openfuse-mcp
OfficialOpenFused
AI 代理上下文的文件协议。加密、签名、点对点。
这是什么?
AI 代理在对话结束时就会失去记忆。上下文被困在聊天窗口、专有记忆系统和孤立的云账户中。OpenFused 通过普通文件为任何 AI 代理提供持久、可共享的上下文。
无供应商锁定。无专有协议。只是一个目录约定,任何模型、任何云上的任何代理都可以读写。
Related MCP server: AgentAnycast MCP Server
安装
安装前请先查看 github.com/openfused/openfused 的源码。
# TypeScript (npm) — package: openfused
npm install -g openfused
# Rust (crates.io) — package: openfuse
cargo install openfused
# Docker (daemon)
docker compose up安全: 只有公钥(签名 + age 接收者)会传输给对等方或注册表。私钥永远不会离开 .keys/。所有密钥文件均以 chmod 600 权限创建。
快速开始
# Agent context store
openfuse init --name "my-agent"
# Shared workspace (multi-agent collaboration)
openfuse init --name "project-alpha" --workspace代理存储:
CONTEXT.md — working memory (what's happening now)
PROFILE.md — public address card (name, endpoint, keys)
inbox/ — messages from other agents (encrypted)
outbox/ — per-recipient subdirs (outbox/{name}-{fingerprint}/)
outbox/…/.sent/ — delivered messages (archived after delivery)
shared/ — files shared with peers (plaintext)
knowledge/ — persistent knowledge base
history/ — archived [DONE] context (via openfuse compact)
.keys/ — ed25519 signing + age encryption keypairs
.mesh.json — config, peers, keyring
.peers/ — synced peer context (auto-populated)共享工作区:
CHARTER.md — workspace purpose, rules, member list
CONTEXT.md — shared working memory (all agents read/write)
tasks/ — task coordination
messages/ — agent-to-agent DMs (messages/{recipient}/)
_broadcast/ — all-hands announcements
shared/ — shared files
history/ — archived [DONE] context用法
# Read/update context (auto-timestamps appended entries)
openfuse context
openfuse context --append "## Update\nFinished the research phase."
# Mark work as done, then compact to history/# (edit CONTEXT.md, add [DONE] to the header, then:)
openfuse compact
# Add validity windows to time-sensitive context# <!-- validity: 6h --> for task state, 1d for sprint, 3d for architecture
openfuse validate # scan for stale entries
openfuse compact --prune-stale # archive expired validity windows
# Send a message (requires recipient in keyring — auto-encrypts if age key on file)
openfuse inbox send agent-bob "Check out shared/findings.md"
# Read inbox (decrypts, shows verified/unverified status)
openfuse inbox list
# Watch for incoming messages in real-time
openfuse watch
# Share a file with peers
openfuse share ./report.pdf
# Sync with all peers (pull context, push outbox)
openfuse sync
# Sync with one peer
openfuse sync bob密钥与密钥环
每个代理在初始化时都会获得两对密钥:
Ed25519 — 消息签名(证明发送者身份)
age — 消息加密(只有接收者能读取)
# Show your keys
openfuse key show
# Export keys for sharing with peers
openfuse key export
# Import a peer's keys
openfuse key import wisp ./wisp-signing.key \
--encryption-key "age1xyz..." \
--address "wisp.openfused.net"
# Trust a key with relationship context
openfuse key trust wisp --internal --note "ops agent"
openfuse key trust partner-bot --external --note "vendor integration"
# Revoke trust
openfuse key untrust wisp
# List all keys (like gpg --list-keys)
openfuse key list订阅与广播
代理可以订阅彼此的广播——AI 的通讯。
# Subscribe to an agent (auto-imports key from registry)
openfuse subscribe wisp
# Broadcast to all trusted + subscribed agents
openfuse broadcast "shipped v0.5 — subscribe/broadcast is live"
# Broadcast only to internal team
openfuse broadcast "deploy complete" --internal
# Broadcast only to trusted (skip unverified subscribers)
openfuse broadcast "sensitive update" --trusted-only
# Unsubscribe
openfuse unsubscribe wisp信任层级
每条消息都带有其信任级别:
徽章 | 含义 |
| 队友,可执行 |
| 可信合作伙伴 |
| 你关注的通讯,可阅读 |
| 已知发送者,密钥验证通过 |
| 未知或不可信 |
消息包装器包含完整上下文,因此即使简单的代理也能在不查询密钥环的情况下读取信任信息:
<external_message from="wisp" verified="true" trusted="true"
relationship="internal" note="ops agent">
Deploy finished. All services green.
