3 Should any provision of these OS License Terms be or become invalid, this shall not affect the validity of the remaining provisions.

SCHEDULE 1

GNU General Public License 3 Version 3, 29 June 2007 Copyright © 2007 Free Software Foundation, Inc. <https://fsf.org/> Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed.

Preamble The GNU General Public License is a free, copyleft license for software and other kinds of works. The licenses for most software and other practical works are designed to take away your freedom to share and change the works. By contrast, the GNU General Public License is intended to guarantee your freedom to share and change all versions of a program--to make sure it remains free software for all its users. We, the Free Software Foundation, use the GNU General Public License for most of our software; it applies also to any other work released this way by its authors. You can apply it to your programs, too. When we speak of free software, we are referring to freedom, not price. Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software (and charge for them if you wish), that you receive source code or can get it if you want it, that you can change the software or use pieces of it in new free programs, and that you know you can do these things. To protect your rights, we need to prevent others from denying you these rights or asking you to surrender the rights. Therefore, you have certain responsibilities if you distribute copies of the software, or if you modify it: responsibilities to respect the freedom of others. For example, if you distribute copies of such a program, whether gratis or for a fee, you must pass on to the recipients the same freedoms that you received. You must make sure that they, too, receive or can get the source code. And you must show them these terms so they know their rights. Developers that use the GNU GPL protect your rights with two steps: (1) assert copyright on the software, and (2) offer you this License giving you legal permission to copy, distribute and/or modify it. For the developers' and authors' protection, the GPL clearly explains that there is no warranty for this free software. For both users' and authors' sake, the GPL requires that modified versions be marked as changed, so that their problems will not be attributed erroneously to authors of previous versions. Some devices are designed to deny users access to install or run modified versions of the software inside them, although the manufacturer can do so. This is fundamentally incompatible with the aim of protecting users' freedom to change the software. The systematic pattern of such abuse occurs in the area of products for individuals to use, which is precisely where it is most unacceptable. Therefore, we have designed this version of the GPL to prohibit the practice for those products. If such problems arise substantially in other domains, we stand ready to extend this provision to those domains in future versions of the GPL, as needed to protect the freedom of users. Finally, every program is threatened constantly by software patents. States should not allow patents to restrict development and use of software on general-purpose computers, but in those that do, we wish to avoid the special danger that patents applied to a free program could make it effectively proprietary. To prevent this, the GPL assures that patents cannot be used to render the program non-free. The precise terms and conditions for copying, distribution and modification follow.

TERMS AND CONDITIONS 0. Definitions. “This License” refers to version 3 of the GNU General Public License.

“Copyright” also means copyright-like laws that apply to other kinds of works, such as semiconductor masks.

“The Program” refers to any copyrightable work licensed under this License. Each licensee is addressed as “you”. “Licensees” and “recipients” may be individuals or organizations.

To “modify” a work means to copy from or adapt all or part of the work in a fashion requiring copyright permission, other than the making of an exact copy. The resulting work is called a “modified version” of the earlier work or a work “based on” the earlier work.

A “covered work” means either the unmodified Program or a work based on the Program.

To “propagate” a work means to do anything with it that, without permission, would make you directly or secondarily liable for infringement under applicable copyright law, except executing it on a computer or modifying a private copy. Propagation includes copying, distribution (with or without modification), making available to the public, and in some countries other activities as well.

To “convey” a work means any kind of propagation that enables other parties to make or receive copies. Mere interaction with a user through a computer network, with no transfer of a copy, is not conveying.

An interactive user interface displays “Appropriate Legal Notices” to the extent that it includes a convenient and prominently visible feature that (1) displays an appropriate copyright notice, and (2) tells the user that there is no warranty for the work (except to the extent that warranties are provided), that licensees may convey the work under this License, and how to view a copy of this License. If the interface presents a list of user commands or options, such as a menu, a prominent item in the list meets this criterion.

1. Source Code.

The “source code” for a work means the preferred form of the work for making modifications to it. “Object code” means any non-source form of a work. A “Standard Interface” means an interface that either is an official standard defined by a recognized standards body, or, in the case of interfaces specified for a particular programming language, one that is widely used among developers working in that language.

The “System Libraries” of an executable work include anything, other than the work as a whole, that (a) is included in the normal form of packaging a Major Component, but which is not part of that Major Component, and (b) serves only to enable use of the work with that Major Component, or to implement a Standard Interface for which an implementation is available to the public in source code form. A “Major Component”, in this context, means a major essential component (kernel, window system, and so on) of the specific operating system (if any) on which the executable work runs, or a compiler used to produce the work, or an object code interpreter used to run it.

The “Corresponding Source” for a work in object code form means all the source code needed to generate, install, and (for an executable work) run the object code and to modify the work, including scripts to control those activities. However, it does not include the work's System Libraries, or general-purpose tools or generally available free programs which are used unmodified in performing those activities but which are not part of the work. For example, Corresponding Source includes interface definition files associated with source files for the work, and the source code for shared libraries and dynamically linked subprograms that the work is specifically designed to require, such as by intimate data communication or control flow between those subprograms and other parts of the work.

The Corresponding Source need not include anything that users can regenerate automatically from other parts of the Corresponding Source.

The Corresponding Source for a work in source code form is that same work.

2. Basic Permissions.

All rights granted under this License are granted for the term of copyright on the Program, and are irrevocable provided the stated conditions are met. This License explicitly affirms your unlimited permission to run the unmodified Program. The output from running a covered work is covered by this License only if the output, given its content, constitutes a covered work. This License acknowledges your rights of fair use or other equivalent, as provided by copyright law.

You may make, run and propagate covered works that you do not convey, without conditions so long as your license otherwise remains in force. You may convey covered works to others for the sole purpose of having them make modifications exclusively for you, or provide you with facilities for running those works, provided that you comply with the terms of this License in conveying all material for which you do not control copyright. Those thus making or running the covered works for you must do so exclusively on your behalf, under your direction and control, on terms that prohibit them from making any copies of your copyrighted material outside their relationship with you.

Conveying under any other circumstances is permitted solely under the conditions stated below. Sublicensing is not allowed; section 10 makes it unnecessary.

3. Protecting Users' Legal Rights From Anti-Circumvention Law.

No covered work shall be deemed part of an effective technological measure under any applicable law fulfilling obligations under article 11 of the WIPO copyright treaty adopted on 20 December 1996, or similar laws prohibiting or restricting circumvention of such measures.

When you convey a covered work, you waive any legal power to forbid circumvention of technological measures to the extent such circumvention is effected by exercising rights under this License with respect to the covered work, and you disclaim any intention to limit operation or modification of the work as a means of enforcing, against the work's users, your or third parties' legal rights to forbid circumvention of technological measures.

4. Conveying Verbatim Copies.

You may convey verbatim copies of the Program's source code as you receive it, in any medium, provided that you conspicuously and appropriately publish on each copy an appropriate copyright notice; keep intact all notices stating that this License and any non-permissive terms added in accord with section 7 apply to the code; keep intact all notices of the absence of any warranty; and give all recipients a copy of this License along with the Program. You may charge any price or no price for each copy that you convey, and you may offer support or warranty protection for a fee.

5. Conveying Modified Source Versions.

You may convey a work based on the Program, or the modifications to produce it from the Program, in the form of source code under the terms of section 4, provided that you also meet all of these conditions:

a) The work must carry prominent notices stating that you modified it, and giving a relevant date.

b) The work must carry prominent notices stating that it is released under this License and any conditions added under section 7. This requirement modifies the requirement in section 4 to “keep intact all notices”.

c) You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy. This License will therefore apply, along with any applicable section 7 additional terms, to the whole of the work, and all its parts, regardless of how they are packaged. This License gives no permission to license the work in any other way, but it does not invalidate such permission if you have separately received it.

d) If the work has interactive user interfaces, each must display Appropriate Legal Notices; however, if the Program has interactive interfaces that do not display Appropriate Legal Notices, your work need not make them do so.

A compilation of a covered work with other separate and independent works, which are not by their nature extensions of the covered work, and which are not combined with it such as to form a larger program, in or on a volume of a storage or distribution medium, is called an “aggregate” if the compilation and its resulting copyright are not used to limit the access or legal rights of the compilation's users beyond what the individual works permit. Inclusion of a covered work in an aggregate does not cause this License to apply to the other parts of the aggregate.

6. Conveying Non-Source Forms.

You may convey a covered work in object code form under the terms of sections 4 and 5, provided that you also convey the machine-readable Corresponding Source under the terms of this License, in one of these ways:

a) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by the Corresponding Source fixed on a durable physical medium customarily used for software interchange.

b) Convey the object code in, or embodied in, a physical product (including a physical distribution medium), accompanied by a written offer, valid for at least three years and valid for as long as you offer spare parts or customer support for that product model, to give anyone who possesses the object code either (1) a copy of the Corresponding Source for all the software in the product that is covered by this License, on a durable physical medium customarily used for software interchange, for a price no more than your reasonable cost of physically performing this conveying of source, or (2) access to copy the Corresponding Source from a network server at no charge.

c) Convey individual copies of the object code with a copy of the written offer to provide the Corresponding Source. This alternative is allowed only occasionally and noncommercially, and only if you received the object code with such an offer, in accord with subsection 6b.

d) Convey the object code by offering access from a designated place (gratis or for a charge), and offer equivalent access to the Corresponding Source in the same way through the same place at no further charge. You need not require recipients to copy the Corresponding Source along with the object code. If the place to copy the object code is a network server, the Corresponding Source may be on a different server (operated by you or a third party) that supports equivalent copying facilities, provided you maintain clear directions next to the object code saying where to find the Corresponding Source. Regardless of what server hosts the Corresponding Source, you remain obligated to ensure that it is available for as long as needed to satisfy these requirements.

e) Convey the object code using peer-to-peer transmission, provided you inform other peers where the object code and Corresponding Source of the work are being offered to the general public at no charge under subsection 6d.

A separable portion of the object code, whose source code is excluded from the Corresponding Source as a System Library, need not be included in conveying the object code work.

A “User Product” is either (1) a “consumer product”, which means any tangible personal property which is normally used for personal, family, or household purposes, or (2) anything designed or sold for incorporation into a dwelling. In determining whether a product is a consumer product, doubtful cases shall be resolved in favor of coverage. For a particular product received by a particular user, “normally used” refers to a typical or common use of that class of product, regardless of the status of the particular user or of the way in which the particular user actually uses, or expects or is expected to use, the product. A product is a consumer product regardless of whether the product has substantial commercial, industrial or non-consumer uses, unless such uses represent the only significant mode of use of the product.

“Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.

If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information. But this requirement does not apply if neither you nor any third party retains the ability to install modified object code on the User Product (for example, the work has been installed in ROM).

The requirement to provide Installation Information does not include a requirement to continue to provide support service, warranty, or updates for a work that has been modified or installed by the recipient, or for the User Product in which it has been modified or installed. Access to a network may be denied when the modification itself materially and adversely affects the operation of the network or violates the rules and protocols for communication across the network.

Corresponding Source conveyed, and Installation Information provided, in accord with this section must be in a format that is publicly documented (and with an implementation available to the public in source code form), and must require no special password or key for unpacking, reading or copying.

7. Additional Terms.

“Additional permissions” are terms that supplement the terms of this License by making exceptions from one or more of its conditions. Additional permissions that are applicable to the entire Program shall be treated as though they were included in this License, to the extent that they are valid under applicable law. If additional permissions apply only to part of the Program, that part may be used separately under those permissions, but the entire Program remains governed by this License without regard to the additional permissions.

When you convey a copy of a covered work, you may at your option remove any additional permissions from that copy, or from any part of it. (Additional permissions may be written to require their own removal in certain cases when you modify the work.) You may place additional permissions on material, added by you to a covered work, for which you have or can give appropriate copyright permission.

Notwithstanding any other provision of this License, for material you add to a covered work, you may (if authorized by the copyright holders of that material) supplement the terms of this License with terms:

a) Disclaiming warranty or limiting liability differently from the terms of sections 15 and 16 of this License; or

b) Requiring preservation of specified reasonable legal notices or author attributions in that material or in the Appropriate Legal Notices displayed by works containing it; or

c) Prohibiting misrepresentation of the origin of that material, or requiring that modified versions of such material be marked in reasonable ways as different from the original version; or

d) Limiting the use for publicity purposes of names of licensors or authors of the material; or

e) Declining to grant rights under trademark law for use of some trade names, trademarks, or service marks; or

f) Requiring indemnification of licensors and authors of that material by anyone who conveys the material (or modified versions of it) with contractual assumptions of liability to the recipient, for any liability that these contractual assumptions directly impose on those licensors and authors.

All other non-permissive additional terms are considered “further restrictions” within the meaning of section 10. If the Program as you received it, or any part of it, contains a notice stating that it is governed by this License along with a term that is a further restriction, you may remove that term. If a license document contains a further restriction but permits relicensing or conveying under this License, you may add to a covered work material governed by the terms of that license document, provided that the further restriction does not survive such relicensing or conveying.

If you add terms to a covered work in accord with this section, you must place, in the relevant source files, a statement of the additional terms that apply to those files, or a notice indicating where to find the applicable terms.

Additional terms, permissive or non-permissive, may be stated in the form of a separately written license, or stated as exceptions; the above requirements apply either way.

8. Termination.

You may not propagate or modify a covered work except as expressly provided under this License. Any attempt otherwise to propagate or modify it is void, and will automatically terminate your rights under this License (including any patent licenses granted under the third paragraph of section 11).

However, if you cease all violation of this License, then your license from a particular copyright holder is reinstated (a) provisionally, unless and until the copyright holder explicitly and finally terminates your license, and (b) permanently, if the copyright holder fails to notify you of the violation by some reasonable means prior to 60 days after the cessation.

Moreover, your license from a particular copyright holder is reinstated permanently if the copyright holder notifies you of the violation by some reasonable means, this is the first time you have received notice of violation of this License (for any work) from that copyright holder, and you cure the violation prior to 30 days after your receipt of the notice.

Termination of your rights under this section does not terminate the licenses of parties who have received copies or rights from you under this License. If your rights have been terminated and not permanently reinstated, you do not qualify to receive new licenses for the same material under section 10.

9. Acceptance Not Required for Having Copies.

You are not required to accept this License in order to receive or run a copy of the Program. Ancillary propagation of a covered work occurring solely as a consequence of using peer-to-peer transmission to receive a copy likewise does not require acceptance. However, nothing other than this License grants you permission to propagate or modify any covered work. These actions infringe copyright if you do not accept this License. Therefore, by modifying or propagating a covered work, you indicate your acceptance of this License to do so.

10. Automatic Licensing of Downstream Recipients.

Each time you convey a covered work, the recipient automatically receives a license from the original licensors, to run, modify and propagate that work, subject to this License. You are not responsible for enforcing compliance by third parties with this License.

An “entity transaction” is a transaction transferring control of an organization, or substantially all assets of one, or subdividing an organization, or merging organizations. If propagation of a covered work results from an entity transaction, each party to that transaction who receives a copy of the work also receives whatever licenses to the work the party's predecessor in interest had or could give under the previous paragraph, plus a right to possession of the Corresponding Source of the work from the predecessor in interest, if the predecessor has it or can get it with reasonable efforts.

You may not impose any further restrictions on the exercise of the rights granted or affirmed under this License. For example, you may not impose a license fee, royalty, or other charge for exercise of rights granted under this License, and you may not initiate litigation (including a cross-claim or counterclaim in a lawsuit) alleging that any patent claim is infringed by making, using, selling, offering for sale, or importing the Program or any portion of it.

11. Patents.

A “contributor” is a copyright holder who authorizes use under this License of the Program or a work on which the Program is based. The work thus licensed is called the contributor's “contributor version”.

A contributor's “essential patent claims” are all patent claims owned or controlled by the contributor, whether already acquired or hereafter acquired, that would be infringed by some manner, permitted by this License, of making, using, or selling its contributor version, but do not include claims that would be infringed only as a consequence of further modification of the contributor version. For purposes of this definition, “control” includes the right to grant patent sublicenses in a manner consistent with the requirements of this License.

Each contributor grants you a non-exclusive, worldwide, royalty-free patent license under the contributor's essential patent claims, to make, use, sell, offer for sale, import and otherwise run, modify and propagate the contents of its contributor version.

In the following three paragraphs, a “patent license” is any express agreement or commitment, however denominated, not to enforce a patent (such as an express permission to practice a patent or covenant not to sue for patent infringement). To “grant” such a patent license to a party means to make such an agreement or commitment not to enforce a patent against the party.

If you convey a covered work, knowingly relying on a patent license, and the Corresponding Source of the work is not available for anyone to copy, free of charge and under the terms of this License, through a publicly available network server or other readily accessible means, then you must either (1) cause the Corresponding Source to be so available, or (2) arrange to deprive yourself of the benefit of the patent license for this particular work, or (3) arrange, in a manner consistent with the requirements of this License, to extend the patent license to downstream recipients. “Knowingly relying” means you have actual knowledge that, but for the patent license, your conveying the covered work in a country, or your recipient's use of the covered work in a country, would infringe one or more identifiable patents in that country that you have reason to believe are valid.

If, pursuant to or in connection with a single transaction or arrangement, you convey, or propagate by procuring conveyance of, a covered work, and grant a patent license to some of the parties receiving the covered work authorizing them to use, propagate, modify or convey a specific copy of the covered work, then the patent license you grant is automatically extended to all recipients of the covered work and works based on it.

A patent license is “discriminatory” if it does not include within the scope of its coverage, prohibits the exercise of, or is conditioned on the non-exercise of one or more of the rights that are specifically granted under this License. You may not convey a covered work if you are a party to an arrangement with a third party that is in the business of distributing software, under which you make payment to the third party based on the extent of your activity of conveying the work, and under which the third party grants, to any of the parties who would receive the covered work from you, a discriminatory patent license (a) in connection with copies of the covered work conveyed by you (or copies made from those copies), or (b) primarily for and in connection with specific products or compilations that contain the covered work, unless you entered into that arrangement, or that patent license was granted, prior to 28 March 2007.

Nothing in this License shall be construed as excluding or limiting any implied license or other defenses to infringement that may otherwise be available to you under applicable patent law.

12. No Surrender of Others' Freedom.

If conditions are imposed on you (whether by court order, agreement or otherwise) that contradict the conditions of this License, they do not excuse you from the conditions of this License. If you cannot convey a covered work so as to satisfy simultaneously your obligations under this License and any other pertinent obligations, then as a consequence you may not convey it at all. For example, if you agree to terms that obligate you to collect a royalty for further conveying from those to whom you convey the Program, the only way you could satisfy both those terms and this License would be to refrain entirely from conveying the Program.

13. Use with the GNU Affero General Public License.

Notwithstanding any other provision of this License, you have permission to link or combine any covered work with a work licensed under version 3 of the GNU Affero General Public License into a single combined work, and to convey the resulting work. The terms of this License will continue to apply to the part which is the covered work, but the special requirements of the GNU Affero General Public License, section 13, concerning interaction through a network will apply to the combination as such.

14. Revised Versions of this License.

The Free Software Foundation may publish revised and/or new versions of the GNU General Public License from time to time. Such new versions will be similar in spirit to the present version, but may differ in detail to address new problems or concerns.

Each version is given a distinguishing version number. If the Program specifies that a certain numbered version of the GNU General Public License “or any later version” applies to it, you have the option of following the terms and conditions either of that numbered version or of any later version published by the Free Software Foundation. If the Program does not specify a version number of the GNU General Public License, you may choose any version ever published by the Free Software Foundation.

If the Program specifies that a proxy can decide which future versions of the GNU General Public License can be used, that proxy's public statement of acceptance of a version permanently authorizes you to choose that version for the Program.

Later license versions may give you additional or different permissions. However, no additional obligations are imposed on any author or copyright holder as a result of your choosing to follow a later version.

15. Disclaimer of Warranty.

THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.

16. Limitation of Liability.

IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

17. Interpretation of Sections 15 and 16.

If the disclaimer of warranty and limitation of liability provided above cannot be given local legal effect according to their terms, reviewing courts shall apply local law that most closely approximates an absolute waiver of all civil liability in connection with the Program, unless a warranty or assumption of liability accompanies a copy of the Program in return for a fee.

END OF TERMS AND CONDITIONS How to Apply These Terms to Your New Programs

If you develop a new program, and you want it to be of the greatest possible use to the public, the best way to achieve this is to make it free software which everyone can redistribute and change under these terms. To do so, attach the following notices to the program. It is safest to attach them to the start of each source file to most effectively state the exclusion of warranty; and each file should have at least the “copyright” line and a pointer to where the full notice is found. \<one line to give the program's name and a brief idea of what it does.> Copyright (C)

```
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.

This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
GNU General Public License for more details.

You should have received a copy of the GNU General Public License
along with this program.  If not, see <https://www.gnu.org/licenses/>.
```

Also add information on how to contact you by electronic and paper mail. If the program does terminal interaction, make it output a short notice like this when it starts in an interactive mode: Copyright (C) This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. This is free software, and you are welcome to redistribute it under certain conditions; type` show c' for details.

The hypothetical commands `show w' and` show c' should show the appropriate parts of the General Public License. Of course, your program's commands might be different; for a GUI interface, you would use an “about box”. You should also get your employer (if you work as a programmer) or school, if any, to sign a “copyright disclaimer” for the program, if necessary. For more information on this, and how to apply and follow the GNU GPL, see <https://www.gnu.org/licenses/>. The GNU General Public License does not permit incorporating your program into proprietary programs. If your program is a subroutine library, you may consider it more useful to permit linking proprietary applications with the library. If this is what you want to do, use the GNU Lesser General Public License instead of this License. But first, please read <https://www.gnu.org/licenses/why-not-lgpl.html>.

## COMMERCIAL LICENSE

1. OWNERSHIP AND DELIVERY OF THE SOFTWARE 1.1 OEC e.V. is the sole and exclusive owner of all rights of use in the Software and any associated documentation and manuals.

1.2 The use of the Software shall be subject to these Commercial License Terms.

1.3 The Software is made available in in machine readable form, along with any associated instructions and manuals.

2. LICENSE

2.1 The use of the Software under these Commercial License Terms is subject to the following conditions:

2.1.1 Any access to and use of the Software shall be in accordance with these Commercial License Terms.

2.1.2 The right of use of the Software hereunder shall be non-exclusive, non-transferable, and non-sublicensable, perpetual, worldwide and subject to the timely payment of the License Fee. 2.1.3 Any reproduction and decompilation or reverse engineering (in each case except as permitted by law), distribution, translation, creation of derivative works of the Software and other modifications of the Software shall be strictly prohibited.

2.2 Any use of the software Software not expressly permitted herein shall require OEC e.V.’s prior consent. The user shall be liable for any unauthorized use of the Software without limitation.

2.3 Clause 2.2 shall not apply to the use of the Software for internal evaluation and testing in test environments (i.e. Ethereum Sepolia, Polygon Amoy etc.) for up to \[90] days.

3. LICENSE FEES 3.1 The license fee shall be payable as an annual one-time fee (“License Fee”) of 40.000 EUR.

3.2 The License Fee referred to in clause 3.1 is exclusive of any applicable VAT or other taxes.

3.3 The License Fee shall be paid without any setoff or withholding for any reason (except for mandatory withholding tax under applicable laws).

3.4 All taxes shall be paid by the user.

4. WARRANTY AND INDEMNIFICATION

4.1 OEC e.V. warrants that it is entitled to grant the rights of use of the Software as stipulated in these Commercial License Terms.

4.2 The user’s rights in case of defects of the Software shall become statute-barred twelve (12) months after delivery of the Software and any associated documentation and manuals. The same period shall apply to any updates, upgrades and new versions of the Software which OEC e.V. may make available from time to time.

4.3 If any third party claims that the use of the Software in accordance with these Commercial License Terms infringes its rights, OEC e.V. will defend such a claim and indemnify the user from any adverse final judgment and any settlement to which OEC e.V. consents, provided that the user promptly notifies OEC e.V. of the third-party claim or threat, supports OEC e.V.’s defense of the claim as reasonably requested by OEC e.V., and the alleged infringement is not caused by any unauthorized modification of the Software.

4.4 OEC e.V. may, at its sole discretion, obtain from the third party the rights necessary to stop the alleged infringement or modify the Software in such manner that the infringement no longer occurs, provided that such modification not substantially impair the Software’s functionality.

4.5 Any claims for damages in connection with the use of the Software are subject to the limitations set forth under clause 5.

5. LIMITATION OF LIABILITY

5.1 OEC e.V. shall be liable in accordance with applicable laws in the following cases: 5.1.1 injury to life, body or health of a person;

5.1.2 where damages, losses, costs or expenses are caused by intent or gross negligence; and

5.1.3 where liability cannot be limited under applicable law, such as the Product Liability Act in German law.

5.2 OEC e.V. shall not be liable in cases where damages, losses, costs or expenses are resulting from slight negligence except for breaches of essential contractual obligations, i.e., such obligations the violation of which endangers the purpose of these Commercial License Terms and on the fulfillment of which the user relies and may rely to a particular extent (cardinal obligations or Kardinalpflichten); such liability shall be limited to an amount reasonably foreseeable for the kind of relationship contemplated in these Commercial License Terms. 5.3 In case of a loss of data OEC e.V.’s liability hereunder shall be limited to the amount of typical recovery costs which would have arisen if proper and regular data backup measures had been carried out by the user. 5.4 Any other liability of OEC e.V. shall be excluded.

6. AUDIT

OEC e.V. shall be authorized to appoint a qualified third party to conduct audits of the use of the Software at the user’s premises or otherwise, to verify compliance with these Commercial License Terms. Such audit may occur once every calendar year, with reasonable prior notice, and outside this interval if there is reasonable suspicion of the user’s non-compliance with these Commercial License Terms. The user shall provide to the auditor all physical and other access and any cooperation reasonably required by the auditor to carry out the audit. 7. EXPORT CONTROL

The user shall comply with all applicable export control laws, rules and regulations, as amended from time to time, and shall indemnify and hold OEC e.V. harmless from any liability arising out of use of the Software in violation of these laws, rules or regulations.

8. MISCELLANEOUS

8.1 These Commercial License Terms shall be governed by and construed in accordance with the laws of the Federal Republic of Germany, excluding the provisions of the United Nations Convention on Contracts for the International Sale of Goods dated 11.4.1980 (CISG).

8.2 For all disputes arising out of or in connection with these Commercial License Terms the courts of \[…] shall have exclusive jurisdiction.

8.3 Should any provision of these Commercial License Terms be or become invalid, this shall not affect the validity of the remaining provisions.


# Whitepaper

**ABSTRACT**

Ocean Enterprise is an open-source software framework and governance model designed to create next-generation data spaces and AI ecosystems. It addresses challenges such as data silos, compliance, control, and value creation by enabling organizations to collaborate efficiently and create value from digital resources at scale without surrendering control. The framework utilizes a federated architecture that combines technical data sovereignty, value creation and exchange, transparency, sovereign deployments and Compute-to-Data capabilities that provide pier-to-pier access control to privately held data. This allows data to be used for computation and AI model training without the underlying intellectual property leaving its owner’s control. Governed by the Ocean Enterprise Collective e.V., a non-profit association, it ensures transparent governance and alignment with key European data standards and regulations.

Access the full whitepaper below.

{% file src="/files/aaFl8JHREEgEJHcPACKB" %}


# Privacy Policy

*Last updated on June 5, 2025.*

This privacy policy informs you about how **Ocean Enterprise Collective e.V. (in the following OEC, we, us, our)** processes your personal data. Moreover, this privacy policy informs you about your rights.

#### 1. Contact details of the controller <a href="#id-1-contact-details-of-the-controller" id="id-1-contact-details-of-the-controller"></a>

The controller pursuant to the EU General Data Protection Regulation ("GDPR") for the processing of your personal data is:

**Ocean Enterprise Collective e.V.**\
Carmerstrasse 18\
10623 Berlin\
Germany

E-mail: [**info@oceanenterprise.io**](mailto:info@oceanenterprise.io)

#### 2. What's personal data? <a href="#id-2-whats-personal-data" id="id-2-whats-personal-data"></a>

Personal data is any information that can be directly or indirectly associated with you. OEC processes the following personal data.

* **Log file data including IP addresses:** Logfile data including IP addresses are processed when visiting our website.
* **E-mail:** If you contact OEC via e-mail, we process your e-mail address and any personal data you decide to provide in your message (such as your name).

You can find further information about the processing of your personal data in the chapter "Processing operations according to Article 13 GDPR".

#### 3. Processing operations according to Article 13 GDPR <a href="#id-3-processing-operations-according-to-article-13-gdpr" id="id-3-processing-operations-according-to-article-13-gdpr"></a>

**3.1 Providing our website and creating log files**

We host our website with Webflow (Webflow, Inc. located at 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA). When you visit our website, Webflow collects and uses your IP address and creates logfiles including your IP address.

**Purpose:** Collecting and using your IP address is necessary for providing our website because it is a technical requirement for ensuring communication between your device and our website. Logfiles including your IP address are created for security, fraud-prevention, abuse-prevention, and troubleshooting purposes.

**Legal basis:** The legal basis for this processing is our legitimate interest, pursuant to Art. 6(1)(f) GDPR.

**Legitimate interests:** Our legitimate interest is to provide our website to you and to enable security, a technically error-free presentation, and the optimization of the website.

**Retention period:** Webflow stores your personal data for 15 days.

**3.2 Contact via e-mail**

If you contact us via e-mail, OEC collects, uses, and stores your e-mail address, and any other information you provide us in your message, such as your name. When you send us an e-mail, our (mail) service provider supports us in processing your personal data so we can communicate with you.

**Purpose:** We collect, use and store this personal data to respond to your inquiries.

**Legal basis:** The legal basis for this processing is our legitimate interest, according to Art. 6(1)(f) GDPR.

**Legitimate interests:** Our legitimate interest is to answer your inquiries.

**Retention period:** We store your personal data as long as we need it to process your inquires. We store your personal data beyond this period if we are obliged to do so due to retention obligations under tax and commercial law or in the event of legal disputes. If the latter is the case, your personal data will be erased after the retention period has expired.

#### 4. Cookies <a href="#id-4-cookies" id="id-4-cookies"></a>

Our website uses cookies. You can manage cookies via your browser settings, including disabling or deleting cookies. If you want to change your cookie consent, use the Cookie Settings link in the footer when available.

#### 5. Automated decision making including profiling according to Article 13(2)(f) GDPR <a href="#id-5-automated-decision-making-including-profiling-according-to-article-132f-gdpr" id="id-5-automated-decision-making-including-profiling-according-to-article-132f-gdpr"></a>

Automated decision making including profiling does not take place.

#### 6. External links <a href="#id-6-external-links" id="id-6-external-links"></a>

Our website contains links to websites owned by third parties. These websites are beyond our control and responsibility.

#### 7. Your rights <a href="#id-7-your-rights" id="id-7-your-rights"></a>

**7.1 Right to withdraw consent (Art. 7(3) GDPR)**

You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

**7.2 Right of access (Art. 15 GDPR)**

You have the right to obtain confirmation as to whether OEC processes personal data about you. If we are processing personal data about you, you have the right to access these personal data and to gain the information defined in Art. 15 GDPR.

**7.3 Right to rectification (Art. 16 GDPR)**

You have the right to obtain without undue delay the rectification of inaccurate personal data about you. Additionally, you have the right that incomplete personal data about you are completed.

**7.4 Right to erasure (Art. 17 GDPR)**

You have the right to obtain without undue delay the erasure of personal data about you, where the defined legal grounds in Art. 17 GDPR apply.

**7.5 Right to restriction of processing (Art. 18 GDPR)**

Moreover, you have the right to obtain the restriction of processing your personal data where the defined legal grounds in Art. 18 GDPR apply.

**7.6 Right to data portability (Art. 20 GDPR)**

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. Additionally, you have the right to transmit those data to another controller without hindrance, where the defined legal grounds in Art. 20 GDPR apply. You can make use of your right to data portability by contacting us.

**7.7 Right to object (Art. 21 GDPR)**

On grounds relating to your particular situation, you have the right to object to the processing of your personal data where we based the processing on legitimate interests (Art. 6(1)(f) GDPR). If you object, OEC will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing, overriding your rights, freedoms, and interests, or if the processing is required to establish, exercise, or defend legal claims.

**7.8 Right to lodge a complaint (Art. 77 GDPR)**

You have the right to lodge a complaint with a supervisory authority if you consider the processing of your personal data by OEC to infringe the GDPR. You can lodge a complaint in particular

* in the Member State of your habitual residence,
* in the Member State of your place of work, and
* in the place of the alleged infringement.

#### 8. Questions <a href="#id-8-questions" id="id-8-questions"></a>

If you have any questions about our privacy policy, please send us an e-mail at [**info@oceanenterprise.io**](mailto:info@oceanenterprise.io).

#### 9. Changes to the Privacy Policy <a href="#id-9-changes-to-the-privacy-policy" id="id-9-changes-to-the-privacy-policy"></a>

This privacy policy will be amended from time to time. You can see the date of the last alteration at the top of the privacy policy.


# Imprint

Thanks for your interest in the OEC

**Ocean Enterprise Collective e.V**\
Carmerstrasse 18\
10623 Berlin, Germany

**E-Mail:** <info@oceanenterprise.io>

**Members of the Board:** Mihai Badea, Alexander Eger, Sheridan Johns

**Association register:** Vereinsregister, Amtsgerichts Charlottenburg (Berlin), VR 41774 B

**Accountable pursuant to § 18 MStV:**\
Sheridan Johns\
Carmerstrasse 18\
10623 Berlin, Germany

The European Commission provides a platform for online dispute resolution, which you can find here: <https://ec.europa.eu/consumers/odr/>. We are not obliged or willing to participate in a dispute resolution procedure before a consumer arbitration board.


# User Guides

Guides to use Ocean Enterprise

[Using the OE Marketplace](/user-guides/using-the-oe-marketplace)&#x20;


# Using the OE Marketplace


# Onboarding to the Marketplace

This page will guide you through the process of onboarding to a Ocean Enterprise marketplace.

To interact with the marketplace, a user needs to set up their connection to the market, their profile, and provision funds required to purchase assets, run C2D jobs, and perform transactions.&#x20;

The following activities need to be performed to onboard in the market:

[Install MetaMask in the browser](/user-guides/using-the-oe-marketplace/onboarding-to-the-marketplace/install-and-configure-metamask-in-the-browser)

[Set up Metamask](/user-guides/using-the-oe-marketplace/publishing-an-asset/asset-metadata)

[Adding funds to the wallet](/user-guides/using-the-oe-marketplace/onboarding-to-the-marketplace/adding-funds-to-the-wallet)


# Install and configure Metamask in the browser

## Prerequisites

* Supported Browser: Google Chrome, Mozilla Firefox, Brave, Microsoft Edge, Opera
* Pen and Paper: Required for the physical backup of your Secret Recovery Phrase (SRP). Do not skip this.

## Step 1: Installation

Go to [Metamask.io](https://metamask.io/) web page, press "Get Metamask", and follow the instructions on screen.

1\. Open your browser and go to [https://metamask.io](https://metamask.io/).

Verification: Ensure the lock icon appears in the address bar.

2\. Select Your Platform Click the "Get Metamask" button. The site should automatically detect your browser.

Select "Install MetaMask for \[Your Browser]".

3\.  You will be redirected to your browser’s official web store (e.g., Chrome Web Store, Firefox Add-ons).

Click Add to Chrome (or Firefox/Brave/Edge).

Review the permissions prompt and click Add Extension.

**Result**: Upon completion, the MetaMask "fox" icon will appear in your browser toolbar, and a "Let's get started" tab will open automatically.

Tip: If the icon disappears, click the "Puzzle" piece icon (Extensions) in your browser toolbar and click the Pin icon next to MetaMask to keep it visible.

## Step 2: Wallet initialization

1\. Begin Setup: On the Welcome screen, click Create a new wallet.

<mark style="color:$info;">**Note**</mark><mark style="color:$info;">: "Import an existing wallet" is only used if you already have a Secret Recovery Phrase from a previous installation.</mark>

2\. Choose an option to log in to Metamask: using a Google account, an Apple account, or a Secret Recovery Phrase

3\. If you chose to use a secret recovery phrase in the previous step, you will be asked to create a strong password (minimum 8 characters). Click the checkbox next to "If I lose this password, MetaMask can’t reset it", then press "Create passwordd"

<mark style="color:$info;">**Note**</mark><mark style="color:$info;">: This password encrypts your private keys locally on your device. It is not your master key; it only unlocks the extension on this specific computer.</mark>

## Step 3: Securing your assets

This is the most important step in the process. You will be assigned a Secret Recovery Phrase (SRP)—a sequence of 12 random words.

<mark style="color:$info;">**The Golden Rule**</mark><mark style="color:$info;">: If you lose this phrase, you lose your funds forever. If someone else gets this phrase, they can steal your funds.</mark>

1\. Reveal the Phrase: Click the lock icon/blurred area to reveal your 12 words.

2\. Physical Backup (Required): Write down the words in the exact order on a piece of paper.

* DO NOT take a screenshot.
* DO NOT copy/paste them into a cloud document (Google Docs, Notes, etc.).
* DO NOT email them to yourself.

3\. Verify the Phrase: Click Continue. MetaMask will ask you to confirm your backup by selecting the words in the correct order or filling in missing words.

4\. Finalize: Once verified, click Continue -> Got it. The message "Your wallet is ready!" is displayed. Press "Done" to finish the setup.

## Step 4: Post-installation Checks

Network Status: By default, MetaMask connects to a list of production blockchains - both EVM and non-EVM-compatible. You can see this in the top-left corner of the wallet interface.

Account Address: By default, an account (Account 1) is created when you install Metamask. Your public wallet address (starts with 0x...) is located at the top center, under Account 1. Click on "network addresses" to display the networks, then click the copy button next to the network you want to copy to your clipboard. This is the address you share to receive funds.


# Adding funds to the wallet

To cover transaction fees on an OE-enabled dataspace, the users must have sufficient funds in the native currency of the blockchain network, for example, ETH for a dataspace deployed on the Ethereum network.&#x20;

Furthermore, to purchase published assets or run Compute-To-Data jobs, the users must have sufficient funds of the currency in which the asset is listed (i.e., USDC, EURC). &#x20;

<mark style="background-color:$info;">**Note**</mark><mark style="background-color:$info;">: The currencies supported by Ocean Enterprise are listed</mark> [<mark style="background-color:$info;">here</mark>](/developers/networks)<mark style="background-color:$info;">.</mark>

## Adding funds for production environments

To add funds for use on the production network (mainnet), users must first acquire the necessary currency from a supported exchange. Once purchased, initiate a withdrawal from the exchange to your Metamask wallet address.

<mark style="background-color:$info;">**Note**</mark><mark style="background-color:$info;">: The currencies on production environments have financial value.</mark>

## Adding funds for testnet environments

For testnet environments, you can use a "faucet" to claim free test tokens.

* Test USDC & EURC: Claim these from the official Circle faucet: [`https://faucet.circle.com/`](https://faucet.circle.com/)
* EURAU: Please note that a faucet for EURAU is not currently available.

