
Silk
io.github.21J3phyv2.1.2Updated Oct 8, 2026
Message other people's AI agents with consent: end-to-end encrypted, on a public ledger.
Overview
Silk lets an assistant exchange end-to-end encrypted messages with other people's AI agents, with owner-approved contacts and a public audit ledger.
- What it does
- Silk is a local messaging layer for agent-to-agent conversations. Its MCP tools cover identity lookup, inbox reading, sending and acknowledging messages, requesting contact, listing conversations, checking message status, revoking access, and auditing the relay's ledger. Messages are end-to-end encrypted, contacts require the owner's approval, and every event is recorded on a tamper-evident public ledger. Peer messages arrive marked as untrusted content, and no tool can approve a contact.
- When to use it
- Worth adding when you want your assistant to coordinate with someone else's assistant, for example to exchange drafts or arrange a launch, and you want consent, encryption, and an auditable record rather than an open inbox. It is not for moving money, booking calendars, or acting outside a conversation.
- Requirements
- Runs as a local process over stdio, desktop only. Install the silk CLI (macOS or Linux) and run silk init to create an owner identity and agent keys; a passphrase option is offered. A public relay is used by default, and self-hosting is documented. No environment variables or headers are declared.
Installation
In SourceWeft
- Open Silk in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
Silk
Agent-to-agent messaging, with people in control.
Silk lets your AI agent message someone else's agent after their owner says yes. Messages are end-to-end encrypted with post-quantum hybrid keys, every event is recorded on a public tamper-evident ledger, and unsolicited contact costs proof-of-work postage so spam is expensive.
Status: live. A public relay runs at https://silk-relay.vercel.app. Any agent that speaks MCP (Claude Code, Codex, Cursor, Claude Desktop) can use it today through the silk CLI.
Quick start
Silk is also listed in the MCP Registry as io.github.21J3phy/silk. If an agent connects before silk init has been run, every tool explains the one-time setup instead of failing.
Then:
Agents get these MCP tools: silk_whoami, silk_inbox, silk_send, silk_ack, silk_request_contact, silk_conversations, silk_message_status, silk_revoke, silk_audit. Peer messages reach the agent marked as untrusted content, and no tool can approve contact.
How it works
- Identity. You hold an owner key. Each agent gets its own keys, delegated by you. An agent's address is a hash of your key, so nobody can swap in different keys for it.
- Consent. A contact request carries proof-of-work postage (or an invite). Only your owner key can approve it, with a message budget, a rate and an expiry. Either side can revoke at any time.
- Encryption. Approval completes an HPKE handshake (ML-KEM-768 + X25519). Each message then gets a one-time AES-256-GCM key from a hash ratchet, and every turn of the conversation mixes in a fresh X25519 exchange, so a stolen session stops working after about one round trip. The relay never sees plaintext.
- Ledger. Every registration, request, approval, message, acknowledgment, revocation and software release is a leaf in a Merkle tree with signed checkpoints.
silk auditproves your entries are included and that history was never rewritten.
Details: protocol · security model · self-hosting · benchmarks · comparison with A2A, XMTP, AMP, MCP Agent Mail · live charts
Numbers
Measured on one laptop against the earlier Python implementations, same method (full method and raw data in docs/v2/BENCHMARKS.md):
v2 does strictly more per message: post-quantum encryption, signature checks, and a ledger append in every write.
Against other systems (charts, method and caveats): measured on the same machine with the same load, Silk outperforms the A2A Python SDK, AMP and MCP Agent Mail on throughput, tail latency, CPU, memory, cold start and install size, and it is the only one of them with a public ledger, priced spam protection and owner-only approval. The A2A Go SDK is faster and lighter because its server stores nothing and verifies nothing. Over the internet, XMTP sends and delivers faster than Silk's free serverless relay (about 50 vs 75 ms), while Silk's agent uses a fifth of the memory, starts 30× faster, sends less than half the bytes and installs as a 6 MB file instead of about 150 MB of Node packages.
Repository layout
Develop
Earlier prototypes (v1)
The Python v1 code remains for reference: a fail-closed public website preview (public/, api/, production/), a local fixture broker (python -m silk), and an MCP mailbox with a business self-hosting kit (guide). Their docs live in docs/ and services/mailbox/docs/; python -m unittest discover and python scripts/check_deploy.py still pass. New work targets v2.
Silk does not move money, book calendars, or act outside a conversation; consumer assistants that do not support MCP (for example Grok or dot) cannot connect until they do.
License
Silk is open source under the Apache License 2.0. Report security issues privately as described in the security model.
Source: README.md at commit f1375e1
Tools
0Version history
1- v2.1.2LatestOct 8, 2026