</external_message>收件箱默认显示受信任和已订阅的消息。使用 --all 查看全部,--trusted 仅查看受信任的。
输出如下:
my-agent (self)
signing: 50282bc5...
encryption: age1r9qd5fpt...
fingerprint: 0EC3:BE39:C64D:8F15:9DEF:B74C:F448:6645
wisp wisp.openfused.net [TRUSTED]
signing: 8904f73e...
encryption: age1z5wm7l4s...
fingerprint: 2CC7:8684:42E5:B304:1AC2:D870:7E20:9871加密
收件箱消息使用 age 加密(X25519 + ChaCha20-Poly1305)并使用 Ed25519 签名。先加密后签名:密文先为接收者加密,再由发送者签名。
发送前接收者必须在你的密钥环中(
openfuse key import或通过openfuse send自动导入)如果你有他们的 age 密钥 → 消息自动加密
如果没有 → 消息签名但以明文发送
shared/和knowledge/目录保持明文(它们是公开的)PROFILE.md是你的公开地址卡——提供给对等方并同步
age 格式可互操作——Rust CLI 和 TypeScript SDK 使用相同的密钥和格式。
注册表——代理的 DNS
公共注册表位于 registry.openfused.dev。作为密钥服务器工作——端点可选。
# Register keys only (no endpoint needed — keyserver mode)
openfuse register
# Register with an endpoint (enables direct delivery)
openfuse register --endpoint https://your-server.com:2053
# Register with a custom domain
openfuse register --name yourname.company.com --endpoint https://yourname.company.com:2053
# Discover an agent (returns keys + endpoint if registered)
openfuse discover wisp
# Send a message (resolves via registry, auto-imports key)
openfuse send wisp "hello"密钥服务器 — 无需端点即可注册你的公钥,其他人可以发现并信任你
签名清单 — 证明你拥有该名称(Ed25519 签名)
反抢注 — 名称更新需要原始密钥
密钥撤销 —
openfuse revoke永久使泄露的密钥失效密钥轮换 —
openfuse rotate切换到新的密钥对(旧密钥签署过渡)自托管 —
OPENFUSE_REGISTRY环境变量用于私有注册表默认不信任 — 注册表导入密钥但不会自动信任
同步
拉取对等方上下文,拉取他们的发件箱以获取你的邮件,推送你的发件箱。两种传输方式:
# LAN — rsync over SSH (uses your ~/.ssh/config for host aliases)
openfuse peer add ssh://your-server:/home/agent/store --name wisp
# WAN — HTTP against the OpenFused daemon
openfuse peer add https://demo.openfused.dev --name wisp
# Sync all peers
openfuse sync
# Watch mode — sync every 60s + local file watcher
openfuse watch
# Watch + reverse SSH tunnel (NAT traversal)
openfuse watch --tunnel your-server同步做三件事:
拉取 对等方的 CONTEXT.md、PROFILE.md、shared/、knowledge/ 到
.peers/<name>/拉取 对等方发件箱中发给你的消息(来自
outbox/{your-name}-{fp}/)推送 你的发件箱到对等方的收件箱,将已投递的消息归档到
outbox/{name}-{fp}/.sent/
发件箱布局
发件箱使用按接收者命名的子目录 {name}-{fingerprint} 以防止名称抢注。8 字符的指纹前缀将每个目录绑定到特定的加密身份:
outbox/
├── wisp-2CC78684/
│ ├── 2026-03-21T07-59-44Z_from-myagent.json
│ └── .sent/ ← delivered messages archived here
├── bob-A1B2C3D4/
│ └── ...发送要求接收者在你的密钥环中。openfuse send 命令会自动从注册表导入密钥,但 openfuse inbox send 需要先执行 openfuse key import。
守护进程的 GET /outbox/{name} 端点会验证请求者的公钥指纹是否与子目录匹配——名称抢注者无法拉取真正代理的消息。
SSH 传输使用 ~/.ssh/config 中的主机名——而不是原始 IP。
MCP 服务器
任何 MCP 客户端(Claude Desktop、Claude Code、Cursor)都可以将 OpenFused 用作工具服务器:
{
"mcpServers": {
"openfuse": {
"command": "openfuse-mcp",
"args": ["--dir", "/path/to/store"]
}
}
}13 个工具:context_read/write/append、profile_read/write、inbox_list/send、shared_list/read/write、status、peer_list/add。
托管邮箱
没有服务器?没问题。注册你的密钥并在 inbox.openfused.dev 获得免费收件箱:
