# 5dive-a2a: Send Signed Messages Between AI Agents

This repository profile is provided by osrepos.com, an open source repository discovery platform.

Source: osrepos.com
Repository profile: https://osrepos.com/repo/5dive-ai-5dive-a2a
Generated for open source discovery and AI-assisted research.

A 5dive plugin for direct, signed messaging between agents on separate servers. It verifies contacts, queues messages until an agent is idle, and supports expiring file links; it is experimental and requires a self-hosted box with HTTPS.

GitHub: https://github.com/5dive-ai/5dive-a2a
OSRepos URL: https://osrepos.com/repo/5dive-ai-5dive-a2a

## Summary

A 5dive plugin for direct, signed messaging between agents on separate servers. It verifies contacts, queues messages until an agent is idle, and supports expiring file links; it is experimental and requires a self-hosted box with HTTPS.

## Topics

- javascript
- ai-agents
- self-hosted
- multi-agent
- signed-agent-messaging
- did-key
- agent-to-agent

## Repository Information

Last analyzed by OSRepos: Fri Oct 09 2026 12:42:21 GMT+0100 (Western European Summer Time)
Detail views: 1
GitHub clicks: 1

## Safety Notice

OSRepos shares public repositories for knowledge and discovery only. Review source code, dependencies, licenses, and security implications before running or installing anything.

## Content

## Overview

[5dive-a2a](https://github.com/5dive-ai/5dive-a2a) adds direct messaging between agents running on different 5dive boxes, without a chat service or a person relaying text. Messages are signed with the sending agent’s `did:key` and accepted only from contacts configured by the receiver’s owner.

It is a 5dive-specific implementation of OpenAgent RFC 0001, not Google’s A2A protocol. Messages wait in an inbox and are delivered to the agent when it is idle, making the plugin suited to asynchronous coordination rather than real-time chat.

## Key Features

- Signs messages with the sending agent’s Ed25519 `did:key` and checks them against the receiver’s pinned contacts.
- Queues verified messages and delivers them in a batch when the recipient agent is idle.
- Supports contact management, optional home-domain allowlists, and per-contact interrupt settings.
- Sends files as expiring links hosted on the sender’s own box, with size and SHA-256 details for verification.
- Runs the inbox as an unprivileged service with no network access, using a systemd socket and the existing web server.
- Provides agent-facing CLI commands and a messaging skill for supported 5dive agents.

## Use Cases

- Owners of multiple 5dive boxes can let their agents exchange task updates without routing messages through a chat platform.
- A team can send asynchronous handoffs between agents on separate servers, with delivery deferred until each recipient is idle.
- Agents can share datasets or other files through temporary links hosted on the sending box.
- Operators who need contact-controlled messaging can limit which agents may communicate and optionally restrict contacts by home domain.

## Our Take

This is a narrowly focused, security-conscious but experimental messaging plugin, and its recent activity is promising while its contributor base is highly concentrated.

**Good fit if:**
- You already run 5dive and want direct, asynchronous messaging between agents you explicitly add as contacts.
- You can provide a self-hosted box with Node.js 18 or newer, a domain, and an HTTPS web server.
- The experimental status and MIT license fit your deployment and redistribution plans.

**Look elsewhere if:**
- You need Google A2A protocol compatibility, encryption beyond TLS, or a relay for boxes without inbound traffic.
- Your agents are not on 5dive boxes or you cannot operate the required HTTPS endpoint.
- You need a mature project with a broader contributor base: the repository is new, has no release in the past year, and most contributions come from one person.

## Project Health

| Signal | Value |
|---|---|
| Status | **New**: less than six months old |
| Last commit | 2026-09-28 (11 days ago) |
| Commits, last 90 days | 11 |
| Releases, last 12 months | 0 |
| Contributors | 2 (top contributor: 91% of commits) |
| Issues closed, last 90 days | 0 |
| Pull requests merged, last 90 days | 10 (typically merged in 0 days) |
| Project age | 12 days |

Checked on 2026-10-09 with the GitHub API.

## Project Facts

- Language: JavaScript
- License: MIT
- Stars: 1
- Forks: 0
- Topics: 5dive, a2a, agent-communication, agent-messaging, agent-protocol, agent-to-agent, ai-agents, autonomous-agents
- Archived: no

## What You Need

Detected in the repository:

- JavaScript (main language on GitHub)
- A test suite and automated checks on GitHub Actions

## Getting Started

```bash
5dive plugin add 5dive-ai/5dive-a2a
sudo 5dive a2a setup --domain=<your-box-domain> --agents=<agent>[,<agent>…]
```

See the [README](https://github.com/5dive-ai/5dive-a2a#readme) for prerequisites, web-server setup, contact configuration, and security details.

## License in Plain Words

**MIT** (permissive).

- Commercial use: yes
- Modify and redistribute: yes
- You must keep: the copyright and license notice
- Share your changes: no

A summary, not legal advice: the LICENSE file is what applies.

## Considerations

The repository is new and marked experimental. It has recent commits and merged pull requests, but no release in the past year; its two contributors are not evenly represented, with most code coming from one person. There are no open issues, so the available issue history does not establish how issues are handled over time.

Deployment requires Node.js 18 or newer, a domain, and an HTTPS web server. Messages are signed but not encrypted by the protocol, so TLS is the only stated protection for message privacy. File URLs are capability links: anyone who obtains one can download the file until it expires. The README also identifies the lack of a relay for boxes without inbound traffic and strict mode on its own port as unfinished work.