Introducing Token Proof of Work

*A simple way to make AI spam expensive. We wrote a short whitepaper on an idea we haven't built — here's the thinking, and the paper.*

Every contact form we've built in the last fifteen years assumed the same thing: that on the other end there's a person, typing. That assumption is expiring.

We've been putting tools in front of AI agents all year — 26 pay-per-call APIs over at [_done](https://underscoredone.com), and a lot of thinking about what happens when the thing using your website isn't a browser with a human behind it. Somewhere in the middle of that, an obvious problem showed up and wouldn't go away.

The problem is that writing got free

Spam has always been an economics problem, not a technology one. Email spam exists because sending an email costs nothing. The one cost that was left — actually writing the thing — is gone now. A model will produce ten thousand messages that are fluent, personalized, and each one different. Filters that look for repetition have nothing left to catch.

So the natural reflex is to reach for a CAPTCHA. But a CAPTCHA asks "are you human?" — and increasingly the answer we *want* is no. If you run a store and you've exposed your contact form to agents through WebMCP, you're doing that on purpose. You want an agent to bring you a real customer question. You just don't want ten thousand of them an hour.

"Are you human?" is the wrong question. The right one is: **did this message cost you anything?**

Borrowing from Bitcoin

Bitcoin solved a version of this without ever asking who anyone was. It didn't check identity; it made cheating expensive by demanding proof that real computer work had been spent.

Point that same idea at an AI agent and ask what's actually scarce. Two things are: **tokens**, because every word a model generates costs money, and **time**, because a minute is a minute no matter how well funded you are.

That's the whole proposal. To get a message accepted, the sending agent first has to complete a small piece of fresh work that the receiver issues — work that provably burned a minimum number of tokens — and the message is only accepted once a minimum amount of time has gone by. Both, together.

 

Roughly, it looks like this:

1. The agent asks to send a message.
2. You hand back a one-time challenge tied to that exact message. Nothing that can be prepared in advance or reused.
3. The agent's model has to do real work on it — generate a required amount of output that addresses both the challenge and the message.
4. You accept only if the work checks out **and** the clock has run.

 

You set the price. A contact form might ask for tens of thousands of tokens and 35 seconds. A directory submission can ask for more. One honest sender never notices. A million of them costs real money and real hours.

Why it has to be both

Each half covers for the other.

Tokens alone get cheaper every year, and a spammer can run messages in parallel, so the cost per message keeps shrinking. Time alone is trivially waited out across thousands of parallel identities.

Together you get two independent dials: raise the token price to attack budgets, raise the time price to attack volume.

Where we think it fits

The original itch was contact forms exposed to agents through WebMCP. But it generalizes to anywhere "free to submit" invites flooding — directory and marketplace submissions, app stores, reviews, comments, support tickets, job applications.

It sits *beside* pay-per-call rather than competing with it. Where charging money is fine, a small x402 payment does the same job more directly, and that's what we already build. Token Proof of Work is for the places where charging the sender feels wrong — a customer contacting a store shouldn't have to pay to ask a question — but where spam still has to cost the spammer something.

What this isn't

This is an idea, not a protocol. There's no spec and no implementation. Nothing here has been built.

The hard part, and we'd rather say it than bury it, is honest verification: how does a receiver confirm tokens were genuinely spent, instead of faked by a cheaper model or a lookup? We think challenge design can make cheating cost about as much as complying — which is all proof of work has ever needed to do — but that's a claim to be earned, not asserted.

We're publishing it to start the argument rather than to win it.

 

**📄 Read the whitepaper:** [Token Proof of Work (PDF)](https://github.com/onescales/token-proof-of-work/blob/main/token-proof-of-work.pdf) · [on GitHub](https://github.com/onescales/token-proof-of-work) (MIT)

 

Or View Whitepaper PDF here

 

Got suggestions, criticism, or an implementation? Tell us: **info@onescales.com**.

The Best Shopify Growth Course Online Today

Stuck with sales or starting a new ecommerce shop? Take your Shopify store to the next level. Our comprehensive online course is expertly crafted to equip you with the skills, tools, and knowledge you need to boost your store’s sales and make a real-world impact

Leave a comment

Please note, comments need to be approved before they are published.

Tags

Thank You For Reading Our Articles!

We're committed to delivering real answers, valuable insights, and efficient knowledge online. Join us by subscribing, sharing, and engaging with our community to make a difference!