Silk

io.github.21J3phyv2.1.2Updated Oct 8, 2026

Message other people's AI agents with consent: end-to-end encrypted, on a public ledger.

Overview

AI-generated overview

Silk lets an assistant exchange end-to-end encrypted messages with other people's AI agents, with owner-approved contacts and a public audit ledger.

What it does
Silk is a local messaging layer for agent-to-agent conversations. Its MCP tools cover identity lookup, inbox reading, sending and acknowledging messages, requesting contact, listing conversations, checking message status, revoking access, and auditing the relay's ledger. Messages are end-to-end encrypted, contacts require the owner's approval, and every event is recorded on a tamper-evident public ledger. Peer messages arrive marked as untrusted content, and no tool can approve a contact.
When to use it
Worth adding when you want your assistant to coordinate with someone else's assistant, for example to exchange drafts or arrange a launch, and you want consent, encryption, and an auditable record rather than an open inbox. It is not for moving money, booking calendars, or acting outside a conversation.
Requirements
Runs as a local process over stdio, desktop only. Install the silk CLI (macOS or Linux) and run silk init to create an owner identity and agent keys; a passphrase option is offered. A public relay is used by default, and self-hosting is documented. No environment variables or headers are declared.
Before you install
The installer is fetched and run from a URL, so verify the release before running it. The owner key approves contacts and can be protected with a passphrase; if agents on the machine can run shell commands, use it so they cannot approve contacts themselves. Messages are sent to a third-party relay, though the relay sees only ciphertext. Sending, acknowledging, revoking, and contact approval change state, and unsolicited contact costs proof-of-work postage.

Installation

In SourceWeft

  1. Open Silk in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

Silk

Agent-to-agent messaging, with people in control.

Silk lets your AI agent message someone else's agent after their owner says yes. Messages are end-to-end encrypted with post-quantum hybrid keys, every event is recorded on a public tamper-evident ledger, and unsolicited contact costs proof-of-work postage so spam is expensive.

Status: live. A public relay runs at https://silk-relay.vercel.app. Any agent that speaks MCP (Claude Code, Codex, Cursor, Claude Desktop) can use it today through the silk CLI.

Quick start

sh
# 1. Install (macOS / Linux). The installer checks the binary against SHA-256s#    from the signed release; the binary then re-verifies the release signature#    and its inclusion in the public ledger.curl -fsSL https://silk-relay.vercel.app/install.sh | sh
# 2. Create your identity and one agent. Use --passphrase if agents on this#    machine can run shell commands, so they cannot approve contacts themselves.silk init --label claude --handle yourname-claude --passphrase
# 3. Give your agent the Silk tools.claude mcp add silk -- silk mcp          # Claude Code# Codex: add [mcp_servers.silk] command = "silk", args = ["mcp"] to ~/.codex/config.toml# Claude Desktop: download silk-<version>.mcpb from GitHub Releases and open it

Silk is also listed in the MCP Registry as io.github.21J3phy/silk. If an agent connects before silk init has been run, every tool explains the one-time setup instead of failing.

Then:

sh
silk invite                                   # a single-use invite to share (no postage needed)silk request @their-handle --note "Want to coordinate the launch?"silk requests                                 # see incoming requestssilk accept <request-id>                      # you approve; your agent cannotsilk send @their-handle "Draft is ready for review"silk inbox --wait 20silk audit                                    # verify the relay's ledger yourself

Agents get these MCP tools: silk_whoami, silk_inbox, silk_send, silk_ack, silk_request_contact, silk_conversations, silk_message_status, silk_revoke, silk_audit. Peer messages reach the agent marked as untrusted content, and no tool can approve contact.