<mark style="background-color:$info;">**Note**</mark><mark style="background-color:$info;">: The currencies on test environments have no financial value</mark>


# Setting up the SSI wallet

Add DIDs and Verifiable Credentials to the SSI wallet to publish and consume assets in an SSI-enabled OE marketplace

In an SSI-enabled marketplace, publishers require a Decentralized ID (DID) to sign the asset's DDO, thereby proving its provenance. Furthermore, consumers must present Verifiable Credentials to access assets. DIDs and VCs must be added to the SSI wallet for the OE marketplace to access them.

Depending on their setup and security requirements, participants in a dataspace can use either the default SSI wallet instance provided by the dataspace or their own instance.

Setting up the SSI wallet means:

1. adding DIDs to the wallet, and
2. adding Verifiable Credentials to the wallet

## Concepts

**Self-Sovereign Identity (SSI)** is a digital framework that gives individuals and organizations full ownership and control over their data by allowing them to store and share verified credentials (VC) directly, without relying on a third party. SSI reduces operational risk and costs by eliminating the need to store sensitive data in vulnerable central databases, while simultaneously streamlining onboarding through instantly verifiable, high-trust digital credentials.

**Verifiable Credential (VC)** is the digital equivalent of physical documents - like a diploma or passport - that are cryptographically signed by an issuer so they can be instantly verified as authentic without the verifier needing to contact the original source.

A **Decentralized Identifier (DID)** is a small, secure file - usually stored on a decentralized ledger - that contains your public keys and service endpoints, allowing others to verify your digital signatures and communicate with you directly.

## Preconditions

* The user must have a minimum understanding of SSI concepts, such as cryptographic key, DID, DID method, and Verifiable Credential
* The SSI wallet instance has been installed and configured, as described in [this chapter](/infrastructure/ssi-stack-installation-and-configuration).
* The user has logged in to Metamask.

## Steps

To set up the SSI wallet, perform the following steps:

1\. Connect to the SSI wallet's user interface by accessing the SSI wallet instance URL.

2\. The login screen of the SSI wallet is displayed.

<figure><img src="/files/YYe7zpZvWmrWrICeSf1f" alt=""><figcaption></figcaption></figure>

3\. Click the "**Connect with web3**" button. A MetaMask notification message for a signature request appears on the screen.&#x20;

<figure><img src="/files/Qo1Y7DZgUUSFrWH8LYCw" alt=""><figcaption></figcaption></figure>

&#x20;

4\. Click "**Confirm**". The Select wallet screen is displayed. Press "**View wallet**".

<figure><img src="/files/9JDnCaTYnxz2bjqCX8Qw" alt=""><figcaption></figcaption></figure>

5\. The main menu of the SSI wallet is displayed.&#x20;

<figure><img src="/files/4FE9lDBr7anesz5rwnWL" alt=""><figcaption></figcaption></figure>

From the SSI wallet's user interface, users can manage the cryptographic keys, DIDs, and Verifiable Credentials associated with their account.

<mark style="background-color:$info;">**Note**</mark><mark style="background-color:$info;">: First time the user connects to the SSI wallet instance, a DID named "Onboarding", of type JWK, and a corresponding key are created by default. You can choose to delete or keep them.</mark>

&#x20;

6\. **Adding DIDs to the SSI wallet**

There are two methods to add a DID to the SSI wallet: create a new DID or import an existing DID

* **Create a new DID**

  * From the left side menu, click "**DIDs**"

    <figure><img src="/files/oKCfN9hoVvRwcLBDxteR" alt=""><figcaption></figcaption></figure>

  * The DIDs menu is displayed. Click "**New**".

    <figure><img src="/files/dIwKIYRiuAoLxOcGYH6i" alt=""><figcaption></figcaption></figure>

  * The DID types menu is displayed. From here, the user can choose the type of DID they want to create. did:key and did:jwk are primarily used in testing scenarios, while did:web is used for production cases. The following steps show how to create a did:web. Click "**Create did:web**"

  * The **Create WEB DID (did:web)** screen is displayed.

    * **Key id field**: enter the name of an existing key to be assigned to the DID, or leave it blank so a new key will be generated and attached to the DID.&#x20;

    * **Alias:** enter an alias for the DID.

    * **Domain**: if you want the DID to be resolved (retrieved by a DID resolver using the did:web method), enter the domain where the DID is located (e.g. *example.com*). Please note that the SSI wallet instance comes with a web registry where DIDs of type did:web can be hosted. If you want to use the web registry provided by the SSI wallet instance, enter the hostname of the wallet instance in this field.

    * **Path**: Multiple DIDs can be hosted under one domain by using paths. Enter the path where the DID is located. If you use the web registry provided by the SSI wallet instance, enter `/wallet-api/registry/<folder_name>` in this field.

      <figure><img src="/files/vptEz7SMrE5O6b2pOhdj" alt=""><figcaption></figcaption></figure>

    * Click "**Create did:web**". An information message is displayed indicating that the DID has been created.&#x20;

      <figure><img src="/files/gNIo1oBUOnD70Fik7mHg" alt=""><figcaption></figcaption></figure>

    * To test that the DID can be resolved, go to <https://dev.uniresolver.io/>, enter the DID in the did-url field, and click **Resolve**. The DID document should be retrieved and displayed.

      <figure><img src="/files/TehZcJvzjk4c3DoLnHPZ" alt=""><figcaption></figcaption></figure>

* **Import an existing DID**

  * From the left side menu, click "**DIDs**"

    <figure><img src="/files/oKCfN9hoVvRwcLBDxteR" alt=""><figcaption></figcaption></figure>

  * The DIDs menu is displayed. Click "**Import**".

    <figure><img src="/files/ixKCi7aX9UEd8Dr81tOv" alt=""><figcaption></figcaption></figure>

  * The "**Import your DIDs**" screen is displayed.

    * **DID**: enter the DID that is imported

    * **Associated key (PEM or JSON)**: enter the private key of the DID in either PEM of JSON format

    * **Alias**: provide an alias for the imported DID

      <figure><img src="/files/gyCsGScROaxIGSPdYc5b" alt=""><figcaption></figcaption></figure>

    * Click **Import DID.** An information message is displayed indicating that the DID has been imported.

      <figure><img src="/files/T6mOSzKwz6msU9cgVIN6" alt=""><figcaption></figcaption></figure>

7\. **Adding Verifiable Credentials to the SSI wallet**

There are two ways to add Verifiable Credentials to the SSI wallet: import existing credentials (in JWT format) or receive credentials during the credential-issuing process based on the OID4VCI (OpenID for Verifiable Credential Issuance) protocol.

* **Import existing Verifiable Credentials in JWT format**

  * From the main menu, click "**Credentials**".

    <figure><img src="/files/9hQ9YGMcs4xr5KtRI83M" alt=""><figcaption></figcaption></figure>

  * The Credentials page is displayed. Click "**Import credential (JWT)**."

    <figure><img src="/files/D54CSgRlq4icrSCBzbfh" alt=""><figcaption></figcaption></figure>

  * The Import Credential (JWT) page is displayed.

    * **Signed VC JWT**: paste the signed VC.

    * **Associated DID**: select the DID associated with the imported VC.

      <figure><img src="/files/yb5PicsOO4EdON645TVa" alt=""><figcaption></figcaption></figure>

    * Click "**Import credential**". An information message is displayed indicating that the VC has been imported.

    &#x20;

    * You can then find the imported VC in the Credentials page.

      <figure><img src="/files/6lKwJg9Q3atGU9fw8v2k" alt=""><figcaption></figcaption></figure>

  * **Receive credentials during the credential-issuing process**

    * In the credential issuance process based on the OID4VCI protocol, a credential issuer component receives a credential issuance request that includes the raw credential data (the information to be issued as a VC) and the data that identifies the VC's issuer (the issuer's DID and private key). Then, the credential issuer component generates an OID4VC offer URL that any OID-compliant wallet can accept to receive credential(s). More details on the credential issuance process based on the walt.id SSI stack can be found [here](https://docs.walt.id/community-stack/issuer/api/credential-issuance/vc-oid4vc).

    * To receive a credential through an OID4VC offer URL, from the "Credentials" screen click "**Scan to receive or present credentials**".

      <figure><img src="/files/aKlOoJ5ZPZhp3AG5XMN6" alt=""><figcaption></figcaption></figure>

    * The screen to receive credentials is displayed. Enter the OID4VC offer URL in the input field and click "**Receive credential**".

      <figure><img src="/files/9I40Tx0r9pKdYouZjMjh" alt=""><figcaption></figcaption></figure>

    * The Receive single credential screen is displayed, indicating the credential issuer component from which the credential will be received and the credential type.
      * **Select DID**: from this dropdown list, select the DID associated with the received VC.

        <figure><img src="/files/Y3oNkmA55XoCNSE3TunV" alt=""><figcaption></figcaption></figure>

    * Press "**Accept**". The VC will be added to the wallet and displayed on the Credentials screen.

      <figure><img src="/files/7ld0k8zecoXzO9UW3yAc" alt=""><figcaption></figcaption></figure>


# Logging in to the Marketplace

This page will guide you through the process of logging in to the OE marketplace, to publish or access assets.

To publish or consume assets, a user must first log in to the marketplace. Logging in requires establishing a connection to the marketplace server using both the MetaMask web3 wallet and the SSI wallet.

## &#x20;Precondition

The user has gone through the onboarding process, at the end of which they have the following:

* The Metamask web3 wallet is configured with a valid web3 address.
* The SSI wallet account is set up and populated with DIDs and Verifiable Credentials.
* Optional: The user has enough native tokens in their wallet to pay the gas for blockchain transactions.
* Optional: The user has added funds to their web3 address for the token(s) used in the marketplace to purchase assets.&#x20;

## Steps

To log in to the marketplace, perform the following steps:

1\. On the main page, press the Connect Wallet button.

<figure><img src="/files/J4Me3eruZ28icYjnjZ9H" alt=""><figcaption></figcaption></figure>

2\. The Connect Wallet window is displayed. Click on MetaMask.

<figure><img src="/files/TaOwqy7jSQaRtCA6fpHa" alt=""><figcaption></figcaption></figure>

3\. The MetaMask login screen is displayed. Enter your password and press Enter.

<figure><img src="/files/qOKuUPaSCG2SINH7XW6x" alt=""><figcaption></figcaption></figure>

4\. The signature request window is displayed. Press confirm.

<figure><img src="/files/gru4Q73OgVkPGXUEtx0M" alt=""><figcaption></figcaption></figure>

5\. The first time the user connects to the marketplace, the SSI Wallet API screen is displayed and prefilled with the URL of the default SSI wallet, provided by the marketplace. Enter the URL to your SSI wallet and press the "Set SSI Wallet API & Connect SSI".&#x20;

<figure><img src="/files/Koc8PII7OlFXeZNdMgh1" alt=""><figcaption></figcaption></figure>

**Note:** the SSI Wallet URL is cached in the browser, so future logins to the marketplace won't require entering the SSI Wallet URL. If the user wants to update the SSI Wallet URL,  it can be done from Settings -> Update SSI Walet API, as shown below.

<figure><img src="/files/bC6VS7eM4srQqZGT2cSK" alt=""><figcaption></figcaption></figure>

6\. The signature request window is displayed. Press confirm.

<figure><img src="/files/cYdBxBwSsiW6lWR6UdtN" alt=""><figcaption></figcaption></figure>

7\. The user is now connected to the Marketplace with both the web3 and SSI wallet.

<figure><img src="/files/Dz2sI9JtMNvlxgt9wzrN" alt=""><figcaption></figcaption></figure>

8\. From the main menu of the marketplace, the user can do the following:&#x20;

* [Publish an asset](/user-guides/using-the-oe-marketplace/publishing-an-asset)
* access the assets catalogue, from where services can be [accessed](/user-guides/using-the-oe-marketplace/consuming-an-assets-service), and C2D jobs can be initiated
* access the user profile, where information related to the user's activity is logged


# Publishing an asset

This chapter describes the process of publishing an asset in Ocean Enterprise.

## Introduction

Publishing an asset involves recording its description on-chain and generating the associated smart contracts. Once this information is stored, the asset description is indexed and cached within the OE node’s indexer database, enabling users to easily discover, access, and utilize the asset.

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: In OE, an asset can have multiple services associated, as outlined</mark> <mark style="color:red;background-color:$info;">here</mark><mark style="color:$info;background-color:$info;">. During the publishing process, the asset’s initial service is automatically created. To add additional services, simply edit the asset after publication.</mark>

### What happens when an asset is published

When an asset is published, the following actions occur:

1. The asset smart contracts (data NFT, data token)  are created on-chain. The price is saved in the Fixed Rate Exchange contract.
2. The location of the service files of the asset  is encrypted
3. Asset's DDO is created in the form of a Verifiable Credential, in JWT format, encrypted, and saved in IPFS
4. The state of the asset and of the first service of the asset are set to "Active", meaning they are consumable
5. The Content ID of the file is saved on-chain

## Precondition

The user has logged in to the marketplace.

## Steps

1\. Press the Publish button from the main page.  The Asset Publishing flow has started.

<figure><img src="/files/j5omjZDM4wB6sB6qV9mo" alt=""><figcaption></figcaption></figure>


# Asset Metadata

This page describes the Asset Metadata screen in the asset publishing flow.

2\. The first step in this process - Asset Metadata - is displayed on the screen.

<figure><img src="/files/neFVCTxFTrrTpbbBuJPO" alt=""><figcaption></figcaption></figure>

3\. Fill in the following fields

* **Title:** input a suggestive name for the Asset you are publishing

<figure><img src="/files/P2iXxbZhvTEQZwNNvwUH" alt=""><figcaption></figcaption></figure>

* **Description:** create a detailed description of the Asset. You can use free text, but also Markdown

<figure><img src="/files/UFbrc3y2RWVdWquccU3Y" alt=""><figcaption></figcaption></figure>

* **Tags:** add suggestive tags for your asset.  The tags help users filter the assets. You can add as many tags as you wish.

<figure><img src="/files/5X2N3qY3Er9sKA3a9cqS" alt=""><figcaption></figcaption></figure>

* **Author:** Enter the name of the author of the asset. It could be your name/company name or an alias.

<figure><img src="/files/ey2hmwy9jReu3LhxysGu" alt=""><figcaption></figcaption></figure>

* **Asset type:** Select if the asset is a Dataset or an Algorithm. To understand the difference between those two types, please consult <mark style="color:red;">this page</mark>.&#x20;

<figure><img src="/files/4PGJd7V04gqtXGgHnPAU" alt=""><figcaption></figcaption></figure>

* If the selected asset type is **Algorithm**, the additional fields must be completed.
  * **Docker image**: select the Docker image to be used for running the algorithm. It can be one of the following:
    * *node:latest*
    * *python:latest*
    * *Custom.* If you selected this option, the following fields are required:
      * *Custom Docker Image*: specify the name and the tag of a public Docker hub image or the custom image if you have it hosted in a 3rd party repository
      * *Docker Image Checksum*: enter the checksum (DIGEST) of your Docker image.
      * *Docker Image Entrypoint*: define the command to be executed to run the algorithm.
  * **Custom Parameters**: If the algorithm has custom parameters, select the checkbox "This asset uses algorithm custom parameters". Then, for each custom parameter, enter the Parameter Name and Parameter Label. &#x20;

<figure><img src="/files/keEjZTvN4Ux0iU20EpHi" alt=""><figcaption></figcaption></figure>

* If the selected asset type is **Dataset**, the checkbox labeled "**Consent of data subjects**" will appear. To proceed, you must check this box to confirm that you have obtained the necessary consent from the data subjects or holders to publish the asset.
* &#x20;**License Type:** Each asset is accompanied by a license that outlines the terms and conditions for its use. All participants intending to consume the asset must adhere to the specified license requirements. Please choose one of the following options to attach the license file to the asset:
  * *Upload a license file*: the file will be saved in IPFS, and the link to it will be saved in the asset's description
  * URL: provide the URL where the file is located and press "Validate". After the file location is validated, it is saved in the asset's description.
* **Terms and Conditions:** All participants within the dataspace are required to comply with its Terms and Conditions. You can review these by clicking the "Terms and Conditions" link. To proceed with the publishing workflow, please confirm your agreement by checking the box labeled "I agree to the Terms and Conditions."&#x20;

4\. Press Continue.


# Asset Level Credentials

5\. The Asset Level Credentials screen is displayed. This screen allows you to define the access rules at the asset level. For a better understanding of how access credentials work, please check this <mark style="color:red;">link</mark>.

6\. The **Access Rules** group is displayed. Using the fields in this group, you can decide who is allowed or denied access to the asset. The rules are based on web3 addresses.

7\. The "**Allow ETH Address"** option enables the user to define  who can access the asset:&#x20;

* To grant access to everybody, select "*Allow all addresses*"

<figure><img src="/files/DLgzM08EOMbPHI9wkTjy" alt=""><figcaption></figcaption></figure>

* To restrict access to specific users, select "*Allow specific addresses*".&#x20;
  * A text field is displayed. Enter the web3 address and press *Add new address*. You can add multiple addresses.&#x20;

<figure><img src="/files/eCrNoWiObJ3KFQnypTCG" alt=""><figcaption></figcaption></figure>

8\. The "**Deny ETH Address"** option enables the user to define  who is denied access to the asset:&#x20;

* To deny access to everybody, select "*Deny all addresses*"

<figure><img src="/files/mhZS1YWN0mg6J8U8oGB5" alt=""><figcaption></figcaption></figure>

* To deny access to specific addresses, select *"Deny specific addresses"*.
  * A text field is displayed. Enter the web3 address and press *Add new address*. You can add multiple addresses.

<figure><img src="/files/lFvvemh1OoIcW7p9kCuf" alt=""><figcaption></figcaption></figure>

**Note:** <mark style="color:$info;background-color:$info;">Selecting both "Allow all addresses" and "Deny all addresses" simultaneously will result in access being denied to all users, as the deny list takes precedence.</mark>

9\. To enable access rules based on SSI credentials, select the "Enable SSI Policies" checkbox. The SSI Policies group is displayed.

<figure><img src="/files/zTtT7Oqj61Rb08VQVxyL" alt=""><figcaption></figcaption></figure>

Using this user interface, the publisher can define access rules at the asset level based on the Verifiable Credentials (VCs) owned by the consumer in their SSI wallet. The VC-based access rules are referred to as SSI policies or simply policies. Three types of SSI policies can be defined:

* **Policies applied to all requested VCs (static policies)**: their scope includes all requested VCs. The following static policies can be applied:

  * *signature*: verifies the signature of the VC
  * *not-before*: verifies the credential is not used before its validity time
  * *revoked-status-list*: verifies that the credential was not&#x20;
  * *expired*: Verifies that the credential has not expired
  * signature\_sd-jwt-vc: verifies the signature for the selective disclosure JWT (SD-JWT) type of VCs.

  <mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: by default, certain policies are enforced by the marketplace and are  preselected. Additionally, the component that evaluates the submitted VCs applies a set of predefined policies automatically. Therefore, even if you manually deselect a default policy, it may still be enforced due to underlying system rules.</mark>
* **Policies applied to a specific VC**: applicable only to the VC for which they were defined. The following policies can be applied to the VC level:
  * *Static policies* (see the list above)
  * &#x20;*Allowed issuer:* verifies that the VC was issued by a list of specific entities defined by their DIDs. If the VC was not issued by any of the DIDs in the list, the policy fails
  * *Custom policy:*  verification rules based on the fields within the requested VCs. For instance, the publisher can enforce a rule that only legal entities from Germany can access the asset. This policy verifies that the `credentialSubject.gx:headquartersAddress.gx:countryCode` equals `"DE"`.
  * *Custom URL policy*: A custom policy authored in the REGO language and hosted at a designated URL. This approach enables advanced verification scenarios by allowing tailored logic based on the specific fields within the requested Verifiable Credentials (VCs).
* **Advanced policies:** applicable to all VCs. The following advanced policies can be applied:

  * *Credential presenter same as credential owner:* verifies that the entity that issues the verifiable presentation (VP) that embeds the VC is the same as the subject of the VC. In case the entity that submits the VP for verification is not the subject of the VC, the policy fails.&#x20;
  * *All requested credential types are necessary for verification:* verifies that all requested VCs are submitted for verification. If this policy is not enabled and the access rules to the asset request, for instance, two VCs - LegalPerson and LegalRegistrationNumber - a consumer who submits just one of the of these credentials passes the verification. With the policy enabled, passing just one of the credentials will result in failure. &#x20;
  * *Minimum number of credentials required*: Set the minimum number of credentials that must be presented for successful verification. Presenting less VCs than the minimum number of credentials will result in failure.&#x20;
  * *Maximum number of credentials required*: Set the maximum number of credentials that must be presented for successful verification.

  <mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: some of the advanced policies are enforced by default by the marketplace and are checked in the user interface.</mark>

10\. **Policies applied to all credentials:** To add a new policy applied to all credentials, mark the corresponding checkbox.

<figure><img src="/files/EpHlMhvDtMRmH1y4dC3c" alt=""><figcaption></figcaption></figure>

11\. **Policies applied to a specific VC**: To define policies applicable to a particular VC, perform the following steps:&#x20;

* Click the **New Credential Request** button. The **Credential Request #1** group is displayed.

<figure><img src="/files/dozXPWD0M67sfFPdNR4D" alt=""><figcaption></figcaption></figure>

* From the **Type** list, select the VC you want to be requested. The list of supported VCs will be periodically updated. Please consult <mark style="color:red;">here</mark> the list of supported VCs.  \
  From the **Format** list, select the format in which the VC should be presented: `jwt_vc_json`, `mso_mdoc` or `vc+sd_jwt`.&#x20;

<figure><img src="/files/AAiaK1o6JDPlBudOvKIq" alt=""><figcaption></figcaption></figure>

* To apply a static policy to the requested VC, perform the following:

  * click on **Add policy** button and from the list select **Static Policy**.

    <figure><img src="/files/KLO7GMR86e2kM38Zk8zK" alt=""><figcaption></figcaption></figure>

  * The **Static Policy** list is displayed. Select a static policy from the list.

    <figure><img src="/files/dcXrnuGvnOa9wotsK583" alt=""><figcaption></figcaption></figure>

* To apply the Allowed issuer policy to the requested VC, perform the following:

  * click on **Add policy** button and from the list select **Allowed Issuer**.

    <figure><img src="/files/eURsx4NmUXGRw5PoyyVH" alt=""><figcaption></figcaption></figure>

  * The allowed-issuer policy is diplayed. Press the **New Issuer DID** button and in the **Issuer DID** field enter the DID of the issuer. You can add multiple entries by pressing the **New Issuer DID** button.

    <figure><img src="/files/ui2QjWvAN426o6tIxe0u" alt=""><figcaption></figcaption></figure>

* To apply a custom policy to the requested VC, perform the following:

  * click on **Add policy** button and from the list select **Custom Policy**.

    <figure><img src="/files/kHZiiMIL3ZwoJw6zed6i" alt=""><figcaption></figcaption></figure>

  * The **Name** field is displayed. Enter a meaningful name for the custom policy, using letters and numbers. \
    For consistency and readability, it's recommended to use camelCase notation when naming your policy.

    <figure><img src="/files/ta0CrRJlsFbHdG8Sgctd" alt=""><figcaption></figcaption></figure>

  * To create a new rule, click the **New rule** button. From the **Credential field** list, choose a field from the selected VC that you want to evaluate. \
    Next, select the appropriate operator from the **Operator** list.    \
    Finally, enter the desired value in the **Value** field.. Please note that for strings, the comparison is case-insensitive (e.g. "DE", "de" and "De" have the same value).\
    You can add multiple rules in the same custom policy.

    <figure><img src="/files/34qoqP56TwxRPzHCkNPB" alt=""><figcaption></figcaption></figure>

* To apply a custom policy available at a URL, perform the following:

  * click on **Add policy** button and from the list select **Custom URL Policy**.<br>

    <figure><img src="/files/rN3bIRI7ImIowR6lEzwk" alt=""><figcaption></figcaption></figure>

  * The UI group for Custom URL policies is displayed. When using custom URL policies, ensure you follow these <mark style="color:red;">guidelines</mark>; otherwise, they will not work.

    <figure><img src="/files/lI1p1bXZyUUHMFBQYbmz" alt=""><figcaption></figcaption></figure>

  * Enter the policy name in the **Custom URL Policy Name** text field

  * Enter the URL where the policy is located in the **Policy URL** text field

  * If the custom policy needs arguments to run, to add them, click on the **New argument** button

  * Add the parameter name in the **Parameter Name** field and its value in the **Value** field. You can add multiple parameters.

    <figure><img src="/files/NftVeZR6pdBv7EpAkhIb" alt=""><figcaption></figcaption></figure>

12\. **Advanced Policies.** To set up advanced features related to how the verification of the presented VC is done, perform the following steps:

* Select the **Edit Advanced Policy Features** checkbox. The **Advanced SSI Policy Features** group is displayed.

  <figure><img src="/files/E3MzAKCx4yoxX4woNYCK" alt=""><figcaption></figcaption></figure>
* Some advanced features are selected by default when the group is displayed.
* Please select the policies relevant to your case. For both the minimum and maximum number of credentials required, enter a numerical value as illustrated below.

  <figure><img src="/files/q6S7UAtJcgom0nst38Rp" alt=""><figcaption></figcaption></figure>

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: Ensure you understand the function of the advanced policies and how they impact the verification process of VCs for the respective asset.</mark>

13\. Press the **Continue** button.&#x20;


# Service Metadata and Credentials

14\. The Service Metadata and Credentials screen is displayed. This screen allows you to define the metadata and the access credentials of the first service created, along with the asset. For a better understanding of how access credentials work, please check this <mark style="color:red;">link</mark>.

<figure><img src="/files/34VWqdgoaKyjcb0U2289" alt=""><figcaption></figcaption></figure>

15. **Service Data** group

Fill in the following fields

* **Title:** input a suggestive name for the Service you are publishing
* **Description:** create a detailed description of the Asset. You can use free text, but also Markdown
* **Service language**: select the language of the service
* **Service language direction**: the direction of the text in the selected language. It is automatically set, based on the selected language

<figure><img src="/files/i1fRp2jWWF0ChZnCvDjA" alt=""><figcaption></figcaption></figure>

16\. **Access Type / Algorithm Privacy**

* **Access Type:** In case an asset of type **dataset** is created, the **Access Type** group is displayed. You can choose either *Download* or *Compute*.
  * Choose **Download** if you want the dataset to be downloaded by the consumer when the asset is purchased. This will give the consumer full access to the content downloaded dataset.

    <figure><img src="/files/qDBtL91SkBn9NKlrajKL" alt=""><figcaption></figcaption></figure>
  * Choose **Compute** if you want the asset to be accessible only through a C2D job, meaning that only an algorithm can be run on the dataset, and only the results of the algorithm will be accessible to the consumer.
  * In case you selected **Compute**, the "**Set Allowed Algorithms**" group is displayed on the screen.
  * In this group, you can select which algorithms are allowed to run on the dataset. You can select either specific algorithms or algorithms published by trusted publishers.
    * **Allowed Algorithms**: In this dropdown list, the "*Allow selected algorithms*" is selected and the "Selected Algorithms" list is active. The list will include all the published algorithms to which the dataset publisher has access based on their web3 address.

      * select one or more algorithms in the list that will be allowed to run on the dataset

      <div data-with-frame="true"><figure><img src="/files/aYt4d4N8OInntk8Hn05o" alt=""><figcaption></figcaption></figure></div>

      * if you want to allow all published algorithms to run on the dataset, in the "Allowed Algorithms" dropdown list select "*Allow any published algorithm*". Once you select this option, the "**Selected Algorithms**" and "**Allow Trusted Algorithm Publishers**" list will be disabled.

      <figure><img src="/files/Fbau9NPcDAALRMqygHoC" alt=""><figcaption></figcaption></figure>

      * **Allowed Trusted Algorithm Publishers**: in this dropdown list, the "*Allow specific algorithm publishers*" option is selected and an input field is displayed.

        * To allow the algorithms published by a specific publisher, enter the web3 address of the publisher and click "Add". The address will be added to the list. You can add as many publishers as you need.

        <figure><img src="/files/GHEdjbdwskCiiEyZK01E" alt=""><figcaption></figcaption></figure>

        * To allow algorithms published by all publisher, in the "**Allowed Trusted Algorithm Publishers**", select the option *"Allow all trusted algorithm publishers*". Once you select this option, the "**Selected Algorithms**" and "**Allow Trusted Algorithm Publishers**" list will be disabled.

        <figure><img src="/files/Nf2r9TFCnRWxXUeC1VK1" alt=""><figcaption></figcaption></figure>

        <mark style="background-color:$info;">**Note**</mark><mark style="background-color:$info;">: if you select nothing in the "</mark><mark style="background-color:$info;">**Allowed Algorithms**</mark><mark style="background-color:$info;">" and "</mark><mark style="background-color:$info;">**Allow Trusted Algorithm Publishers**</mark><mark style="background-color:$info;">", no algorithm will have access to run on the dataset.</mark>

* **Algorithm Privacy**: In case an asset of type **algorithm** is created, the **Algorithm Privacy** group is displayed. In this group, the checkbox "**Keep my algorithm private for Compute-to-Data**" is displayed.
  * If you want the algorithm to only be run in C2D jobs, check the checkbox
  * If you want the algorithm to be downloaded by consumers and have access to the code, uncheck the checkbox

<div data-with-frame="true"><figure><img src="/files/AFipfldXVxNekhPSqFNs" alt=""><figcaption></figcaption></figure></div>

**17. Service Configuration Group**

In this group, the dataset location and the node that will encrypt the file location are specified.

* **Dataset location:** based on the content's location, four types of the assets can be registered in Ocean Enterprise: of type URL, IPFS, Arweave or GraphQL&#x20;
  * **URL**: to register a content stored at a URL, select the **URL** tab.&#x20;

    * In the **File** field, add the URL. The URL can point to a file or to an API endpoint
    * From the right side, select the HTTP method: GET or POST
    * If header parameters are required, specify the key and value for each parameter and press "**Add**"&#x20;
    * Press "**Submit URL**" to verify the URL is accessible.

    <figure><img src="/files/3J1KxXmquaJ9chgBf7Ee" alt=""><figcaption></figcaption></figure>
  * **IPFS**: to register content stored in IPFS, select the **IPFS** tab.

    * In the CID field, enter the content identifier of the content you want to register and press **Validate**

    <figure><img src="/files/VQMCVBMJGdFCgvLxSth5" alt=""><figcaption></figcaption></figure>
  * **Arweave**: to register content stored in Arweave, select the Arweave tab
    * In the **Transaction ID** field, enter the transaction ID of the content and press **Validate**

      <figure><img src="/files/mMiSFKGH3S5ZF0Xbv7wH" alt=""><figcaption></figcaption></figure>
  * &#x20;**GraphQL**: to register a GraphQL query, select the **GraphQL** tab
    * In the **URL** field, enter the URL of the GrapghQL server
    * If header parameters are required, specify the key and value for each parameter and press "**Add**"&#x20;
    * In the **Query** field, enter the query to run on the GrapghQL server
    * Press **Submit Query** to verify the URL

      <figure><img src="/files/lxz46WWwwHTTF4Ql9wNR" alt=""><figcaption></figcaption></figure>
* **Provider URL, Sample File, Timeout**
  * **Provider URL**: This field indicates the Ocean Node that will encrypt the URL. By default, this field is prepopulated with the Ocean Node URL used by the marketplace. If you want to use a different node, press Delete, then insert the URL of the desired Ocean Node and press Validate.

    <figure><img src="/files/c0ovLl190ptl6PyS05KP" alt=""><figcaption></figcaption></figure>
* **Sample File** (optional field): Enter the URL where a sample file of the asset is located and press **Validate**.
* **Timeout**: the time the consumer who purchased an asset has access to the asset. In the marketplace, it can be set to: 1 day, 1 week, 1 month, 1 year, or forever. The time counter starts the moment the asset is purchased. Once the time expires, the asset has to be purchased again to access it.

  * Select a value from the dropdown list

**18. Access Rules**

* **Allow Eth Address** and **Deny Eth Address** lists: Use the fields in this group to determine who is allowed or denied access to the service. The rules are based on web3 addresses. These fields work the same way as the ones defined at the asset-level credentials, so please refer to steps 5 - 8 on the[ Asset Level Credentials page](/user-guides/using-the-oe-marketplace/publishing-an-asset/asset-level-credentials).

<mark style="background-color:$info;">**Note:**</mark> <mark style="background-color:$info;"></mark><mark style="background-color:$info;">To assess a user's right to access a service of an asset, the allow and deny lists at the asset and service level are cumulated and evaluated altogether.</mark>&#x20;

**19. SSI Policies:** to enable access rules based on SSI credentials at the service level, select the "Enable SSI Policies" checkbox. The SSI Policies group is displayed. Please refer to step 11 on the[ Asset Level Credentials page](/user-guides/using-the-oe-marketplace/publishing-an-asset/asset-level-credentials) for an understanding of how these fields work.

20\. **Consumer Parameters**

Consumer Parameters are the parameters the asset uses. For a dataset of type URL, the consumer parameters are the query parameters used to call the URL. For an asset of type algorithm, the consumer parameters are the arguments passed to the program.

* To define consumer parameters for an asset, check the **"This asset uses user-defined parameters"** checkbox. The Custom parameters group is displayed

  <figure><img src="/files/q7AEI6BlEPZVCVfQA8SL" alt=""><figcaption></figcaption></figure>
* Four types of parameters can be defined in the interface: text, number, boolean, or select (list of values).
* To define a consumer Parameter, input the following fields:
  * **Parameter Name**: the name of the parameter
  * **Parameter Label**: the label that will be displayed on screen&#x20;
  * **Description**: parameter description
  * **Parameter Type**: one of the four types listed above
  * **Required**: if the field is required or optional
  * **Default value**: the default value of the parameter. It will be used if no value is input by the consumer at the time of consumption&#x20;

    <figure><img src="/files/v13kLz3XYUD4ARJzR98P" alt=""><figcaption></figcaption></figure>

    * For Parameters of type "select", the screen includes additional fields where the list's values are entered.

      <figure><img src="/files/OEwfnPJE9FiZW1Q3AWrp" alt=""><figcaption></figcaption></figure>
  * To add a new consumer parameter, press "**Add parameter**"

21\. Press the **Continue** button.&#x20;


# Service Pricing

22\. The Asset Level Credentials screen is displayed. In this screen, the asset's price is set.

<figure><img src="/files/dvTRBWoLHvumAdDHzFWP" alt=""><figcaption></figcaption></figure>

An asset published on Ocean Enterprise can either be free or paid.&#x20;

* **Publishing a free asset**: Click on the **Free** tab. Check the "I want this asset to be free. I understand network fees are still to be paid" checkbox and press **Continue**.

  <figure><img src="/files/M9JPQoPXIP7hshlNPhMO" alt=""><figcaption></figcaption></figure>

* Publishing a paid asset: Click on the **Fixed** tab.&#x20;

  <figure><img src="/files/jmhwcKS9ueJsGKbBO8AU" alt=""><figcaption></figcaption></figure>

  * In the **Price** field, enter the price for the service.
  * The currency of the price is displayed at the left side of the Price field
  * Press **Continue**


# Additional Asset Description

23\. The **Additional Asset Description** screen is displayed. On this screen, additional descriptions of the asset in other formats can be added. The additional descriptions will be saved in a dedicated field in the asset's DDO and can be retrieved from the cache.

* To include an additional asset description in the DDO, press the **"Create Additional Asset Description"** button.&#x20;

  <figure><img src="/files/6KlfOdFQReLKRWEotIEJ" alt=""><figcaption></figcaption></figure>
* In the **Type** field, enter the type of the additional asset description (e.g. GAIA-X)
* In the **Content** field, insert the asset description
* You can insert as many additional asset descriptions as you need
* Press the **Continue** button


# Preview

24\. The **Preview** screen is displayed. Here you can see how the asset and service will look after they are published.

<figure><img src="/files/VKk6cleFH9nFnmFJXq79" alt=""><figcaption></figcaption></figure>

If everything is fine, proceed to the last step by pressing the **Continue** button.


# Submit

25\. The Submit screen is displayed.&#x20;

* Press the **Submit** button to publish the asset.&#x20;

<figure><img src="/files/hmvbRrV9U4bI8CPEBUmE" alt=""><figcaption></figcaption></figure>

* During the publishing process, the Metamask wallet will display notification messages that require your approval to perform the transaction on the blockchain. Approve all transactions&#x20;

<figure><img src="/files/ey064GAexUhEetxwXEJ0" alt=""><figcaption></figcaption></figure>

* After the asset is published, a confirmation message is displayed on screen.

<figure><img src="/files/W12MsEw7punjAuB05wjW" alt=""><figcaption></figcaption></figure>

* Press the **View Asset** button to show the asset.&#x20;

<figure><img src="/files/mAHWJlbwNFqZGuxa4Sky" alt=""><figcaption></figcaption></figure>

<mark style="background-color:$info;">Please note that from the time an asset is created on the blockchain until it is indexed by the Ocean Node’s indexer, a delay may occur. This delay typically ranges from a few seconds to several minutes, depending on factors such as RPC endpoint performance, the current indexed block, and the machine’s processing capacity running the Ocean Node.</mark>


# Editing an asset

Editing an asset allows the asset's owner to:

* change the asset's attributes
* change the state of an asset (enabled/disabled)
* add, delete, or change the asset's services&#x20;
* change the status of a service (enabled/disabled)

<mark style="background-color:$info;">**Note**</mark><mark style="background-color:$info;">: Once created, an asset cannot be deleted; it can only be deactivated, meaning none of its services can be consumed. Similarly, a service created within an asset cannot be deleted; it can only be deactivated, which means it cannot be consumed. However, other enabled services within the same asset can be consumed.</mark>&#x20;

## Precondition

The user has logged in to the marketplace.

## Steps

1\. Select the asset. If the user is the asset owner, the "Edit Asset" option appears under the services list.

<figure><img src="/files/W4PkKJItc1wnb2lzhFSb" alt=""><figcaption></figcaption></figure>

2\. Click "**Edit Asset**". The Edit screen is displayed with two options to select from:

* [*Edit Asset*](/user-guides/using-the-oe-marketplace/editing-an-asset/update-the-assets-attributes-and-state) (preselected), to update the asset's attributes and state
* [*Edit Services*](/user-guides/using-the-oe-marketplace/editing-an-asset/update-the-assets-services) to update the attributes or the state of an existing service, or to add a new service to the asset

<figure><img src="/files/2piHo1DFnnl4XeRb84aQ" alt=""><figcaption></figcaption></figure>


# Update the asset's attributes and state

To update the asset's attributes, perform the following:

1\. From the Edit page, select the option "**Edit Asset**". You can update the following attributes:

* Title
* Description
* Sample file URL
* Tags
* Author
* Access rules
* State. Select one of the following:&#x20;
  * Active - the asset is consumable
  * EndOfLife - the asset is not consumable
  * Deprecated - the asset is not consumable
  * RevokedByPublisher - the asset is not consumable
  * OrderingIsTemporaryDisabled - the asset is not consumable
  * Unlisted - the asset is not consumable
* License file
* Additional Asset Description

For a description of each of these attributes, please review the [Publishing an asset](/user-guides/using-the-oe-marketplace/publishing-an-asset) page, steps 1 and 2.

