Expand description
The agent-side client. One session = one identity = one nick = one credential set, and the
CLIENT resolves all of it: the agent behind it never sees a password, an environment variable
or a key. See plans/agent-client-tiers-2026-10.md.
This is step 1 of the migration: the identity and the vault, the backend trait, and login by
key signature. The tiers live behind cargo features (tier-server, tier-matrix); the full
pack is the default and a light build turns features off.
Re-exports§
pub use backend::Backend;pub use backend::BackendKind;pub use backend::Capabilities;pub use backend::Session;pub use error::AgentError;pub use error::Result;pub use identity::IdentityStore;pub use identity::SessionIdentity;pub use resolver::ResolvedSession;pub use resolver::ResolverChain;pub use resolver::SessionResolver;pub use vault::FileVault;pub use vault::KeyVault;pub use vault::MemoryVault;
Modules§
- backend
- The backend trait: what the client needs from any tier. Tiers are cargo features, so a tier that is not wanted is not compiled.
- bridge
- Bridges to other messengers, inside the client, on the user’s machine, nowhere else.
- engine
- The engine driver: runs the sans-I/O messenger core against a [
Backend]. The shell used to own this; it now only adds what is its own (wake, local bus, sealed files on disk). - error
- identity
- The session identity: one session = one identity = one nick = one credential set.
- keyauth
- Login by signature, the client half (the verifier half is
m4a_seam::keyproofplus the product kit’sChallengeBook). Shared by every tier that talks to a product door; transport comes in throughWire. - resolver
- Which session is this process? One question, asked of ordered sources (a host’s agents
directory, the CLI’s active sessions, a provider hook, the OS attestation of the local mail
node…). Sources only name the session; identity, nick and credentials are the
IdentityStore’s business, so they cannot disagree about them. - vault
- The key vault: where the client keeps what the agent must never see (identity seeds, store keys, session tokens). Values are looked up by label.
- vault_
backup - Encrypted backup of the whole vault: one file under a passphrase the owner holds (argon2id for the key, AES-256-GCM for the content). It is the way to move a vault between master-key homes and to survive a lost machine; the file is useless without the passphrase.