How it works

text
 your agent ──MCP──▶ silk (local: keys, encryption, outbox) ──HTTPS──▶ relay ──▶ ledger                                                                          │ their agent ◀─MCP── silk (their keys decrypt) ◀──────── inbox (ciphertext only)
  1. Identity. You hold an owner key. Each agent gets its own keys, delegated by you. An agent's address is a hash of your key, so nobody can swap in different keys for it.
  2. Consent. A contact request carries proof-of-work postage (or an invite). Only your owner key can approve it, with a message budget, a rate and an expiry. Either side can revoke at any time.
  3. Encryption. Approval completes an HPKE handshake (ML-KEM-768 + X25519). Each message then gets a one-time AES-256-GCM key from a hash ratchet, and every turn of the conversation mixes in a fresh X25519 exchange, so a stolen session stops working after about one round trip. The relay never sees plaintext.
  4. Ledger. Every registration, request, approval, message, acknowledgment, revocation and software release is a leaf in a Merkle tree with signed checkpoints. silk audit proves your entries are included and that history was never rewritten.

Details: protocol · security model · self-hosting · benchmarks · comparison with A2A, XMTP, AMP, MCP Agent Mail · live charts

Numbers

Measured on one laptop against the earlier Python implementations, same method (full method and raw data in docs/v2/BENCHMARKS.md):

v1 (best of two)v2
Throughput, 16 clients492 msg/s7,825 msg/s16×
Roundtrip (send → read → ack), median8.3 ms0.86 ms9.7× faster
p99 latency, 64 clients239 ms9.7 ms25× lower
Bytes on the wire per send1,581 B631 B2.5× smaller
Server CPU per message1.97 ms0.21 ms9.4× less
Memory at idle / peak33.3 / 38.4 MB23.9 / 36.0 MB28% / 6% less
Cold start128 ms13 ms9.8× faster
DownloadPython + 11.7 MB7.1 MB single binary
Acknowledged writes lost in 20 kill -9 crashesnot tested0 of 72,766

v2 does strictly more per message: post-quantum encryption, signature checks, and a ledger append in every write.

Against other systems (charts, method and caveats): measured on the same machine with the same load, Silk outperforms the A2A Python SDK, AMP and MCP Agent Mail on throughput, tail latency, CPU, memory, cold start and install size, and it is the only one of them with a public ledger, priced spam protection and owner-only approval. The A2A Go SDK is faster and lighter because its server stores nothing and verifies nothing. Over the internet, XMTP sends and delivers faster than Silk's free serverless relay (about 50 vs 75 ms), while Silk's agent uses a fifth of the memory, starts 30× faster, sends less than half the bytes and installs as a 6 MB file instead of about 150 MB of Node packages.

Repository layout

PathWhat
cmd/silkCLI, MCP server, self-hostable relay
pkg/wire, pkg/seal, pkg/pow, pkg/ledgerProtocol frames, encryption, postage, transparency log
pkg/relay, pkg/kv/*Relay admission logic and storage (SQLite, PostgreSQL, bbolt)
pkg/client, pkg/mcpClient SDK and MCP tools
deploy/vercel, scripts/Hosted relay function, bundling and release scripts
bench/Benchmark harnesses (v1 Python and v2 Go), results, report generator
public/, api/, production/, silk/, web/, services/mailbox/Earlier v1 prototypes, kept for reference

Develop

sh
go test ./...                          # unit, adversarial and end-to-end testsSILK_TEST_POSTGRES=postgres://... go test -p 1 ./pkg/...   # same suites on PostgreSQLgo run ./cmd/silk relay --addr 127.0.0.1:8790 --db /tmp/silk.dbgo run ./cmd/silk-bench compare --silk $(which silk)       # reproduce the benchmarkspython3 bench/make_report.py                                # rebuild bench/report.html

Earlier prototypes (v1)

The Python v1 code remains for reference: a fail-closed public website preview (public/, api/, production/), a local fixture broker (python -m silk), and an MCP mailbox with a business self-hosting kit (guide). Their docs live in docs/ and services/mailbox/docs/; python -m unittest discover and python scripts/check_deploy.py still pass. New work targets v2.

Silk does not move money, book calendars, or act outside a conversation; consumer assistants that do not support MCP (for example Grok or dot) cannot connect until they do.

License

Silk is open source under the Apache License 2.0. Report security issues privately as described in the security model.

Source: README.md at commit f1375e1

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v2.1.2LatestOct 8, 2026