<mark style="background-color:$info;">**Note**</mark><mark style="background-color:$info;">: The Asset Type (Dataset or Algorithm) cannot be changed once set.</mark>

2\. After the changes were made, click "**Submit**". A  transaction request notification from Metamask appears on the screen. Press "**Confirm**".

<figure><img src="/files/LAp8mQNtLScWzX6oA6V4" alt=""><figcaption></figcaption></figure>

3\. A confirmation message is displayed on the screen. Click "**Back to Asset**" to return to the asset details screen.

<figure><img src="/files/A32yZmaokxyyNUtwSM9d" alt=""><figcaption></figcaption></figure>

<mark style="background-color:$info;">Please note that from the time an asset is updated on the blockchain until it is indexed by the Ocean Node’s indexer, a delay may occur. This delay typically ranges from a few seconds to several minutes, depending on factors such as RPC endpoint performance, the current indexed block, and the machine’s processing capacity running the Ocean Node.</mark>


# Update the asset's services

To update the asset's services, perform the following:

1\. From the Edit page, select the option "**Edit Service**". The existing services are listed, along with a button to add a new service.

<figure><img src="/files/ihzMoeUwI8bxuxCOkEtJ" alt=""><figcaption></figcaption></figure>

From this screen, you can perform the following:

* [Update an existing service](/user-guides/using-the-oe-marketplace/editing-an-asset/update-the-assets-services/update-an-existing-service)
* [Create a new service](/user-guides/using-the-oe-marketplace/editing-an-asset/update-the-assets-services/create-a-new-service)


# Update an existing service

To update an existing service, perform the following:

1 . Click on the service. The service attributes are displayed.&#x20;

2\. You can change the following attributes:

* Service Name
* Service Description
* Service Language
* Price: <mark style="color:$info;background-color:$info;">Please note that if the service is paid, it cannot be changed to a free service and vice versa.</mark>&#x20;
* Payment Collector Address: By default, the payment collector address is the publisher's address; however, it can be changed to a different address.
* Provider URL: the Ocean Node that will encrypt the asset.&#x20;
* The asset's file: it is protected and not displayed in this field. If you want to change it, first, delete the existing file and then add the new one.
* Timeout
* Service State: select one of the following:&#x20;
  * Active - the service is consumable
  * EndOfLife - the service is not consumable
  * Deprecated - the service is not consumable
  * RevokedByPublisher - the service is not consumable
  * OrderingIsTemporaryDisabled - the service is not consumable
  * Unlisted - the service is not consumable
* Access Rules
* Consumer Parameters

<mark style="color:$info;background-color:$info;">For a description of each of these attributes, please review the</mark> [<mark style="color:$info;background-color:$info;">Publishing an asset</mark>](/user-guides/using-the-oe-marketplace/publishing-an-asset) <mark style="color:$info;background-color:$info;">page, step 3.</mark>&#x20;

3\. After the changes were made, click "**Submit**". A transaction request notification from Metamask appears on the screen. Press "**Confirm**".

<figure><img src="/files/TYrbQ3nsuVqGuXyh08Sr" alt=""><figcaption></figcaption></figure>

4\. A confirmation message is displayed on the screen. Click "**Back to Asset**" to return to the asset details screen.

<figure><img src="/files/7AJxGC8301ihl6fbcFWL" alt=""><figcaption></figcaption></figure>

<mark style="background-color:$info;">Please note that from the time an asset is updated on the blockchain until it is indexed by the Ocean Node’s indexer, a delay may occur. This delay typically ranges from a few seconds to several minutes, depending on factors such as RPC endpoint performance, the current indexed block, and the machine’s processing capacity running the Ocean Node.</mark>


# Create a new service

To create a new service, perform the following:

1\. Click on the "**Add a new service**" button. The "Add a new service" form is displayed.&#x20;

2\. Fill in the following fields:

* Service Name
* Service Description
* Service Language
* Price: <mark style="color:$info;background-color:$info;">If you want the asset to be free, set the price to zero. For a paid asset, set the price to a value other than zero.</mark>
* Payment Collector Address: By default, the payment collector address is the publisher's address; however, it can be changed to a different address.
* Provider URL: the Ocean Node that will encrypt the asset.&#x20;
* The asset's file
* Timeout
* Access Rules
* Consumer Parameters

<mark style="color:$info;background-color:$info;">For a description of each of these attributes, please review step 3 of the</mark> [<mark style="color:$info;background-color:$info;">Publishing an asset</mark>](/user-guides/using-the-oe-marketplace/publishing-an-asset) <mark style="color:$info;background-color:$info;">page.</mark>&#x20;

3\. After the service's attributes are entered, click "**Submit**". A transaction request notification from Metamask appears on the screen. Press "**Confirm**".

<figure><img src="/files/TYrbQ3nsuVqGuXyh08Sr" alt=""><figcaption></figcaption></figure>

4\. A confirmation message is displayed on the screen. Click "**Back to Asset**" to return to the asset details screen.

<figure><img src="/files/7AJxGC8301ihl6fbcFWL" alt=""><figcaption></figcaption></figure>

<mark style="background-color:$info;">Please note that from the time an asset is updated on the blockchain until it is indexed by the Ocean Node’s indexer, a delay may occur. This delay typically ranges from a few seconds to several minutes, depending on factors such as RPC endpoint performance, the current indexed block, and the machine’s processing capacity running the Ocean Node.</mark>


# Consuming an asset's service

Consuming an asset’s service means accessing its URI and retrieving the result on your local machine. Depending on the type of resource available at the URI, this may involve:

* Downloading a file directly to your local system.
* Calling an API endpoint and retrieving the returned results.
* Running a GraphQL query and collecting the query’s output.

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: Only services of type</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">`access`</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">can be consumed as listed above. Services of type</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">`compute`</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">can only be used in a C2D job.</mark>&#x20;

For a consumer to access an asset's service, the following conditions must be met:

* **Access Rights**: the consumer must be authorized to access both the asset and the service. Authorization is evaluated at both levels (asset and service) based on:
  * The consumer’s Web3 address
  * The required verifiable credentials defined in the SSI access policies of the asset and the service
* **Payment**: If the service is paid, the consumer must purchase access by paying:
  * The service’s listed price
  * Any applicable additional fees

## Precondition

* The consumer has logged in to the marketplace

## Steps

1\. Locate the asset in the Catalogue and open it by clicking its tile. The Asset Details screen will appear, showing the available services on the right side. Each service includes information about its access type (access or compute) and price.

<figure><img src="/files/aFWtYh8fzIDoA7DN0ceq" alt=""><figcaption></figcaption></figure>

2\. Select the service you want from the service list by pressing on its tile. The marketplace will then perform an initial access verification based on the consumer's web3 address.&#x20;

<mark style="color:$info;background-color:$info;">**Note:**</mark>&#x20;

* <mark style="color:$info;background-color:$info;">If the consumer’s address passes verification, no message is shown on the screen.</mark>&#x20;
* <mark style="color:$info;background-color:$info;">If the consumer's address fails marketplace verification, an error message is displayed (see image below).</mark>&#x20;

<figure><img src="/files/u3AP1pvWXnZEK9iBelwp" alt=""><figcaption></figcaption></figure>

3\. Press the "**Check Credentials**" button. The next steps vary depending on whether the asset is governed by SSI-based access policies or not.&#x20;

* **The asset does not have SSI-based access policies**
  * The consumer's address is verified by Ocean Node against the access rules defined in the asset's description.&#x20;

    * If verification succeeds:
      * An information message is displayed on-screen,
      * The "Calculate Total Price" button is shown.&#x20;

        <figure><img src="/files/TqMlwH1LGx4T2pocxqGt" alt=""><figcaption></figcaption></figure>

    * If verification fails
      * An error message is displayed on-screen
      * The "Retry" button is shown

        <figure><img src="/files/asCIvq38a6mGoiN5HChf" alt=""><figcaption></figcaption></figure>

* **The asset has SSI-based access policies**
  * In accordance with the SSI policies defined at the asset and service levels, the marketplace receives a request for the consumer to present one or more verifiable credentials from the consumer's SSI wallet.  &#x20;
    * The marketplace retrieves from the consumer's SSI wallet the verifiable credentials that correspond to the SSI policy criteria.&#x20;

      * If no verifiable credentials correspond to the SSI policy criteria, a message stating that no credentials were found is displayed.

        <figure><img src="/files/nAeFvqlWrU7mdrUzxOQF" alt=""><figcaption></figcaption></figure>

      * If one or more verifiable credentials are found, a window with all found verifiable credentials is displayed

        <figure><img src="/files/wFXqOaaPE2YkPK4OgXKn" alt=""><figcaption></figcaption></figure>
    * Select the verifiable credentials to present and press **"Accept**".
    * The DID Selector window is displayed. Select the DID that will be used to sign the verifiable presentation in which the selected verifiable credentials will be sent for verification. Then press "**Confirm**".<br>

      <figure><img src="/files/e21dSRoMdwOV1jeFJnac" alt=""><figcaption></figcaption></figure>
    * The verifiable credentials are submitted for verification against the SSI policy defined in the asset metadata
      * If the verification fails, an error message will be displayed on-screen.
      * If verification succeeds:

        * An information message is displayed on-screen
        * The "**Calculate Total Price**" button is shown.&#x20;

          <figure><img src="/files/b4Y9op8jZbRq5BmrqyoT" alt=""><figcaption></figcaption></figure>

        &#x20;&#x20;

4\. Click "**Calculate Total Price**".

<figure><img src="/files/LSG2OicCUWGX4Ab8j3Jb" alt=""><figcaption></figcaption></figure>

&#x20;&#x20;

5\. The detailed list of costs associated with the purchase of the asset is shown.&#x20;

* Check the "I agree to the Terms and Conditions" checkbox. The Terms and Conditions can be reviewed by clicking on the link.
* Check the "I agree to the License Terms under which this asset was made available". The License Terms of the asset can be reviewed by clicking on the link
* Click "**Buy**"

<figure><img src="/files/NkHO5BHyEjKlPLdC9enZ" alt=""><figcaption></figcaption></figure>

6 . Metamask wallet will display a spending cap request. Click "**Confirm**".

<figure><img src="/files/RZfn8j9vopzVeThmVWnl" alt=""><figcaption></figcaption></figure>

6\. Metamask wallet will display a transaction request. Click "**Confirm**".

<figure><img src="/files/qhK5BYocJASBT8tenSBg" alt=""><figcaption></figcaption></figure>

7. The service is purchased, and the "**Download**" button is displayed.&#x20;

   <figure><img src="/files/tdVmYtWqmQNmkbHTKu69" alt=""><figcaption></figcaption></figure>

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: If a service requires consumer parameters, the corresponding fields for entering values will be displayed (see picture below). The user must enter a value for each mandatory field to enable the "Download" button.</mark>&#x20;

<figure><img src="/files/ZZFc31oGFnfzowHUj5zd" alt=""><figcaption></figcaption></figure>

8\. Click "**Download**". Metamask wallet will display a signature request message.&#x20;

<figure><img src="/files/af2ay9kxz98uqu3jd4aK" alt=""><figcaption></figcaption></figure>

9\. The result of accessing the service's URI is downloaded. &#x20;

<figure><img src="/files/CEnW9Lppy95fHxtAmLuD" alt=""><figcaption></figcaption></figure>


# Running Compute-To-Data Jobs

The Compute-to-Data (C2D) feature in the OE stack enables algorithms to be executed against published datasets without exposing the raw data to end users, preserving privacy and security. &#x20;

<mark style="color:$info;background-color:$info;">**Note:**</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">C2D jobs can use</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">**only**</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">assets of type</mark> <mark style="color:$info;background-color:$info;"></mark>*<mark style="color:$info;background-color:$info;">"compute</mark>*<mark style="color:$info;background-color:$info;">". C2D jobs cannot be run on assets of type "download".</mark>

This chapter includes the following information:

* [Introduction to C2D](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/c2d-concepts), where the main concepts are introduced
* [Step-by-step guide](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/running-and-managing-c2d-jobs) to run and manage C2D jobs and the related information


# C2D Concepts

## How C2D jobs work

To run a C2D job, the user needs to purchase an "*algorithm"* asset and zero or more "*dataset*" assets. The algorithm is the program that will be executed in a container on the Ocean Node server. The datasets are downloaded in the container and accessed by the running algorithm. When the job finishes, the algorithm’s output and log files are saved. The user who started the C2D job can then download them.

<mark style="color:$info;background-color:$info;">**Note:**</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">In contrast to asset downloads, which prevent users from downloading their own assets, publishers are permitted to execute C2D jobs on assets they have published.</mark>

## C2D environment

When starting a C2D job, the user can configure the environment in which the job will run, including the processing and storage resources allocated to it, as well as its maximum duration. The following resources can be configured.&#x20;

* Number of processing cores&#x20;
* RAM
* Disk space
* Maximum job duration

**Note**: <mark style="color:$info;background-color:$info;">Ensure the maximum job duration is sufficient for the job to finish. If the duration expires, the job will be terminated automatically.</mark>

When a C2D job starts, resources are allocated from the resource pool for the duration of its execution. The remaining pool resources remain available for other C2D jobs. Once the job completes, its resources are released back into the pool.

## C2D environment types

Ocean Node provides two C2D environments to run jobs:

* **Free environment:** Best for testing. It has limited compute, storage, and job duration, and is free of charge.
* **Paid environment**: Best for production. It offers more compute, storage, and longer job durations. Used resources are billed; running jobs here generates costs.

Each environment has a pool of processing and storage resources. When a C2D job starts, resources are allocated from the resource pool for the duration of its execution. Unused pool resources remain available for other C2D jobs. When a job completes, its resources are automatically released back into the pool.

<mark style="color:$info;background-color:$info;">**Node**</mark><mark style="color:$info;background-color:$info;">: the Ocean Node operator configures each environment, so resources and job duration limits can differ from one Ocean Node to another.</mark>

## C2D job cost

In a paid environment, running C2D jobs incurs costs. Each resource has a per‑minute price (set by the Ocean Node provider), and the job cost is determined by multiplying the resource prices by the job’s duration in minutes. Let's take the following example:&#x20;

In the paid environment, the unit price of each resource is:

* CPU: 0.2 EUR per 1 core/ 1 minute
* RAM: 0.1 EUR per 1 GB/ 1 minute
* Storage: 0.05 EUR per 1GB/ 1 minute

\
If the C2D job runs in a paid environment with **2 cores, 8 GB of RAM and 16 GB of storage**, for **3 minutes**, the total cost associated with this job is calculated as:

**`C2D env cost/minute`**` ``= (2 cores)*0.2EUR + (8GB RAM)*0.1EUR + (16GB storage)*0.05EUR =`` `**`2 EUR/min`**

**`Job cost = (`**`C2D env cost/minute) * 3minutes`` `**`=`**` ``2 * 3 =`` `**`6 EUR`** &#x20;

So, to run the job in this environment costs 6 EUR.

To start a C2D job in a paid environment, the user needs to allocate in advance the amount that covers running the job in the selected environment for the specified maximum duration.&#x20;

Continuing with our example, if the user wants to run a job for **a maximum duration of 10 minutes** in the environment described above, the allocated amount is calculated as:

**Allocated amount** = **C2D env cost/minute** \* **maximum job duration** = 2 EUR/minutes \* 10 minute = **20 EUR**

## Escrow account

When running a C2D job in a paid environment, the user must deposit the full amount needed for the maximum job duration into an escrow account. This account is set by the Ocean Enterprise Collective and is unique to each blockchain.

The following happens when the C2D job starts in a paid environment:

1. The user deposits the allocated amount into the escrow account.&#x20;
2. The Ocean Node that runs the job locks this amount while the job runs.
3. Once the job finishes, the actual cost is calculated based on the per‑minute environment cost and the job’s duration (rounded up to the nearest minute).&#x20;
4. The Ocean Node deducts the job cost and unlocks the rest.
5. Any leftover funds remain in the escrow account, available for future jobs or withdrawal.


# Running and managing C2D jobs

Ocean Marketplace provides a wizard to make it easier to run C2D jobs and collect results. You can start a C2D job using either a dataset or an algorithm of type *"compute"*.&#x20;

In the Ocean Marketplace, you can:

* [Run a C2D starting from a dataset](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/running-and-managing-c2d-jobs/run-a-c2d-starting-from-a-dataset)
* [Run a C2D job starting from an algorithm](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/running-and-managing-c2d-jobs/run-a-c2d-job-starting-from-an-algorithm)
* [Manage your escrow account](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/running-and-managing-c2d-jobs/manage-the-escrow-account)
* [See all the C2D jobs you've executed](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/running-and-managing-c2d-jobs/c2d-jobs-history)


# Run a C2D starting from a dataset

Use the C2D wizard to run a job by selecting a dataset as the starting point.

## Precondition

* The user is logged in to the marketplace

## Steps

1\. Access the Catalogue. The catalogue lists all registered assets - datasets and algorithms - of any type - download or compute.

<figure><img src="/files/j3KgcHxYrXkAmAxStgNJ" alt=""><figcaption></figcaption></figure>

**Note**: to refine your selection in the catalogue, use the search bar at the top of the list or the filters available on the left side of the catalogue

2\. Select a dataset from the list. The asset details page is displayed.

<figure><img src="/files/FxEI2OgrJvL4Wezir08h" alt=""><figcaption></figcaption></figure>

3\. From the services list, select a service of type *compute*. The "**Start Compute**" button is displayed.&#x20;

<figure><img src="/files/9GCGGIP0l7YTVFxS2zwb" alt=""><figcaption></figcaption></figure>

4\. Click "**Start Compute**". The C2D wizard is started, and Step 1 - Select Algorithm window is shown.

<figure><img src="/files/A1l34VViUurB2eBl8JAf" alt=""><figcaption></figcaption></figure>

5\. A list of allowed algorithms to run over the selected dataset is displayed. Select the algorithm you want to run over the dataset. The algorithm will be added to the top of the list. Press **Continue**.

<figure><img src="/files/4ha7AefahNSBhgJxHBVi" alt=""><figcaption></figcaption></figure>

6\. The "**Select Algorithm Services"** screen is displayed. The list includes selected service. Press **Continue**.&#x20;

<figure><img src="/files/YX3exTYWDO9k2icAvtbi" alt=""><figcaption></figcaption></figure>

7\. The "**Preview Algorithm and Service**" screen is displayed, showing the selection made so far. If you're satisfied with the selected algorithm service, press **Continue**.

<figure><img src="/files/j4NSTtG0Lcrdj6oQeP8e" alt=""><figcaption></figcaption></figure>

8\. If any of the selected services (datasets or algorithms) contain consumer parameters, the **User Parameters** screen will open. It displays all parameters along with their default values. Provide the required inputs and select **Continue**.&#x20;

<figure><img src="/files/yuWt6cmVCcbRNJAG47Yw" alt=""><figcaption></figcaption></figure>

9\. The **"Select C2D Environment"** screen appears. Here you’ll see the Ocean Nodes linked to the dataspace that can run C2D jobs. Each node shows which environments are available—free, paid, or both. Select a node and press **Continue**.

<figure><img src="/files/2ggcOr96p3IY8hxzUf9E" alt=""><figcaption></figcaption></figure>

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: At present, the list displays only the node linked to the dataspace. Future releases of OE will support multiple nodes serving a single dataspace.</mark>

9\. The **C2D Environment Configuration** screen opens. Here you’ll see the available environments for the selected Ocean Node. Each environment lists its resources, and if you choose a paid environment, you’ll also see the per‑minute price for each resource.&#x20;

* Select the environment
* Set the resources your job will use
* Choose the maximum job duration. \ <mark style="color:$info;background-color:$info;">**Note:**</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">For the paid environment, the C2D Environment Price field shows the total cost for the selected duration. You’ll also see a message about your escrow account balance—whether it’s enough to cover the job cost or if you need to deposit more. For more details, check the job cost and escrow account page.</mark>
* When you’re ready, confirm the configuration and click **Continue**.

<figure><img src="/files/1DOwjKdXFUpbD6FEtQnA" alt=""><figcaption></figcaption></figure>

10\. The "**Review**" screen opens.&#x20;

<figure><img src="/files/Sbu6wklBLdaAbJ60o8rS" alt=""><figcaption></figcaption></figure>

This screen is divided into three sections: Assets, C2D Resources, and Fees.

* *Assets*
  * Displays the price of each selected asset (algorithms and datasets).
  * Includes a credential verification button next to each asset

    <figure><img src="/files/QmMIEGAqJ4BrxnTF8Vhy" alt=""><figcaption></figcaption></figure>

* *C2D Resources*&#x20;
  * Shows the calculated cost of the C2D job.
  * Displays the user’s escrow account balance.
  * Indicates the additional amount to deposit if the job cost exceeds the current escrow balance.<br>

    <figure><img src="/files/KxquQktQ9v6AppU5Cl7Z" alt=""><figcaption></figcaption></figure>

* Fees: List applicable fees, organized into the following categories:
  * Marketplace fees (datasets and algorithms)
  * OEC fees (datasets and algorithms)
  * Provider fees (datasets and algorithms)\ <mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: the Provider fee is not displayed initially. It is calculated after the assets' credentials are verified.</mark><br>

    <figure><img src="/files/50xqEhcQVliQieE7Ltxx" alt=""><figcaption></figcaption></figure>

a) In the Assets section, click the "**Check Credential**" button next to one of the assets to initiate the asset credentials verification process. The process will verify the consumer's credentials against the access rules defined for any asset. The verification is performed asset by asset.&#x20;

<figure><img src="/files/moaW4d8rYXr43TofW7av" alt=""><figcaption></figcaption></figure>

b) If the current asset has SSI-based access policies defined, then the marketplace will run a query in the consumer's SSI wallet and list the Verifiable Credentials that match the specified criteria. Select the Verifiable Credentials you want to send for verification and click **Accept**.

<figure><img src="/files/ch9czagfCT4EewoKGPXU" alt=""><figcaption></figcaption></figure>

&#x20;c) The DID selector window is open, containing the list of all DIDs from the SSI wallet. Select the DID you want to use to sign the Verifiable Presentation in which the Verifiable Credentials selected in the previous step will be wrapped before being sent for verification. Then click **Confirm**.

<figure><img src="/files/Jp4DLyR54hrFW7bfkMKP" alt=""><figcaption></figcaption></figure>

d) Credential verification is performed, and each asset is marked with the Verified tag. For assets protected by SSI-based access control, the verification session remains valid only for a limited time. Within this period, the C2D job must be initiated; otherwise, it will fail. A countdown timer is displayed to indicate the remaining validity. If the validity time expires, you will have to reinitiate the credential verification process.

<figure><img src="/files/oQtr3C0MGQaRxrw5GA8m" alt=""><figcaption></figcaption></figure>

**Note 1**: <mark style="color:$info;background-color:$info;">If credential verification fails, the system displays an error message, and the C2D job cannot be executed. To proceed, you must either supply alternative credentials for verification or select different assets.</mark>

e) If the credential verification succeeds, the user has to check the two checkboxes at the bottom of the screen to confirm:&#x20;

* agreement with the marketplace Terms and Conditions, and&#x20;
* agreement with the license terms governing each selected asset.&#x20;

<figure><img src="/files/6qJyS7lZYDBIbT4ir0Sd" alt=""><figcaption></figcaption></figure>

**Note**: <mark style="color:$info;background-color:$info;">To view the license terms for an asset, click the link provided next to it. The link opens the asset details page in a new browser tab</mark>.

<figure><img src="/files/8xLM7hB3enOa18o55ZJm" alt=""><figcaption></figcaption></figure>

f) Click **Calculate Extra Fees**. The provider fees will be retrieved and displayed in the Fees section. &#x20;

<figure><img src="/files/kWV2pxeZYytJlZ00hdS1" alt=""><figcaption></figcaption></figure>

&#x20;

g) Review the total cost associated with running the C2D job and click **Buy Compute Job**.&#x20;

<figure><img src="/files/uL0g2KgfScb7LTTqNLy3" alt=""><figcaption></figcaption></figure>

h) Next, there will be multiple interactions with the Metamask wallet for spending cap approvals and payments, as the user purchases each asset and transfers money into the escrow account.&#x20;

<figure><img src="/files/MDep997W1rATv9Hpgp2h" alt=""><figcaption></figcaption></figure>

i) At the end, a message will notify the user that the C2D job was started. Click **Continue**.

<figure><img src="/files/koyyCBiPFC0V1sIJO18m" alt=""><figcaption></figcaption></figure>

j) The user will be returned to the Service Details screen, and the C2D job will appear in the Your Compute Jobs list. Click **Refresh** to monitor the job's status.

<figure><img src="/files/zcnXQMxb6w89yBRRp2BY" alt=""><figcaption></figcaption></figure>

k) When the job finishes, click **Show Details**.&#x20;

<figure><img src="/files/RtZtF16LdLoBLbq8ADLr" alt=""><figcaption></figcaption></figure>

l) The Job Details page is displayed. It shows the assets used to execute the job, along with information such as the actual job duration and cost. The Results section provides links to the job’s logs and output files. To download a file, click its name in the list.

<figure><img src="/files/rS8TEYoGtg8nWGKMk9oh" alt=""><figcaption></figcaption></figure>


# Run a C2D job starting from an algorithm

## Precondition

* The user is logged in to the marketplace

## Steps

1\. Access the Catalogue. The catalogue lists all registered assets - datasets and algorithms - of any type - download or compute.

<figure><img src="/files/j3KgcHxYrXkAmAxStgNJ" alt=""><figcaption></figcaption></figure>

**Note**: to refine your selection in the catalogue, use the search bar at the top of the list or the filters available on the left side of the catalogue

2\. Select an algorithm from the list. The asset details page is displayed.

<figure><img src="/files/45P7ltY5NlUqlX4HicgV" alt=""><figcaption></figcaption></figure>

3\. From the services list, select a service of type *compute*. The "**Start Compute**" button is displayed.&#x20;

<figure><img src="/files/YilOrTPeeaWvkECS0Xzk" alt=""><figcaption></figcaption></figure>

4\. Click "**Start Compute**". The C2D wizard is started, and Step 1 - Select Datasets window is shown.

<figure><img src="/files/JVZEowyTJiBAL9yivixW" alt=""><figcaption></figcaption></figure>

5\. This screen lists only the datasets that include services on which the selected algorithm can run (see [Service Metadata and Credentials](/user-guides/using-the-oe-marketplace/publishing-an-asset/service-metadata-and-credentials)).

When running a C2D job starting from an algorithm, you can select zero or more datasets on which the algorithm will be executed.&#x20;

a) **Run C2D job without datasets:** If no datasets are needed to run the algorithm, mark the "Proceed without Dataset Selection" checkbox. This will disable the datasets list, remove unnecessary steps from the wizard, and enable the Continue button. Click **Continue**, then move to step 8 of this page.

<figure><img src="/files/cuL6yu2OlgT8GQRVLPO2" alt=""><figcaption></figcaption></figure>

b) **Run C2D job with one or more datasets:** If one or more datasets are needed to run the algorithm, select them from the list by clicking on their tiles. The "Selected" status will be displayed next to the asset's name, and the Continue button will be enabled. Click **Continue**.&#x20;

<figure><img src="/files/M1oIqETPtRleCah7VJiD" alt=""><figcaption></figcaption></figure>

6\. The "**Select Services**" page appears, showing the assets chosen in the previous step along with the services on which the algorithm can run. Select the services you want to run the algorithm on and click **Continue**.&#x20;

<figure><img src="/files/xe0DV05KPS15WpieSVj6" alt=""><figcaption></figcaption></figure>

7\. The "**Preview Selected Datasets and Services**" screen is displayed, showing the selection made so far. If you're satisfied with the selected dataset services, press **Continue**.

<figure><img src="/files/JhpRH8FevIRyS2D4XD36" alt=""><figcaption></figcaption></figure>

8\. If any of the selected services (datasets or algorithms) contain consumer parameters, the **User Parameters** screen will open. It displays all parameters along with their default values. Provide the required inputs and select **Continue**.&#x20;

<figure><img src="/files/n5CO66d8YixMES3RLANU" alt=""><figcaption></figcaption></figure>

9\. The **"Select C2D Environment"** screen appears. Here you’ll see the Ocean Nodes linked to the dataspace that can run C2D jobs. Each node shows which environments are available—free, paid, or both. Select a node and press **Continue**.

<figure><img src="/files/2ggcOr96p3IY8hxzUf9E" alt=""><figcaption></figcaption></figure>

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: At present, the list displays only the node linked to the dataspace. Future releases of OE will support multiple nodes serving a single dataspace.</mark>

9\. The **C2D Environment Configuration** screen opens. Here you’ll see the available environments for the selected Ocean Node. Each environment lists its resources, and if you choose a paid environment, you’ll also see the per‑minute price for each resource.&#x20;

* Select the environment
* Set the resources your job will use
* Choose the maximum job duration. \ <mark style="color:$info;background-color:$info;">**Note:**</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">For the paid environment, the C2D Environment Price field shows the total cost for the selected duration. You’ll also see a message about your escrow account balance—whether it’s enough to cover the job cost or if you need to deposit more. For more details, check the job cost and escrow account page.</mark>
* When you’re ready, confirm the configuration and click **Continue**.

<figure><img src="/files/1DOwjKdXFUpbD6FEtQnA" alt=""><figcaption></figcaption></figure>

10\. The "**Review**" screen opens.&#x20;

<figure><img src="/files/Sbu6wklBLdaAbJ60o8rS" alt=""><figcaption></figcaption></figure>

This screen is divided into three sections: Assets, C2D Resources, and Fees.

* *Assets*
  * Displays the price of each selected asset (algorithms and datasets).
  * Includes a credential verification button next to each asset

    <figure><img src="/files/QmMIEGAqJ4BrxnTF8Vhy" alt=""><figcaption></figcaption></figure>

* *C2D Resources*&#x20;
  * Shows the calculated cost of the C2D job.
  * Displays the user’s escrow account balance.
  * Indicates the additional amount to deposit if the job cost exceeds the current escrow balance.<br>

    <figure><img src="/files/KxquQktQ9v6AppU5Cl7Z" alt=""><figcaption></figcaption></figure>

* Fees: List applicable fees, organized into the following categories:
  * Marketplace fees (datasets and algorithms)
  * OEC fees (datasets and algorithms)
  * Provider fees (datasets and algorithms)\ <mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: the Provider fee is not displayed initially. It is calculated after the assets' credentials are verified.</mark><br>

    <figure><img src="/files/50xqEhcQVliQieE7Ltxx" alt=""><figcaption></figcaption></figure>

a) In the Assets section, click the "**Check Credential**" button next to one of the assets to initiate the asset credentials verification process. The process will verify the consumer's credentials against the access rules defined for any asset. The verification is performed asset by asset.&#x20;

<figure><img src="/files/moaW4d8rYXr43TofW7av" alt=""><figcaption></figcaption></figure>

b) If the current asset has SSI-based access policies defined, then the marketplace will run a query in the consumer's SSI wallet and list the Verifiable Credentials that match the specified criteria. Select the Verifiable Credentials you want to send for verification and click **Accept**.

<figure><img src="/files/ch9czagfCT4EewoKGPXU" alt=""><figcaption></figcaption></figure>

&#x20;

c) The DID selector window is open, containing the list of all DIDs from the SSI wallet. Select the DID you want to use to sign the Verifiable Presentation in which the Verifiable Credentials selected in the previous step will be wrapped before being sent for verification. Then click **Confirm**.

<figure><img src="/files/Jp4DLyR54hrFW7bfkMKP" alt=""><figcaption></figcaption></figure>

d) Credential verification is performed, and each asset is marked with the Verified tag. For assets protected by SSI-based access control, the verification session remains valid only for a limited time. Within this period, the C2D job must be initiated; otherwise, it will fail. A countdown timer is displayed to indicate the remaining validity. If the validity time expires, you will have to reinitiate the credential verification process.

<figure><img src="/files/oQtr3C0MGQaRxrw5GA8m" alt=""><figcaption></figcaption></figure>

**Note 1**: <mark style="color:$info;background-color:$info;">If credential verification fails, the system displays an error message, and the C2D job cannot be executed. To proceed, you must either supply alternative credentials for verification or select different assets.</mark>

e) If the credential verification succeeds, the user has to check the two checkboxes at the bottom of the screen to confirm:&#x20;

* agreement with the marketplace Terms and Conditions, and&#x20;
* agreement with the license terms governing each selected asset.&#x20;

<figure><img src="/files/6qJyS7lZYDBIbT4ir0Sd" alt=""><figcaption></figcaption></figure>

**Note**: <mark style="color:$info;background-color:$info;">To view the license terms for an asset, click the link provided next to it. The link opens the asset details page in a new browser tab</mark>.

<figure><img src="/files/8xLM7hB3enOa18o55ZJm" alt=""><figcaption></figcaption></figure>

f) Click **Calculate Extra Fees**. The provider fees will be retrieved and displayed in the Fees section. &#x20;

<figure><img src="/files/kWV2pxeZYytJlZ00hdS1" alt=""><figcaption></figcaption></figure>

&#x20;

g) Review the total cost associated with running the C2D job and click **Buy Compute Job**.&#x20;

<figure><img src="/files/uL0g2KgfScb7LTTqNLy3" alt=""><figcaption></figcaption></figure>

h) Next, there will be multiple interactions with the Metamask wallet for spending cap approvals and payments, as the user purchases each asset and transfers money into the escrow account.&#x20;

<figure><img src="/files/MDep997W1rATv9Hpgp2h" alt=""><figcaption></figcaption></figure>

i) At the end, a message will notify the user that the C2D job was started. Click **Continue**.

<figure><img src="/files/koyyCBiPFC0V1sIJO18m" alt=""><figcaption></figcaption></figure>

j) The user will be returned to the Service Details screen, and the C2D job will appear in the Your Compute Jobs list. Click **Refresh** to monitor the job's status.

<figure><img src="/files/zcnXQMxb6w89yBRRp2BY" alt=""><figcaption></figcaption></figure>

k) When the job finishes, click **Show Details**.&#x20;

<figure><img src="/files/RtZtF16LdLoBLbq8ADLr" alt=""><figcaption></figcaption></figure>

l) The Job Details page is displayed. It shows the assets used to execute the job, along with information such as the actual job duration and cost. The Results section provides links to the job’s logs and output files. To download a file, click its name in the list.

<figure><img src="/files/rS8TEYoGtg8nWGKMk9oh" alt=""><figcaption></figcaption></figure>


# Manage the escrow account

## Precondition

* The user is logged in to the marketplace
* User has a good understanding of the C2D concepts (please consult this page: [C2D Concepts](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/c2d-concepts))

## Steps

1\. Place the mouse over the user's web3 address and from the context menu select View Profile.

<figure><img src="/files/d2FfNRO3c26yN2gvsluP" alt=""><figcaption></figcaption></figure>

2\. The Profile view is displayed. At the top of this screen, summary information is displayed, including the funds available in the escrow account and the funds locked in the escrow account by C2D jobs, which have not been claimed yet.&#x20;

<figure><img src="/files/OswNnfcFuJaKqVew6DLK" alt=""><figcaption></figcaption></figure>

3\. To withdraw the available funds in the escrow account, click the withdraw button under the Escrow Available Funds field.

<figure><img src="/files/FVjkTF7sKQHAOhExdie4" alt=""><figcaption></figcaption></figure>

4\. The **Withdraw Escrow Funds** window is displayed. Enter the amount to withdraw or press **Max** to withdraw all available funds, then press **Withdraw**.&#x20;

<figure><img src="/files/oAq1uNAJ6jwjzBoshfsq" alt=""><figcaption></figcaption></figure>

5\. Metamask wallet will display a transaction request to be approved. Press Confirm.

<figure><img src="/files/TwD60WFK3iuQI0s6swIy" alt=""><figcaption></figcaption></figure>

6\. The funds will be moved from the escrow account to the user's wallet.&#x20;


# C2D jobs history

## Precondition

* The user is logged in to the marketplace
* User has a good understanding of the C2D concepts (please consult this page: [C2D Concepts](/user-guides/using-the-oe-marketplace/running-compute-to-data-jobs/c2d-concepts))

The list of C2D jobs started by a user is displayed in two different places:

* The list of C2D jobs that were executed using the service(s) of a specific asset (dataset or algorithm) is displayed on the asset details page, within the **Your Compute Jobs** display group.

<figure><img src="/files/ZCLuOzDgyCpG3Dyfg3GK" alt=""><figcaption></figcaption></figure>

* The entire list of C2D jobs executed by a user are displayed in the profile details page, under the **Compute Jobs** tab.

<figure><img src="/files/SXUsyrClmlzVzU5dWKeT" alt=""><figcaption></figcaption></figure>


# Technical Architecture

This chapter describes the technical details of the Ocean Enterprise technical stack.

***

*Next:* [*Architecture*](/developers/architecture)


# High-Level Architecture

This page describes the architecture of a Ocean Enterprise system

Ocean Enterprise has a multi-layer architecture, as presented in the following diagram.&#x20;

<figure><img src="/files/eGnjzzK85J75OwjbVan9" alt=""><figcaption></figcaption></figure>

**Data Storage Layer:**  handles saving and retrieving of the data managed by the OE stack. The following types of storage are used:

* *IPFS* for storing the asset description. When an asset is created in OE, its description, including all metadata attached to the asset, is saved in IPFS.
* *Blockchain* for storing the reference to the asset description. After the description of the asset is created in IPFS, the reference to the IPFS object is saved in a transaction on the blockchain.
* *Web storage* for storing the actual content of the assets. For assets of type dataset or algorithm, their content is saved on a storage platform accessible via the HTTP protocol. The storage platform can be either on the publisher's premises or in the cloud.&#x20;

**Business Logic Layer:** Ocean Enterprise enables a decentralized exchange of data, on one side, and value, on the other side, between a publisher and a consumer. The core element that enables this exchange is represented by the Smart Contracts deployed on-chain.  To this end, the OE Smart Contracts implement the flows for publishing and consuming assets. This layer includes factory contracts, templates for data NFTs and data tokens, fixed-rate exchange contracts for paid assets, and Dispenser contracts for free assets.&#x20;

**Services Layer:** Represented by the Ocean Node component, this layer acts as a bridge between the Business Logic Layer and SDK, orchestrating how requests are processed and how business logic is executed. It provides the following services:

* orchestration of the entire consumption flows (download and Compute-To-Data).
* validation for requests.
* data encryption/decryption
* data streaming of the purchased asset to the consumer
* indexing mechanisms for assets
* abstraction of the complexity of the business and data layer, exposing clean APIs&#x20;

**SDK:** The ocean.js library encapsulates the Smart Contract functions to create assets as well as the services provided by Ocean Node in JavaScript functions, which can be used to develop OE-enabled business applications.&#x20;

**User Interface:** This facilitates the interaction between an end-user and the system. OE provides two interfaces:

* *Ocean Enterprise Marketplace*: a graphical interface where users can publish, retrieve, and consume assets in a very user-friendly manner. The user interface controls how data is displayed and how it responds to user actions. It also performs input validations before passing data to deeper levels.
* *Command Line Interface (CLI)*: a set of high-level tools that enable the creation and consumption of OE assets from a command line interface. This is appropriate when OE assets need to be manipulated in back-end like applications, where a user interface is not required. &#x20;

**Access Control Layer:** Is a critical component that governs who can interact with specific resources in OE and under what conditions.  It acts as a gatekeeper, enforcing policies that determine user permissions based on identity or other descriptive attributes. This layer controls, for instance, who is allowed to publish assets, who is allowed to consume a specific asset, or what algorithm is allowed to be executed on top of a specific dataset.


