Zero Trust Execution Boundary.
-
Updated
Jul 20, 2026 - TypeScript
Zero Trust Execution Boundary.
An Identity, Security, and Governance Framework for autonomous agents
Per-message signing + replay protection for MCP and A2A traffic. TypeScript / Python / Rust. Wire version aip/0.1.
A cryptographically verifiable distributed time system, designed for systems that require trusted, monotonic, replay‑resistant time.
Authenticated secure-messaging core using X25519, Ed25519, HKDF, and AEAD, with canonical versioned envelopes, replay protection, and encrypted local storage. Testable, hybrid-extensible, and built as a cryptographic engine rather than a full chat application.
Encrypted API relay with replay protection.
Governed infrastructure for clinical sign-offs. Immutable ledger, atomicity, idempotency, and zero-drift contracts. Published as proof of governance.
PiProof v1.0 — portable verifiable evidence on the PEP/1 protocol: Proof Passports, Dispute Engine, cross-application proofs and AI Agent Evidence, with the AUREVIA dashboard. Zero dependencies.
Server-side hardening middleware for x402 payment endpoints: mitigations for settlement races, replay, cross-resource substitution, and cache leakage. Zero-dependency, ESM-only, auditable TypeScript.
Async Python library for decentralized, hubless federation between peer directory services.
Helps AI applications discover nearby compute and data safely without letting untrusted network information decide what they are allowed to do.
Signed outbound-only cloud-plan and local-execution reference protocol
Small C++17 reference monitor for authorization certificates, path witnesses, version bindings, and replay protection.
Notes and guides for implementing x402 micropayments on APIs.
Permission kernel for AI agents: capability-based policies, call allowlists, TTL, instant revoke, modular validators — no approve(∞).
Secure-channel protocol for IoT in C++17: mutually authenticated handshake (ephemeral X25519 + PSK), ChaCha20-Poly1305 record layer, HKDF key schedule, and sliding-window anti-replay — crypto implemented from scratch and validated against RFC test vectors.
Constant-time HMAC verification for inbound webhooks, with timestamp and delivery-ID replay protection. Zero dependencies.
Tenant-aware signed webhook verification with canonical-host checks and replay protection.
Secure V2I - authenticated Diffie‑Hellman, RSA identity, AES+HMAC, replay protection
To associate your repository with the replay-protection topic, visit your repo's landing page and select "manage topics."