moxzi alpha — a Motoko compiler written in Motoko, and the runtimes to go with it
░░░▒▒▒▒▒░▒░░░▒░░░░░░░░░░░░▒▒▓ ░▒ ░ ▓ █▓▒ ░░ ▒▒▒░░░░░▒▒▒░░░▒▒▒░░░░░░░░░░░░▒
░░░░▒░▒░░▒▒▒░░▒░░░░░░░░░░░░▒ ░░ ▒▒▓▒ ▒▓░▒▒░▒▒░▒░░░░▒▒▒▒▒░▒▒░░▒░░░░░░░░▒▒
░░░░ ▒░▒ ░░▒░▒▒▒▒▒▓▓▒▒▒▒ ▒ ▓▒▒░░░░▒▒▒▒▒▒▒▒▒▒▒░░░░░░░▒▒▒
▒▒▒░ We hear you like ▒▒░ ░░░░░░░▒▒▒▒░▒▒▒▒▒▒ █░ ▒▒▒░░▒░▒▒▒▒░░▒▒▒▒▒▒▒▒▒░░░▒▒▒
▒░▒▒ motoko, so we put ░▒░ ░░░░░░░░░▒▒▒▒▒▒▒▒▒▒ ▓ ▓▒░░▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒░░▒▒▒
▒░▒░ a motoko compiler ░▒░ ░ ░░░░▒░░░▒▓▒▒▒▒▒▓█ ▓▒░░░▒▒▒▒▒░▒▒▒░▒▒▒▒▒▒▒▒░▒▒▒
▒░░░ in your motoko so ░▒░ ░░░▒░▒░▓▒ ▓░░ ░░▒▒▒▓░▒░▒▒▒░▒▒▒▒▒░▒▒▒░▒▒▒▒▒▒▒▒▒▒▒▒
▒▒░░ so you can motoko ▒▒▒ ░ ░░░░▒░░▒▓▓▓▒▒▒▒▒░░▒▒▒░░░░▒▒▒▒▒▒▒▒░▒▒▒▒▒▒▒▒▒▒▒
░░░░ while you motoko! ▒▒▓ ░░▒▒░░░ ▓▒ ░▒▒▒▒▒░▒▓▒▒▒▒▒░▒▒░░▒▒▒▒░░▒▒▒▒▒▒▒▒▒▒
▒░░▒ ░░▒▓ ░░▒ ▒▒▓▒▒▓▒▒▒▒▒▒░░▒▒▒▒▒▒▒▒▒░░▒▒▒▒▒▒▒▒▒▒▒▒▒░░▒
▒░▒▒░░░▒▒▒▒░░▒▒▒░░░░▒▒▒░░░▒▓▒ ░▒▒▒░ ░▒▒▒▒▒░ ▒▒▓▒▒▒░▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒
▒░░▒▒░░░▒▒▒ -xzibit (maybe)▒▓ ░▒▒░░▒▓▓█▓░▒▓▓░ ░░░▒░▓▒▒▒▒▒▒▒▒▒▒░▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒
▒▒░░░░░░▒▒▒░░░▒▒▒▒░░▒▒▒▒▒░░░▓ ░░░ ░▒▒▒░░░░▒▒░ ▒▓█████▓▓▒▒▒▒▒▒▒▒░░░▒▒▒▒▒▒
▒▒░░░▒░░▒▒▒░░░▒▒▒▒░░░░▒▒▒▒░░▒▓ ░ ░░░░░░░░█ ░ ░░░ ░▒ ▒▓████▓▓▒▒░░▒▒▒▒▒
░░░░░░░░░▒▒░░░▒▒▒▒▒░░░░░░▒▒░▒▒▓ ░░ ░▓█▓█▒░▓▓▓░ ░ ▒▓▓ ▒████▓▒▒▒▒
░░▒░░░▒░▒░▒░░░▒▒▒░░░░░░▒▒▒▓█▓▒█▓ ░░░░░░░░▒▒▒▒▒ ░░░▒░█ ░▓█▓▓
░░░▒▒░░░░░▒░▒░▒▒▒▒▒░▒▒▓█▓▒ ░░ ░▒▒▓░ ░░▒▒░█ ░ ░
░░▒▒▒▒░░░░▒▒░░░▒▓████ ░░ ░░▒▓▒▒░ ░▒▒▒▓ █ ░ ░
░░░▒░▒░░▒░░▒▒▒██▒ ▒ ░░ ░░░░▒░ █ ░
▒▒░░░░▒▒░▒▒▒▓░ █ ░░░░░░░░ █ ░
▒░▒▒░░░░▒▓▓ █ ██ ░
▒▒░░▒░░░▓ █▒ ██ ░
░
Today we’re releasing the first public alpha of moxzi (0.1.0-alpha.1): a self-hosted
Motoko toolchain. The compiler is written in Motoko and compiled to WebAssembly — by
itself — and the same wasm runs in four places:
moxzi— a local CLI.moxzi build hello.moin about 0.69s, no OCaml toolchain,
no Nix.- On-chain builder — the same compiler deployed as a canister.
moxzi build --remote
escrows ICP escrows 3× what the compile estimated cost is, and
refunds the difference after compile. moxzid— a server that hosts Motoko actors off-chain with IC compatible semantics: one
message at a time, traps roll back, timers, upgrades that keep state, cycles as a real
budget, inter-actor calls, HTTPS outcalls, crash durability.moxzi-web— the same runtime in a browser tab. Install actors, call them through
theidlFactorydfx generatealready writes, persist to IndexedDB.