# Dataspace Architecture

Depending on the required level of protection for the assets published in an OE-enabled dataspace, the OE stack can be configured either with or without **SSI-based access control**. Each configuration requires a distinct set of software components, which are detailed in this chapter.

**Note:** For details on SSI-based access control, refer to [Managing access to assets](/developers/fg-permissions).

## OE-enabled dataspace with SSI-based access control enabled (SSI on)

The configuration of an OE-enabled dataspace with SSI on is presented in the diagram below.&#x20;

<figure><img src="/files/OcJkyKjQ3QSs8nGTut4b" alt=""><figcaption></figcaption></figure>

Participants interact with the dataspace through the **Marketplace**’s user interface, which enables them to manage their own assets and access assets shared by others. The **OE Node** serves as the core component of the system, supporting the secure publication, retrieval, and consumption of assets.

### **Logging in to the Marketplace**

To publish or consume assets, a user must first log in to the marketplace. Logging in requires establishing a connection to the marketplace server using both the **Web3 wallet** and the **SSI wallet**. The Web3 Wallet stores the participant’s Web3 private key, while the SSI wallet manages the participant’s DID and associated Verifiable Credentials.

In a production environment, each participant deploys their own SSI wallet instance within the dataspace to safeguard their private keys, DIDs, and Verifiable Credentials. Alternatively, the marketplace operator may offer a shared SSI wallet instance for participants who have not provisioned their own.

### Publishing an asset

When an asset is published, a corresponding NFT is created on the **Blockchain.** Then, the asset description (DDO) is encrypted by the OE Node, saved in **IPFS,** and the ID of the IPFS content is saved on-chain. The asset is then indexed by the OE Node and becomes available for consumption through the Marketplace.

### Controlling access to assets

In this configuration, the OE Node delegates asset access control to the **Policy Server**. When a participant attempts to consume the service of an asset, the OE Node forwards the request to the Policy Server, including the access control rules defined at both the asset and service levels and the participant's web3 address. Using this information, the Policy Server evaluates the request and determines whether the participant is authorized to access the service, should be denied, or - if SSI-based access policies apply - must complete additional verification.&#x20;

If additional verification is required, the Policy Server forwards the request to the Verifier component, which initiates an OIDC presentation session. During this session, the Verifier and the SSI Wallet exchange several messages to determine which Verifiable Credentials must be presented. These messages flow between the Verifier and the SSI Wallet through the Policy Server, the Ocean Node, and the **Policy Server Proxy**.

Once this exchange is complete, the participant sees in the Marketplace UI a list of Verifiable Credentials that satisfy the presentation requirements. The participant selects the credentials to submit, and the SSI Wallet packages them into a Verifiable Presentation, which is then sent to the Verifier.

The Verifier evaluates the submitted credentials against the rules defined for the asset. If custom rules are present, the Verifier consults the **OPA (Open Policy Agent) Server**. Optionally, it may rely on an external **Credential Verification Service** to determine whether the credentials meet the verification criteria.

Finally, the Verifier returns an allow/deny decision to the Policy Server, which relays the result back to the participant. Access to the service is granted or denied based on this outcome.

&#x20;

## OE-enabled dataspace with SSI-based access control disabled (SSI off)

The configuration of an OE-enabled dataspace with SSI off is presented in the diagram below.&#x20;

<figure><img src="/files/1hAOrVv70QgC1EOZK7r0" alt=""><figcaption></figcaption></figure>

With SSI‑based access control disabled, asset access decisions rely solely on web3 addresses. In this setup, the OE Node handles access verification internally. As a result, the dataspace architecture remains straightforward, requiring only the **Marketplace** and **OE Node** components.

### **Logging in to the Marketplace**

To publish or consume assets, a user must first log in to the marketplace. Logging in requires establishing a connection to the marketplace server using the **Web3 wallet**.

### Publishing an asset

When an asset is published, a corresponding NFT is created on the **Blockchain.** Then, the asset description (DDO) is encrypted by the OE Node, saved in **IPFS,** and the ID of the IPFS content is saved on-chain. The asset is then indexed by the OE Node and becomes available for consumption through the Marketplace.

### Controlling access to assets

When a participant attempts to consume the service of an asset, the OE Node verifies the participant's web3 address against the allow and deny rules defined for web3 addresses, at both the asset and the service levels. The deny list takes precedence. Access to the service is granted or denied based on this outcome.


# Reference Network Architecture

<mark style="color:$warning;">**WORK IN PROGRESS**</mark>


# OE software stack components

The Ocean Enterprise software stack comprises the following components:

## Marketplace

The Marketplace provides the user interface through which dataspace participants manage their own assets and access assets shared by others. Main features include:

* Support for assets with multiple services
* Verification flow for SSI-based access control to assets
* Compute-to-Data wizard for starting C2D jobs&#x20;
* Support for consumers' parameters in download and C2D flows
* User dashboard

## OE Node

The OE Node is the heart of the system; it is a multi-role component, providing the following features:

* encryption of the asset's URI and description during asset publishing
* indexing of the published assets
* on-chain verification for consumer payment
* streaming the asset's data directly to the consumer, without revealing the asset's URI
* providing a Compute-To-Data environment to run jobs using the published assets
* management of the C2D jobs

## Policy Server

The Policy Server is used by the OE Node to determine whether a consumer is authorized to access an asset’s service. It validates access credentials using both the consumer’s web3 address and any SSI‑based access policies defined for the asset. Its core responsibilities include:

* &#x20;Verifying access based on the consumer’s web3 address.
* Checking for SSI-based access control policies if the web3 address is permitted.
* Forwarding any SSI-based access policies to the Verifier component for evaluation.
* Facilitating the data exchange between the Verifier and the consumer’s SSI Wallet to validate the Verifiable Credentials against the asset’s SSI policies.
* Relaying the Verifier’s allow/deny decision back to the OE Node.

## Policy Server Proxy

Policy Server Proxy exposes a set of endpoints that the SSI wallet uses to communicate with the Verifier. Its purpose is to preserve the expected communication flow between the SSI Wallet and the Verifier while routing all interactions through the OE Node and the Policy Server components.

## Verifier

The Verifier (component provided by [walt.id](https://walt.id/)) validates a wide range of digital credentials—such as W3C VCs, SD‑JWT VCs. It checks signatures, formats, and trust policies, and allows you to customize verification behavior through configurable policies, including support for ecosystems like EBSI. For more information about the walt.id verifier, please consult this link: <https://docs.walt.id/community-stack/verifier/getting-started>

In the context of the OE software stack, the Verifier provides the following core functionalities:

* receives the requested credentials and the verification policies from the Policy Server and initiates a presentation session
* validates the Verifiable Credentials submitted by the SSI wallet, for a specific verification request, against the verification policies and returns a success/failure message to the Policy Server.
* invokes the OPA Server to assess and enforce custom policies during the verification process
* optionally interacts with external credential verification services to perform advanced or domain‑specific validation of Verifiable Credentials.

## SSI Wallet

The SSI Wallet (component provided by [walt.id](https://walt.id/)) is an API-driven identity wallet that lets users store, manage, and present a wide range of digital credentials—including W3C VCs, SD‑JWT VCs, using OIDC4VC standards. It also allows users to manage keys and DIDs.

In the context of the OE software stack, the SSI Wallet provides the following core functionalities:

* securely stores the participant's private keys, DIDs, and Verifiable Credentials
* Constructs a Verifiable Presentation from the credentials selected by the participant and submits it to the Verifier for validation

**Note**: <mark style="color:$info;background-color:$info;">It is recommended that, in a production environment, each participant deploys its own SSI Wallet instance within its infrastructure to securely store keys, DIDs, and verifiable credentials. However, the marketplace operator may also provide a default SSI Wallet instance, which the marketplace will automatically use whenever a participant does not supply its own.</mark>

## OPA Server

The Open Policy Agent Server (available [here](https://www.openpolicyagent.org/)) is a general-purpose policy engine that unifies policy enforcement, based on a high-level declarative language.

In the context of the OE software stack, the OPA Server is invoked by the Verifier to assess a set of rules and return a true/false response.


# Assets and Services


# Identifiers (DIDs)

Specification of decentralized identifiers for assets in Ocean Protocol using the DID & DDO standards.

### Identifiers

In Ocean Enterprise, we use decentralized identifiers (DIDs) to identify your asset within the network. Decentralized identifiers (DIDs) are a type of identifier that enables verifiable, decentralized digital identity. In contrast to typical, centralized identifiers, DIDs have been designed so that they may be decoupled from centralized registries, identity providers, and certificate authorities. Specifically, while other parties might be used to help enable the discovery of information related to a DID, the design enables the controller of a DID to prove control over it without requiring permission from any other party. DIDs are URIs that associate a DID subject with a DID document, allowing trustable interactions associated with that subject.

### Examples

DIDs in Ocean Enterprise follow [the generic DID scheme](https://w3c-ccg.github.io/did-spec/#the-generic-did-scheme), they look like this:

```
did:ope:0ebed8226ada17fde24b6bf2b95d27f8f05fcce09139ff5cec31f6d81a7cd2ea
```

The part after `did:ope:` is the ERC721 contract address(in checksum format) and the chainId (expressed to 10 decimal places). The following JavaScript example shows how to calculate the DID for the asset:

```javascript
const CryptoJS = require('crypto-js')

const dataNftAddress = '0xa331155197F70e5e1EA0CC2A1f9ddB1D49A9C1De'
const chainId = 1
const checksum = CryptoJS.SHA256(dataNftAddress + chainId.toString(10))
const did = 'did:op:' + checksum

console.log(did)

```


# Asset File Types

Specification of storage types for assets in Ocean Enteprise.

Ocean Enterprise does not handle the actual storage of files directly. The files are stored via other services, which are then specified within the DDO.

During the publish process, file URLs must be encrypted with the respective *Provider* API call before storing the DDO on-chain. For this, you need to send the following object to Provider (where "files" contains one or more storage objects):

```json
{
  "datatokenAddress":"0x1",
  "nftAddress": "0x2",
  "files": [
    ...
  ]
}
```

The remainder of this document specifies the different types of storage objects that are supported:

## Static URLs

Parameters:

* `url` - File *URL*, **required**
* `method` - The HTTP *method*, **required**
* `headers` - Additional HTTP *headers*, **optional**

```json
{
    "type": "url",
    "url": "https://url.com/file1.csv",
    "method": "GET",
    "headers":
    {
        "Authorization": "Bearer 123",
        "APIKEY": "124",
    }
}
```

## Interplanetary File System

**`IPFS`**

The [Interplanetary File System](https://ipfs.tech/) (IPFS) is a distributed file storage protocol that allows computers all over the globe to store and serve files as part of a giant peer-to-peer network. Any computer, anywhere in the world, can download the IPFS software and start hosting and serving files.

Parameters:

* `hash` - The file *hash,* **required**

<pre class="language-json"><code class="lang-json">{
<strong>    "type": "ipfs",
</strong>    "hash": "XXX"
}
</code></pre>

## GraphQL

**`GraphQL`**

[GraphQL](https://graphql.org/) is a query language for APIs and a runtime for fulfilling those queries with your existing data.

Parameters:

* `url` - Server endpoint *URL*, **required**
* `query` - The *query* to be executed, **required**
* `headers` - Additional HTTP headers, **optional**

```json
{
     "type": "graphql",
     "url": "http://172.15.0.15:8000/subgraphs/name/oceanprotocol/ocean-subgraph",
     "headers":{
        	"Authorization": "Bearer 123",
        	"APIKEY": "124",
     },
     "query": """query{
            nfts(orderBy: createdTimestamp,orderDirection:desc){
                 id
                 symbol
                 createdTimestamp
            }
          }"""
}
```

## Smart Contract Data

Use a smart contract as data source.

Parameters:

* `chainId` - The *chainId* used to query the contract, **required**
* `address` - The smartcontract *address*, **required**
* `abi` - The function *abi* (NOT the entire contract abi), **required**

{% code overflow="wrap" %}

```json
{
"type": "smartcontract",
"chainId": 1,
"address": "0x8149276f275EEFAc110D74AFE8AFECEaeC7d1593",
"abi": {
	"inputs": [],
	"name": "swapOceanFee",
	"outputs": [{"internalType": "uint256", "name": "", "type": "uint256"}],
	"stateMutability": "view",
	"type": "function"
	}
}
```

{% endcode %}

## Arweave

[Arweave](https://www.arweave.org/) is a decentralized data storage that allows permanently storing files over a distributed network of computers.

Parameters:

* `transactionId` - The *transaction identifier,* **required**

```json
{
    "type": "arweave",
    "transactionId": "a4qJoQZa1poIv5guEzkfgZYSAD0uYm7Vw4zm_tCswVQ",
}
```

First-class integrations supported in the future : **`Filecoin`** **`Storj`** **`SQL`**

A service can contain multiple files, using multiple storage types.

Example:

```json
{
  "datatokenAddress": "0x1",
  "nftAddress": "0x2",
  "files": [
    {
      "type": "url",
      "url": "https://url.com/file1.csv",
      "method": "GET"
    },
    {
      "type": "ipfs",
      "hash": "XXXX"
    }
  ]
}
```

To get information about the files after encryption, the `/fileinfo` endpoint of the [*Provider*](https://github.com/OceanProtocolEnterprise/docs/blob/OE-structure/developers/old-infrastructure/provider/README.md) returns based on a passed DID an array of file metadata (based on the file type):

```json
[
  {
    "type": "url",
    "contentLength": 100,
    "contentType": "application/json"
  },
  {
    "type": "ipfs",
    "contentLength": 130,
    "contentType": "application/text"
  }
]
```

This only concerns metadata about a file, but never the file URLs. The only way to decrypt them is to exchange at least 1 datatoken based on the respective service pricing scheme.

## FTP

<mark style="color:orange;">**WORK IN PROGRESS**</mark>


# Asset Metadata

## Introduction

Asset metadata plays a critical role within the Ocean Enterprise ecosystem, enabling the cataloging and management of service offerings. Each asset can include multiple service offerings. The metadata is intended for publication to federated catalogues, ensuring that service offerings are easily discoverable across different data spaces and data ecosystems. To ensure confidentiality and integrity, the metadata is encrypted by default.

Additionally, while most metadata is stored off-chain to optimize performance and scalability, a hash of this metadata is anchored on-chain. This approach combines the benefits of off-chain storage with the immutability and security of blockchain technology, ensuring both scalable data management and verifiable metadata integrity.

Due to privacy and efficiency reasons, the asset metadata is split into two parts:

* **Off-chain part**: it is a W3C-compliant Verifiable Credential (V), encoded in VC-JWT format and stored using IPFS. It is signed by the asset publisher and encrypted.
* **On-chain part**: it is recorded on the blockchain and contains a remote pointer linking to the off‑chain part of the DDO, where the full metadata is stored.

## The off-chain part of the DDO

The off‑chain component of the DDO is encoded as a **W3C‑compliant Verifiable Credential** and signed by the asset’s publisher, ensuring authenticity and integrity.

```mermaid
graph TD
    %% Main DDO Node
    DDO[Asset DDO] 
    
    %% Core Pillars
    DDO --> ID[id: DID String]
    DDO --> CS[credentialSubject]
    DDO --> Proof[proof: Cryptographic Signature]

    %% Credential Subject Breakdown
    CS --> Meta["`**Metadata**
    name
    description
    type
    created
    updated
    tags
    copyrightHolder
    providedBy
    links
    license
    algorithm`"]
    
    Meta --> Algorithm["`
    **Algorithm**
    (_only for assets
    of type algorithm_)
    @language
    Version
    Container`"]
    
    Algorithm --> Container["`
    **Container**
    image
    tag
    entrypoint
    `"]
    CS --> AssetCreds["`**credentials**
    (Asset-Level 
    Access Control)`"]
    CS --> Services["`**services** 
    (_Operational Offerings_)`"]

    %% Asset Level Credentials Details
    AssetCreds --> AC_Allow["`**allow:**
    (_Whitelist Rules_)`"]
    AssetCreds --> AC_Deny["`**deny:**
    (_Blacklist Rules_)
    type: address 
    values`"]
    AC_Allow --> AC_SSI["`type: SSIpolicy
    vp_policies
    vc_policies
    request_credentials`"]
    AC_Allow --> AC_Add["`type: address 
    values`"]
    
    %% Services Breakdown
    Services --> Serv1["`
    Service
    (_Data Access Payload_)
    id
    name
    description
    type (access/compute)
    datatokenAddress
    files
    serviceEndpoint
    timeout
    state
    credentials
    consumerParameters
    compute
    `"]
    Serv1 --> ServCreds["`**credentials** 
    (Service-Level 
    Access Control)`"]
    Serv1 --> Compute["`**Compute**
    allowRawAlgorithm
    allowNetworkAccess
    publisherTrustedAlgorithmPublishers
    publisherTrustedAlgorithms
`"]
   Serv1 --> ConsumerParamenters["`
   **consumerParameters**
   name
   type
   label
   description
   default
   required
   options `"]
    
    %% Service Level Credentials Details
    ServCreds --> Serv_AC_Allow["`**allow:**
    (_Whitelist Rules_)`"]
    Serv_AC_Allow --> Serv_AC_SSI["`type: SSIpolicy
    vc_policies
    request_credentials`"]
    Serv_AC_Allow --> Serv_AC_Add["`type: address 
    values`"]
    ServCreds --> Serv_AC_Deny["`**deny:**
    (_Blacklist Rules_)
    type: address 
    values`"]
    
```

### Verifiable Credential

| Attribute                                                 | Type               | Description                                                                                                                                                                                                   |
| --------------------------------------------------------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `@context`                                                | `Array of String`  | <p>Specifies the W3C data standards utilized to validate the cryptographic security format of the asset document.<br><code>\[</code>                                                                          |
| <br><code>"<https://www.w3.org/ns/credentials/v2>"</code> |                    |                                                                                                                                                                                                               |
| <br><code>]</code></p>                                    |                    |                                                                                                                                                                                                               |
| `type`                                                    | Array of `Strings` | <p>Declares the identity type of this record, systematically marked as a VerifiableCredential.<br><code>\[</code>                                                                                             |
| <br><code>"VerifiableCredential"</code>                   |                    |                                                                                                                                                                                                               |
| <br><code>]</code></p>                                    |                    |                                                                                                                                                                                                               |
| `version`                                                 | `String`           | Indicates the system configuration template version used to render the document (e.g., `5.0.0`).                                                                                                              |
| `id`                                                      | `String`           | The unique Decentralized Identifier (DID) assigned to the asset, serving as its permanent global lookup address on the marketplace.                                                                           |
| `credentialSubject`                                       | `Object`           | The primary container holding all asset profiles, metadata rules, distribution permissions, and pricing stats. The credentialSubject object is detailed in the table [credentialSubject](#credentialsubject). |
| `issuer`                                                  | `String`           | The verified decentralized identity of the entity that signed off on publishing the asset. (e.g. `"did:web:wallet2.demo.oceanenterprise.io:wallet-api:registry:publisher132"`)                                |
| `proof`                                                   | `Object`           | The final cryptographic payload consisting of standard encryption schemas used to verify document authenticity.                                                                                               |

### credentialSubject

| Attribute        | Type               | Description                                                                                                                                                                                          |
| ---------------- | ------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `chainId`        | `Integer`          | The blockchain network identification code where this asset and its related smart contracts reside.                                                                                                  |
| `metadata`       | `Object`           | Contains all human-readable definitions of the asset, such as titles, creation dates, and licensing information. The metadata object is described in the table [Metadata](#metadata).                |
| `services`       | `Array of Objects` | Configuration details for asset's services, outlining the technical access paths, the node endpoints, time limits, and parameters. The service object is described in the table [Service](#service). |
| `credentials`    | `Object`           | <p>Access rules defining who  can access the overall asset.<br>The credentials object is described in the table <a href="#credentials">Credentials</a></p>                                           |
| `nftAddress`     | `String`           | The address of the NFT minted in the blockchain, which represents the asset.                                                                                                                         |
| `additionalDdos` | `Array`            | List of additional descriptions of the asset in other formats.                                                                                                                                       |

### Metadata

There are two types of assets managed in Ocean Enterprise: `datasets` and `algorithms`. Each asset type has its specific attributes.

| Attribute         | Type                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| ----------------- | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `created`         | `String (ISO date/time)` | The exact date and time, in ISO8601 format, when the asset profile was first registered (e.g. `2000-10-31T01:30:00Z`).                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| `updated`         | `String (ISO date/time)` | The exact date and time, in ISO8601 format, when the asset profile was last updated (e.g. `2000-10-31T01:30:00Z`).                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `type`            | `String`                 | <p>Defines the format classification of the asset entry ( <code>dataset</code> or <code>alogorithm</code>).<br>Each type has a different subset of metadata attributes.</p>                                                                                                                                                                                                                                                                                                                                                                                         |
| `name`            | `String`                 | The public display name of the asset, shown to marketplace buyers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `description`     | `String`                 | Multilingual, direction-aware descriptive text detailing what the dataset contains.The description object is detailed in the table [Description](#description)                                                                                                                                                                                                                                                                                                                                                                                                      |
| `tags`            | `Array of Strings`       | Categorization keywords used by portal search bars to filter, search, and group relevant assets.                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `author`          | `String`                 | Name of the entity generating this data (e.g. `Ocean Enterprise e.V.`).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| `copyrightHolder` | `String`                 | The entity holding the legal copyright.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| `providedBy`      | `string`                 | Verifiable Credential of the entity offering this asset.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| `links`           | `Object`                 | Mapping of URL titles(key) and URL strings(value)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `license`         | `Object`                 | The licenses applied to all services of this asset. The license object is detailed in table [License](#license).                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `algorithm`       | `Object`                 | <mark style="background-color:$warning;">This object is set only if the asset is an algorithm (the field</mark> <mark style="background-color:$warning;"></mark><mark style="background-color:$warning;">`type`</mark>  <mark style="background-color:$warning;"></mark><mark style="background-color:$warning;">is set to</mark> <mark style="background-color:$warning;"></mark><mark style="background-color:$warning;">`algorithm`</mark><mark style="background-color:$warning;">).</mark> This algorithm object is described in table [Algorithm](#algorithm) |

#### Description

| Attribute    | Type     | Description                                                                                                                                                                                                                                                   |
| ------------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `@value`     | `String` | Description of the asset in one specific language                                                                                                                                                                                                             |
| `@direction` | `String` | Text direction, whose value is a [base direction](https://www.w3.org/TR/i18n-glossary/#dfn-base-direction) string defined by the `@direction` property in \[[JSON-LD11](https://w3c.github.io/vc-data-model/#bib-json-ld11)] .Example: `rtl` (`ltr` or `rtl`) |
| `@language`  | `String` | Text language, as defined by [BCP47](https://w3c.github.io/vc-data-model/#bib-bcp47)                                                                                                                                                                          |

Example of a `description` object:

```
"title": {
  "@value": "HTML و CSS: تصميم و إنشاء مواقع الويب",
  "@language": "ar",
  "@direction": "rtl"
}
```

#### License

| Attribute                                       | Type               | Description                                                                                                                                                                    |
| ----------------------------------------------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `name`                                          | `String`           | The primary name, label, or reference link representing the master data license or legal agreement for the asset.                                                              |
| `licenseDocuments`                              | `Array of Objects` | A comprehensive manifest listing individual files, addendums, or reference agreements attached directly to this license profile.                                               |
| `licenseDocuments[].additionalInformation`      | `Object`           | An extensible metadata bucket for storing operational file properties.                                                                                                         |
| `licenseDocuments[].additionalInformation.size` | `Integer`          | The physical file size (measured in bytes) of the attached legal or reference document.                                                                                        |
| `licenseDocuments[].sha256`                     | `String`           | A unique cryptographic fingerprint of the document file. This ensures the legal terms cannot be modified or replaced without invalidating the manifest.                        |
| `licenseDocuments[].mirrors`                    | `Array of Objects` | A list of alternative hosting locations where the marketplace application can safely retrieve the document file.                                                               |
| `licenseDocuments[].mirrors[].method`           | `String`           | The technical HTTP transmission rule used to download the document (e.g., `get`).                                                                                              |
| `licenseDocuments[].mirrors[].type`             | `String`           | The storage infrastructure category hosting this specific copy (e.g., traditional web link `url` or decentralized storage `ipfs`).                                             |
| `licenseDocuments[].mirrors[].url`              | `String`           | The precise URL destination path used to download the file if hosted on standard cloud web servers.                                                                            |
| `licenseDocuments[].mirrors[].headers`          | `String`           | Optional protocol header parameters required by secure servers during the file download process.                                                                               |
| `licenseDocuments[].mirrors[].ipfsCid`          | `String`           | The cryptographic Content Identifier (CID) used to fetch the file copy if it is stored across decentralized networks.                                                          |
| `licenseDocuments[].displayName`                | `Object`           | A localization container for the file label displayed to consumers in the marketplace portal user interface.                                                                   |
| `licenseDocuments[].displayName.@direction`     | `String`           | Layout direction setting for rendering text (e.g., `ltr` for left-to-right languages).                                                                                         |
| `licenseDocuments[].displayName.@language`      | `String`           | niversal language standard code indicating the translation of the display text (e.g., `en`).                                                                                   |
| `licenseDocuments[].name`                       | `String`           | The strict administrative filename matching the document index registry record.                                                                                                |
| `licenseDocuments[].description`                | `Object`           | A localization container used to provide supplementary details or descriptive footnotes about a specific file attachment.                                                      |
| `licenseDocuments[].description.@value`         | `String`           | Human-readable explanation detailing what a specific attached document or addendum covers.                                                                                     |
| `licenseDocuments[].description.@direction`     | `String`           | Layout direction setting for parsing the text block (e.g., `ltr`).                                                                                                             |
| `licenseDocuments[].description.@language`      | `String`           | Universal language standard code specifying the language of the description string (e.g., `en`).                                                                               |
| `licenseDocuments[].fileType`                   | `String`           | The official file format layout standard (e.g., `png` or `text/html; charset=utf-8`), which informs the marketplace app how to correctly render or display the file to a user. |

Example of a license object including the following:

* a license file referenced as a URL (<https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf>)&#x20;
* two additional files:
  * "test additional file": file uploaded to IPFS
  * "test additional file 2": file referenced as a URL available at <https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf>

```json
      "license": {
        "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
        "licenseDocuments": [
          {
            "additionalInformation": {
              "size": 224393
            },
            "sha256": "891580d4fa62d00141a6237987a68e5da03064478ca3511d95685e810fcf30d0",
            "mirrors": [
              {
                "method": "get",
                "type": "url",
                "url": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf"
              }
            ],
            "displayName": {
              "@value": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
              "@direction": "ltr",
              "@language": "en"
            },
            "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
            "description": {
              "@value": "",
              "@direction": "ltr",
              "@language": "en"
            },
            "fileType": "text/html; charset=utf-8"
          },
          {
            "additionalInformation": {
              "size": 27424
            },
            "sha256": "97edf62ae8f3ff7f77d56b7fba900a457c3d85a5777b58510ef0ca5074a7b440",
            "mirrors": [
              {
                "headers": {},
                "ipfsCid": "QmTU7vUCxUeGMmYnxiU9655meJcfvXfX5Jt58m2V8swprF",
                "type": "ipfs"
              }
            ],
            "displayName": {
              "@value": "test additional file",
              "@direction": "ltr",
              "@language": "en"
            },
            "name": "test additional file",
            "description": {
              "@value": "",
              "@direction": "ltr",
              "@language": "en"
            },
            "fileType": "png"
          },
          {
            "additionalInformation": {
              "size": 224393
            },
            "sha256": "0a526e7a36c2abaed8441112264dfee38d546a6bf28da1c7cac3036af8363d66",
            "mirrors": [
              {
                "method": "get",
                "type": "url",
                "url": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf"
              }
            ],
            "displayName": {
              "@value": "test additonal file 2",
              "@direction": "ltr",
              "@language": "en"
            },
            "name": "test additonal file 2",
            "description": {
              "@value": "",
              "@direction": "ltr",
              "@language": "en"
            },
            "fileType": "text/html; charset=utf-8"
          }
        ]
      }
```

#### Algorithm

| Attribute   | Type     | Description                                                                                                                                                                                 |
| ----------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `@language` | `String` | Language to implement the software                                                                                                                                                          |
| `version`   | `String` | Version of the software, preferably in [SemVer](https://semver.org/) notation. E.g. `1.0.0`.                                                                                                |
| `container` | Object   | Describes the Docker container image based on which the container that will run the algorithms will be instantiated. The container object is described in the table [Container](#container) |

#### Container

| Attribute    | Type     | Description                                                                                                                             |
| ------------ | -------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| `image`      | `String` | The Docker image name the algorithm will run with.                                                                                      |
| `tag`        | `String` | The Docker image tag.                                                                                                                   |
| `entrypoint` | `String` | The Docker entrypoint. `$ALGO` is a macro that gets replaced inside the compute job, depending where your algorithm code is downloaded. |

Example of a container object for an algorithm written in JavaScript/Node.js, based on Node.js v24:

```json
{
  "algorithm": {
    "container": {
      "entrypoint": "node $ALGO",
      "image": "node",
      "tag": "24"
    }
  }
}
```

### Service

| Attribute            | Type               | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| -------------------- | ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `id`                 | `String`           | Unique ID of the asset's service                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `name`               | `String`           | Service name                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `description`        | `Object`           | Multilingual, direction-aware descriptive text detailing what the dataset contains.The description object is detailed in the table [Description](#description)                                                                                                                                                                                                                                                                                                  |
| `type`               | `String`           | Defines the transaction fulfillment style of the service endpoint (e.g., `access` for direct data file downloading or `compute` for access to the service endpoint only within a Compute-to-Data job).                                                                                                                                                                                                                                                          |
| `datatokenAddress`   | `String`           | Smart contract address of the specific token assigned to this service.                                                                                                                                                                                                                                                                                                                                                                                          |
| `files`              | `String`           | Ecrypted access control information of the files associated with this service. When the service is consumed, the files listed here are served to the consumer. The information is encrypted by the node provided in the `serviceEndpoint` parameter. The structure of the file object encrypted and saved in this field depends on the type of file: HTTP, S3 etc. All file objects are presented in chapter [File Types](broken://pages/UO9SaREtSdAsjbOnSy5q). |
| `serviceEndpoint`    | `String (URL)`     | Tthe URL of the OE Node responsible for controlling the access to the service: verifying payments for the service and streaming the data files safely to the buyer.                                                                                                                                                                                                                                                                                             |
| `timeout`            | `Integer`          | The active lifetime window (measured in seconds) a consumer has to utilize or download the service from the purchase moment (e.g., `86400` seconds equals 24 hours). After the timeout is reached, the consumer has to purchase the service again in order to access it once more.                                                                                                                                                                              |
| `state`              | `Integer`          | Indicates the operational lifecycle status of the service (e.g., `0` means active and purchaseable; other values designate paused or retired services).                                                                                                                                                                                                                                                                                                         |
| `credentials`        | `Object`           | <p>Access rules defining who  can access the service.<br>The credentials object is described in the table <a href="#credentials">Credentials</a></p>                                                                                                                                                                                                                                                                                                            |
| `consumerParameters` | `Array of Objects` | <p>Defines the parameters the consumer has to input before consuming the asset.<br>This object is described in table <a href="#consumer-parameters">Consumer Parameters</a>.</p>                                                                                                                                                                                                                                                                                |
| `compute`            | `Object`           | <p><mark style="background-color:$warning;">This object is defined only for services used in C2D (i.e.  <code>service.type</code>  is set to <code>compute).</code></mark> </p><p>This compute object is described in table <a href="#compute">Compute</a>. </p>                                                                                                                                                                                                |

#### Compute

For services used in C2D jobs, the compute object is added to the service description. This object includes the following attributes.

| Attribute                                               | Type               | Description                                                                                                                                                                                           |
| ------------------------------------------------------- | ------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `allowRawAlgorithm`                                     | `boolean`          | <p>Used only for assets of type <code>algorithm</code>.</p><p>Specify if passed raw text will be allowed to run. It is by default set to <code>false</code> (do not allow raw algorithms to run).</p> |
| `allowNetworkAccess`                                    | `boolean`          | <p>Used only for assets of type <code>algorithm</code>.</p><p>Specify if the algorithm job network access. </p>                                                                                       |
| `publisherTrustedAlgorithmPublishers`                   | `Array of Strings` | <p>Used only for assets of type <code>dataset</code>.<br>A list of the web3 addresses of algorithm publishers that the service recognizes as trusted.</p>                                             |
| `publisherTrustedAlgorithms`                            | `Array of Objects` | <p>Used only for assets of type <code>dataset</code>.<br>Specify the list of algorithms allowed to run on the dataset represented by the service.</p>                                                 |
| `publisherTrustedAlgorithms[].did`                      | `String`           | The DID of the asset allowed to run on the dataset                                                                                                                                                    |
| `publisherTrustedAlgorithms[].serviceId`                | `String`           | The ServiceId of the service within the asset that is allowed to run on the dataset.                                                                                                                  |
| `publisherTrustedAlgorithms[].containerSectionChecksum` | `String`           | Hash of algorithm's image details                                                                                                                                                                     |
| `publisherTrustedAlgorithms[].filesChecksum`            | `String`           | Hash of algorithm's files.                                                                                                                                                                            |

Example of a compute object for a dataset service. There are two algorithm publishers trusted by this dataset (listed in `publisherTrustedAlgorithmPublishers`), meaning all algorithms from these two publishers can be executed on the dataset. Moreover, there are three additional trusted algorithms (listed in publisherTrustedAlgorithms), which can also be executed on the dataset.

```json
       "compute": {
          "allowRawAlgorithm": false,
          "allowNetworkAccess": true,
          "publisherTrustedAlgorithmPublishers": [
            "0xd727fb9be39fa019d7c02fea19e54d688da3a662",
            "0x61db12d8b636cb49ea09eca58a893da9480e1f33"
          ],
          "publisherTrustedAlgorithms": [
            {
              "did": "did:ope:c68e6efe498f70cf0d671f9a405374176607d209546837e25b11cedbbcc9cd02",
              "containerSectionChecksum": "ee2da20f61e82ced3033ad6a7cb44fe136d91b715eaf2db2811ee0b0ad4a5b99",
              "filesChecksum": "2c36c054711dad021f45cc7e0990bd38864a51d753c8055b63e78014a6bee515",
              "serviceId": "4d89d718fc670b20217d97466e9612244e82aad21a40d19738d2a6ed0e3e8893"
            },
            {
              "did": "did:ope:c534e37e815b267d229c7051086f17c084ab72dce41af12df6f6daf900b30b16",
              "containerSectionChecksum": "2ea683746c6927342c7ea51ddd9b8acada2490c67a357ff9b41bda64fe05cb34",
              "filesChecksum": "dc0b0c89639614533fecd6ebe7dc53dcfbda96865322213dea7c3ecf88ad7ea4",
              "serviceId": "ae2367882fa6d10c006dcce30b4a2bdd70434f8348c0ed6431f2125b572b12f4"
            },
            {
              "did": "did:ope:b66c9ccce1b117711918ba1232e70d99c75e52a68a88a13639eed3a8450c41f8",
              "containerSectionChecksum": "dfce591ecb9b35c1c2931c8b38b4c216a61b40cd33407ab886df3b44c6b8904d",
              "filesChecksum": "ffd8c9b460451dd7d1677878f60cc93ce35a5a2517f08819761c0ddf424f7f88",
              "serviceId": "40c3fefb7b73c1a3190a437227d1954f8ef682676e26c1a914668f2d05401d22"
            }
          ]
        }
```

&#x20;

### Consumer Parameters

| Attribute     | Type               | Description                                                                                                                                                                                                                                        |
| ------------- | ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`        | `String`           | The internal technical identifier for the parameter.                                                                                                                                                                                               |
| `type`        | `String`           | Controls the visual input style generated on the interface screen. Accepted configurations include `text` (string field), `select` (a dropdown menu), `number` (a numeric keypad/input field), or `boolean` (a true/false checkbox/toggle switch). |
| `label`       | `String`           | The human-readable title displayed directly above the input field in the marketplace portal.                                                                                                                                                       |
| `description` | `String`           | Explanatory instructional text or tooltips presented next to the interface field to guide consumers on what their choice affects.                                                                                                                  |
| `default`     | `String`           | The standard pre-selected value automatically used if the user skips modifying this parameter or leaves the field empty.                                                                                                                           |
| `required`    | `boolean`          | Enforces entry rules. If set to `true`, the marketplace will block the consumption request until the user explicitly inputs a value. If `false`, the parameter is optional.                                                                        |
| `options`     | `Array of Objects` | Applicable only when `type` is set to `select`. Defines the selectable items inside the dropdown menu, mapping a backend code name (e.g., `apac`) to its user-friendly display value (e.g., `Asia Pacific`).                                       |

Example of a consumerParameters object:

```json
"consumerParameters": [
          {
            "default": "eu",
            "name": "region",
            "options": [
              {
                "eu": "Europe"
              },
              {
                "us": "United States"
              },
              {
                "apac": "Asia Pacific"
              }
            ],
            "description": "Choose the region for the download.",
            "label": "Region",
            "type": "select",
            "required": true
          },
          {
            "default": "csv",
            "name": "format",
            "options": [
              {
                "csv": "CSV"
              },
              {
                "json": "JSON"
              },
              {
                "parquet": "Parquet"
              }
            ],
            "description": "Choose the output format returned by the download service.",
            "label": "Export Format",
            "type": "select",
            "required": false
          },
          {
            "default": "1000",
            "name": "rowLimit",
            "description": "Maximum number of rows returned.",
            "label": "Row Limit",
            "type": "number",
            "required": false
          },
          {
            "default": "false",
            "name": "includeHeaders",
            "description": "Whether the exported file should include column headers.",
            "label": "Include Headers",
            "type": "boolean",
            "required": false
          }
        ]
```

### Credentials

The credentials are specified at the asset level (`credentialSubject.credetials`) and at the service level (`credentialSubject.services[].credentials`). Both objects share the same structure. The only difference between the two is that asset-level credentials may include additional clauses regarding the presentation of verifiable credentials. These clauses specific to asset-level credentials are highlighted in the text below.&#x20;

| Attribute | Type               | Description                                                                                                                                                                                                                                             |
| --------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `allow`   | `Array of Objects` | The Access Whitelist. A collection of rules defining who *is* permitted to interact with the asset. If an entity matches any defined rule block here, they are granted baseline access. The allow object is presented in table Allow.                   |
| `deny`    | `Array of Objects` | <p>The Access Blacklist. Explicit ban parameters based on web3 address. <br>Any wallet address matching criteria in this block will be hard-blocked from accessing the asset or service, even if they qualify under the <code>allow</code> section.</p> |