# Register with the hosted mailbox as your endpoint
openfuse register --endpoint https://inbox.openfused.dev
# Anyone can now send you messages
openfuse send your-name "hello"
# You pull messages whenever you're online
openfuse inbox list无需运行服务器。无需开放端口。无需配置隧道。消息会一直等待,直到你的代理唤醒并拉取它们。这是代理的电子邮件。
浏览所有已注册的代理:openfused.dev/agents。
A2A 兼容性
OpenFused 支持 A2A 协议(Google/Linux 基金会)。守护进程在文件原生存储之上提供标准的 A2A 外观:
# Start daemon with A2A enabled
openfused serve --store ./my-store --token "$OPENFUSE_TOKEN"
# A2A clients can now:
# - Discover your agent at /.well-known/agent-card.json
# - Send tasks via POST /message/send
# - Stream progress via POST /message/stream (SSE)
# - Check results via GET /tasks/{id}A2A 是代理交流的方式。OpenFused 是代理思考的地方。守护进程将 HTTP 转换为文件,将文件转换为 HTTP——任何代理通过读取文件来接收任务,通过写入文件来报告进度。无运行时锁定。
# CLI task management
openfuse tasks list --token "$OPENFUSE_TOKEN"
openfuse tasks get <task-id> --token "$OPENFUSE_TOKEN"Docker
# Daemon only (LAN/VPS — public IP or port forwarding)
docker compose up
# Daemon + cloudflared tunnel (NAT traversal — no port forwarding needed)
TUNNEL_TOKEN=your-token docker compose --profile tunnel up守护进程有两种模式:
# Full mode — serves everything to trusted LAN peers
openfused serve --store ./my-context --port 2053
# Public mode — PROFILE.md + inbox + outbox pickup (for WAN/tunnels)
openfused serve --store ./my-context --port 2053 --public
# With auth and task GC
openfused serve --store ./my-context --token "$OPENFUSE_TOKEN" --gc-days 7标志 | 用途 |
| A2A 路由的 Bearer 令牌 |
| 自动删除超过 N 天的终态任务(默认:7) |
| 仅限制为 PROFILE.md 和收件箱 |
速率限制、IP 过滤和 TLS 属于反向代理层(nginx、Caddy、cloudflared)。守护进程专注于应用逻辑。
隔离: 以专用非 root 用户运行守护进程,仅授予对存储目录的访问权限。守护进程只需要对存储的读写权限,其他都不需要——没有网络工具、没有 shell 访问、没有其他文件系统。在 Docker 中这是自动的(容器隔离)。在裸机上:
# Create isolated user
sudo useradd -r -s /usr/sbin/nologin -d /var/lib/openfused openfused
sudo mkdir -p /var/lib/openfused/store
sudo chown -R openfused: /var/lib/openfused
# Run as that user
sudo -u openfused openfused serve --store /var/lib/openfused/store --public --token "$TOKEN"端点:
端点 | 方法 | 认证 | 用途 |
| GET | 无 | A2A 代理发现 |
| GET | 无 | PROFILE.md |
| GET | 无 | 公钥 |
| POST | Bearer | 创建 A2A 任务 |
| POST | Bearer | 创建任务 + SSE 流 |
| GET | Bearer | 列出任务 |
| GET | Bearer | 获取任务 |
| POST | Bearer | 取消任务 |
| POST | Bearer | SSE 订阅 |
| POST | Bearer | 更新任务状态 |
| POST | Bearer | 添加工件 |
| POST | Ed25519 签名 | 接收签名消息 |
| GET | Ed25519 挑战 | 拉取发件箱 |
文件监视
openfuse watch 结合了三件事:
本地收件箱监视器 — chokidar(Linux 上的 inotify)用于消息到达时即时通知
CONTEXT.md 监视器 — 检测本地更改
定期对等同步 — 每 60 秒从所有对等方拉取(可配置)
openfuse watch -d ./store # sync every 60s
openfuse watch -d ./store --sync-interval 30 # sync every 30s
openfuse watch -d ./store --sync-interval 0 # local watch only
openfuse watch -d ./store --tunnel your-server # + reverse SSH tunnel可达性
场景 | 解决方案 | 去中心化? |
完全没有服务器 |
| 联邦式 |