Why it exists
Two reasons.
Trustless builds. Today, “this canister is the code I published” is a claim you make
about your laptop. If the compiler is itself a canister, a build becomes on-chain,
reproducible, and auditable end to end — the bytes were produced by a compiler anyone can
inspect, from sources anyone can hash. Every artifact moxzi emits names the compiler that
made it, by hash.
Motoko off the IC. A Motoko actor is a good programming model on its own —
transactional turns, durable state, no ORM. moxzid and moxzi-web let you run one on a
server or in a page, then deploy the same bytes to mainnet when you need consensus.
…more details
The thing binding the four together is byte identity and behavioral identity, gated in CI:
- The compiler self-compiles on-chain to a byte-identical fixed point under mainnet’s
real limits (40B instructions/message, 6 GiB heap). Most recent run: 169 files,
7,650,739 B of source in, 5,652,432 B of wasm out, 2,379 messages, ~1 hour of block
time, identical to the local build. - 221 corpus programs compile byte-identically across independent compiler builds.
- 149 programs behave identically in the browser runtime and the native one — and the
native runtime was validated against a real replica, so browser == native == replica. - The compiler compiles inside a Chrome tab, byte-identical to a native build.
moxzidsurviveskill -9by snapshot and by write-ahead-log replay, proven by a
gate, not a design note.
make alpha-check runs all of it — 60+ gates.
Language compatibility
moxzi began as a port of moc 1.8.2 and now matches 1.14.1:
Some limits:
- No certificates off-chain. A certificate is a subnet threshold signature; there is no
subnet in a server process or a tab, and a forged one makes no sense. So
@dfinity/agent’sActoris unsupported (generatedidlFactorys are), and
certified-data patterns need the real IC. - Browser metering is opt-in. V8 has no fuel, so
moxzi-webrewrites the module to
count its own instructions — worth it for untrusted code, off by default. moxzidis single-node, with one shared bearer token; TLS belongs in your reverse
proxy.- On-chain builds serialize per canister, and canister operators can read uploaded source
(mops-tag builds upload nothing).
License
Business Source License 1.1 — source-available, free for non-commercial use and for
commercial development, testing and evaluation. Commercial production use and competing
hosted offerings need a commercial license. Each released version converts to
Apache-2.0 four years after release. Not OSI open source yet. The goal is to accelerate this, but we need a funded supporting organization. ICDevs.org stands ready to take it on but needs a permanent endowment to provide long-term support. see: https://icdevs.org/donations.html
Try it
curl -fsSL https://moxzi.ai/install.sh | sh
echo 'persistent actor { public query func greet(n : Text) : async Text { "Hello, " # n # "!" } };' > hello.mo
moxzi build hello.mo -o hello.wasm
That wasm deploys to the IC as-is, runs under moxzid, and runs in a browser via
moxzi-web. Same bytes, same behavior.
In a browser
npm install moxzi-web @dfinity/candid @dfinity/principal
import * as glue from 'moxzi-web/runtime';
import { Moxzi } from 'moxzi-web';
import { indexedDbStore } from 'moxzi-web/storage';
import { idlFactory } from './declarations/greeter/greeter.did.js'; // what dfx generate wrote
const moxzi = await Moxzi.start({ glue, store: await indexedDbStore('my-app'), autosave: true });
const greeter = await moxzi.install({ name: 'greeter', wasm: '/greeter.wasm', idlFactory });
await greeter.greet('world'); // "Hello, world!"
await greeter.visitors(); // 2n — a candid nat is a BigInt, as agent-js users expect
install means make sure this actor exists: first visit installs, a return visit
restores from IndexedDB — including actors your actors spawned. Upgrades keep state.
Moxzi.start({ worker: true, deadlineMs: 5000, http: true }) adds a killable message
deadline and HTTPS outcalls.
If you code with an agent
The whole platform ships as agent-readable skills — one per product, in the standard
SKILL.md layout. Point your agent at the router skill and it fetches the rest as needed:
curl --create-dirs -o .claude/skills/moxzi/SKILL.md https://moxzi.ai/skills/moxzi.md
Browse them at moxzi.ai/skills — moxzi-cli,
moxzid-server, moxzi-web, moxzi-onchain-builds, each with real commands, real
output shapes, and an error → cause → fix table. They’re versioned in the same repo as
the code they describe, so an agent building against moxzi isn’t working from whatever
it happened to be trained on.
Docs at moxzi.ai. Bug reports and disagreements very welcome.