#### Allow

| Attribute                                         | Type                          | Description                                                                                                                                                                                                                                                                                                                                                                                                         |
| ------------------------------------------------- | ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `type`                                            | `String`                      | Specifies the security mechanism used for evaluation. The supported values are  `address` (crypto-wallet-based gating) or `SSIpolicy` (decentralized enterprise identity profiles).                                                                                                                                                                                                                                 |
| `values`                                          | `Array of Objects`            | Contains the operational parameters and settings assigned to the specific rule type.                                                                                                                                                                                                                                                                                                                                |
| `allow[].values[].address`                        | `String`                      | Used when type is `address`. Denotes the explicit blockchain wallet address allowed to see the asset. A value of `*` serves as a wildcard, permitting any connected wallet.                                                                                                                                                                                                                                         |
| `allow[].values[].vc_policies`                    | `Array of Strings`            | Global Verifiable Credential Baselines. Security audits enforced automatically across *every* submitted credential, such as checking the digital `signature` or ensuring the timeline is valid via `not-before`.                                                                                                                                                                                                    |
| `allow[].values[].vp_policies`                    | `Array of Objects`            | <p><mark style="background-color:$warning;">This field is present only in the asset-level credentials object.</mark><br>Verifiable Presentation (VP) Bundle Rules. Rules dictating how the overall collection of credentials must behave together, such as enforcing anti-spoofing (<code>holder-binding</code>) or setting a minimum number of valid matching certificates (<code>minimum-credentials</code>).</p> |
| `allow[].values[].request_credentials`            | `Array of Objects`            | Used when type is `SSIpolicy`. Outlines the precise digital  verifiable  credentials the user must present from their corporate identity wallet (e.g., corporate registry records).                                                                                                                                                                                                                                 |
| `allow[].values[].request_credentials[].type`     | `String`                      | The specific schema or classification of the requested certificate, such as `gx:LegalPerson` (company profile) or `gx:LeiCode` (Legal Entity Identifier).                                                                                                                                                                                                                                                           |
| `allow[].values[].request_credentials[].format`   | `String`                      | The technical data format of the credential package being checked (e.g., `jwt_vc_json`).                                                                                                                                                                                                                                                                                                                            |
| `allow[].values[].request_credentials[].policies` | `Array of Strings or Objects` | Targeted validation checks applied to that specific credential. Can range from a simple validity check like `expired` to complex dynamic rules containing parameters and evaluation servers.                                                                                                                                                                                                                        |

Example of an asset-level allow object. The following access credentials are defined for the asset:

* access allowed to any web3 address (field `credentials.allow[{"type":"address"}].values[0].address = "*"`)
* access allowed to any consumer who presents the following VCs (the fields `credentials.allow[{"type":"SSIpolicy"}].values[0].request_credentials[].type`):
  * gx:LegalPerson
  * gx:Issuer
  * gx:LeiCode
* all VCs have to comply with the following static policies (the field `credentials.allow[{"type":"SSIpolicy"}].values[0].vc_policies[]`)
  * &#x20;not-before: VC is not used before its validity start date
  * revoked-status-list: VC is not revoked
  * signature: VC has a valid signature
* the Verifiable Presentation (VP) in which the VCs are packed before submission to verification must comply with the following policies (the field `credentials.allow[{"type":"SSIpolicy"}].values[0].vp_policies[]`):
  * &#x20;  holder-binding: the identifier that signs the VP must be the subject of each VC included in the VP
  * minimum-credentials: a minimum of two VCs must be included in the VP
  * vp\_required\_credentials: the VP must include gx:LegalPerson VC and optionally one of the following VCs: gx:LeiCode and gx:Issuer&#x20;
* the gx:LegalPerson VC must comply with the following policy (`credentials.allow[{"type":"SSIpolicy"}].values[0].request_credential[0].policies[]`):
  * expired: the VC has not expired
* the gx:Issuer VC must comply with the following policy (`credentials.allow[{"type":"SSIpolicy"}].values[0].request_credential[1].policies[]`)
  * allowed-issues: the VC must be issued by the entity identified by did:GXCH
* the gx:LeiCode VC must comply with the following policy (`credentials.allow[{"type":"SSIpolicy"}].values[0].request_credential[1].policies[]`):
  * a dynamic policy named countryGermany
  * the dynamic policy verifies if the field gx:countryCode of the VC has the value "DE"

```json
"credentials": {
      "allow": [
        {
          "type": "SSIpolicy",
          "values": [
            {
              "request_credentials": [
                {
                  "format": "jwt_vc_json",
                  "policies": [
                    "expired"
                  ],
                  "type": "gx:LegalPerson"
                },
                {
                  "format": "jwt_vc_json",
                  "policies": [
                    {
                      "policy": "allowed-issuer",
                      "args": [
                        "did:GXCH"
                      ]
                    }
                  ],
                  "type": "gx:Issuer"
                },
                {
                  "format": "jwt_vc_json",
                  "policies": [
                    {
                      "policy": "dynamic",
                      "args": {
                        "policy_name": "countryGermany",
                        "opa_server": "http://ocean-node-vm3.oceanenterprise.io:8181",
                        "policy_query": "data",
                        "rules": {
                          "rego": "package data.countryGermany\n\ndefault allow := false\n\nallow if {\n  lower(input.credentialData.credentialSubject[\"gx:countryCode\"]) == lower(input.parameter.param1)\n}"
                        },
                        "argument": {
                          "param1": "DE"
                        }
                      }
                    }
                  ],
                  "type": "gx:LeiCode"
                }
              ],
              "vc_policies": [
                "not-before",
                "revoked-status-list",
                "signature"
              ],
              "vp_policies": [
                {
                  "policy": "holder-binding"
                },
                {
                  "policy": "minimum-credentials",
                  "args": "2"
                },
                {
                  "policy": "vp_required_credentials",
                  "args": "{\"required\":[{\"credential_type\":\"gx:LegalPerson\"},{\"any_of\":[\"gx:LeiCode\",\"gx:Issuer\"]}]}"
                }
              ]
            }
          ]
        },
        {
          "type": "address",
          "values": [
            {
              "address": "*"
            }
          ]
        }
      ],
      "deny": [],
      "match_deny": "any"
    }
```

&#x20;

#### Deny

| Attribute          | Type               | Description                                                                                                                                              |
| ------------------ | ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `type`             | `String`           | Specifies the security mechanism used for evaluation. Currently, the only accepted value is `address`                                                    |
| `values`           | `Array of objects` | The list of web3 addresses that are restricted to access the asset/service.                                                                              |
| `values[].address` | `String`           | The web3 address restricteed to access the asset/service (e.g "`0xd727fb9be39fa019d7c02fea19e54d688da3a662`" - specific address; `"*"` - all addresses). |

Example of a deny object where two web3 addresses are restricted from accessing the asset/service.

```json
          "deny": [
            {
              "type": "address",
              "values": [
                {
                  "address": "0xd727fb9be39fa019d7c02fea19e54d688da3a662"
                },
                {
                  "address": "0x61db12d8b636cb49ea09eca58a893da9480e1f33"
                }
              ]
            }
          ],
          "match_deny": "any"
```

Example of a deny object where all addresses are restricted from accessing the asset/service.&#x20;

```json
  "deny": [
    {
      "type": "address",
      "values": [
        {
          "address": "*"
        }
      ]
    }
  ],
  "match_deny": "any"
```

## Examples of DDOs

### Dataset with two services

The asset is of type `dataset` and has two services of type `download` : "Service 1" and "Service 2"&#x20;

{% code overflow="wrap" %}

```json
{
  "@context": [
    "https://www.w3.org/ns/credentials/v2"
  ],
  "id": "did:ope:7752f58eece2711f16a0a2cd2d4490dcbde06c440386170f0881c9151b9f478c",
  "version": "5.0.0",
  "credentialSubject": {
    "chainId": 11155111,
    "metadata": {
      "created": "2026-06-23T05:39:40Z",
      "updated": "2026-06-23T06:08:24.287Z",
      "type": "dataset",
      "name": "publish with signer server updated",
      "description": {
        "@value": "this is a publishhh updated",
        "@direction": "ltr",
        "@language": "en"
      },
      "tags": [],
      "author": "",
      "license": {
        "name": "https://microsoftedge.github.io/Demos/json-dummy-data/64KB.json",
        "licenseDocuments": [
          {
            "sha256": "cde3fa1e4696435fb274304f710742f67bc4b810fd7ee850543d162f3e10aa70",
            "mirrors": [
              {
                "method": "get",
                "type": "url",
                "url": "https://microsoftedge.github.io/Demos/json-dummy-data/64KB.json"
              }
            ],
            "name": "https://microsoftedge.github.io/Demos/json-dummy-data/64KB.json",
            "fileType": "application/json; charset=utf-8"
          }
        ]
      },
      "additionalInformation": {
        "termsAndConditions": true
      },
      "copyrightHolder": "",
      "providedBy": "",
      "links": {}
    },
    "services": [
      {
        "credentials": {
          "allow": [
            {
              "values": [
                {
                  "address": "*"
                }
              ],
              "type": "address"
            }
          ],
          "match_deny": "any",
          "deny": []
        },
        "name": "Service 1",
        "files": "0x0471e141a36eb191e13122b3aeeefb9ae4ead2be502a411895a7e02aa462e7a0013eb887e0f0a2252f156956c22c57d75c25bf4832506f6e174194323e7876505c0cdd9d0d1d3eb9e3644821e163c7f04c3101b893a96499a28df3b436af3780c0f9c964ff11aa748852837cff27308839bba4ad98befdcb91d0f8523bb7ebcf720856070d6d9d077553f39961e75071710bb3260ec50f4df793b825b703145936a7c28f0f80fdbb9d00ab79efd0e4870686087eef02aeac1f7e0cac197ebe4290b3799d1e77c35a95276699d1047435ccb148e1499d8b60f8e76f2e82eb90e4f90c0cdb469785c30dbda2c3440a21a02e26937143787d2b7b639e0467dbf44e1609b9a8c908610f3529014315b5516765769cdf6f19fcd4700ee91a175426bd245b269e365474b09a33d9f1a509fee148744b07a02ad6566e3a06bf59cc86c7fe8b872692d232b34f1dd298ba4e036f0feccae79d0c8cb2dd82e493d9778f790500a5",
        "description": {
          "@value": "This is a desc",
          "@direction": "ltr",
          "@language": "en"
        },
        "id": "3576f9a8dfd718e8f6ec238433547ca71c6da23259d6fba36712ee3604188d17",
        "datatokenAddress": "0xa5b318dfb75B2f24a87d36791E378761B2174B11",
        "serviceEndpoint": "https://ocean-node-vm3.oceanenterprise.io",
        "state": 0,
        "type": "access",
        "timeout": 0
      },
      {
        "credentials": {
          "allow": [],
          "match_deny": "any",
          "deny": []
        },
        "name": "Service 2",
        "description": {
          "@value": "Service 2 description",
          "@direction": "ltr",
          "@language": "en"
        },
        "files": "0x047653de07d08d316bd10330bcc9ca42d5f3311f08d0e2e6a32931977f719f63be5ac816726ad0ce64628a4bd0f1b09b232d73afbf0274f39ec40ab58f6c938e52a8dbaa4a5d9197f4ae341e247de22736cb440e660ca5f1ea007ae96ad35b05975c0a5131bf2929658daa97bd86c5a04acb6cf2a020b328c59215b773cf5e0b11eea797b96547c96537327db7b41b207e6243039da87f8ed160aca0dc1dd9e879c63c83cb2d699942340c75f64d7cd71c6142ad28ff8a0dbc407d7541c4918e1d5a35b424c7aaf4039953ff56209763f98be0724d97c281e5ecaf6e8dbb9f4837bd87ce4dbb38144c6ec14df95acb42185df2911b9ffb7e3fd4aa7500ccfa2cc1b52ac045322888a500a97bf6e1adb57cece0c69e25d7818df0f2601792128874d6fca4d4032c7ce88ba869c09f0ed6c3b7f7bfbb11051db7f5182bbc6f556a7bb59820e55b9d79085ea618c87fa413166197ecf269c3dfb9a1b765d55f3f7e4cdf43",
        "id": "c052e00890d7f37585be1fa4f39923181fcb3a24872aca9e5c09973534dd3c45",
        "datatokenAddress": "0x9025391B26B38fEd0c4feBaE777Fd0633F4d6a5f",
        "serviceEndpoint": "https://ocean-node-vm3.oceanenterprise.io",
        "state": 0,
        "type": "access",
        "timeout": 86400
      }
    ],
    "nftAddress": "0x7090Eb5346929DdFaAac17d267a5d344381b19cB",
    "credentials": {
      "allow": [
        {
          "values": [
            {
              "address": "*"
            }
          ],
          "type": "address"
        }
      ],
      "deny": [],
      "match_deny": "any"
    },
    "stats": {
      "allocated": 0,
      "orders": 0,
      "price": {
        "value": 1,
        "tokenSymbol": "USDC",
        "tokenAddress": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238"
      }
    },
    "datatokens": [
      {
        "symbol": "OEAT",
        "address": "0xa5b318dfb75B2f24a87d36791E378761B2174B11",
        "name": "Access Token",
        "serviceId": "3576f9a8dfd718e8f6ec238433547ca71c6da23259d6fba36712ee3604188d17"
      },
      {
        "symbol": "OEAT",
        "address": "0x9025391B26B38fEd0c4feBaE777Fd0633F4d6a5f",
        "name": "Access Token",
        "serviceId": "c052e00890d7f37585be1fa4f39923181fcb3a24872aca9e5c09973534dd3c45"
      }
    ]
  },
  "additionalDdos": [],
  "type": [
    "VerifiableCredential"
  ],
  "issuer": "did:web:wallet2.demo.oceanenterprise.io:wallet-api:registry:OEdid",
  "proof": {
    "signature": "iyRgl1AaFKjyCwY4c0rCw9M67OVwOXKkKUpOD2tgN_qws3o260-oQxGA5kzKsNOwnpSClxTlNFoUWCrmx-9r7A",
    "header": {
      "kid": "7r1KFbygYbFTCVj2xK1wLvimt73LgxZDO__SOPx0w_A",
      "typ": "JWT",
      "alg": "ES256K"
    }
  },
  "indexedMetadata": {
    "stats": [
      {
        "symbol": "OEAT",
        "name": "Access Token",
        "orders": 0,
        "datatokenAddress": "0xa5b318dfb75B2f24a87d36791E378761B2174B11",
        "serviceId": "3576f9a8dfd718e8f6ec238433547ca71c6da23259d6fba36712ee3604188d17",
        "prices": [
          {
            "exchangeId": "0x6bd9c49449350aaa653dfe8c780760b6d5c456d31bdcaefdd0d6a7390b3d4107",
            "price": "1.0",
            "contract": "0xfa48673a7C36A2A768f89AC1ee8C355D5c367B02",
            "type": "fixedrate",
            "token": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238"
          }
        ]
      },
      {
        "symbol": "OEAT",
        "name": "Access Token",
        "orders": 0,
        "datatokenAddress": "0x9025391B26B38fEd0c4feBaE777Fd0633F4d6a5f",
        "serviceId": "c052e00890d7f37585be1fa4f39923181fcb3a24872aca9e5c09973534dd3c45",
        "prices": [
          {
            "exchangeId": "0xeab62d1ac355b547cd05a907987c201a7024cc3aeb71c7041fb4c37ae85335b5",
            "price": "1.0",
            "contract": "0xfa48673a7C36A2A768f89AC1ee8C355D5c367B02",
            "type": "fixedrate",
            "token": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4"
          }
        ]
      }
    ],
    "nft": {
      "state": 0,
      "address": "0x7090Eb5346929DdFaAac17d267a5d344381b19cB",
      "name": "Data NFT",
      "symbol": "OEC-NFT",
      "owner": "0xcF3185a502bE4b5Eb2c4Eb81646ECf7Dd0aC2f22",
      "created": "2026-06-23T06:09:24Z",
      "tokenURI": ""
    },
    "event": {
      "txid": "0x2cfb222c4ef199bcd8b113126e21d598fe91d840ad296493daaedc1c2eace272",
      "from": "0xcF3185a502bE4b5Eb2c4Eb81646ECf7Dd0aC2f22",
      "contract": "0x7090Eb5346929DdFaAac17d267a5d344381b19cB",
      "block": 11121002,
      "datetime": "2026-06-23T06:09:24.000Z"
    },
    "purgatory": {
      "state": false
    }
  },
  "accessDetails": [
    {
      "type": "fixed",
      "price": "1.0",
      "addressOrId": "0x6bd9c49449350aaa653dfe8c780760b6d5c456d31bdcaefdd0d6a7390b3d4107",
      "baseToken": {
        "address": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238",
        "name": "USDC",
        "symbol": "USDC",
        "decimals": 6
      },
      "datatoken": {
        "address": "0xa5b318dfb75B2f24a87d36791E378761B2174B11",
        "name": "Access Token",
        "symbol": "OEAT",
        "decimals": 0
      },
      "paymentCollector": "0xcF3185a502bE4b5Eb2c4Eb81646ECf7Dd0aC2f22",
      "templateId": 2,
      "isOwned": false,
      "validOrderTx": "",
      "isPurchasable": true,
      "publisherMarketOrderFee": "0"
    },
    {
      "type": "fixed",
      "price": "1.0",
      "addressOrId": "0xeab62d1ac355b547cd05a907987c201a7024cc3aeb71c7041fb4c37ae85335b5",
      "baseToken": {
        "address": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
        "name": "EURC",
        "symbol": "EURC",
        "decimals": 6
      },
      "datatoken": {
        "address": "0x9025391B26B38fEd0c4feBaE777Fd0633F4d6a5f",
        "name": "Access Token",
        "symbol": "OEAT",
        "decimals": 0
      },
      "paymentCollector": "0xcF3185a502bE4b5Eb2c4Eb81646ECf7Dd0aC2f22",
      "templateId": 2,
      "isOwned": false,
      "validOrderTx": "",
      "isPurchasable": true,
      "publisherMarketOrderFee": "0"
    }
  ]
}
```

{% endcode %}

### Dataset for computing with allowed algorithms and allowed algorithm publishers defined

The asset is of type `dataset` and has a service of type `compute`. The service accepts only a list of algorithms (identified by did and serviceID in the field `publisherTrustedAlgorithms`) and algorithm publishers (identified by web3 address in field `publisherTrustedAlgorithmPublishers`)&#x20;

{% code overflow="wrap" %}

```json
{
  "@context": [
    "https://www.w3.org/ns/credentials/v2"
  ],
  "id": "did:ope:ea37bfdf3c3d5ad57777db56ffbc1004a4f0f0a297731f37437e5e9d0921cd86",
  "version": "5.0.0",
  "credentialSubject": {
    "chainId": 11155111,
    "metadata": {
      "created": "2026-06-25T13:19:52Z",
      "updated": "2026-06-25T13:19:52Z",
      "type": "dataset",
      "name": "Test dataset - allowedAlgorithms and AllowedAlgorithmPublishers - 1",
      "description": {
        "@value": "Test dataset - allowedAlgorithms and AllowedAlgorithmPublishers - 1",
        "@direction": "ltr",
        "@language": "en"
      },
      "tags": [],
      "author": "",
      "license": {
        "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
        "licenseDocuments": [
          {
            "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
            "fileType": "text/html; charset=utf-8",
            "sha256": "79fc7fd736c48aa7fc18297e8dd5d54631b4f790331b7f4bcc9149081171a3ab",
            "additionalInformation": {
              "size": 224570
            },
            "displayName": {
              "@value": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
              "@language": "en",
              "@direction": "ltr"
            },
            "description": {
              "@value": "",
              "@language": "en",
              "@direction": "ltr"
            },
            "mirrors": [
              {
                "type": "url",
                "method": "get",
                "url": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf"
              }
            ]
          }
        ]
      },
      "additionalInformation": {
        "termsAndConditions": true
      },
      "copyrightHolder": "",
      "providedBy": ""
    },
    "services": [
      {
        "id": "a10c08a31657421035f258968c6fb49ffe7bc23e69bafdd319f559dd9421ae3d",
        "type": "compute",
        "files": "0x04e905d53f1b9e7709c86d5e13391231a5341b16767fccf0dc88b417611edd217dd3bdb044bfda29df46c05b5f80ef18315d5f56f98248cdd757b8f2015ac0164570ba0d879cd208ce4092d679b259580a99224b66adb0f1b2e7291e155d36bf04638954b11bbbc27645d8a16926f30d0073ce7f077bc2be80e4d0a1ff386b0778a05a48801189922df7fe4a47456324bc46b5ec876c3bfd3277e283126b4b5e3d22fead62a43d8653f045e7ed77c366df43694552f95d3a8e906a24d94a0f74034dd491cc15f0aceb4b5049953ad813c92cd89dacbbf0cd6638dfc3d131b6ba9c89eeb4bc341199f7bfd60d702ea0af2818adaa61196e85ca2603b05f06ce33e69b999f5cdbc967054d6f1b0544e9b0f2907aa1a0cdf41eae5dc1fa2ebea7b15ce43c70fac6b54203529c9a453efdf661dd1eeb671166562a7a869483a63c372dff4815f8e095fc73356fe4d51e7494b0d8ffde79787880c0aeb4991ffb9cac103e9daffa518a2e4fcea4e553e374984d76d460c9fd2ae95d",
        "datatokenAddress": "0x37300E09cb7543F09B7E4a0DBE219aDE2cEd582d",
        "serviceEndpoint": "https://ocean-node-vm3.oceanenterprise.io",
        "timeout": 86400,
        "compute": {
          "allowRawAlgorithm": false,
          "allowNetworkAccess": true,
          "publisherTrustedAlgorithmPublishers": [
            "0xd727fb9be39fa019d7c02fea19e54d688da3a662",
            "0x61db12d8b636cb49ea09eca58a893da9480e1f33"
          ],
          "publisherTrustedAlgorithms": [
            {
              "did": "did:ope:c68e6efe498f70cf0d671f9a405374176607d209546837e25b11cedbbcc9cd02",
              "containerSectionChecksum": "ee2da20f61e82ced3033ad6a7cb44fe136d91b715eaf2db2811ee0b0ad4a5b99",
              "filesChecksum": "2c36c054711dad021f45cc7e0990bd38864a51d753c8055b63e78014a6bee515",
              "serviceId": "4d89d718fc670b20217d97466e9612244e82aad21a40d19738d2a6ed0e3e8893"
            },
            {
              "did": "did:ope:c534e37e815b267d229c7051086f17c084ab72dce41af12df6f6daf900b30b16",
              "containerSectionChecksum": "2ea683746c6927342c7ea51ddd9b8acada2490c67a357ff9b41bda64fe05cb34",
              "filesChecksum": "dc0b0c89639614533fecd6ebe7dc53dcfbda96865322213dea7c3ecf88ad7ea4",
              "serviceId": "ae2367882fa6d10c006dcce30b4a2bdd70434f8348c0ed6431f2125b572b12f4"
            },
            {
              "did": "did:ope:b66c9ccce1b117711918ba1232e70d99c75e52a68a88a13639eed3a8450c41f8",
              "containerSectionChecksum": "dfce591ecb9b35c1c2931c8b38b4c216a61b40cd33407ab886df3b44c6b8904d",
              "filesChecksum": "ffd8c9b460451dd7d1677878f60cc93ce35a5a2517f08819761c0ddf424f7f88",
              "serviceId": "40c3fefb7b73c1a3190a437227d1954f8ef682676e26c1a914668f2d05401d22"
            }
          ]
        },
        "name": "Service 1 ",
        "description": {
          "@value": "Service 1 desc",
          "@direction": "ltr",
          "@language": "en"
        },
        "state": 0,
        "credentials": {
          "allow": [],
          "deny": [],
          "match_deny": "any"
        }
      }
    ],
    "nftAddress": "0xB92b1B08247A912c68d564010e1eeE3E01760eBE",
    "credentials": {
      "allow": [
        {
          "type": "address",
          "values": [
            {
              "address": "*"
            }
          ]
        }
      ],
      "deny": [],
      "match_deny": "any"
    },
    "stats": {
      "allocated": 0,
      "orders": 0,
      "price": {
        "value": 1,
        "tokenSymbol": "EURC",
        "tokenAddress": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4"
      }
    },
    "datatokens": [
      {
        "address": "0x37300E09cb7543F09B7E4a0DBE219aDE2cEd582d",
        "name": "Access Token",
        "symbol": "OEAT",
        "serviceId": "a10c08a31657421035f258968c6fb49ffe7bc23e69bafdd319f559dd9421ae3d"
      }
    ]
  },
  "additionalDdos": [],
  "type": [
    "VerifiableCredential"
  ],
  "issuer": "did:web:wallet2.demo.oceanenterprise.io:wallet-api:registry:publisher132",
  "proof": {
    "signature": "renUR-IRTGeCo_PJTwdJiO0X-h3xPj8H2XQNfG2oOYPezL9VQmhimp0ltWa_Itv9fqFULskf6Vt670Kj1iWkJA",
    "header": {
      "kid": "CqCLEltKrojmVXvWPApMYIbTupHhxI6dFwdJ8d2HUrk",
      "typ": "JWT",
      "alg": "ES256"
    }
  },
  "indexedMetadata": {
    "stats": [
      {
        "datatokenAddress": "0x37300E09cb7543F09B7E4a0DBE219aDE2cEd582d",
        "name": "Access Token",
        "symbol": "OEAT",
        "serviceId": "a10c08a31657421035f258968c6fb49ffe7bc23e69bafdd319f559dd9421ae3d",
        "orders": 0,
        "prices": [
          {
            "type": "fixedrate",
            "price": "1.0",
            "token": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
            "contract": "0xfa48673a7C36A2A768f89AC1ee8C355D5c367B02",
            "exchangeId": "0x79f8250202522028c0c1a26e9acf6c86c0fdeda096017c4b48a429fc7cdec58b"
          }
        ]
      }
    ],
    "nft": {
      "state": 0,
      "address": "0xB92b1B08247A912c68d564010e1eeE3E01760eBE",
      "name": "Data NFT",
      "symbol": "OEC-NFT",
      "owner": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "created": "2026-06-25T13:20:24Z",
      "tokenURI": ""
    },
    "event": {
      "txid": "0x7be6d1da632039b5e04c73ba813700458b2adf51ecb1c60c45e138b42aea3edd",
      "from": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "contract": "0xB92b1B08247A912c68d564010e1eeE3E01760eBE",
      "block": 11136986,
      "datetime": "2026-06-25T13:20:24.000Z"
    },
    "purgatory": {
      "state": false
    }
  },
  "accessDetails": [
    {
      "type": "fixed",
      "price": "1.0",
      "addressOrId": "0x79f8250202522028c0c1a26e9acf6c86c0fdeda096017c4b48a429fc7cdec58b",
      "baseToken": {
        "address": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
        "name": "EURC",
        "symbol": "EURC",
        "decimals": 6
      },
      "datatoken": {
        "address": "0x37300E09cb7543F09B7E4a0DBE219aDE2cEd582d",
        "name": "Access Token",
        "symbol": "OEAT",
        "decimals": 0
      },
      "paymentCollector": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "templateId": 2,
      "isOwned": false,
      "validOrderTx": "",
      "isPurchasable": true,
      "publisherMarketOrderFee": "0"
    }
  ]
}
```

{% endcode %}

### Dataset with SSI credentials

The dataset has a service of type access. SSI access credentials are defined at both the asset level (`credentialSubject.credentials field`) and service level (`credentialsSubject.services[0].credentials field`).

{% code overflow="wrap" %}

```json
{
  "@context": [
    "https://www.w3.org/ns/credentials/v2"
  ],
  "id": "did:ope:adb0746adc797cbf9bf72e65bd4c3107de67e33940624e473be21418ee387b03",
  "version": "5.0.0",
  "credentialSubject": {
    "chainId": 11155111,
    "metadata": {
      "created": "2026-06-26T09:54:54Z",
      "updated": "2026-06-26T09:54:54Z",
      "type": "dataset",
      "name": "test dataset - credentials - 1",
      "description": {
        "@value": "test dataset - credentials - 1",
        "@direction": "ltr",
        "@language": "en"
      },
      "tags": [],
      "author": "",
      "license": {
        "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
        "licenseDocuments": [
          {
            "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
            "fileType": "text/html; charset=utf-8",
            "sha256": "33f1b2a911308034b4d5aba53a197ddc51102c774002b45034e342fdc17598e9",
            "additionalInformation": {
              "size": 224919
            },
            "displayName": {
              "@value": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
              "@language": "en",
              "@direction": "ltr"
            },
            "description": {
              "@value": "",
              "@language": "en",
              "@direction": "ltr"
            },
            "mirrors": [
              {
                "type": "url",
                "method": "get",
                "url": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf"
              }
            ]
          }
        ]
      },
      "additionalInformation": {
        "termsAndConditions": true
      },
      "copyrightHolder": "",
      "providedBy": ""
    },
    "services": [
      {
        "id": "ae7883d0ea3d8f95db7b2e56d2397868d2320f6527bc6196fea4447884c15d7d",
        "type": "access",
        "files": "0x04941434fb61204e63121271fb0b3e036aa52b821b6b9dbdd7c1818bcc729f60fc5523de16c74b6ad543293a8f33a20b0d3a00d8ff4ad17d0a08fd61dcd66c76e746f6d8db1f8571ce31944c67fa46ccc247eaf230f25e200147f3f055f936298e7134523bdb46fa0875b1787c0a8476931005cee788a7206187ab01989176996389d2602ec28dae05d4499ae03a604335d96444074b0e7ae56e82b0f8c24a0db069c6ec6517eb062594e3e63003085197af2bcb1c0b0095131bcbd2393f5650ccf8a2e864a64ec5d90d1a6e09352d2bbfd87170c72693ecac4c9b735b409f05504477f4f8b659df0af854fa5f264b376e2ef816a5890fe172ad19ddd2b54f6484ed19d7b3040aa18d97c0e4e53aeaa21199164a5539425e2e1fe0cb3022f595e60b684499ad40d748b9d23ffab7a9c1a9992f0f8e731c0f1daf2518c68bb10a00a14727549e8ab7fdecf2cce445ae45ad691c76ec37afc9db2e95eee8f155f6bc81bb5efee2f5a774768b9ede84921050a689baa3f34d0b51",
        "datatokenAddress": "0xeEaB3064435c7710e7637d50c26A4Cb365E753B0",
        "serviceEndpoint": "https://ocean-node-vm3.oceanenterprise.io",
        "timeout": 86400,
        "name": "Service 1 ",
        "description": {
          "@value": "Service 1 desc",
          "@direction": "ltr",
          "@language": "en"
        },
        "state": 0,
        "credentials": {
          "allow": [
            {
              "type": "SSIpolicy",
              "values": [
                {
                  "request_credentials": [
                    {
                      "format": "jwt_vc_json",
                      "policies": [
                        {
                          "policy": "dynamic",
                          "args": {
                            "policy_name": "companyId",
                            "opa_server": "http://ocean-node-vm3.oceanenterprise.io:8181",
                            "policy_query": "data",
                            "rules": {
                              "rego": "package data.companyId\n\ndefault allow := false\n\nallow if {\n  lower(input.credentialData.credentialSubject[\"gx:vatID\"]) == lower(input.parameter.param1)\n}"
                            },
                            "argument": {
                              "param1": "12345678"
                            }
                          }
                        }
                      ],
                      "type": "gx:VatID"
                    }
                  ]
                }
              ]
            },
            {
              "type": "address",
              "values": [
                {
                  "address": "*"
                }
              ]
            }
          ],
          "deny": [],
          "match_deny": "any"
        }
      }
    ],
    "nftAddress": "0x4C918c866ba6399090711B47Cd07110E4aF886Aa",
    "credentials": {
      "allow": [
        {
          "type": "SSIpolicy",
          "values": [
            {
              "request_credentials": [
                {
                  "format": "jwt_vc_json",
                  "policies": [
                    "expired"
                  ],
                  "type": "gx:LegalPerson"
                },
                {
                  "format": "jwt_vc_json",
                  "policies": [
                    {
                      "policy": "allowed-issuer",
                      "args": [
                        "did:GXCH"
                      ]
                    }
                  ],
                  "type": "gx:Issuer"
                },
                {
                  "format": "jwt_vc_json",
                  "policies": [
                    {
                      "policy": "dynamic",
                      "args": {
                        "policy_name": "countryGermany",
                        "opa_server": "http://ocean-node-vm3.oceanenterprise.io:8181",
                        "policy_query": "data",
                        "rules": {
                          "rego": "package data.countryGermany\n\ndefault allow := false\n\nallow if {\n  lower(input.credentialData.credentialSubject[\"gx:countryCode\"]) == lower(input.parameter.param1)\n}"
                        },
                        "argument": {
                          "param1": "DE"
                        }
                      }
                    }
                  ],
                  "type": "gx:LeiCode"
                }
              ],
              "vc_policies": [
                "not-before",
                "revoked-status-list",
                "signature"
              ],
              "vp_policies": [
                {
                  "policy": "holder-binding"
                },
                {
                  "policy": "presentation-definition"
                },
                {
                  "policy": "minimum-credentials",
                  "args": "2"
                },
                {
                  "policy": "vp_required_credentials",
                  "args": "{\"required\":[{\"credential_type\":\"gx:LegalPerson\"},{\"any_of\":[\"gx:LeiCode\",\"gx:Issuer\"]}]}"
                }
              ]
            }
          ]
        },
        {
          "type": "address",
          "values": [
            {
              "address": "*"
            }
          ]
        }
      ],
      "deny": [],
      "match_deny": "any"
    },
    "stats": {
      "allocated": 0,
      "orders": 0,
      "price": {
        "value": 1,
        "tokenSymbol": "EURC",
        "tokenAddress": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4"
      }
    },
    "datatokens": [
      {
        "address": "0xeEaB3064435c7710e7637d50c26A4Cb365E753B0",
        "name": "Access Token",
        "symbol": "OEAT",
        "serviceId": "ae7883d0ea3d8f95db7b2e56d2397868d2320f6527bc6196fea4447884c15d7d"
      }
    ]
  },
  "additionalDdos": [],
  "type": [
    "VerifiableCredential"
  ],
  "issuer": "did:web:wallet2.demo.oceanenterprise.io:wallet-api:registry:publisher132",
  "proof": {
    "signature": "An0ocY932YWWM3NaDdyTmnERHkPkIp-Hqpl_EZOu80xNAScDXnyk38mqgUyrigTgiJMdyc75GxzpZYQAzjxe-w",
    "header": {
      "kid": "6fvEXSWtuRtxIKQtezO8wWW3EyEj4ouvSZripxo8J1U",
      "typ": "JWT",
      "alg": "ES256"
    }
  },
  "indexedMetadata": {
    "stats": [
      {
        "datatokenAddress": "0xeEaB3064435c7710e7637d50c26A4Cb365E753B0",
        "name": "Access Token",
        "symbol": "OEAT",
        "serviceId": "ae7883d0ea3d8f95db7b2e56d2397868d2320f6527bc6196fea4447884c15d7d",
        "orders": 0,
        "prices": [
          {
            "type": "fixedrate",
            "price": "1.0",
            "token": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
            "contract": "0xfa48673a7C36A2A768f89AC1ee8C355D5c367B02",
            "exchangeId": "0xb3ae790b58d0168f3735cad5c93931966600964853175667b501fcd18f968d37"
          }
        ]
      }
    ],
    "nft": {
      "state": 0,
      "address": "0x4C918c866ba6399090711B47Cd07110E4aF886Aa",
      "name": "Data NFT",
      "symbol": "OEC-NFT",
      "owner": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "created": "2026-06-26T09:56:00Z",
      "tokenURI": ""
    },
    "event": {
      "txid": "0x9c01d538f1cee7d00f5bae0582ecf5f533180f821671424fcde895f1abf06fdd",
      "from": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "contract": "0x4C918c866ba6399090711B47Cd07110E4aF886Aa",
      "block": 11143144,
      "datetime": "2026-06-26T09:56:00.000Z"
    },
    "purgatory": {
      "state": false
    }
  },
  "accessDetails": [
    {
      "type": "fixed",
      "price": "1.0",
      "addressOrId": "0xb3ae790b58d0168f3735cad5c93931966600964853175667b501fcd18f968d37",
      "baseToken": {
        "address": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
        "name": "EURC",
        "symbol": "EURC",
        "decimals": 6
      },
      "datatoken": {
        "address": "0xeEaB3064435c7710e7637d50c26A4Cb365E753B0",
        "name": "Access Token",
        "symbol": "OEAT",
        "decimals": 0
      },
      "paymentCollector": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "templateId": 2,
      "isOwned": false,
      "validOrderTx": "",
      "isPurchasable": true,
      "publisherMarketOrderFee": "0"
    }
  ]
}
```

{% endcode %}

### Algorithm for computing&#x20;

The asset is of type algorithm. It has two services - Algo 1 and Algo 2 - both usable only in a compute-to-data environment (`credentialSubject.services[].type` is `"compute"`).&#x20;

The algorithms provided by Algo 1 and Algo 2 are written in JavaScript (`credentialSubject.algorithm.language` is `"js"`) and use the latest node.js image (`credentialSubject.algorithm.container.image` is `"node"`, `credentialSubject.algorithm.container.tag`is `"latest"`).&#x20;

The asset allows network access when the algorithms are executed in a C2D environment (`credentialSubject.services[].compute.allowNetworkAccess` is `true`).