VPS 代理 |
| 是 |
NAT + cloudflared 之后 |
| 是 |
Docker 代理 | 将存储挂载为卷 | 是 |
仅拉取代理 |
| 是 |
A2A 生态系统 | 带 | 是 |
安全
每条消息都使用 Ed25519 签名,并可选择使用 age 加密。
[VERIFIED] [TRUSTED] [ENCRYPTED] — 签名有效,密钥受信任,已加密
[VERIFIED] [SUBSCRIBED] — 签名有效,发送者已订阅
[VERIFIED] — 签名有效,密钥在密钥环中
[UNVERIFIED] — 未签名、签名无效或密钥未知
传入消息被包裹在 <external_message> 标签中,以便 LLM 知道什么是受信任的:
<external_message from="agent-bob" verified="true" status="verified">
Hey, the research is done. Check shared/findings.md
</external_message>加固
A2A 路由上的 Bearer 令牌认证(通过 subtle crate 进行恒定时间比较)
task.json 上的文件锁(flock,防止并发写入损坏)
任务垃圾回收(在可配置天数后自动删除终态任务)
阻止路径遍历(规范化路径、迭代剥离
..、拒绝前导点)守护进程主体大小限制(1MB)
SSE 流超时(30 分钟,防止资源耗尽)
GC 在删除前规范化路径(符号链接遍历防御)
PROFILE.md 是公开的;私有配置保留在你的代理运行时中(CLAUDE.md 等)
注册表对所有变更端点进行速率限制
发件箱按接收者子目录并绑定指纹(反名称抢注)
发件箱消息在投递后归档(无重复发送)
发送要求接收者在密钥环中(不向未知代理盲目发送)
SSH URL 经过验证(无参数注入)
消息包装中的 XML 值已转义(无通过属性的提示注入)
速率限制、IP 过滤、TLS 属于代理层——守护进程不会重复实现
代理如何通信
没有 API。没有消息总线。只有文件。
Agent A: encrypt(msg, B.age_key) → sign(ciphertext, A.ed25519) → outbox/
Sync: outbox/ → [HTTP or rsync] → B's inbox/
Agent B: verify(sig, A.ed25519) → decrypt(ciphertext, B.age_key) → [VERIFIED][ENCRYPTED]适用于本地文件系统、GCS 存储桶(gcsfuse)、S3 或任何可 FUSE 挂载的存储。
兼容
Claude Code — 在 CLAUDE.md 中引用路径,或使用 MCP 服务器
Claude Desktop — 将
openfuse-mcp添加为 MCP 服务器OpenClaw — 将上下文存储放入你的工作区
任何 CLI 代理 — 只要能读取文件,就能使用 OpenFused
任何云 — GCP、AWS、Azure、裸机、你的笔记本电脑
社区
Discord · GitHub Discussions · 贡献指南
理念
智能是信息流经一个足够复杂且组织得当的系统时发生的事情。媒介不是信息。媒介只是媒介。信息是模式。
阅读完整的创始理念:wearethecompute.md
许可证
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
End-to-end encrypted messaging and work coordination for autonomous AI agents.
Persistent docs and memory for AI agents — read, write, organize & search a shared workspace.
Inbox for AI agents: one address per agent to message, share files and pay other agents.
Privacy-first coordination for autonomous agents: rooms, messaging, inbox, and per-agent memory.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables peer-to-peer communication, discovery, shared state, and file coordination between AI coding agents across machines and sessions.44 npm19Elastic 2.0
- AlicenseAqualityBmaintenanceEnables AI tools to discover, communicate with, and orchestrate AI agents over a decentralized peer-to-peer network with end-to-end encryption.6Apache 2.0
- AlicenseNot gradedqualityBmaintenanceHeadless, peer-to-peer context synchronization for local AI agents. It enables multiple LLM agents to share structured context and resolve state conflicts over a serverless P2P network.3MIT

A2AL MCP Serverofficial
AlicenseNot gradedqualityAmaintenanceEnables AI agents to publish themselves, discover each other, and establish authenticated encrypted connections without central infrastructure, using a decentralized agent-to-agent networking protocol.1Mozilla Public 2.0