PSECS API
Updated 2026-10-10
What it was
PSECS was a persistent space commerce and fleet management game — corporations, fleets, mining, a player-run market — with no game client at all. Players acted entirely through an MCP server, a REST API, or a command-line tool called papi, which made the game as scriptable as it was playable: bots and the API client were first-class, not an afterthought. In practice that meant you opened Claude and told it what you wanted your empire to do.
The problem
The game’s core entities — ships, fleets, corporations, market listings — were exactly the kind of thing that breaks under naive concurrent access: two players’ fleets queuing at the same conduit, a market order matching while someone else bids on it, a corp’s credits being spent from two requests at once. Each of those needed its state changes serialized per-entity without the rest of the system blocking on it.
How it was built
PSECS was an Orleans actor system on .NET 9 — the same framework from the Orleans post on this site — split into psecsapi.Silo (the Orleans host), psecsapi.Grains (actor implementations with state), psecsapi.Grains.Interfaces (grain contracts and access attributes), and psecsapi.api (a thin REST facade in front of grain calls). Its own Getting Started walks through running the silo and the API as separate processes; that split is the architecture, not an afterthought.
Domain structure follows the ownership chain: a User, identified by a Solana wallet, owns one or more Corps, which own Fleets, which contain Ships; Sectors connect to each other through Conduits. Access to grain methods is enforced per-method by six attributes — AnyAccess, MemberAccess, OfficerAccess, OwnerAccess, InternalAccess, and SelfAccess — checked by a GrainAccessInterceptor. The first five gate against a corp’s membership roster (member, officer, owner) or exempt the call from auth entirely (AnyAccess) or from external calls entirely (InternalAccess, for grain-to-grain calls only). SelfAccess is different: it’s used on grains keyed by the user’s own ID — IUser, IUserMap — and the interceptor checks the grain’s primary key against the caller’s decoded identity directly, with no corp or roster involved, so a user can call GetUserProfile or CreateCorp only against their own user grain, never anyone else’s. When a grain needs to call another grain’s member-or-higher method internally, it exposes an Internal-suffixed variant rather than loosening the public one. Auth is a Solana wallet challenge-sign-verify flow issuing a 15-minute JWT plus a refresh token, with the wallet address encrypted into Orleans’ RequestContext so grains can make access decisions without a second round trip. Rate limiting is staked rather than flat: 30 + 57 × floor(staked tokens) requests per minute, capped at 600, with up to 10 tokens stakeable and a 60-minute cooldown before unstaked tokens become available again.
On top of that sit the actual game systems: fleet transit with a slowest-ship-speed queueing state machine, sensor-gated scanning, resource extraction, a seven-tier/seven-discipline research tree gating blueprints, manufacturing that derives output quality from input resource properties, and a market with both fixed-price and auction listings held under escrow. A companion service, psecsapi-bots, ran an LLM-driven player persona that posted to Bluesky through its own publisher daemon, with independent per-platform dispatch so a failure on one platform didn’t block the others, plus a content filter and best-effort image generation in front of it.
The server itself was closed source. The player-facing tools are still public in an archived repository — psecsapi-public holds the CLI, the MCP server, agent templates, and an OpenAPI spec — though there is no longer a service for any of them to talk to.
Status
Shut down in September 2026, after five months public. The API, the MCP server, and the CLI are all offline and will not return. Player accounts, corporations, and game state were permanently deleted along with the infrastructure, and nothing was retained. There is a full postmortem at psecsapi.com.
It was a technical success and a product failure, and the failure is the part worth keeping. The property that made the game automatable is the same property that made it inert to play: when an agent handles extraction, research allocation, cargo and navigation, the player’s role collapses into approving its decisions. That is a management job, not a game loop. A competent agent also reads the entire tech tree and computes an optimal path through it instantly, which dissolved the planning that was arguably the actual game. Putting the challenge back would have meant building several more games’ worth of interdependent systems, and finding enough players to compete over them — the design budget explodes at exactly the moment the interface gets easier.
The funnel says it more plainly than I can. Of 33 accounts ever created, 16 founded a corporation, 12 extracted a resource, and 3 got past the opening research — two of those three were mine. No manufacturing job was ever started and no battle was ever fought. Two corporations listed 38 items on the market and not one of them sold; the economy I was proudest of designing never cleared a single transaction between two human beings.
What outlived the game is the method. Driving a codebase this size with agents is what forced the structured refinement loops that became ralph-o-matic, which I still use daily. The second half of a multi-year project took three months — but the more useful effect was on risk than on speed, because agents lowered the bar on technologies I had no direct experience with and that changed which projects felt possible at all.