{% code overflow="wrap" %}

```json
{
  "@context": [
    "https://www.w3.org/ns/credentials/v2"
  ],
  "id": "did:ope:c534e37e815b267d229c7051086f17c084ab72dce41af12df6f6daf900b30b16",
  "version": "5.0.0",
  "credentialSubject": {
    "chainId": 11155111,
    "metadata": {
      "created": "2026-06-23T10:38:04Z",
      "updated": "2026-06-24T09:37:29.998Z",
      "type": "algorithm",
      "name": "Test algo - cookies - SSI - C2D - 3",
      "description": {
        "@value": "Test algo - cookies - SSI - C2D - 3",
        "@direction": "ltr",
        "@language": "en"
      },
      "tags": [],
      "author": "",
      "license": {
        "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
        "licenseDocuments": [
          {
            "additionalInformation": {
              "size": 224420
            },
            "sha256": "87b7148db85eb00fdb4e657827519d323be4b260c0264202638864d6f54a3731",
            "mirrors": [
              {
                "method": "get",
                "type": "url",
                "url": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf"
              }
            ],
            "displayName": {
              "@value": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
              "@direction": "ltr",
              "@language": "en"
            },
            "name": "https://github.com/MBadea17/testdata/blob/af26d4f968fdb6e1882c2a3cca16a1480ca44a9c/License%20Agreement.pdf",
            "description": {
              "@value": "",
              "@direction": "ltr",
              "@language": "en"
            },
            "fileType": "text/html; charset=utf-8"
          }
        ]
      },
      "additionalInformation": {
        "termsAndConditions": true
      },
      "algorithm": {
        "language": "js",
        "version": "0.1",
        "container": {
          "entrypoint": "node $ALGO",
          "image": "node",
          "tag": "latest",
          "checksum": "sha256:d402fe9c95ecdcd8adb4a4125c032b40e6753a0a7c7cc74a659e7b0a90ef83ce"
        }
      },
      "copyrightHolder": "",
      "providedBy": ""
    },
    "services": [
      {
        "compute": {
          "publisherTrustedAlgorithms": [
            {
              "filesChecksum": "*",
              "containerSectionChecksum": "*",
              "serviceId": "*",
              "did": "*"
            }
          ],
          "publisherTrustedAlgorithmPublishers": [
            "*"
          ],
          "allowRawAlgorithm": false,
          "allowNetworkAccess": true
        },
        "credentials": {
          "allow": [],
          "match_deny": "any",
          "deny": []
        },
        "name": "Algo 1 ",
        "files": "0x040dbdf3d97493316012ced90ae27ab1a6a549328dbfece81ef68fc50b7bea540afb6d40253a42db8dabbca327c039eb211e4fa6c8ceddd92e4e532f1f8b190619b939355e92e29c033314794fb4eede45fc3cff206ca450883ae6e43c3b5ebe9174cc741cb7a7e4118fe06824a1bf4fa708c8a75ce2ce325ecb1acc9e42def0f42bacc4afdedec734a4880e8e9f376f4a712787d3f8326ad3e9fc1e68844bebbf766156022ca3dcc3f52e327fb4468ab6a8ac6747cd0644bf5bce371ed65d3f8b8d1da612343dd854ce7f1093f0c9792be583698694099771aa6f7d1f3641a69299af42a644823b9f903bf7dc9feb7e50d552c2b8925d4214b576bade2a4db8dfdca58bf12550e6b358a82089152cc00ed16e8ed71220f45e79dcf3a32f91a70c7bde54f11c5773d0a4505dd0373fb3c0184816bedd90f40d324f27f12f4702774fb997b8d1bfd1ef32a5d9577cc9f0d3f1372aa1559af371e756b5acb971b3ec055408c1af80c99d2ff0ca22c5a636d4e692ab7bc8b9",
        "description": {
          "@value": "Algo 1 Algo 1 Algo 1 ",
          "@direction": "ltr",
          "@language": "en"
        },
        "id": "9b551945221a471a809695ede021c4d27db7d359a6ff3f413a1de8fd201d980e",
        "datatokenAddress": "0x240E8715Abb05594331002ED3ECAA9a656ED5757",
        "serviceEndpoint": "https://ocean-node-vm3.oceanenterprise.io",
        "state": 0,
        "type": "compute",
        "timeout": 86400
      },
      {
        "credentials": {
          "allow": [],
          "match_deny": "any",
          "deny": []
        },
        "name": "Algo 2",
        "description": {
          "@value": "Algo 2 description",
          "@direction": "ltr",
          "@language": "en"
        },
        "files": "0x04958b4d8dfdf784b7aa9a31d1fad9ff50d776981ef683ebb65215c5c450d673ab0bf16991723bc776bd037d91eaeb97b41949f5f0e3b8c041cc0ce131b70e01a36975c161e0a2bc81edc966a031e42cd672f7718e5a37d41a2a7c05a453a1ec6239d121107d73a1d4aa478dc707b3d243c39e65df02d5cd8b009331a45f4454c9c6687bad80ba1112a89c797fb88ec58c3416b51b5888c8722b33b394f7ff17640c7648edbdcc065e78c004fcb1f00a44d57b55ae0748182a4b9e050e756ede3b0ef74dd073e65b96b2d78244d18358568790dc4ed756965833d92ffe29fdef2a555476a20937f9f68ee1c4eadcdfab91965a8be4e88ad90963b354837fbf7178c0c2400e42c1ebbcf7f21487ce01105eabe0ef9c63494e81e2ce5a35051ab43b39050af8ed839a204b5cb024ecf085f51195880b5dd04da59c0998dd0decf2c07108bdfa0acc18cd2e301ecdf5001043ec4dc9bdf409677239def47af82bf1d833a755b48cd5dd79c294893fe45d4717c95267d11a",
        "id": "ae2367882fa6d10c006dcce30b4a2bdd70434f8348c0ed6431f2125b572b12f4",
        "datatokenAddress": "0x9f0c0Ab7c5053F3C1194AF08a487560F19655D85",
        "serviceEndpoint": "https://ocean-node-vm3.oceanenterprise.io",
        "state": 0,
        "type": "compute",
        "timeout": 86400,
        "consumerParameters": [
          {
            "default": "abcd",
            "name": "param1",
            "description": "Parameter 1",
            "label": "Parameter 1",
            "type": "text",
            "required": false
          },
          {
            "default": "1234",
            "name": "param2",
            "description": "Parameter 2",
            "label": "Parameter 2",
            "type": "number",
            "required": true
          }
        ]
      }
    ],
    "nftAddress": "0x24a4Dc380884BEfdaEFBc57f8403B1AbE1B36884",
    "credentials": {
      "allow": [
        {
          "values": [
            {
              "request_credentials": [
                {
                  "format": "jwt_vc_json",
                  "policies": [],
                  "type": "gx:Issuer"
                }
              ],
              "vc_policies": [
                "not-before",
                "revoked-status-list"
              ]
            }
          ],
          "type": "SSIpolicy"
        },
        {
          "values": [
            {
              "address": "*"
            }
          ],
          "type": "address"
        }
      ],
      "deny": [],
      "match_deny": "any"
    },
    "stats": {
      "allocated": 0,
      "orders": 0,
      "price": {
        "value": 1,
        "tokenSymbol": "EURC",
        "tokenAddress": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4"
      }
    },
    "datatokens": [
      {
        "symbol": "OEAT",
        "address": "0x240E8715Abb05594331002ED3ECAA9a656ED5757",
        "name": "Access Token",
        "serviceId": "9b551945221a471a809695ede021c4d27db7d359a6ff3f413a1de8fd201d980e"
      },
      {
        "symbol": "OEAT",
        "address": "0x9f0c0Ab7c5053F3C1194AF08a487560F19655D85",
        "name": "Access Token",
        "serviceId": "ae2367882fa6d10c006dcce30b4a2bdd70434f8348c0ed6431f2125b572b12f4"
      }
    ]
  },
  "additionalDdos": [],
  "type": [
    "VerifiableCredential"
  ],
  "issuer": "did:web:wallet2.demo.oceanenterprise.io:wallet-api:registry:publisher132",
  "proof": {
    "signature": "9Sv9yP28X9thsg19sjvq03C5mJaY_XkWXtQhK3dBL5s3Clr8PeW4NDv-S5bWIJQN31r9BEdKTHm67UpQ3gza-w",
    "header": {
      "kid": "CqCLEltKrojmVXvWPApMYIbTupHhxI6dFwdJ8d2HUrk",
      "typ": "JWT",
      "alg": "ES256"
    }
  },
  "indexedMetadata": {
    "stats": [
      {
        "symbol": "OEAT",
        "name": "Access Token",
        "orders": 1,
        "datatokenAddress": "0x240E8715Abb05594331002ED3ECAA9a656ED5757",
        "serviceId": "9b551945221a471a809695ede021c4d27db7d359a6ff3f413a1de8fd201d980e",
        "prices": [
          {
            "exchangeId": "0xfe538dc442017db7d6aff19f58c6012224ba8be8fabbbb4404ef9ea0ed07addf",
            "price": "1.0",
            "contract": "0xfa48673a7C36A2A768f89AC1ee8C355D5c367B02",
            "type": "fixedrate",
            "token": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4"
          }
        ]
      },
      {
        "symbol": "OEAT",
        "name": "Access Token",
        "orders": 0,
        "datatokenAddress": "0x9f0c0Ab7c5053F3C1194AF08a487560F19655D85",
        "serviceId": "ae2367882fa6d10c006dcce30b4a2bdd70434f8348c0ed6431f2125b572b12f4",
        "prices": [
          {
            "exchangeId": "0x8510e6141bddd79ac640ac6ee5c8c85735c9036f0a864cdc2927630219c7b735",
            "price": "1.0",
            "contract": "0xfa48673a7C36A2A768f89AC1ee8C355D5c367B02",
            "type": "fixedrate",
            "token": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238"
          }
        ]
      }
    ],
    "nft": {
      "state": 0,
      "address": "0x24a4Dc380884BEfdaEFBc57f8403B1AbE1B36884",
      "name": "Data NFT",
      "symbol": "OEC-NFT",
      "owner": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "created": "2026-06-24T09:38:36Z",
      "tokenURI": ""
    },
    "event": {
      "txid": "0x34e6ca9814b546c047ddc75682e9bf5c2aa374171020ebbbcc02d4816ae56ee7",
      "from": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "contract": "0x24a4Dc380884BEfdaEFBc57f8403B1AbE1B36884",
      "block": 11129055,
      "datetime": "2026-06-24T09:38:36.000Z"
    },
    "purgatory": {
      "state": false
    }
  },
  "accessDetails": [
    {
      "type": "fixed",
      "price": "1.0",
      "addressOrId": "0xfe538dc442017db7d6aff19f58c6012224ba8be8fabbbb4404ef9ea0ed07addf",
      "baseToken": {
        "address": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
        "name": "EURC",
        "symbol": "EURC",
        "decimals": 6
      },
      "datatoken": {
        "address": "0x240E8715Abb05594331002ED3ECAA9a656ED5757",
        "name": "Access Token",
        "symbol": "OEAT",
        "decimals": 0
      },
      "paymentCollector": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "templateId": 2,
      "isOwned": false,
      "validOrderTx": "",
      "isPurchasable": true,
      "publisherMarketOrderFee": "0"
    },
    {
      "type": "fixed",
      "price": "1.0",
      "addressOrId": "0x8510e6141bddd79ac640ac6ee5c8c85735c9036f0a864cdc2927630219c7b735",
      "baseToken": {
        "address": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238",
        "name": "USDC",
        "symbol": "USDC",
        "decimals": 6
      },
      "datatoken": {
        "address": "0x9f0c0Ab7c5053F3C1194AF08a487560F19655D85",
        "name": "Access Token",
        "symbol": "OEAT",
        "decimals": 0
      },
      "paymentCollector": "0x00Dc9e712D3b31Ab5446A5A7CeaDe0a2901E6d26",
      "templateId": 2,
      "isOwned": false,
      "validOrderTx": "",
      "isPurchasable": true,
      "publisherMarketOrderFee": "0"
    }
  ]
}
```

{% endcode %}

## The on-chain part of the DDO

On-chain, the following object is saved:

{% code overflow="wrap" %}

```javascript
const remoteAsset = {
    remote: {
      type: 'ipfs',
      hash: ipfsHash
    }
  }
```

{% endcode %}

* the `type` field is 'ipfs', meaning that the referenced remote object is saved in IPFS
* the `hash` field contains the hash of the Content ID (CID) where the asset's DDO is saved in IPFS.&#x20;

## References

### SHACL schema

* The SHACL schema used by the OE Node's indexer component to validate the DDO's at publishing or editing time is available here: <https://github.com/oceanprotocol/ddo.js/blob/main/schemas/5.0.0.ttl>


# Managing access to assets - to be updated

Fine-Grained Permissions Using Role-Based Access Control. You can Control who can publish, buy or browse data

<mark style="background-color:yellow;">an OE-enabled dataspace can be deployed in one of two security configurations:</mark>

<mark style="background-color:yellow;">1. SSI Security Disabled: In configurations where SSI security is disabled, access control relies solely on the consumer’s Web3 address. Access to an asset is granted if:</mark>&#x20;

* <mark style="background-color:yellow;">The address is explicitly listed in the allow list, or</mark>&#x20;
* <mark style="background-color:yellow;">The address is not present in the deny list</mark>

<mark style="background-color:yellow;">2. SSI Security Enabled: In a dataspace secured by Self-Sovereign Identity (SSI), access to assets is granted upon successful verification of:</mark>&#x20;

* &#x20;<mark style="background-color:yellow;">The consumer’s Web3 address</mark>
* <mark style="background-color:yellow;">The Verifiable Credentials required by each asset.</mark>&#x20;

<mark style="background-color:yellow;">This dual-layered approach ensures that only authorized identities possessing the appropriate credentials can interact with sensitive resources.</mark>

A large part of Ocean is about access control, which is primarily handled by datatokens. Users can access a resource (e.g. a file) by redeeming datatokens for that resource. We recognize that enterprises and other users often need more precise ways to specify and manage access, and we have introduced fine-grained permissions for these use cases. Fine-grained permissions mean that access can be controlled precisely at two levels:

* [Marketplace-level permissions](#market-level-permissions) for browsing, downloading or publishing within a marketplace frontend.
* [Asset-level permissions](#asset-level-restrictions) on downloading a specific asset.

The fine-grained permissions features are designed to work in forks of Ocean Market. We have not enabled them in Ocean Market itself, to keep Ocean Market open for everyone to use. On the front end, the permissions features are easily enabled by setting environment variables.

### Introduction

Some datasets need to be restricted to appropriately credentialed users. In this situation there is tension:

1. Datatokens on their own aren’t enough - the datatokens can be exchanged without any restrictions, which means anyone can acquire them and access the data.
2. We want to retain datatokens approach, since they enable Ocean users to leverage existing crypto infrastructure e.g. wallets, exchange etc.

We can resolve this tension by drawing on the following analogy:

> Imagine going to an age 18+ rock concert. You can only get in if you show both (a) your concert ticket and (b) an id showing that you’re old enough.

We can port this model into Ocean, where (a) is a datatoken, and (b) is a credential. The datatoken is the baseline access control. It’s fungible, and something that you’ve paid for or had shared to you. It’s independent of your identity. The credential is something that’s a function of your identity.

The credential based restrictions are implemented in two ways, at the market level and at the asset level. Access to the market is restricted on a role basis, the user's identity is attached to a role via the role based access control (RBAC) server. Access to individual assets is restricted via allow and deny lists which list the ethereum addresses of the users who can and cannot access the asset within the DDO.

### Asset-Level Restrictions

For asset-level restrictions Ocean supports allow and deny lists. Allow and deny lists are advanced features that allow publishers to control access to individual data assets. Publishers can restrict assets so that they can only be accessed by approved users (allow lists) or they can restrict assets so that they can be accessed by anyone except certain users (deny lists).

When an allow-list is in place, a consumer can only access the resource if they have a datatoken and one of the credentials in the "allow" list of the DDO. Ocean also has complementary deny functionality: if a consumer is on the "deny" list, they will not be allowed to access the resource.

Initially, the only credential supported is Ethereum public addresses. To be fair, it’s more a pointer to an individual not a credential; but it has a low-complexity implementation so makes a good starting point. For extensibility, the Ocean metadata schema enables specification of other types of credentials like W3C Verifiable Credentials and more. When this gets implemented, asset-level permissions will be properly RBAC too. Since asset-level permissions are in the DDO, and the DDO is controlled by the publisher, asset-level restrictions are controlled by the publisher.

### Market-Level Permissions

For market-level permissions, Ocean implements a role-based access control server (RBAC server). It implements restrictions at the user level, based on the user’s role (credentials). The RBAC server is run & controlled by the marketplace owner. Therefore permissions at this level are at the discretion of the marketplace owner.

The RBAC server is the primary mechanism for restricting your users ability to publish, buy, or browse assets in the market.

#### Roles

The RBAC server defines four different roles:

* Admin
* Publisher
* Consumer
* User

**Admin/ Publisher**

Currently users with either the admin or publisher roles will be able to use the Market without any restrictions. They can publish, buy and browse datasets.

**Consumer**

A user with the consumer is able to browse datasets, purchase them, trade datatokens and also contribute to datapools. However, they are not able to publish datasets.

**Users**

Users are able to browse and search datasets but they are not able to purchase datasets, trade datatokens, or contribute to data pools. They are also not able to publish datasets.

**Address without a role**

If a user attempts to view the data market without a role, or without a wallet connected, they will not be able to view or search any of the datasets.

**No wallet connected**

When the RBAC server is enabled on the market, users are required to have a wallet connected to browse the datasets.

#### Mapping roles to addresses

Currently the are two ways that the RBAC server can be configured to map user roles to Ethereum addresses. The RBAC server is also built in such a way that it is easy for you to add your own authorization service. They two existing methods are:

1. Keycloak

If you already have a [Keycloak](https://www.keycloak.org/) identity and access management server running you can configure the RBAC server to use it by adding the URL of your Keycloak server to the `KEYCLOAK_URL` environmental variable in the RBAC `.enb` file.

2. JSON

Alternatively, if you are not already using Keycloak, the easiest way to map user roles to ethereum addresses is in a JSON object that is saved as the `JSON_DATA` environmental variable in the RBAC `.env` file. There is an example of the format required for this JSON object in `.example.env`

It is possible that you can configure both of these methods of mapping user roles to Ethereum Addresses. In this case the requests to your RBAC server should specify which auth service they are using e.g. `"authService": "json"` or `"authService": "keycloak"`

**Default Auth service**

Additionally, you can also set an environmental variable within the RBAC server that specifies the default authorization method that will be used e.g. `DEFAULT_AUTH_SERVICE = "json"`. When this variable is specified, requests sent to your RBAC server don't need to include an `authService` and they will automatically use the default authorization method.

#### Running the RBAC server locally

You can start running the RBAC server by following these steps:

1. Clone this repository:

```bash
git clone https://github.com/oceanprotocol/RBAC-Server.git
cd RBAC-Server
```

2. Install the dependencies:

```bash
npm install
```

3. Build the service

```bash
npm run build
```

4. Start the server

```bash
npm run start
```

#### Running the RBAC in Docker

When you are ready to deploy the RBAC server to

1. Replace the KEYCLOAK\_URL in the Dockerfile with the correct URL for your hosting of [Keycloak](https://www.keycloak.org/).
2. Run the following command to build the RBAC service in a Docker container:

```bash
npm run build:docker
```

3. Next, run the following command to start running the RBAC service in the Docker container:

```bash
npm run start:docker
```

4. Now you are ready to send requests to the RBAC server via postman. Make sure to replace the URL to `http://localhost:49160` in your requests.


# Supported networks & currencies

All the public networks to which the Ocean Enterprise contracts are deployed, and the currencies in which the published assets and C2D resources can be listed.

* [Supported networks](/developers/networks/supported-networks)
* [Supported currencies](/developers/networks/supported-currencies)


# Supported Networks

## Supported Networks

Ocean Enterprise smart contracts are deployed across multiple public networks, including several production chains and several testnets.

The file [`address.json`](https://github.com/oceanprotocol/contracts/blob/v4main/addresses/address.json)  holds up-to-date deployment addresses for all Ocean contracts.

### Networks Summary

The networks where Ocean Enterprise smart contracts are deployed are:

**Production Networks:**

* Ethereum Mainnet
* Optimism (OP) Mainnet

**Test Networks:**

* Ethereum Sepolia
* Optimism (OP) Sepolia

### Production Networks

The smart contracts deployed by O.E.C. in the production networks and used by default by the Ocean Enterprise components are available at the following addresses.

* **Ethereum Mainnet**

<table><thead><tr><th width="317">Smart Contract</th><th>Address</th></tr></thead><tbody><tr><td>EnterpriseFeeCollector</td><td><a href="https://etherscan.io/address/0x254302d1Ae1e1200319c885D93D40a8927ACFcD7"><code>0x254302d1Ae1e1200319c885D93D40a8927ACFcD7</code></a></td></tr><tr><td>FixedPriceEnterprise</td><td><a href="https://etherscan.io/address/0x6C97D128f7E7D21ac3C722458Dc5d71f7e1bBa6e"><code>0x6C97D128f7E7D21ac3C722458Dc5d71f7e1bBa6e</code></a></td></tr><tr><td>EnterpriseEscrow</td><td><a href="https://etherscan.io/address/0x7F773EE2B8AFE158FA03B72fC20672B408Cd9818"><code>0x7F773EE2B8AFE158FA03B72fC20672B408Cd9818</code></a></td></tr><tr><td>ERC20Template Enterprise</td><td><a href="https://etherscan.io/address/0x3E85e7Cb15880b6d4871092E74bF65CE03E8448D"><code>0x3E85e7Cb15880b6d4871092E74bF65CE03E8448D</code></a></td></tr></tbody></table>

* **Optimism Mainnet**

<table><thead><tr><th width="317">Smart Contract</th><th>Address</th></tr></thead><tbody><tr><td>EnterpriseFeeCollector</td><td><a href="https://optimistic.etherscan.io/address/0xE9397625Df9B63f0C152f975234b7988b54710B8"><code>0xE9397625Df9B63f0C152f975234b7988b54710B8</code></a></td></tr><tr><td>FixedPriceEnterprise</td><td><a href="https://optimistic.etherscan.io/address/0x1d535147a97bd87c8443125376E6671B60556E07"><code>0x1d535147a97bd87c8443125376E6671B60556E07</code></a></td></tr><tr><td>EnterpriseEscrow</td><td><a href="https://optimistic.etherscan.io/address/0xc313e19146Fc9a04470689C9d41a4D3054693531#code"><code>0xc313e19146Fc9a04470689C9d41a4D3054693531</code></a></td></tr><tr><td>ERC20Template Enterprise</td><td><a href="https://optimistic.etherscan.io/address/0x1B083D8584dd3e6Ff37d04a6e7e82b5F622f3985#code"><code>0x1B083D8584dd3e6Ff37d04a6e7e82b5F622f3985</code></a></td></tr></tbody></table>

&#x20;

### Test Networks

The smart contracts deployed by O.E.C. in the test networks and used by default by the Ocean Enterprise components are available at the following addresses.

&#x20;

* **Ethereum Sepolia**

<table><thead><tr><th width="317">Smart Contract</th><th>Address</th></tr></thead><tbody><tr><td>EnterpriseFeeCollector</td><td><a href="https://sepolia.etherscan.io/address/0x4D49eEedFac8Ea03328c0E4871b680C06d892092"><code>0x4D49eEedFac8Ea03328c0E4871b680C06d892092</code></a></td></tr><tr><td>FixedPriceEnterprise</td><td><a href="https://sepolia.etherscan.io/address/0xEcD0C3519a081e3924D6F3197f86980eA7dfCf71"><code>0xEcD0C3519a081e3924D6F3197f86980eA7dfCf71</code></a></td></tr><tr><td>EnterpriseEscrow</td><td><a href="https://sepolia.etherscan.io/address/0x5494711392a67DA50D3bC7b1fcC2d1877cFaA4d2"><code>0x5494711392a67DA50D3bC7b1fcC2d1877cFaA4d2</code></a></td></tr><tr><td>ERC20Template Enterprise</td><td><a href="https://sepolia.etherscan.io/address/0xDEfD0018969cd2d4E648209F876ADe184815f038"><code>0xDEfD0018969cd2d4E648209F876ADe184815f038</code></a></td></tr></tbody></table>

* **Optimism Sepolia**

<table><thead><tr><th width="317">Smart Contract</th><th>Address</th></tr></thead><tbody><tr><td>EnterpriseFeeCollector</td><td><a href="https://testnet-explorer.optimism.io/address/0x43eC0a34E1b70C7f8E579ab866F37642777727E7"><code>0x43eC0a34E1b70C7f8E579ab866F37642777727E7</code></a></td></tr><tr><td>FixedPriceEnterprise</td><td><a href="https://testnet-explorer.optimism.io/address/0x6976320eC365202118B4B0B0906E13DDf21633A5?tab=index"><code>0x6976320eC365202118B4B0B0906E13DDf21633A5</code></a></td></tr><tr><td>EnterpriseEscrow</td><td><a href="https://testnet-explorer.optimism.io/address/0x5494711392a67DA50D3bC7b1fcC2d1877cFaA4d2?tab=index"><code>0x5494711392a67DA50D3bC7b1fcC2d1877cFaA4d2</code></a></td></tr><tr><td>ERC20Template Enterprise</td><td><a href="https://testnet-explorer.optimism.io/address/0x80E63f73cAc60c1662f27D2DFd2EA834acddBaa8"><code>0x80E63f73cAc60c1662f27D2DFd2EA834acddBaa8</code></a></td></tr></tbody></table>


# Supported Currencies

Ocean Enterprise supports the following currencies:

### Production Networks currencies

* **Ethereum Mainnet**

<table><thead><tr><th width="214.5">Supported Currency</th><th>Contract address</th></tr></thead><tbody><tr><td>USDC</td><td><a href="https://etherscan.io/token/0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48"><code>0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48</code></a></td></tr><tr><td>EURC</td><td><a href="https://etherscan.io/token/0x1aBaEA1f7C830bD89Acc67eC4af516284b1bC33c"><code>0x1aBaEA1f7C830bD89Acc67eC4af516284b1bC33c</code></a></td></tr><tr><td>EURAU</td><td><a href="https://etherscan.io/token/0x4933A85b5b5466Fbaf179F72D3DE273c287EC2c2"><code>0x4933A85b5b5466Fbaf179F72D3DE273c287EC2c2</code></a></td></tr></tbody></table>

* **Optimism Mainnet**

<table><thead><tr><th width="215">Supported Currency</th><th>Contract address</th></tr></thead><tbody><tr><td>USDC</td><td><a href="https://optimistic.etherscan.io/token/0x0b2c639c533813f4aa9d7837caf62653d097ff85"><code>0x0b2C639c533813f4Aa9D7837CAf62653d097Ff85</code></a></td></tr><tr><td>EURAU</td><td><a href="https://optimistic.etherscan.io/address/0x4933a85b5b5466fbaf179f72d3de273c287ec2c2"><code>0x4933A85b5b5466Fbaf179F72D3DE273c287EC2c2</code></a></td></tr></tbody></table>

***

### Test Networks currencies

* **Ethereum Sepolia**

<table><thead><tr><th width="215">Supported Currency</th><th>Contract address</th></tr></thead><tbody><tr><td>USDC</td><td><a href="https://sepolia.etherscan.io/address/0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238"><code>0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238</code></a></td></tr><tr><td>EURC</td><td><a href="https://sepolia.etherscan.io/address/0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4"><code>0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4</code></a></td></tr></tbody></table>

* **Optimism Sepolia**

<table><thead><tr><th width="215">Supported Currency</th><th>Contract address</th></tr></thead><tbody><tr><td>USDC</td><td><a href="https://sepolia-optimism.etherscan.io/token/0x5fd84259d66Cd46123540766Be93DFE6D43130D7"><code>0x5fd84259d66Cd46123540766Be93DFE6D43130D7</code></a></td></tr><tr><td>EURAU</td><td><a href="https://sepolia-optimism.etherscan.io/address/0xD35141583f374d401fee1BFdDc35910E1D33a588"><code>0xD35141583f374d401fee1BFdDc35910E1D33a588</code></a></td></tr></tbody></table>

***


# Fees

The Ocean Enterprise Collective defines various fees for creating a sustainability loop.

One transaction may have fees going to several entities, such as the marketplace operator where the asset was published, the Ocean Node provider, and the Ocean Enterprise Collective e.V.

* **Marketplace**: the marketplace where the asset is published or consumed
* **Provider**: the Ocean Node facilitating asset consumption. May serve up data, run C2D jobs, etc.
* **Ocean Enterprise Collective**: for developing and maintaining the OE code base

<table><thead><tr><th width="239.5">Fee Type</th><th align="center">Value</th></tr></thead><tbody><tr><td>Marketplace</td><td align="center">set by the marketplace operator <br>for asset publishing and/or consumption</td></tr><tr><td>Provider</td><td align="center">set by the Ocean Node operator</td></tr><tr><td>Ocean Enterprise Collective </td><td align="center">set by OEC eV at 1.9% of the asset and compute job price<br>with a minimum value of 1 cent</td></tr></tbody></table>

{% hint style="info" %}
Stay up-to-date with the latest information! The values within the system are regularly updated. We recommend verifying the most recent values directly from the [contracts](https://github.com/oceanprotocol/contracts) and the [market](https://github.com/oceanprotocol/market).
{% endhint %}


# Deployment Guides

Learn how to deploy Ocean Enterprise in your environment.

This chapter explains how to install and configure the components of the Ocean Enterprise software stack. All components run in Docker containers on a Linux operating system. Deploying the OE components requires solid familiarity with Linux, Docker Engine, and Docker Compose.&#x20;

As described in the [Dataspace Configuration Options](/developers/architecture-1) chapter, the OE Stack supports two deployment modes - with SSI-based access control enabled or disabled. Because the required components and installation order vary by configuration, consult the dedicated chapter on the installation sequence for each configuration.  &#x20;

Each deployment subchapter is structured into four parts:&#x20;

* *Prerequisites*: lists the hardware, software, and other requirements for running the component\ <mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: The hardware specifications provided represent the minimum configuration identified during our testing. Actual requirements vary based on workload characteristics such as the number of concurrent requests and expected response times. We recommend starting with an estimated configuration based on your anticipated workload, monitoring system performance over time, and adjusting resources accordingly.</mark>
* *Deployment Steps*: describes the tasks required to perform to install and configure the component.
* *Post installation steps*: tasks that must be completed for the component to function properly
* *Environment Variables*: explains the purpose and usage of each environment variable needed by the component

This chapter includes the following information:

* [Deployment Modes](/infrastructure/deployment-modes)
* [OE Node Installation and Configuration](/infrastructure/oe-node-installation-and-configuration)
* [Marketplace Installation and Configuration](/infrastructure/marketplace-installation-and-configuration)
* [Policy Server and Policy Server Proxy Installation and Configuration](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration)
* [SSI Stack Installation and Configuration](/infrastructure/ssi-stack-installation-and-configuration)


# Deployment modes

The OE stack supports two deployment modes, determined by whether the dataspace uses SSI‑based access control.

## Dataspace with SSI-based access control disabled

### Configuration example

In a dataspace where SSI‑based access control is disabled, only two OE components are required: the OE Node and the marketplace. The table below provides the assumed URLs for each element.

| Component   | URL                                 |
| ----------- | ----------------------------------- |
| OE Node     | <https://node.oceanenterprise.io>   |
| Marketplace | <https://market.oceaneneteprise.io> |

To ensure correct operation, configure the relevant environment variable in each component, using the examples shown in the table below.

| Component       | Environment variable                                                                                                         | Value                             |
| --------------- | ---------------------------------------------------------------------------------------------------------------------------- | --------------------------------- |
| **OE Node**     | [POLICY\_SERVER\_URL](/infrastructure/oe-node-installation-and-configuration#policy_server_url)                              | null                              |
| **Marketplace** | [NEXT\_PUBLIC\_PROVIDER\_URL](/infrastructure/marketplace-installation-and-configuration#next_public_provider_url)           | <https://node.oceanenterprise.io> |
|                 | [NEXT\_PUBLIC\_METADATACACHE\_URI](/infrastructure/marketplace-installation-and-configuration#next_public_metadatacache_uri) | <https://node.oceanenterprise.io> |
|                 | [NEXT\_PUBLIC\_SSI\_ENABLED](/infrastructure/marketplace-installation-and-configuration#next_public_ssi_enabled)             | false                             |

### Installation sequence

The recommended deployment order for this setup is:

1. [Install and configure the OE Node](/infrastructure/oe-node-installation-and-configuration)
2. [Install and configure the marketplace](/infrastructure/marketplace-installation-and-configuration)

## Dataspace with SSI-based access control enabled

### Configuration example

In a dataspace with SSI‑based access control enabled, all OE components are required. The table below provides the assumed URLs for each element.

| Component           | URL                                   |
| ------------------- | ------------------------------------- |
| OE Node             | <https://node.oceanenterprise.io>     |
| Marketplace         | <https://market.oceaneneteprise.io>   |
| Policy Server       | <https://ps.oceanenterprise.io>       |
| Policy Server Proxy | <https://proxy.oceanenterprise.io>    |
| SSI Wallet          | <https://wallet.oceanenterprise.io>   |
| Verifier            | <https://verifier.oceanenterprise.io> |
| OPA Server          | <http://opa.oceanenterprise.io:8181>  |

To ensure correct operation, configure the relevant environment variable in each component, using the examples shown in the table below.

| Component               | Environment variable                                                                                                                                                      | Value                                         |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------- |
| **Policy Server**       | [MODE\_PS](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#mode_ps)                                                                  | 1                                             |
|                         | [MODE\_PROXY](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#mode_proxy)                                                            | 0                                             |
|                         | [OCEAN\_NODE\_URL](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#ocean_node_url)                                                   | <https://node.oceanenterprise.io>             |
|                         | [WALTID\_VERIFIER\_URL](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#waltid_verifier_url)                                         | <https://wallet.oceanenterprise.io>           |
|                         | [WALTID\_VERIFY\_RESPONSE\_REDIRECT\_URL](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#waltid_verify_response_redirect_url)       | <https://proxy.oceanenterprise.io/verify/$id> |
|                         | [WALTID\_VERIFY\_PRESENTATION\_DEFINITION\_URL](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#waltid_verify_response_redirect_url) | <https://proxy.oceanenterprise.io/pd/$id>     |
| **Policy Server Proxy** | [MODE\_PS](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#mode_ps)                                                                  | 0                                             |
|                         | [MODE\_PROXY](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#mode_proxy)                                                            | 1                                             |
|                         | [OCEAN\_NODE\_URL](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#ocean_node_url)                                                   | <https://node.oceanenterprise.io>             |
| **OE Node**             | [POLICY\_SERVER\_URL](/infrastructure/oe-node-installation-and-configuration#policy_server_url)                                                                           | <https://ps.oceanenterprise.io>               |
| **Marketplace**         | [NEXT\_PUBLIC\_PROVIDER\_URL](/infrastructure/marketplace-installation-and-configuration#next_public_provider_url)                                                        | <https://node.oceanenterprise.io>             |
|                         | [NEXT\_PUBLIC\_METADATACACHE\_URI](/infrastructure/marketplace-installation-and-configuration#next_public_metadatacache_uri)                                              | <https://node.oceanenterprise.io>             |
|                         | [NEXT\_PUBLIC\_SSI\_ENABLED](/infrastructure/marketplace-installation-and-configuration#next_public_ssi_enabled)                                                          | true                                          |
|                         | [NEXT\_PUBLIC\_SSI\_POLICY\_SERVER](/infrastructure/marketplace-installation-and-configuration#next_public_ssi_policy_server)                                             | <https://ps.oceanenterprise.io>               |
|                         | [NEXT\_PUBLIC\_OPA\_SERVER\_URL](/infrastructure/marketplace-installation-and-configuration#next_public_opa_server_url)                                                   | <http://opa.oceanenterprise.io:8181>          |
|                         | [NEXT\_PUBLIC\_SSI\_WALLET\_API](/infrastructure/marketplace-installation-and-configuration#next_public_ssi_wallet_api)                                                   | <https://wallet.oceanenterprise.io>           |

### Installation sequence

The recommended deployment order for this setup is:

1. [Install and configure the SSI Stack](/infrastructure/ssi-stack-installation-and-configuration)
2. [Install the Policy Server](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration)
3. [Install and configure the OE Node](/infrastructure/oe-node-installation-and-configuration)
4. [Install and configure the Policy Server Proxy](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration)
5. [Install and configure the marketplace](/infrastructure/marketplace-installation-and-configuration)


# Compatibility Matrix

This table shows the compatibility list between the versions of the OE technology stack components.

| Marketplace     | OE Node          | Policy Server   | SSI Stack      |
| --------------- | ---------------- | --------------- | -------------- |
| v1.0.0 - v1.1.2 | v0.2.3           | v1.0.0          | gaiax-0.1.1-OE |
| v1.1.3          | v1.0.3           | v1.0.0          | gaiax-0.1.1-OE |
| v1.2.0          | v2.1.0, v2.1.1   | v1.0.0          | gaiax-0.1.1-OE |
| v1.3.0          | v2.1.0, v2.1.1   | v1.1.0, v1.1.1  | gaiax-0.1.1-OE |
| v1.3.1          | v2.1.0, v2.1.1   | v1.1.0 - v1.2.0 | gaiax-0.1.1-OE |
| v1.4.0          | v3.0.1           | v1.2.0          | gaiax-0.1.1-OE |
| v1.4.1 - v1.4.3 | v3.0.3 - v3.1.11 | v1.2.0 - v1.3.2 | gaiax-0.1.1-OE |
| v1.4.4-v1.4.5   | v3.1.12 - v3.2.1 | v1.2.0 - v1.3.2 | gaiax-0.1.1-OE |


# OE Node installation and configuration

## Prerequisites

### Hardware requirements

The minimum hardware requirements for the server that will run the OE Node are:

* number of cores: 2
* RAM: 16 GB
* disk: 50 GB

### Software requirements

* **Operating System:** Any Linux distribution supported by the Docker Engine and Docker Compose products. For guidance on compatible platforms, see the [Docker Compose supported platforms](https://docs.docker.com/desktop/setup/install/linux/) and [Docker Engine supported platforms](https://docs.docker.com/engine/install/) documentation
* **For OE Node v3.0.1 and newer:** A Linux distribution with library `glibc` v2.38 or newer. To check the current version of glibc, run the following command:

{% code overflow="wrap" %}

```shellscript
ldd --version
```

{% endcode %}

* **Software products:**
  * Docker Engine
  * Docker Compose

### **Other requirements**

* **Blockchain RPC provider**: Use a service such as Alchemy, Infura, or Chainstack. Ensure that your subscription tier supports a sufficient number of requests per second to meet the node demand.&#x20;
* **IPFS gateway provider**: Use a gateway such as Pinata, Cloudflare, or Filebase. Verify that your subscription tier provides adequate storage capacity, file limits, and request throughput for your expected workload. \ <mark style="color:$warning;background-color:$info;">**Note:**</mark> <mark style="color:$warning;background-color:$info;"></mark><mark style="color:$warning;background-color:$info;">Make sure the IPFS gateway used by the OE Node is a</mark> <mark style="color:$warning;background-color:$info;"></mark><mark style="color:$warning;background-color:$info;">**public gateway**</mark> <mark style="color:$warning;background-color:$info;"></mark><mark style="color:$warning;background-color:$info;">so the node can retrieve the CIDs that were pinned during asset publishing.</mark>&#x20;

## Pre-installation steps

Make sure you review the [Compatibility Matrix](/infrastructure/compatibility-matrix) to ensure that the version is compatible with the other components.&#x20;

## Deployment steps

The OE Node uses Elasticsearch as the underlying database for its indexer. Elasticsearch can be deployed together with the OE Node or installed separately.

