Expand description
Agent-to-agent messaging for Claude Code and Codex CLI.
Claude Code and Codex CLI agents each run an MCP server: outbound is the
send_message tool. Claude inbound is delivered by default to a local inbox that a
background interlink-mcp wait listener drains (plain claude, no flags), with
native notifications/claude/channel push as an opt-in enhancement (interlinked
/ INTERLINK_CHANNELS=1). A small bus routes messages between agents and
buffers for agents that are offline.
Codex CLI uses the same protocol and trust gate, with local lifecycle hooks
binding the MCP instance to a thread and codex delivering through its queue.
§Trust
An agent’s identity is its Ed25519 public key (identity); names are
local petnames. Every message is signed, and the channel server verifies the
signature and checks the sender against an allowlist before pushing —
so an unverified message never reaches the model.
Authority comes from the server’s instructions string, which lands in
the host’s MCP context. The peer’s text is untrusted data that parameterises
an action; it never authorises one. An ungated channel is a prompt-injection
vector.
§Pieces (each behind a feature)
Modules§
- agent
- The per-agent channel server and its decision logic.
- bus
- The broker: a durable, keep-until-acked FIFO per recipient over HTTP.
- codex
- Delivery to an existing local Codex CLI thread through its shared daemon.
- delivery
- Recoverable host-delivery failures, persisted before releasing a bus message.
- identity
- Ed25519 identity. The public key is the identity; names are local petnames.
- inbox
- A restart-safe JSONL inbox with a single reader and atomic cursor updates.
- pairing
- Durable, session-scoped pairing requests and their control-message outbox.
- policy
- Per-peer authorization policy:
peers.json. - policy_
store - Shared peer settings. Readers reload complete snapshots; writers serialize updates.
- route
- Bus routing addresses.
- state
- Atomic local state replacement shared by session queues and peer settings.
- store
- A durable, keep-until-acked FIFO queue — one logical queue per recipient key.
Functions§
- now_ms
- Unix milliseconds.