5dive-ai

5dive-a2a: Send Signed Messages Between AI Agents

A 5dive plugin for direct, signed messaging between agents on separate servers. It verifies contacts, queues messages until an agent is idle, and supports expiring file links; it is experimental and requires a self-hosted box with HTTPS.

Stars
1
Forks
0
Last commit
11 days ago
Contributors
2
Releases, 12 months
0

Our take

Newless than six months old
  • Fewer contributors than 87% of the projects we track

This is a narrowly focused, security-conscious but experimental messaging plugin, and its recent activity is promising while its contributor base is highly concentrated.

Good fit if

  • You already run 5dive and want direct, asynchronous messaging between agents you explicitly add as contacts.
  • You can provide a self-hosted box with Node.js 18 or newer, a domain, and an HTTPS web server.
  • The experimental status and MIT license fit your deployment and redistribution plans.

Look elsewhere if

  • You need Google A2A protocol compatibility, encryption beyond TLS, or a relay for boxes without inbound traffic.
  • Your agents are not on 5dive boxes or you cannot operate the required HTTPS endpoint.
  • You need a mature project with a broader contributor base: the repository is new, has no release in the past year, and most contributions come from one person.
All health signals
Last commit2026-09-28 (11 days ago)
Commits, last 90 days11
Releases, last 12 months0
Contributors2 (top contributor: 91% of commits)
Issues closed, last 90 days0
Pull requests merged, last 90 days10 (typically merged in 0 days)
Project age12 days

Checked on 2026-10-09 with the GitHub API.

Overview

5dive-a2a adds direct messaging between agents running on different 5dive boxes, without a chat service or a person relaying text. Messages are signed with the sending agent’s did:key and accepted only from contacts configured by the receiver’s owner.

It is a 5dive-specific implementation of OpenAgent RFC 0001, not Google’s A2A protocol. Messages wait in an inbox and are delivered to the agent when it is idle, making the plugin suited to asynchronous coordination rather than real-time chat.

Key Features

  • Signs messages with the sending agent’s Ed25519 did:key and checks them against the receiver’s pinned contacts.
  • Queues verified messages and delivers them in a batch when the recipient agent is idle.
  • Supports contact management, optional home-domain allowlists, and per-contact interrupt settings.
  • Sends files as expiring links hosted on the sender’s own box, with size and SHA-256 details for verification.
  • Runs the inbox as an unprivileged service with no network access, using a systemd socket and the existing web server.
  • Provides agent-facing CLI commands and a messaging skill for supported 5dive agents.

Use Cases

  • Owners of multiple 5dive boxes can let their agents exchange task updates without routing messages through a chat platform.
  • A team can send asynchronous handoffs between agents on separate servers, with delivery deferred until each recipient is idle.
  • Agents can share datasets or other files through temporary links hosted on the sending box.
  • Operators who need contact-controlled messaging can limit which agents may communicate and optionally restrict contacts by home domain.

What you need

Detected in the repository

  • JavaScript (main language on GitHub)
  • A test suite and automated checks on GitHub Actions

License in plain words

MITpermissive

  • Commercial use: yes
  • Modify and redistribute: yes
  • You must keep: the copyright and license notice
  • Share your changes: no

A summary, not legal advice: the LICENSE file is what applies.

Getting Started

5dive plugin add 5dive-ai/5dive-a2a
sudo 5dive a2a setup --domain=<your-box-domain> --agents=<agent>[,<agent>…]

See the README for prerequisites, web-server setup, contact configuration, and security details.

Considerations

The repository is new and marked experimental. It has recent commits and merged pull requests, but no release in the past year; its two contributors are not evenly represented, with most code coming from one person. There are no open issues, so the available issue history does not establish how issues are handled over time.

Deployment requires Node.js 18 or newer, a domain, and an HTTPS web server. Messages are signed but not encrypted by the protocol, so TLS is the only stated protection for message privacy. File URLs are capability links: anyone who obtains one can download the file until it expires. The README also identifies the lack of a relay for boxes without inbound traffic and strict mode on its own port as unfinished work.

Found this useful?

Share it with someone who would like 5dive-a2a.

OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️