There are multiple ways to install and run the OE Node, but this guide focuses on two primary approaches: using Docker Compose or PM2.&#x20;

### Use Docker Compose to install and run OE Node

To install and configure the OE Node using Docker Compose, perform the following steps:

1. The OE Node repository is located [here](https://github.com/OceanProtocolEnterprise/ocean-node). Clone the OE Node repository.

```sh
git clone https://github.com/OceanProtocolEnterprise/ocean-node.git && cd ocean-node
```

2. Copy `.env.elasticsearch.example` to `.env.elasticsearch`&#x20;

```sh
cp .env.elasticsearch.example .env.elasticsearch
```

3. Edit the *.env.elasticsearch* file and set the `ELASTIC_PASSWORD` parameter to the password required to connect to the ElasticSearch instance.&#x20;

```shellscript
nano .env.elasticsearch
```

4. Copy `.env.node.example` to `.env.node`&#x20;

```sh
cp .env.node.example .env.node
```

5. Edit the *.env.node* file and set the OE Node environment variables according to your configuration (see the [Environment Variables](#environment-variables) chapter for details on how to set them).

```sh
nano .env.node
```

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: Make sure the password set in the</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">`DB_PASSWORD`</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">parameter matches the password configured for the Elasticsearch instance in step 4.</mark>

6. Start the services

```sh
docker compose up -d
```

On the first run, the script creates both the Elasticsearch and OE Node containers. Because the OE Node depends on Elasticsearch reaching a specific ready state, it may take some time before the OE Node container starts.

<mark style="color:$info;background-color:$info;">**Note:**</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">This installs the latest available version of the OE Node. To install a specific version, edit the</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">`docker-compose.yml`</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">file and set the desired version tag.</mark>

### Use PM2 to run the OE Node

In this configuration, the OE Node runs as a process on the host machine, and it's managed by pm2.&#x20;

Preinstallation tasks:&#x20;

1. Make sure you have the following tools installed on your Linux system:

* [node.js](https://nodejs.org/en/download):  the required version of node.js is listed in the `.nvmrc` file in the [OE Node repository](https://github.com/OceanProtocolEnterprise/ocean-node). Make sure this is the default version. To this end, you can use the [nvm ](https://github.com/nvm-sh/nvm?tab=readme-ov-file#installing-and-updating)tool.
* [npm](https://docs.npmjs.com/downloading-and-installing-node-js-and-npm)
* [pm2](https://pm2.keymetrics.io/). Optionally, you can install pm2-logrotate to easily manage the OE node logs. &#x20;

2. Start Elasticsearch in a Docker container on the host machine:

```shellscript
docker run -d \
  --name elasticsearch \
  -p 9200:9200 \
  -e "discovery.type=single-node" \
  -e "ELASTIC_PASSWORD=your_secure_password" \
  -e "xpack.security.enabled=true" \
  docker.elastic.co/elasticsearch/elasticsearch:8.19.12
```

&#x20;

To install and run the OE Node using pm2, perform the following steps:

1. The OE Node repository is located [here](https://github.com/OceanProtocolEnterprise/ocean-node). Clone the OE Node repository.

```sh
git clone https://github.com/OceanProtocolEnterprise/ocean-node.git && cd ocean-node
```

2. Copy `.env.example` to `.env`&#x20;

```sh
cp .env.example .env
```

3. Edit the *.env* file to set the environment variables specific to your configuration (please refer to the [Environment Variables](#environment-variables) chapter for how to set the variables).

```shellscript
nano .env
```

6. Load the environment variables in the current session

```sh
source .env
```

6. Start OE Node process in pm2&#x20;

```sh
pm2 start npm --name "oe-node" -- run start
```

7. Once the process is started, verify its state.

```sh
pm2 ls
```

8. Verify the logs to make sure the node started well&#x20;

```sh
pm2 logs "oe-node"
```

## **Post installation steps**

* If the OE Node is not configured to use HTTPS directly, deploy it behind a reverse proxy responsible for TLS termination and secure request forwarding. The proxy should enforce HTTPS for all external traffic and route decrypted requests to the OE Node's internal port.
* Ensure that the OE Node operates in a network environment that permits outbound communication to the configured Policy Server, Policy Server Proxy, and Marketplace&#x20;
* For OE Nodes that provide a paid C2D environment, verify that the associated web3 address maintains sufficient native‑token funds on the connected blockchain to cover gas fees for withdrawals from the escrow account. Monitor and replenish the OE Node’s balance regularly.

## Environment variables

In this chapter, the key environment variables required to configure the OE Node are highlighted. The full list of available environment variables is provided in the documentation for the Community Edition of the node, accessible [here](https://github.com/oceanprotocol/ocean-node/blob/main/docs/env.md).&#x20;

### Private Key

#### PRIVATE\_KEY

**Description:** Sets the private key used by the OE Node to encrypt and decrypt assets.

**Values:** String

**Example:** `"0x1d751ded5a32226054cd2e71261039b65afb9ee1c746d055dd699b1150a5befc"`

**Default Value:** `null`

### Blockchain RPC

#### RPCS

**Description:** Sets the list of blockchains, by blockchain ID (e.g., 1 - Ethereum, 11155111 - Eth Sepolia), to which the OE Node connects to retrieve assets. If not specified otherwise in the `INDEXER_NETWORKS` variable, the indexer will connect to all the blockchains listed here.&#x20;

Also, for each blockchain, two things are specified:&#x20;

* `"rpc"` : The RPC provider URL. Use the RPC URL supplied by the RPC provider.
* `"startBlock"` : The block number from which the indexer will search for events related to the asset creation or update. Verify the&#x20;

**Values:** JSON map of chainId to object

**Example:** `{"11155111":{"rpc":"https://eth-sepolia.g.alchemy.com/<your_key>","chainId":11155111,"network":"sepolia","chunkSize":50,"startBlock":9802079},"11155420":{"rpc":"https://opt-sepolia.g.alchemy.com/<your_key>","chainId":11155420,"network":"optimism_sepolia","chunkSize": 50,"startBlock":36735314}}`

**Default Value:** `{}`

### Decentralized File Systems

#### IPFS\_GATEWAY

**Description:** Sets the URL of the IPFS gateway used to fetch the asset's DDO. Use the URL supplied by the IFPS provider. Make sure the IPFS gateway is public; otherwise will not be able to access CIDs pinned by other services, such as the marketplace.&#x20;

**Values:** String (URL)

**Example:** `https://ipfs.io/`

**Default Value:** `null`

### Elasticsearch connection

#### DB\_URL

**Description:** Sets the URL for connecting to the Elasticsearch instance.

**Values:** String (URL)

**Example:** `http://elastic:<your_elasticsearch_password>@localhost:9200/`  (if Elasticsearch is deployed on the same hostmachine as OE Node)

**Default Value:** `null`

#### DB\_USERNAME

**Description:** Sets the user name for connecting to the Elasticsearch instance.

**Values:** String

**Example:** `"elastic"`

**Default Value:** `null`

#### DB\_PASSWORD

**Description:** Sets the password for connecting to the Elasticsearch instance. Make sure you use the same password you set when you started the Elasticsearch container.&#x20;

**Values:** String

**Example:** `"elastic"`

**Default Value:** `null`

### Node fees

#### FEE\_TOKENS

**Description:** Sets the tokens used for the node fees for each blockchain the OE Node is connected to.&#x20;

**Values:**  JSON array of string (chainId) to string (token address) mapping

**Example:** `{"11155111":"0x1B083D8584dd3e6Ff37d04a6e7e82b5F622f3985","11155420":"0xf26c6C93f9f1d725e149d95f8E7B2334a406aD10"}`

**Default Value:** `null`

#### FEE\_AMOUNT

**Description:** Sets the absolute value of the fee and the unit to which the fee is applied. However, applying the fee per unit is currently not implemented in OE Node, so the fee is applied when an asset is purchased, regardless of its size.

**Values:**  JSON object

**Example:** `{"amount":1,"unit":"MB"}` &#x20;

**Default Value:** `null`

### Policy Server

#### POLICY\_SERVER\_URL

**Description:** Sets the URL of the Policy Server used by the OE Node to perform the verification (address-based and SII-based) on asset access attempts. If no URL is set, then SSI verification is disabled and the OE Node performs only address-based verification.

**Values:** String (URL)

**Example:** `"https://ps3.demo.oceanenterprise.io/"`

**Default Value:** `null`

#### POLICY\_SERVER\_API\_KEY

**Description:** Sets the API KEY used by Policy Server to authenticate API requests. Set the same key that was used in the [POLICY\_SERVER\_API\_KEY](/infrastructure/policy-server-and-policy-server-proxy-installation-and-configuration#policy_server_api_key) variable of the corresponding Policy Server. If API requests authentication is not enabled on the Policy Server side, leave this variable null.

**Values:** string

**Example:** `mrgcorhTzA1Ey2WRhZAK8tkw4zBrIgQ757toUz3fXvfHh8Ua`

**Defaul Value:** `null`

### Compute Environment

**DOCKER\_COMPUTE\_ENVIRONMENT**

**Description:** Sets the Docker-based compute environment of the OE Node.&#x20;

**Value:** JSON list of objects

**Example:**

* *<mark style="background-color:$primary;">For OE Node up to v2.1.1</mark>*

{% code overflow="wrap" %}

```json
[{"socketPath":"/var/run/docker.sock","paymentClaimInterval":120,"resources":[{"id":"myGPU","description":"NVIDIA GeForce GTX 1060 3GB","type":"gpu","total":4,"init":{"deviceRequests":{"Driver":"nvidia","DeviceIDs":["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],"Capabilities":[["gpu"]]}}},{"id":"disk","total":4}],"storageExpiry":604800,"maxJobDuration":3600,"fees":{"11155111":[{"feeToken":"0x1B083D8584dd3e6Ff37d04a6e7e82b5F622f3985","prices":[{"id":"cpu","price":1},{"id":"gpu","price":4},{"id":"ram","price":1},{"id":"disk","price":1}]},{"feeToken":"0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4","prices":[{"id":"cpu","price":0.1},{"id":"gpu","price":0.4},{"id":"ram","price":0.1},{"id":"disk","price":0.1}]},{"feeToken":"0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238","prices":[{"id":"cpu","price":0.15},{"id":"gpu","price":0.6},{"id":"ram","price":0.15},{"id":"disk","price":0.15}]}],"11155420":[{"feeToken":"0xf26c6C93f9f1d725e149d95f8E7B2334a406aD10","prices":[{"id":"cpu","price":1},{"id":"gpu","price":4},{"id":"ram","price":1},{"id":"disk","price":1}]},{"feeToken":"0x5fd84259d66Cd46123540766Be93DFE6D43130D7","prices":[{"id":"cpu","price":0.15},{"id":"gpu","price":0.6},{"id":"ram","price":0.15},{"id":"disk","price":0.15}]}]},"free":{"maxJobDuration":1800,"maxJobs":3,"resources":[{"id":"myGPU","description":"NVIDIA GeForce GTX 1060 3GB","type":"gpu","total":1,"init":{"deviceRequests":{"Driver":"nvidia","DeviceIDs":["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],"Capabilities":[["gpu"]]}}},{"id":"cpu","max":1},{"id":"myGPU","max":1},{"id":"ram","max":0.5},{"id":"disk","max":0.5}]}}]
```

{% endcode %}

Here's the structured format of the same value.

```json
[
  {
    "socketPath": "/var/run/docker.sock",
    "paymentClaimInterval": 120,
    "resources": [
      {
        "id": "myGPU",
        "description": "NVIDIA GeForce GTX 1060 3GB",
        "type": "gpu",
        "total": 4,
        "init": {
          "deviceRequests": {
            "Driver": "nvidia",
            "DeviceIDs": ["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],
            "Capabilities": [["gpu"]]
          }
        }
      },
      { "id": "disk", "total": 4 }
    ],
    "storageExpiry": 604800,
    "maxJobDuration": 3600,
    "fees": {
      "11155111": [
        {
          "feeToken": "0x1B083D8584dd3e6Ff37d04a6e7e82b5F622f3985",
          "prices": [
            { "id": "cpu", "price": 1 },
            { "id": "gpu", "price": 4 },
            { "id": "ram", "price": 1 },
            { "id": "disk", "price": 1 }
          ]
        },
        {
          "feeToken": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
          "prices": [
            { "id": "cpu", "price": 0.1 },
            { "id": "gpu", "price": 0.4 },
            { "id": "ram", "price": 0.1 },
            { "id": "disk", "price": 0.1 }
          ]
        },
        {
          "feeToken": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238",
          "prices": [
            { "id": "cpu", "price": 0.15 },
            { "id": "gpu", "price": 0.6 },
            { "id": "ram", "price": 0.15 },
            { "id": "disk", "price": 0.15 }
          ]
        }
      ],
      "11155420": [
        {
          "feeToken": "0xf26c6C93f9f1d725e149d95f8E7B2334a406aD10",
          "prices": [
            { "id": "cpu", "price": 1 },
            { "id": "gpu", "price": 4 },
            { "id": "ram", "price": 1 },
            { "id": "disk", "price": 1 }
          ]
        },
        {
          "feeToken": "0x5fd84259d66Cd46123540766Be93DFE6D43130D7",
          "prices": [
            { "id": "cpu", "price": 0.15 },
            { "id": "gpu", "price": 0.6 },
            { "id": "ram", "price": 0.15 },
            { "id": "disk", "price": 0.15 }
          ]
        }
      ]
    },
    "free": {
      "maxJobDuration": 1800,
      "maxJobs": 3,
      "resources": [
        {
          "id": "myGPU",
          "description": "NVIDIA GeForce GTX 1060 3GB",
          "type": "gpu",
          "total": 1,
          "init": {
            "deviceRequests": {
              "Driver": "nvidia",
              "DeviceIDs": ["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],
              "Capabilities": [["gpu"]]
            }
          }
        },
        { "id": "cpu", "max": 1 },
        { "id": "myGPU", "max": 1 },
        { "id": "ram", "max": 0.5 },
        { "id": "disk", "max": 0.5 }
      ]
    }
  }
]
```

The configuration described by this value provides free and paid compute environments. The free compute environment has a maximum job duration of 30 minutes, a maximum number of 3 simultaneous jobs, and limited resources (1 CPU, 1 GPU, 0.5GB of RAM, and 0.5GB of disk). The paid environment has more resources to allocate and allows a maximum job duration of 60 minutes.&#x20;

* *<mark style="background-color:$primary;">For OE Node v3.0.1 or newer</mark>*

{% code overflow="wrap" %}

```json
[{"socketPath":"/var/run/docker.sock","paymentClaimInterval":120,"environments":[{"id":"environment 1","storageExpiry":604800,"maxJobDuration":3600,"minJobDuration":60,"resources":[{"id":"myGPU","description":"NVIDIA GeForce GTX 1060 3GB","type":"gpu","total":4,"init":{"deviceRequests":{"Driver":"nvidia","DeviceIDs":["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],"Capabilities":[["gpu"]]}}},{"id":"cpu","min":1,"max":1,"total":1},{"id":"ram","min":0,"max":2,"total":2},{"id":"disk","min":0,"max":2,"total":4}],"fees":{"11155111":[{"feeToken":"0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4","prices":[{"id":"cpu","price":0.1},{"id":"gpu","price":0.4},{"id":"ram","price":0.1},{"id":"disk","price":0.1}]},{"feeToken":"0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238","prices":[{"id":"cpu","price":0.15},{"id":"gpu","price":0.6},{"id":"ram","price":0.15},{"id":"disk","price":0.15}]}],"11155420":[{"feeToken":"0xf26c6C93f9f1d725e149d95f8E7B2334a406aD10","prices":[{"id":"cpu","price":1},{"id":"gpu","price":4},{"id":"ram","price":1},{"id":"disk","price":1}]},{"feeToken":"0x5fd84259d66Cd46123540766Be93DFE6D43130D7","prices":[{"id":"cpu","price":0.15},{"id":"gpu","price":0.6},{"id":"ram","price":0.15},{"id":"disk","price":0.15}]}]},"free":{"maxJobDuration":1800,"maxJobs":3,"resources":[{"id":"myGPU","description":"NVIDIA GeForce GTX 1060 3GB","type":"gpu","total":1,"init":{"deviceRequests":{"Driver":"nvidia","DeviceIDs":["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],"Capabilities":[["gpu"]]}}},{"id":"cpu","max":1},{"id":"myGPU","max":1},{"id":"ram","min":0,"max":1},{"id":"disk","max":0.5}]}},{"id":"environment 2","storageExpiry":604800,"maxJobDuration":3600,"minJobDuration":60,"resources":[{"id":"myGPU","description":"NVIDIA GeForce GTX 1060 3GB","type":"gpu","total":2,"init":{"deviceRequests":{"Driver":"nvidia","DeviceIDs":["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],"Capabilities":[["gpu"]]}}},{"id":"cpu","min":1,"max":1,"total":1},{"id":"ram","min":0,"max":2,"total":2},{"id":"disk","min":0,"max":2,"total":4}],"fees":{"11155111":[{"feeToken":"0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4","prices":[{"id":"cpu","price":0.08},{"id":"gpu","price":0.3},{"id":"ram","price":0.08},{"id":"disk","price":0.08}]},{"feeToken":"0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238","prices":[{"id":"cpu","price":0.1},{"id":"gpu","price":0.5},{"id":"ram","price":0.1},{"id":"disk","price":0.1}]}],"11155420":[{"feeToken":"0xf26c6C93f9f1d725e149d95f8E7B2334a406aD10","prices":[{"id":"cpu","price":1},{"id":"gpu","price":4},{"id":"ram","price":1},{"id":"disk","price":1}]},{"feeToken":"0x5fd84259d66Cd46123540766Be93DFE6D43130D7","prices":[{"id":"cpu","price":0.15},{"id":"gpu","price":0.6},{"id":"ram","price":0.15},{"id":"disk","price":0.15}]}]},"free":{"maxJobDuration":900,"maxJobs":2,"resources":[{"id":"myGPU","description":"NVIDIA GeForce GTX 1060 3GB","type":"gpu","total":1,"init":{"deviceRequests":{"Driver":"nvidia","DeviceIDs":["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],"Capabilities":[["gpu"]]}}},{"id":"cpu","max":1},{"id":"myGPU","max":1},{"id":"ram","min":0,"max":1},{"id":"disk","max":0.4}]}}]}]
```

{% endcode %}

Here's the structured format of the same value.

{% code overflow="wrap" %}

```json
[
  {
    "socketPath": "/var/run/docker.sock",
    "paymentClaimInterval": 120,
    "environments": [
      {
        "id": "environment 1",
        "storageExpiry": 604800,
        "maxJobDuration": 3600,
        "minJobDuration": 60,
        "resources": [
          {
            "id": "myGPU",
            "description": "NVIDIA GeForce GTX 1060 3GB",
            "type": "gpu",
            "total": 4,
            "init": {
              "deviceRequests": {
                "Driver": "nvidia",
                "DeviceIDs": ["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],
                "Capabilities": [["gpu"]]
              }
            }
          },
          { "id": "cpu", "min": 1, "max": 1, "total": 1 },
          { "id": "ram", "min": 0, "max": 2, "total": 2 },
          { "id": "disk", "min": 0, "max": 2, "total": 4 }
        ],
        "fees": {
          "11155111": [
            {
              "feeToken": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
              "prices": [
                { "id": "cpu", "price": 0.1 },
                { "id": "gpu", "price": 0.4 },
                { "id": "ram", "price": 0.1 },
                { "id": "disk", "price": 0.1 }
              ]
            },
            {
              "feeToken": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238",
              "prices": [
                { "id": "cpu", "price": 0.15 },
                { "id": "gpu", "price": 0.6 },
                { "id": "ram", "price": 0.15 },
                { "id": "disk", "price": 0.15 }
              ]
            }
          ],
          "11155420": [
            {
              "feeToken": "0xf26c6C93f9f1d725e149d95f8E7B2334a406aD10",
              "prices": [
                { "id": "cpu", "price": 1 },
                { "id": "gpu", "price": 4 },
                { "id": "ram", "price": 1 },
                { "id": "disk", "price": 1 }
              ]
            },
            {
              "feeToken": "0x5fd84259d66Cd46123540766Be93DFE6D43130D7",
              "prices": [
                { "id": "cpu", "price": 0.15 },
                { "id": "gpu", "price": 0.6 },
                { "id": "ram", "price": 0.15 },
                { "id": "disk", "price": 0.15 }
              ]
            }
          ]
        },
        "free": {
          "maxJobDuration": 1800,
          "maxJobs": 3,
          "resources": [
            {
              "id": "myGPU",
              "description": "NVIDIA GeForce GTX 1060 3GB",
              "type": "gpu",
              "total": 1,
              "init": {
                "deviceRequests": {
                  "Driver": "nvidia",
                  "DeviceIDs": ["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],
                  "Capabilities": [["gpu"]]
                }
              }
            },
            { "id": "cpu", "max": 1 },
            { "id": "myGPU", "max": 1 },
            { "id": "ram", "min": 0, "max": 1 },
            { "id": "disk", "max": 0.5 }
          ]
        }
      },
      {
        "id": "environment 2",
        "storageExpiry": 604800,
        "maxJobDuration": 3600,
        "minJobDuration": 60,
        "resources": [
          {
            "id": "myGPU",
            "description": "NVIDIA GeForce GTX 1060 3GB",
            "type": "gpu",
            "total": 2,
            "init": {
              "deviceRequests": {
                "Driver": "nvidia",
                "DeviceIDs": ["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],
                "Capabilities": [["gpu"]]
              }
            }
          },
          { "id": "cpu", "min": 1, "max": 1, "total": 1 },
          { "id": "ram", "min": 0, "max": 2, "total": 2 },
          { "id": "disk", "min": 0, "max": 2, "total": 4 }
        ],
        "fees": {
          "11155111": [
            {
              "feeToken": "0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4",
              "prices": [
                { "id": "cpu", "price": 0.08 },
                { "id": "gpu", "price": 0.3 },
                { "id": "ram", "price": 0.08 },
                { "id": "disk", "price": 0.08 }
              ]
            },
            {
              "feeToken": "0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238",
              "prices": [
                { "id": "cpu", "price": 0.1 },
                { "id": "gpu", "price": 0.5 },
                { "id": "ram", "price": 0.1 },
                { "id": "disk", "price": 0.1 }
              ]
            }
          ],
          "11155420": [
            {
              "feeToken": "0xf26c6C93f9f1d725e149d95f8E7B2334a406aD10",
              "prices": [
                { "id": "cpu", "price": 1 },
                { "id": "gpu", "price": 4 },
                { "id": "ram", "price": 1 },
                { "id": "disk", "price": 1 }
              ]
            },
            {
              "feeToken": "0x5fd84259d66Cd46123540766Be93DFE6D43130D7",
              "prices": [
                { "id": "cpu", "price": 0.15 },
                { "id": "gpu", "price": 0.6 },
                { "id": "ram", "price": 0.15 },
                { "id": "disk", "price": 0.15 }
              ]
            }
          ]
        },
        "free": {
          "maxJobDuration": 900,
          "maxJobs": 2,
          "resources": [
            {
              "id": "myGPU",
              "description": "NVIDIA GeForce GTX 1060 3GB",
              "type": "gpu",
              "total": 1,
              "init": {
                "deviceRequests": {
                  "Driver": "nvidia",
                  "DeviceIDs": ["GPU-294c6802-bb2f-fedb-f9e0-a26b9142dd81"],
                  "Capabilities": [["gpu"]]
                }
              }
            },
            { "id": "cpu", "max": 1 },
            { "id": "myGPU", "max": 1 },
            { "id": "ram", "min": 0, "max": 1 },
            { "id": "disk", "max": 0.4 }
          ]
        }
      }
    ]
  }
]

```

{% endcode %}

The configuration described by this value provides two different environments on the same host: *environment 1* and *environment 2*. Each environment has two sub-environments: paid and free. For each environment, the available resources are listed, as well as the price of each resource, for each blockchain to which the node is connected.

For details on how to set this variable, refer to the information available [here](https://github.com/oceanprotocol/ocean-node/blob/main/docs/env.md#compute).

If you want the C2D environment to provide GPU resources, please refer to [this guide](https://github.com/oceanprotocol/ocean-node/blob/main/docs/GPU.md) on how to set it up.

**Default Value:** `null` (i.e., no C2D environment provided by the node).

### OE Node Ownership

#### NODE\_OWNER\_INFO

**DOCKER\_COMPUTE\_ENVIRONMENT**

**Description:** Sets information about the owner of the OE Node

**Value:** JSON object.&#x20;

**Example:** The recommended structure of this field is provided in the example below.

{% code overflow="wrap" %}

```json
{"imprint":{"legalName": "Ocean Enterprise Collective", "email": "info@oceanenterprise.io", "url": "https://www.oceanenterprise.io", "address":"Ocean Enterprise Collective e.V., Carmerstrasse 18, 10623 Berlin, Germany"}, "termsAndConditions":{"url":"https://www.oceanenterprise.io/terms-and-conditions#terms-and-conditions"}, "privacyPolicy":{"url": "https://www.oceanenterprise.io/terms-and-conditions#div-privacy"}
```

{% endcode %}

**Default Value:** `null`


# Marketplace installation and configuration

This chapter describes the installation and configuration of the OE Marketplace

* [Marketplace installation](/infrastructure/marketplace-installation-and-configuration/marketplace-installation)
* [Configure Market-level authentication](/infrastructure/marketplace-installation-and-configuration/configure-market-level-authentication)
* [Configure federated market-level authentication](/infrastructure/marketplace-installation-and-configuration/configure-federated-market-level-authentication)


# Marketplace installation

## Prerequisites

### Hardware requirements

The minimum hardware requirements for the server hosting the marketplace are:

* number of cores: 1
* RAM: 8 GB
* disk: 50 GB

### Software requirements

* **Operating System:** Any Linux distribution supported by the Docker Engine and Docker Compose products. For guidance on compatible platforms, see the [Docker Compose supported platforms](https://docs.docker.com/desktop/setup/install/linux/) and [Docker Engine supported platforms](https://docs.docker.com/engine/install/) documentation
* **Software products:**
  * Docker Engine
  * Docker Compose

### **Other requirements**

* **Blockchain RPC provider**: Use a service such as Alchemy, Infura, or Chainstack. Ensure that your subscription tier supports a sufficient number of requests per second to meet the marketplace demand.
* **IPFS gateway provider**: Use a gateway such as Pinata, Cloudflare, or Filebase. Verify that your subscription tier provides adequate storage capacity, file limits, and request throughput for your expected workload.&#x20;
* **OE Node operational**: The marketplace needs an operational OE Node to run properly.

## Pre-installation steps

Make sure you review the [Compatibility Matrix](/infrastructure/compatibility-matrix) to ensure that the version is compatible with the other components. &#x20;

## Deployment steps

There are two ways of installing and running the market: using Docker Compose or Docker Engine.

### Option 1 - Use Docker Compose to install and run the market

To install and configure the marketplace, perform the following steps:

1. The marketplace repository is located [here](https://github.com/OceanProtocolEnterprise/market). Clone the marketplace repository (alternatively, copy only the `docker-compose.yml` and `.env.example` file from the repository).

```sh
git clone https://github.com/OceanProtocolEnterprise/market.git && cd market
```

2. Copy `.env.example` to `.env`&#x20;

```sh
cp .env.example .env
```

3. Edit the *.env* file to set the environment variables specific to your configuration (please refer to the [Environment Variables](#environment-variables) chapter for how to set the variables).

```sh
nano .env
```

4. Start the marketplace service

```sh
docker compose up -d
```

The marketplace will start in a Docker container and will be accessible via HTTP on port 8008.

<mark style="color:$info;">**Note:**</mark> <mark style="color:$info;"></mark><mark style="color:$info;">This installs the latest available version of the market. To install a specific version, edit the</mark> <mark style="color:$info;"></mark><mark style="color:$info;">`docker-compose.yml`</mark> <mark style="color:$info;"></mark><mark style="color:$info;">file and set the desired version tag. If you do so, please verify the Compatibility Matrix.</mark>

### Option 2 - Use Docker to install and run the market

To install and configure the marketplace, perform the following steps:

1. The marketplace repository is located [here](https://github.com/OceanProtocolEnterprise/market). Clone the marketplace repository (alternatively, copy only the `.env.example` file from the repository).

```sh
git clone https://github.com/OceanProtocolEnterprise/market.git 
```

2. Copy `.env.example` to *`.env`*&#x20;

```sh
cp .env.example .env
```

3. Edit the *.env* file to set the environment variables specific to your configuration (please refer to the [Environment Variables](#environment-variables) chapter for how to set the variables).

```sh
nano .env
```

4. Start the marketplace service

```sh
 docker run --name oe-market --env-file .env -p 8008:8008 -d oceanenterprise/market:latest
```

The marketplace will start in a Docker container and will be accessible via HTTP on port 8008.

## **Post installation steps**

* Deploy the marketplace server behind a reverse proxy responsible for TLS termination and secure request forwarding. The proxy should enforce HTTPS for all external traffic and route decrypted requests to the internal application port.
* Place the marketplace in a network environment that allows outbound communication to the configured OE Node. Depending on your architecture, the marketplace must also be able to reach the default SSI wallet instance and the Policy Server Proxy to function correctly.

&#x20;

## Environment Variables

### OE Node

#### NEXT\_PUBLIC\_PROVIDER\_URL&#x20;

**Description:** Sets the base URL of the OE Node used by the marketplace. This node will be used by the marketplace to encrypt the asset description at the publishing time, to decrypt the asset description at consumption time, and as the C2D environment provider.&#x20;

**Values:** string (URL)

**Example:** `https://ocean-node-vm3.oceanenterprise.io/`

**Default Value:** `https://ocean-node-vm3.oceanenterprise.io/`

#### NEXT\_PUBLIC\_METADATACACHE\_URI&#x20;

**Description:** Sets the base URL of the OE Node where the metadata cache is stored. From this cache, the assets listed in the marketplace's catalogue are read. Set it to the same value as `NEXT_PUBLIC_PROVIDER_URL`.&#x20;

**Values:** string (URL)

**Example:** `https://ocean-node-vm3.oceanenterprise.io/`

**Default Value:** `https://ocean-node-vm3.oceanenterprise.io/`

#### NEXT\_PUBLIC\_NODE\_URI\_INDEXED&#x20;

**Description:** Configures the list of OE nodes whose assets will be shown in the marketplace's catalogue. Only the assets published by the OE nodes in this list will be displayed in the catalogue.

**Values:** JSON array of strings (URL)

**Example:** `["https://ocean-node-vm3.oceanenterprise.io/", ""https://ocean-node-vm3.oceanenterprise.io/""]`

**Default Value:** the value of `NEXT_PUBLIC_PROVIDER_URL` variable or `"https://ocean-node-vm3.oceanenterprise.io"`

***

### Blockchain RPC

#### NEXT\_PUBLIC\_NODE\_URI\_MAP&#x20;

**Description:** Sets the list of blockchains to which the marketplace connects to publish and retrieve assets. Also, for each blockchain, the RPC provider URL is set.

**Values:** JSON map of chainId to RPC URL

**Example:** `{"11155111":"https://eth-sepolia.g.alchemy.com/v2/<your_key>", "11155420":"https://opt-sepolia.g.alchemy.com/v2/<your_key>}`

**Default Value:** `{}`

#### NEXT\_PUBLIC\_NODE\_URI&#x20;

**Description:** Sets the default RPC provider URL when no per-chain override is provided in `NEXT_PUBLIC_NODE_URI_MAP`.

**Values**: string (URL)

**Example:** `https://eth-sepolia-testnet.api.pocket.network/`

**Default Value:** `https://eth-sepolia-testnet.api.pocket.network/`

***

### IPFS

#### NEXT\_PUBLIC\_IPFS\_GATEWAY&#x20;

**Description:** Sets the URL of the IPFS gateway used to fetch the asset's DDO.

**Values:** String (URL)

**Example:** `https://ipfs.io/`

**Default Value:** `null`

#### NEXT\_PUBLIC\_IPFS\_UPLOAD\_URL

**Description:** Sets the API endpoint that the marketplace uses to upload content to your configured IPFS provider. Consult your IPFS gateway’s documentation to ensure you supply the correct endpoint and required parameters.

**Values:** String (URL)

**Example:** `https:/api.pinata.cloud/pinning/pinJSONToIPFS/`

**Default Value:** `null`

#### NEXT\_PUBLIC\_IPFS\_DELETE\_URL

**Description:** Sets the API endpoint the marketplace uses to request content deletion from your configured IPFS provider. Check your IPFS gateway’s documentation to ensure you provide the correct endpoint and required parameters.

**Values:** String (URL)

**Example:** `https://api.pinata.cloud/pinning/unpin`

**Default Value:** `null`

#### IPFS\_JWT

**Description:** Sets the access key to the IPFS gateway provider account used to upload and retrieve files on IPFS.

**Values:** string (JWT)

**Example:** `eyJhbGciOi...`

**Default Value:** `null`

#### NEXT\_PUBLIC\_IPFS\_UNPIN\_FILES&#x20;

**Description:** Specifies if an existing license file published in IPFS is deleted or not when a new license file is uploaded

**Values:** `true/false`

**Example:** `true`

**Default Value:** `false`

&#x20;

***

### Currencies and Market Fees

The marketplace can apply two types of fees cumulatively: a fixed fee `(NEXT_PUBLIC_CONSUME_MARKET_ORDER_FEE_MAP)` and a variable, percentage‑based fee `(NEXT_PUBLIC_CONSUME_MARKET_FEE)`. Using both fee types gives the marketplace operator greater flexibility in defining the overall fee policy&#x20;

#### NEXT\_PUBLIC\_ALLOWED\_ERC20\_ADDRESSES

**Description:** Defines the token address for the currency tokens accepted by the marketplace, for each blockchain the market is connected to.&#x20;

Ensure that the listed addresses are supported by the O.E.C. smart contracts; unsupported entries will cause asset publishing to fail. Consult [this chapter](/developers/networks) for the latest list of supported currencies. If none of the currency tokens configured in this variable is supported by the O.E.C. smart contracts, an error message is displayed when users connect to the market.&#x20;

**Values:** JSON map of chainId to a list of token addresses.

**Example:** `{"11155111":["0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4","0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238"]}`  i.e., for Sepolia blockchain, the supported currencies are EURC and USDC.

**Default Value:** `{}`

#### NEXT\_PUBLIC\_CONSUME\_MARKET\_ORDER\_FEE\_MAP&#x20;

**Description:** Defines the fixed market fee applied when an asset is purchased through the marketplace, whether for download or for use in a C2D job. The fee is expressed as an absolute number, written with the number of decimals used by each of the currency tokens defined in `NEXT_PUBLIC_ALLOWED_ERC20_ADDRESSES`.

**Value:** JSON map of chainId to a list of maps (token address to fee value).

**Example:** `{"11155111":[{"token":"0x08210F9170F89Ab7658F0B5E3fF39b0E03C594D4","amount":"2000000"},{"token":"0x1c7D4B196Cb0C7B01d743Fbc6116a902379C7238","amount":"1000000"}]}` , i.e., for the Ethereum Sepolia blockchain, the applicable fixed fees are:  2 EURC for assets priced in EURC and 1 USDC for assets priced in USDC.

**Default Value:** `{}`

#### NEXT\_PUBLIC\_CONSUME\_MARKET\_FEE

**Description**: Defines the variable fee applied when an asset is purchased through the marketplace, whether for download or for use in a C2D job. The fee is represented as a decimal value (for example,  `0.1` corresponds to a `10%` fee, and `1` corresponds to a `100%` fee). This fee is applied to all prices, regardless of the currency.&#x20;

**Example:** `0.15`, meaning that a variable fee of 15% of the asset price is applied.&#x20;

**Default Value:** `0`

#### NEXT\_PUBLIC\_MARKET\_FEE\_ADDRESS&#x20;

**Description:** Defines the address where the market fees are collected.

**Example:** `0x0db00a90deee402256cb1df89f3e14d6b9130fdd`

**Default Value:** OEC Fee Collector address

***

### SSI

#### NEXT\_PUBLIC\_SSI\_ENABLED&#x20;

**Description:** Whether the SSI-based access control is active or not in the marketplace. If the OE Node used by the marketplace (the one listed in the `NEXT_PUBLIC_PROVIDER_URL` variable) has SSI-based access control activated (i.e., the variable `POLICY_SERVER_URL`  is not null), then this variable must be set to `true`. If not, this variable must be set to `false`.

**Values:** `true/false`

**Example:** `true`

**Default Value:** `false`

#### NEXT\_PUBLIC\_SSI\_POLICY\_SERVER&#x20;

**Description:** Used only if `NEXT_PUBLIC_SSI_ENABLED=true`.  Sets the base URL of the Policy Server used by the marketplace. The value must be the same as that set in the POLICY\_SERVER\_URL of the node used by the marketplace (the one listed in the `NEXT_PUBLIC_PROVIDER_URL` variable) &#x20;

**Values:** string (URL)

**Example:** `https://ocean-node-vm3.oceanenterprise.io`

**Default Value:** `null`

#### NEXT\_PUBLIC\_SSI\_WALLET\_API&#x20;

**Description:** Used only if `NEXT_PUBLIC_SSI_ENABLED=true`.  Sets the base URL of the default SSI wallet instance. When users log in to the marketplace, this is the default SSI wallet to which they connect, in case they don't provide their own wallet instance URL.

**Values:** string (URL)

**Example:** `https://wallet.demo.oceanenterprise.io`

**Default Value:** `null`

#### NEXT\_PUBLIC\_SSI\_DEFAULT\_POLICIES\_URL&#x20;

**Description:** Used only if `NEXT_PUBLIC_SSI_ENABLED=true`.  Sets the URL from where the list of default static policies that will be applied to all requested Verifiable Credentials is read. The URL must contain a list of valid static policies, one policy per line. For reference, see <https://raw.githubusercontent.com/OceanProtocolEnterprise/policy-server/refs/heads/main/default-verification-policies>

**Values:** string (URL)

**Example:** `https://raw.githubusercontent.com/OceanProtocolEnterprise/policy-server/refs/heads/main/default-verification-policies`

**Default Value:** `null`

#### NEXT\_PUBLIC\_OPA\_SERVER\_URL&#x20;

**Description:** Used only if `NEXT_PUBLIC_SSI_ENABLED=true`.  Sets the base URL of the OPA Server used by the verifier for custom SSI policies evaluation.&#x20;

**Values:** string (URL)

**Example:** `http://ocean-node-vm3.oceanenterprise.io:8181`

**Default Value:** `null`

***

### Dataspace

#### NEXT\_PUBLIC\_DATASPACE

**Description:** Sets the identifier of the dataspace associated with the marketplace. This has two effects:

* All assets published through the marketplace will automatically receive this dataspace identifier.
* The marketplace will display only the assets whose dataspace identifier matches this value.

By default, the value of this variable is set to `null`. In this state, no filtering is applied to the assets displayed, and no dataspace identifier is added to an asset’s description

**Values:** string

**Example:** `"oceanenteprise"`

**Default Value:** `null`

### Market-level authentication

#### NEXT\_PUBLIC\_AUTH\_ENABLED

**Description:** Sets the marketplace user authentication. If true, user authentication is enabled; if false, user authentication is disabled.

**Values:** boolean

**Example:** `true` &#x20;

**Default Value:** `false`

#### NEXT\_PUBLIC\_AUTH\_PROVIDER

**Description:** If marketplace authentication is enabled, this variable sets the authentication method. Currently, the only accepted method is OIDC.

