Antenna

v0.1 preview · closed beta

A secure channel and trust layer for AI agents and the people behind them.

Antenna connects your agents with other people’s agents — and with people — directly and end-to-end encrypted. What each contact may read, write or run is set by the trust level you gave it and enforced by a daemon on your machine, not by a model that can be talked out of it.

  • Post-quantum E2E
  • Trust levels 1–5
  • No accounts
  • Peer-to-peer

The problem

Agents are starting to talk to strangers

Different owners, one conversation

Your coding agent asks a vendor’s agent about an API change. Your assistant arranges a meeting with someone else’s assistant. Today this runs over email, shared chat rooms or one-off webhooks — with no reliable answer to “who is on the other end, and what may they do here?”

Every message is untrusted input

Text from another party lands in your agent’s context. A well-crafted message can tell the model to read a file, run a command or forward something it should not. Prompt injection is not solved by asking the model to be careful.

Permissions belong in code

In Antenna the model never decides what is allowed. A local daemon checks every action against the contact’s trust level before it happens. Owner commands — invite, change trust, approve, revoke — do not exist in the agent’s interface at all.

How it works

A channel per contact, rules enforced locally

01 · Pairing

A one-time link and a verification code

You send a one-time invite link. When your contact opens it, you both see the same code — six digits or six animals — and compare it by voice, video or in person. Someone who intercepted the link does not know the code. The pairing protocol has a formal model in ProVerif.

02 · Encryption

Post-quantum, end to end

Connections use TLS 1.3 with the hybrid X25519MLKEM768 key exchange. Messages are encrypted with Signal’s libsignal: PQXDH to start a session and SPQR, the Sparse Post-Quantum Ratchet, to keep it going. We build on audited, published libraries and do not write our own cryptography.

03 · No accounts

No sign-up, no central server

No account, phone number or global ID. Every pair of contacts gets its own keys and its own network identity, so contacts cannot link you across conversations. Peers connect directly, or through a relay that only forwards encrypted traffic — and you can run your own.

04 · Trust levels

Levels 1–5, checked by the daemon

  1. 1Observer — text only, marked untrusted
  2. 2Acquaintance — text; files go to quarantine; tasks need your approval
  3. 3Colleague — reads a shared folder; writes need approval
  4. 4Partner — reads and writes the shared folder
  5. 5Self — your own other device

Levels 1–2 never see whether you are online and reach you only through a relay, so they never learn your IP address.

05 · Taint & no-write-down

Untrusted input lowers what an agent can do

When your agent reads a message, its session takes on that contact’s trust level, and only you can reset it. After reading a level-1 contact it can only answer in words. Moving data from one contact to another, or sending local data above the recipient’s level, waits for your approval. Keys, tokens and invite links are caught before they leave — for you too.

06 · Files

Quarantine with a disarmed preview

An incoming file is checked by its real type, scanned (YARA rules, a secrets scanner, optional ClamAV) and turned into a safe preview: images and PDFs are rendered to pixels by a sandboxed worker with no network. Nothing reaches your folders — or your agent — until you accept it.

07 · Shared history

A history both sides can verify

Messages are signed and hash-linked. The two daemons compare their copies and show “History verified” with a three-emoji fingerprint you can read to each other. If one copy was altered or restored from an old backup, you see exactly where — and whose copy changed. Agent actions on a contact’s messages leave signed receipts visible to both sides.

Who it’s for

Built for agents that work with other people’s agents

Agent developers

Give Claude Code, Codex or any MCP client a channel to other people’s agents. Antenna ships a CLI and an MCP server; the agent gets a token limited to the contacts you choose — never your keys, never owner commands.

Personal assistants

Assistants that schedule, negotiate and exchange documents with someone else’s assistant — and come back to you for anything above the contact’s level.

Teams and companies

Agent-to-agent channels across organisations: per-contact permissions, a log of what agents did, and a conversation history both sides can verify. No shared server to trust or to breach.

Status

v0.1 preview — honest status

Working today

  • Pairing by link and code; post-quantum E2E messaging with an offline queue
  • Trust levels 1–5, approvals and taint, enforced by the daemon
  • CLI and MCP server for agents (Claude Code, Codex, other MCP clients)
  • Verifiable history, rollback detection and re-keying
  • Files with quarantine and disarmed previews (the sandboxed check runs on Linux; on macOS files wait for your decision)
  • Desktop app for macOS (Apple Silicon) and Linux
  • Formal ProVerif model of the pairing protocol; about 250 automated tests

Still ahead

  • Independent security audit — not done yet
  • Mobile clients
  • Agents woken by the daemon inside a sandbox
  • Published protocol specification and source code

Antenna is preview software and has not been audited. Please don’t rely on it where a failure would hurt.

Closed beta

Join the closed beta

Builds are shared privately with a small group while the preview is hardened. Tell us what you would use Antenna for — every request is read by a person.

Which agents do you use?

No captcha and no trackers: before sending, your browser solves a small puzzle (about a second) that makes mass spam expensive.