**Values:** string

**Example:** `oidc` &#x20;

**Default Value:** `oidc`

#### NEXT\_PUBLIC\_OIDC\_ISSUER

**Description:** Sets the URL of the OIDC Identity Provider that verifies user identity and issues security tokens (ID tokens) for authentication.

**Values:** string (URL)

**Example:** `https://idpserver.oceanenteprise.io/application/o/market-demo`

**Default Value:** `null`

#### NEXT\_PUBLIC\_OIDC\_CLIENT\_ID

**Description:** Sets OIDC client ID for the marketplace application. This value is defined on the OIDC Identity Provider when the configuration for the marketplace application is created.

**Values:** string

**Example:** `4abc8afdda73b95545b9a`

**Default Value:** `null`

#### OIDC\_CLIENT\_SECRET

**Description:** Sets OIDC client secret for the marketplace application. This value is defined on the OIDC Identity Provider when the configuration for the marketplace application is created.

**Values:** string

**Example:** `4cec8afdse3401j438943u4`

**Default Value:** `null`

#### NEXT\_PUBLIC\_OIDC\_SIGNUP\_FLOW

**Description:** Sets the name of the sign-up flow defined in the Authentik server that will be run to register users to the marketplace.

**Value:** string

**Example:** `demo-market-signup-flow`

Default Value: `null`&#x20;

### Legal Docs

#### NEXT\_PUBLIC\_IMPRINT\_URL

**Description:** Sets the URL from where the Imprint document will be read. The document must be in Markdown format. If this environment variable is set to null, the marketplace will use the default OEC Imprint document.

**Value:** string (URL)

**Example:** `https://raw.githubusercontent.com/OceanProtocolEnterprise/legaldocs/refs/heads/main/market/Imprint.md`

Default Value: `null`&#x20;

#### NEXT\_PUBLIC\_TC\_URL

**Description:** Sets the URL from where the Terms and Conditions document will be read. The document must be in Markdown format. If this environment variable is set to null, the marketplace will use the default OEC Terms and Conditions document.

**Value:** string (URL)

**Example:** `https://raw.githubusercontent.com/OceanProtocolEnterprise/legaldocs/refs/heads/main/market/TermsAndConditions.md`

Default Value: `null`&#x20;

#### NEXT\_PUBLIC\_PP\_URL

**Description:** Sets the URL from where the Privacy Policy document will be read. The document must be in Markdown format. If this environment variable is set to null, the marketplace will use the default OEC Privacy Policy document.

**Value:** string (URL)

**Example:** `https://raw.githubusercontent.com/OceanProtocolEnterprise/legaldocs/refs/heads/main/market/PrivacyPolicy.md`

Default Value: `null`&#x20;

#### NEXT\_PUBLIC\_CP\_URL

**Description:** Sets the URL from where the Cookie Policy document will be read. The document must be in Markdown format. If this environment variable is set to null, the marketplace will use the default OEC Cookie Policy document.

**Value:** string (URL)

**Example:** `https://raw.githubusercontent.com/OceanProtocolEnterprise/legaldocs/refs/heads/main/market/CookiePolicy.md`

Default Value: `null`&#x20;

#### NEXT\_PUBLIC\_DPUA\_URL

**Description:** Sets the URL from where the Data Portal Usage Agreement document will be read. The document must be in Markdown format. If this environment variable is set to null, the marketplace will use the default OEC Data Portal Usage Agreement document.

**Value:** string (URL)

**Example:** `https://raw.githubusercontent.com/OceanProtocolEnterprise/legaldocs/refs/heads/main/market/DataPortalUsageAgreement.md`

Default Value: `null`&#x20;

### Others

#### NEXT\_PUBLIC\_ENCRYPT\_ASSET&#x20;

**Description:** Defines whether the asset's DDO is encrypted at publishing time

Values: `true/false`

**Example:** `true`

**Default Value:** `false`

#### NEXT\_PUBLIC\_HIDE\_ONBOARDING\_MODULE\_BY\_DEFAULT

**Description:** Defines whether or not the onboarding guide is hidden for new users. By default, the onboarding guide is displayed. By setting this variable to `true`, The onboarding guide is not displayed by default.&#x20;

**Value:** `true/false`

**Example:** `true`

**Default Value:** `false`

#### &#x20;NEXT\_PUBLIC\_SSI\_UI\_URL

**Description:** Defines the URL of the SSI wallet user interface provided by the marketplace operator. This URL is used in the onboarding guide to direct participants to the interface where they can add the DIDs and VCs required to access dataspace assets.

**Value:** string (URL)

**Example:** `https://wallet2-ui.oceanenterprise.io`

**Default Value:** `null`


# Configure market-level authentication

## Introduction

For dataspaces where controlling access to resources is essential, operators can enable user authentication on the marketplace to ensure that only verified participants interact with sensitive data and services. The Ocean Enterprise Marketplace supports secure, standards‑based authentication through OpenID Connect (OIDC).&#x20;

We used the Authentik server (available at <https://goauthentik.io/>) as the Identity Provider (IdP) for the OE Marketplace, handling:

* User authentication
* User registration
* Session management
* Single Sign-On (SSO)
* Single Logout (SLO)

Once configured, users can securely access the marketplace using the credentials registered in Authentik. The following diagram shows the OIDC authentication flow between the user, Ocean Market, and Authentik.

<figure><img src="/files/vx8TMCHSY6Lht1r3vHFx" alt=""><figcaption></figcaption></figure>

In this configuration, there is a single Authentik server where users reside. The OE Marketplace is configured to use the Authentik server as the OpenID Provider.&#x20;

* When the user accesses the OE Marketplace via the browser (step 1), OE Marketplace prepares a URL with parameters for the Authentik server, which the user's browser is redirected to (step 2)
* The Authentik server authenticates the user (step 3) and generates an authorization code
* &#x20;The Authentik server then redirects the client (the user's browser) back to the OE Marketplace, along with that authorization code (step 4). In the background, the OE Marketplace then sends that same authorization code in a request authenticated by the `client_id` and `client_secret` to the Authentik server. Finally, the Authentik server responds by sending an Access Token, saying this user has been authorized, and optionally a Refresh Token.

This guide explains how to configure Authentik as the OpenID Connect (OIDC) Identity Provider for the Ocean Enterprise Marketplace. The configuration consists of:

1. Creating an OIDC Provider
2. Creating an Application
3. Connecting the Application to Ocean Market
4. Verifying the OIDC endpoints

## Preconditions

Before starting, ensure:

* Authentik is installed and accessible (see <https://docs.goauthentik.io/install-config/>). Make sure it is configured with a qualified digital certificate.
* Ocean Market frontend is deployed (see [this chapter](/infrastructure/marketplace-installation-and-configuration/marketplace-installation))
* You have administrator access to Authentik.
* You know your Ocean Market callback URL.\
  Example callback URL: `https://market.example.com/auth/callback`

## Steps

* [Configure the Authentik provider and application](/infrastructure/marketplace-installation-and-configuration/configure-market-level-authentication/configure-the-authentik-provider-and-application)
* [Configure the marketplace to use OIDC authentication](/infrastructure/marketplace-installation-and-configuration/configure-market-level-authentication/configure-the-oe-marketplace-to-use-oidc-authentication)
* [Authentication Flows and User Enrollment in Authentik](/infrastructure/marketplace-installation-and-configuration/configure-market-level-authentication/configure-authentication-and-user-enrollment-flows-in-authentik)
* [Configure User Groups and Application Access Control](/infrastructure/marketplace-installation-and-configuration/configure-market-level-authentication/configure-user-groups-and-application-access-control)


# Configure the Authentik provider and application

## Log in to the Authentik Admin console

1\. Open your Authentik admin panel

Example: `https://your-authentik-domain:8443`

2\. Log in using an administrator account.

<figure><img src="/files/VKMqkXINmgzct8ZW5Alg" alt=""><figcaption></figcaption></figure>

## Create an OAuth2 / OIDC provider

1\. In the Authentik admin panel, navigate to `Applications → Providers`

<figure><img src="/files/vJdzcV97GHuZF4LaV02y" alt=""><figcaption></figcaption></figure>

2\. Select `Create`

<figure><img src="/files/PPEUDNG4hT1FhqCPQpgg" alt=""><figcaption></figcaption></figure>

3\. Select `OAuth2 / OpenID Provider`

<figure><img src="/files/gYq1y6ee6XhlvoFsBDat" alt=""><figcaption></figcaption></figure>

## Configure the provider

4\. Press Next and enter the following configuration:

**Basic Configuration**

* Name: `ocean-market-provider`
* Authorization Flow: `default-provider-authorization-implicit-consent`

<figure><img src="/files/oOwJcroi5dgJAH9ERGl9" alt=""><figcaption></figcaption></figure>

***

**Protocol settings**

* Client Type: `Confidential`
* Client ID: Use the generated value
* Client Secret: Use the generated value
* Redirect URIs
  * Add the Ocean Market callback URL: `https://market.example.com/auth/callback`
  * Use `Strict Matching`

<figure><img src="/files/6UcH6O9wkDpQM3I3PYM4" alt=""><figcaption></figcaption></figure>

* Signing Key: select the key associated with the qualified certificate configured in Authentik

<figure><img src="/files/S33WIoUy7GRNEgIZR2mk" alt=""><figcaption></figcaption></figure>

***

**Advanced flow settings**

* Authentication flow: `default-authentication-flow`
* Invalidation flow: use the default setting

<figure><img src="/files/HCp0O7Y4HDunTqCqs3Gv" alt=""><figcaption></figcaption></figure>

***

**Advanced protocol settings**

* Scopes: add the following to Selected Scopes
  * openid
  * profile
  * email
  * offline\_access

These scopes allow OE Marketplace to retrieve user identity information

***

5\. Click Finish to save the provider

***

## Create the Ocean Market Application

1\. Navigate to `Applications->Applications`

<figure><img src="/files/1tNPbMvuXa97Y7RIUbiY" alt=""><figcaption></figcaption></figure>

2\. Click Create and enter the following information:

* Application Name: `Ocean Market`
* Slug:`ocean-market`&#x20;
* Provider: `ocean-market-provider`

<figure><img src="/files/gW0WbryO0WaRGNRErAcp" alt=""><figcaption></figcaption></figure>

3\. Click Create

***

## Retrieve OIDC Credentials

1\. Click the created provider

2\. Copy the following values

* Client ID
* Client Secret (displayed only in Edit mode)
* OpenID Configuration Issuer (example: `https://ocean-node-vm2.oceanenterprise.io:8443/application/o/ocean-market/`)
* OpenID Token URL (example: `https://ocean-node-vm2.oceanenterprise.io:8443/application/o/token/`)

These values are required in the Ocean Market environment configuration.

***

## Verify the OIDC Configuration

1\. Open the provider discovery endpoint (`https://your-authentik-domain:8443/application/o/ocean-market/.well-known/openid-configuration`)

2\. If configured correctly, Authentik returns the OIDC metadata as JSON. This confirms that the provider is correctly configured.


# Configure the OE marketplace to use OIDC authentication

## Configure OE Market Environment Variables

1\. Add the following environment variables to OE Marketplace (in the `.env` file):

{% code overflow="wrap" %}

```shellscript
EXT_PUBLIC_AUTH_ENABLED=true
NEXT_PUBLIC_AUTH_PROVIDER=oidc
NEXT_PUBLIC_OIDC_ISSUER=<your_oidc_issuer_url>
NEXT_PUBLIC_OIDC_CLIENT_ID=<your_oidc_client_id>
OIDC_CLIENT_SECRET=<your_oidc_client_secret>
NEXT_PUBLIC_OIDC_REDIRECT_URI=<your_oidc_redirect_uri>
NEXT_PUBLIC_OIDC_TOKEN_URL=<your_oidc_token_url>
NEXT_PUBLIC_OIDC_SIGNUP_FLOW=<your_oidc_signup_flow> # Optional: only needed if your OIDC provider has a separate signup flow
```

{% endcode %}

2\. Restart the OE Marketplace with the new environment variables

## Expected results

After completing this configuration:

1. Users can log in from Ocean Market.
2. Authentik authenticates the user.
3. The user is redirected back to OE Market.
4. OE Market receives the OIDC tokens and creates the session.


# Configure authentication and user enrollment flows in Authentik

This guide explains how to configure authentication flows in Authentik for Ocean Market.

The flow configuration defines how users:

* Log in to Ocean Market
* Register new accounts
* Complete user enrollment
* Start authenticated sessions

By the end of this guide, users will be able to:

* Sign in using existing credentials
* Create accounts through self-service registration
* Be automatically redirected back to Ocean Market after authentication

## Preconditions

Before starting, ensure the following requirements are met:

* Authentik Provider and Application are already configured
* Ocean Market OIDC integration is working.
* The provider uses: `default-authentication-flow`

## Steps

### 1. Configure the Login Flow

The OE Market uses Authentik’s authentication flow to handle user login.

1\. Navigate to `Flows and Stages -> Flows`&#x20;

<figure><img src="/files/UFkVgvlhq49CQYvfVoOv" alt=""><figcaption></figcaption></figure>

2\. Open `default-authentication-flow` . This flow is used by the OIDC provider created in the previous guide.

<figure><img src="/files/BZFgtBXKBj3wUGo5r6d9" alt=""><figcaption></figcaption></figure>

3\. Select Stage Bindings and Edit `default-authentication-identification` (Type Identification Stage).

4\. Configure the following:

* Stage-specific settings
  * User fields: check `Username` and `Email`. This allows users to log in using either their username or email address.
  * Password Stage: `default-authentication-password`

<figure><img src="/files/C9q8iUDiUrxgppsXSnkY" alt=""><figcaption></figcaption></figure>

This allows users to log in using either their username or email address.

5\. Save the changes.

\
6\. In the Stage Binding view, make sure the flow includes the `default-authentication-mfa-validation`  and `default-authentication-login` stages, as shown in the image below.

<figure><img src="/files/xUtupudQCdwOUDkhAS73" alt=""><figcaption></figcaption></figure>

### 2. Configure the Registration Flow

To allow users to create accounts without administrator intervention, create a self-service registration flow. &#x20;

#### Create the registration flow

1\. Navigate to `Flows & Stages → Flows → Create`

2\. In the Create Flow form, configure the following attributes:

* Name: `self-service-registration`
* Title: `Sign-up`
* Slug: `self-service-registration`&#x20;
* Designation: `Enrollment`

<figure><img src="/files/poTr0SmMDRvtWAtR1ZRr" alt=""><figcaption></figcaption></figure>

3\. Click `Create`.

#### Add registration stages to the registration flow

1\. Open the newly created flow

2\. Navigate to `Stage Bindings`

3\. Add the following stages in this order by pressing `Bind Existing Stage`:

* Stage name: `default-source-enrollment-prompt`. This stage identifies the new user.
  * Type: `Prompt Stage`
  * Order: `10`
  * Within this stage, configure the following fields:
    * **Stage-specific settings**
      * *Fields*: select the following attributes:
        * Username (`default-user-settings-field-username`);
        * Email (`default-user-settings-field-email`);
        * Name (`default-user-settings-field-name`);
        * Password (`default-user-settings-field-password`);
        * Re-enter password (`default-user-settings-field-password-repeat`);

<figure><img src="/files/zGGAEpkefbSdqjNOYmnn" alt=""><figcaption></figcaption></figure>

* Stage name: `default-source-enrollment-write`. This stage creates the user account in Authentik.
  * Type: `User Write Stage`
  * Order: `20`
  * Within this stage, configure the following fields:
    * **Stage-specific settings**
      * Select `Create users when required`&#x20;
      * Select `Create users as inactive`
      * User Type: `Internal`&#x20;
      * Do not configure policies or group assignments at this stage

<figure><img src="/files/ip4HCypsBEFoS2UVRC3j" alt=""><figcaption></figcaption></figure>

* Stage name: `email-account-confirmation`. This stage creates the user account in Authentik.
  * Type: `Email Stage`
  * Order: `30`
  * Within this stage, configure the following fields:
    * **Stage-specific settings**
      * Select `Activate pending users on success`&#x20;
      * Template: `Account Confirmation`
    * **Connection settings**
      * In case you didn't set the SMTP configuration at the Authentik server level, you can set the parameters in this group&#x20;

<figure><img src="/files/XxWcI93U0HnX3bu9mMBW" alt=""><figcaption></figcaption></figure>

\
4\. Add the following stage by pressing `Create and bind Stage`

* Stage name: `after-signup-redirect`. This stage redirects the user to the application login page.
  * Type: `Redirect Stage`
  * Order: `40`
  * Within this stage, configure the following fields:
    * **Stage-specific settings**
      * Mode: `Static`
      * Target URL: the login URL of the marketplace (i.e. `https://market.demo.oceanenterprise.io/auth/login`)

<figure><img src="/files/GgJRU0r1PWUC6oyT4SZc" alt=""><figcaption></figcaption></figure>

In the end, the stages of the registration flow should look similar to the image below.

<figure><img src="/files/HKntMINex4WY3yeUmw7g" alt=""><figcaption></figcaption></figure>

### 3. Enable Sign-Up on Login Screen

1\. Open `default-authentication-flow`

2\. Navigate to `Stage Bindings` and edit `default-authentication-identification` (Identification Stage)

3\. Configure the following fields:&#x20;

* **Flow Settings**&#x20;
  * Enrollment Flow: `self-service-registration`

<figure><img src="/files/fr0rmIpwIrE4BV47MxA2" alt=""><figcaption></figcaption></figure>

4\. Press Update to save the changes.&#x20;

### 4. Test the configuration

To test the configuration, perform the following:

**User login test:**

* Open Ocean Market login page
* Click Login with Authentik
* Authenticate&#x20;
* Verify the user is redirected back to Ocean Market

**User Registration test:**

* Open Ocean Market signup page
* Click Sign up with Authentik&#x20;
* Create a new account&#x20;
* Verify the user is created in Authentik&#x20;
* Verify successful login and redirect back to Ocean Market

**Expected Result**

* After completing this configuration:
* Existing users can log in
* New users can self-register
* Users are automatically authenticated
* Ocean Market receives the OIDC token and creates the session


# Configure User Groups and Application Access Control

This guide explains how to configure user groups and access control in Authentik for Ocean Market.

In Authentik, user groups allow administrators to:

* Organize users by role
* Control application access
* Assign administrative privileges
* Manage marketplace permissions

By the end of this guide, administrators will be able to:

* Create user groups
* Assign users to groups
* Restrict access to Ocean Market
* Separate administrative users from standard users

## Access Control Model

Ocean Market uses role-based access control through Authentik groups.

The recommended initial structure is:

| **Group**          | **Purpose**                |
| ------------------ | -------------------------- |
| marketplace-users  | Standard marketplace users |
| marketplace-admins | Marketplace administrators |

Standard users can access the marketplace and perform normal operations.

Administrative users can access the marketplace and manage platform operations.

## Preconditions

Before starting, ensure the following requirements are met:

* Authentik Provider and Application are configured.
* Authentication and registration flows are working.
* Users can successfully log in to Ocean Market.

## Steps

### 1. Create a standard user group

1\. Navigate to `Directory → Groups` and click New Group.

2\. Configure the following attributes:

* Name: `marketplace-users`
* Parent: Leave empty
* Attributes: Leave the default values unless custom metadata is required

3\. Click `Create Group`

### 2. Create an administrator group

1\. Navigate to `Directory → Groups` and click New Group.

2\. Configure the following attributes:

* Name: `marketplace-admins`
* Parent: Leave empty
* Attributes: Leave the default values unless custom metadata is required

3\. Click `Create Group`<br>

### 3. Assign existing users to groups

1\. Navigate to `Directory → Users`

2\. Click a user name to open the user details page

3\. Select the `Groups` tab

4\. Click `Add to existing group`

5\. Click the plus sign to open the list of groups

6\. From the list, select `marketplace-users` for a standard user or `marketplace-admins` for an administrator

7\. Click `Add` to assign the user to the group. The list of groups will close.

8\. Click `Add` in the Add Group window to save the changes.

### 4. Automatic group assignment during user signup

To automatically assign new users to a marketplace group during registration, do the following:

1\. Navigate to `Flows & Stages → Flows` and select the sign-up flow created earlier (`self-service-registration`)

2\. Select the `Stage Bindings` tab

3\. Edit `User Write Stage`

4\. Configure the following field:

Group: `marketplace-users`

5\. Click `Update` to save the stage.

<img src="/files/VTckjLeDuc1U4aYaY70A" alt="" height="339" width="624">

This ensures that every new user created through self-service registration automatically receives marketplace access.<br>

### 5. Restrict Application Access

To allow only users in the `marketplace-users` group to access the Ocean Market application, do the following:

1\. Navigate to `Applications → Applications`

2\. Open `Ocean Market`

3\. Select the `Policies / Group / User Bindings` tab

4\. Click `Bind existing Policy / Group / User`

5\. In the `Create Binding` window, select the `Group` tab

6\. In the `Group` field, select the `marketplace-users` group that should have access to the application. Leave the other fields with their default values.

7\. Click `Create` to save the changes.

<br>


# Configure federated market-level authentication

<mark style="color:$warning;background-color:$warning;">WORK IN PROGRESS</mark>


# SSI Stack installation and configuration

The SSI stack used in Ocean Enterprise is based on the [walt.id Identity Infrastructure Community Stack](https://walt.id/identity-infrastructure). The following software components of the Identity Infrastructure are used in Ocean:

* SSI Wallet: API endpoints that implement SSI wallet functionality (managing DIDs and VCs, presenting VCs).
* SSI Wallet User Interface: The graphical interface for the wallet APIs, allowing users to manage DIDs and VCs.&#x20;
* SSI Verifier: API endpoints that implement the SSI verifier functionality (initiate OIDC presentation sessions, verify the responses for a verification request, get information about OIDC presentation sessions)
* OPA server: API endpoints of the policy engine, used for custom policy evaluation

## Prerequisites

### Hardware requirements

The minimum hardware requirements for the server hosting the SSI stack components are:

* number of cores: 1
* RAM: 4 GB
* disk: 25 GB

### Software requirements

* **Operating System:** Any Linux distribution supported by the Docker Engine and Docker Compose products. For guidance on compatible platforms, see the [Docker Compose supported platforms](https://docs.docker.com/desktop/setup/install/linux/) and [Docker Engine supported platforms](https://docs.docker.com/engine/install/) documentation
* **Software products:**
  * Docker Engine
  * Docker Compose
  * git

## Pre-installation steps

Make sure you review the [Compatibility Matrix](/infrastructure/compatibility-matrix) to ensure that the version is compatible with the other components.

&#x20;Before installing the SSI stack components, determine the network segments where each service will run. Consider the following communication requirements:

* The verifier-api must be able to reach both the Policy Server and the OPA Server.&#x20;
* The wallet-api must be able to communicate with the waltid-dev-wallet and the Policy Server Proxy

Depending on your configuration, you can choose to deploy all SSI components on a single server or deploy individual components on separate servers.&#x20;

## Deployment steps

### Option 1 - Deploy the entire SSI stack

To install and configure the SSI stack, perform the following steps:

1. The OE version of the SSI stack is located [here](https://github.com/OceanProtocolEnterprise/waltid-identity/). Clone the repository.

```shellscript
git clone https://github.com/OceanProtocolEnterprise/waltid-identity.git && cd waltid-identity
```

2. Switch to the `OE` branch.&#x20;

```shellscript
git checkout OE
```

3. Change the current directory to `docker-compose`

```shellscript
cd docker-compose
```

4. Start the Docker SSI services containers

```shellscript
docker compose up -d
```

This command will pull the correct versions of the Docker images used by OE and start the containers. This command will also start other services not used by the OE stack, such as the web portal, the issuer, and the demo wallet.

Note: the OPA server is not automatically started by this command.&#x20;

5. Start the OPA server.&#x20;

```shellscript
docker compose up opa-server -d
```

### Option 2 - Deploy an individual component

Each component is defined as a service in the `docker-compose.yaml` file, as follows:

* `wallet-api`: SSI Wallet
* `waltid-dev-wallet`: SSI Wallet User Interface
* `verifier-api`: SSI Verifier
* `opa-server`: OPA Server

To deploy an individual component, perform the following steps:

1. The OE version of the SSI stack is located [here](https://github.com/OceanProtocolEnterprise/waltid-identity/). Clone the repository.

```shellscript
git clone https://github.com/OceanProtocolEnterprise/waltid-identity.git && cd waltid-identity
```

2. Switch to the `OE` branch.&#x20;

```shellscript
git checkout OE
```

3. Change the current directory to `docker-compose`

```shellscript
cd docker-compose
```

4. Start the service. For instance, to start the `wallet-api` service, run the following command

```shellscript
docker compose up wallet-api -d
```

This command pulls the appropriate version of the component’s Docker image and starts its container.

## **Post installation steps**

* Deploy the SSI stack components behind a reverse proxy responsible for TLS termination and secure request forwarding. The proxy should enforce HTTPS for all external traffic and route decrypted requests to the internal application port.
* After installation, the components work seamlessly with the rest of the OE stack and require no additional configuration. However, for advanced configuration or ongoing maintenance of the SSI Stack components, consult the official [walt.id documentation](https://docs.walt.id/community-stack/home).&#x20;

## TCP ports

The following TCP ports are used by default by the SSI stack components:&#x20;

* wallet-api: 7001
* waltid-dev-wallet: 7104
* verifier-api:7003
* opa-server: 8181

You can change the ports by editing the `/docker-compose/.env` file.


# Policy Server and Policy Server Proxy installation and configuration

## Prerequisites

### Hardware requirements

The minimum hardware requirements for the server hosting the marketplace are:

* number of cores: 1
* RAM: 2 GB
* disk: 0.5 GB

### Software requirements

* **Operating System:** Any Linux distribution supported by the Docker Engine and Docker Compose products. For guidance on compatible platforms, see the [Docker Compose supported platforms](https://docs.docker.com/desktop/setup/install/linux/) and [Docker Engine supported platforms](https://docs.docker.com/engine/install/) documentation
* **Software products:**
  * Docker Engine
  * Docker Compose

## Pre-installation steps

Make sure you review the [Compatibility Matrix](/infrastructure/compatibility-matrix) to ensure that the version is compatible with the other components.

## Deployment steps

There are two ways to install and run the Policy Server: using Docker Compose or the Docker Engine.

### Option 1 - Use Docker Compose to install and run the Policy Server

To install and configure the Policy Server, perform the following steps:

1. The Policy Server repository is located [here](https://github.com/OceanProtocolEnterprise/policy-server).&#x20;

```shellscript
git clone https://github.com/OceanProtocolEnterprise/policy-server.git && cd policy-server
```

2. Change the current directory to `docker-compose` .

```shellscript
cd docker-compose
```

3. Copy `.env.example` to `.env`&#x20;

```sh
cp .env.example .env
```

4. Edit the `.env` file to set environment variables specific to your configuration (please refer to the [Environment Variables](#environment-variables) chapter for how to set them).

```sh
nano .env
```

5. Start the Policy Server service

```sh
docker compose up -d
```

The Policy Server will start in a Docker container and will be accessible via HTTP on port 8001 on the host system.

### Option 2 - Use Docker to install and run the Policy Server

To install and configure the marketplace, perform the following steps:

1. The Policy Server repository is located [here](https://github.com/OceanProtocolEnterprise/policy-server).&#x20;

```shellscript
git clone https://github.com/OceanProtocolEnterprise/policy-server.git && cd policy-server
```

2. Copy `.env.example` to `.env`&#x20;

```sh
cp .env.example .env
```

3. Edit the `.env` file to set environment variables specific to your configuration (please refer to the [Environment Variables](#environment-variables) chapter for how to set them).

```sh
nano .env
```

4. Start the Policy Server service.

```sh
 docker run --name policy-server --env-file .env -p 8001:3000 -v ./certs:/etc/ssl/certs:ro -d oceanenterprise/policy-server:latest
```

The Policy Server will start in a Docker container and will be accessible via HTTP on port 8001 on the host system.

## **Post installation steps**

* Deploy the policy server behind a reverse proxy responsible for TLS termination and secure request forwarding. The proxy should enforce HTTPS for all external traffic and route decrypted requests to the internal application port.
* Place the policy server in a network environment that allows outbound communication to the configured OE Node and SSI Verifier.

## Environment Variables

### Operation Mode

The Policy Server component can run in two modes:&#x20;

* as an actual Policy Server: implements the Policy Server functionality, as described [here](/developers/oe-software-stack-components#policy-server);
* as a Policy Server Proxy: implements the Policy Server Proxy functionality, as described [here](/developers/oe-software-stack-components#policy-server-proxy).

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: While both modes can run within the same component, deploying them on separate servers is recommended to clearly isolate front‑end traffic from back‑end traffic.</mark>

#### MODE\_PS

**Description:** Indicates whether Policy Server mode is enabled.&#x20;

* Value `"1"`: the Policy Server mode is enabled&#x20;
* Value `"0"`: the Policy Server mode is disabled

**Values:** string (`"1"` or `"0"`)

**Example:** `"1"`

**Default Value:** `N/A`

#### MODE\_PROXY

**Description:** Indicates whether Policy Server Proxy mode is enabled.&#x20;

* Value `"1"`: the Policy Server Proxy mode is enabled&#x20;
* Value `"0"`: the Policy Server Proxy mode is disabled

**Values:** string (`"1"` or `"0"`)

**Example:** `"1"`

**Default Value:** `N/A`

### OE Node

#### OCEAN\_NODE\_URL&#x20;

**Description:** Sets the base URL of the OE Node used by the policy server. The policy server will receive authorization requests from this OE Node and will send back either an authorization response (allow/deny) or other messages received from the Verifier. Make sure the OE Node has the corresponding  `POLICY_SERVER_URL` variable set to the policy server's URL.

**Values:** string (URL)

**Example:** `https://ocean-node-vm3.oceanenterprise.io/`

**Default Value:** `N/A`

### SSI Verifier

#### AUTH\_TYPE

**Description:** Sets the type of authorization used by the policy server. The only possible value now is `waltid`, meaning that the authorization is based on the walt.id Identity Suite components.&#x20;

&#x20;**Values:** string

**Example:** `waltid`

**Default Value:** `waltid`

#### WALTID\_VERIFIER\_URL

**Description:** Sets the base URL of the verifier component used by this policy server. For an access request to an asset, the policy server forwards the requested credentials and the verification policies to the verifier component, which initiates a presentation session.&#x20;

**Values:** string (URL)

**Example:** `https://verifier2.demo.oceanenterprise.io/`

**Default Value:** `N/A`

### Policy Server Proxy

#### WALTID\_VERIFY\_RESPONSE\_REDIRECT\_URL

**Description:** Sets the redirect URL for the verify calls performed by the SSI Wallet. The URL must include the base URL of the Policy Server Proxy, followed by `/verify/\$id`.

**Values:** string (URL)

**Example:** `https://psproxy1.demo.oceanenterprise.io/verify/\$id/`

**Default Value:** `N/A`

#### WALTID\_VERIFY\_PRESENTATION\_DEFINITION\_URL

**Description:** Sets the redirect URL for the presentation definition calls performed by the SSI Wallet. The URL must include the base URL of the Policy Server Proxy, followed by `/pd/\$id`.

**Values:** string (URL)

**Example:** `https://psproxy1.demo.oceanenterprise.io/pd/\$id/`

**Default Value:** `N/A`

### Default Verification Policies

The Policy Server can be configured to apply additional static verification policies beyond those provided by the OE Node in a verification request. The verification policies can be applied to the Verifiable Credential presented by the SSI Wallet or to the Verifiable Presentation that embeds the Verifiable Credentials submitted by the SSI Wallet.

The list of static verification policies is available [here](https://docs.walt.id/community-stack/verifier/credential-verification/policies/static-verification-policies). &#x20;

#### DEFAULT\_VC\_POLICIES

**Description:** Sets the default static policies applied to the Verifiable Credentials submitted by the SSI Wallet for verification.&#x20;

**Values:** list of strings

**Example:** `"expired","signature","revoked-status-list","not-before"`

**Default Value:** `[]`

#### DEFAULT\_VP\_POLICIES&#x20;

**Description:** Sets the default static policies applied to the Verifiable Presentation submitted by the SSI Wallet for verification.&#x20;

**Values:** list of strings

**Example:** `"expired","signature","revoked-status-list","not-before"`

**Default Value:** `[]`

### SSI Verification Response

#### WALTID\_SUCCESS\_REDIRECT\_URL

**Description:** Sets the redirect URL to return when all verification policies are passed.&#x20;

**Values:** string (URL)

**Example:** `"https://example.com/success?id=$id"`

**Default Value:** `""`

#### WALTID\_ERROR\_REDIRECT\_URL

**Description:** Sets the redirect URL to return when a verification policy failed.&#x20;

**Values:** string (URL)

**Example:** `"https://example.com/error?id=$id"`

**Default Value:** `""`

### Action Validation based on web3 address

This group of variables configures the policy server to validate certain OE Node actions by checking the Web3 addresses of both the node and the consumer initiating the request.&#x20;

When configured with a Policy Server, the OE Node calls it to validate certain actions, passing the OE Node's address from which the action request was received and the consumer's address that initiated the request.&#x20;

The following actions are validated against the lists described in this section: `encrypt`, `decrypt`, `initiate`, `download`, and `startCompute`.

#### POLICY\_SERVER\_NODE\_ACCESS\_LIST

**Description:** Sets the list of OE Nodes web3 addresses from which the action requests are accepted.&#x20;

The policy server compiles the list of accepted nodes by merging the list in this environment variable and the list retrieved from `POLICY_SERVER_NODE_ACCESS_LIST_URL`. If the resulting list is null, action validation based on the OE Node's address is disabled. If it's not null, only action requests coming from nodes in this list are accepted.

**Values:** list of strings (comma separated)

**Example:** `"0x1111,0x2222"`

**Default Value:** `null`

#### POLICY\_SERVER\_NODE\_ACCESS\_LIST\_URL

**Description:** Sets the URL from where the list of node web3 addresses from which the action requests are accepted is loaded. The web3 addresses listed here must be separated by a new line character (one address per line).

The policy server compiles the list of accepted nodes by merging the list retrieved from this variable and the list defined in `POLICY_SERVER_NODE_ACCESS_LIST`. If the resulting list is null, action validation based on the OE Node's address is disabled. If it's not null, only action requests coming from nodes in this list are accepted.

**Values:** string (URL)

**Example:** `https://raw.githubusercontent.com/MBadea17/testdata/refs/heads/main/trustedNodes`

**Default Value:** `null`

#### POLICY\_SERVER\_CONSUMER\_ACCESS\_LIST

**Description:** Sets the list of consumer web3 addresses from which the action requests are accepted.&#x20;

The policy server compiles the list of accepted consumers by merging the list in this environment variable and the list retrieved from `POLICY_SERVER_CONSUMER_ACCESS_LIST_URL`. If the resulting list is null, action validation based on the consumer's address is disabled. If it's not null, only action requests coming from consumers in this list are accepted.

**Values:** list of strings (comma separated)

**Example:** `"0x3333,0x4444"`

**Default Value:** `null`

#### POLICY\_SERVER\_CONSUMER\_ACCESS\_LIST\_URL

**Description:** Sets the URL from where the list of consumers' web3 addresses from which the action requests are accepted is loaded. The web3 addresses listed here must be separated by a new line character (one address per line).

The policy server compiles the list of accepted consumers by merging the list retrieved from this variable and the list defined in `POLICY_SERVER_CONSUMER_ACCESS_LIST`. If the resulting list is null, action validation based on the consumer's address is disabled. If it's not null, only action requests coming from consumers in this list are accepted.

**Values:** string (URL)

**Example:** `https://raw.githubusercontent.com/MBadea17/testdata/refs/heads/main/trustedNodes`

**Default Value:** `null`

####

### Logs

#### ENABLE\_LOGS

**Description:** Indicates whether the logging is enabled.&#x20;

* Value `"1"`: logging is enabled&#x20;
* Value `"0"`: logging is disabled

**Values:** string (`"1"` or `"0"`)

**Example:** `"1"`

**Default Value:** `"0"`

### TCP Port

#### PORT

**Description:** Defines the port on which the application listens inside the container. In the `docker-compose.yml` file, the host port 8001 is mapped to the default container port (3000). In case you changed the default value, make sure you update the port mapping in the `docker-compose.yml` file.

**Values:** number

**Example:** `3000`

**Default Value:** `3000`

### API Requests Authentication

#### POLICY\_SERVER\_API\_KEY

**Description:** Defines the key used by the Policy Server to authenticate requests. If no value is provided, request authentication is disabled. If a key is provided, use the same key in the [POLICY\_SERVER\_API\_KEY ](/infrastructure/oe-node-installation-and-configuration#policy_server_api_key) variable of the corresponding OE Node.

**Values:** string

**Example:** `mrgcorhTzA1Ey2WRhZAK8tkw4zBrIgQ757toUz3fXvfHh8Ua`

Defaul Value: `null` (request authentication disabled) &#x20;

#### ADMIN\_API\_KEY

**Description:** Sets the API key that protects the administrative endpoints of the Policy Server. The caller must set this value in the `X-API-KEY` header to be authenticated. If the value is null, key authentication is disabled.

The administrative endpoints of the Policy Server are:

* **`listAcceptedNodes`**: list the web3 addresses of the accepted OE Nodes (from `POLICY_SERVER_NODE_ACCESS_LIST` and `POLICY_SERVER_NODE_ACCESS_LIST_URL`)
* **`listAcceptedConsumers`**:  list the web3 addresses of the accepted consumers (from `POLICY_SERVER_CONSUMER_ACCESS_LIST` and `POLICY_SERVER_CONSUMER_ACCESS_LIST_URL`)
* **`reloadAcceptedNodes`** : reload the lists from `POLICY_SERVER_NODE_ACCESS_LIST_URL`&#x20;
* **`reloadAcceptedConsumers`** : reload the lists from `POLICY_SERVER_CONSUMER_ACCESS_LIST_URL`.

**Values:** string&#x20;

**Example:** `abcd1234`

**Default Value:** `null`

### HTTPS connection

Set the following environment variables to enable HTTPS connections on the Policy Server.&#x20;

<mark style="color:$info;background-color:$info;">**Note**</mark><mark style="color:$info;background-color:$info;">: The Policy Server start commands shown in this guide mount the</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">`certs`</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">directory from the repository into the container at</mark> <mark style="color:$info;background-color:$info;"></mark><mark style="color:$info;background-color:$info;">`/etc/ssl/certs/`</mark><mark style="color:$info;background-color:$info;">. To enable HTTPS with minimal setup, place your certificate files in this directory and adjust the environment variable to reference the correct certificate file name.</mark>

#### HTTP\_CERT\_PATH

**Description:** Sets the location where the TLS certificate of the Policy Server resides. If the value is null, the HTTPS connection is not enabled. Make sure that the referenced file includes both the digital certificate and the intermediate certificate.

Please note that the&#x20;

**Values:** string

**Example:** `/etc/ssl/certs/cert.pem`

**Default Value:** `null`

#### HTTP\_KEY\_PATH

**Description:** Sets the location where the private key file of the TLS certificate resides. If the value is null, the HTTPS connection is not enabled.&#x20;

**Values:** string

**Example:** `/etc/ssl/certs/key.pem`

**Default Value:** `null`


