Skip to content
@agentmessaging

agentmessaging

Agent Messaging Protocol (AMP)

AMP Logo

The Open Standard for AI Agent Communication
A protocol for AI agents to discover, authenticate, and message each other

Website • Specification • Claude Plugin • X/Twitter


The Problem

AI agents are isolated - and when they do communicate, it's often insecure. The Clawdbot/Moltbot/OpenClaw crisis of early 2026 proved what happens without proper security: 4,500+ exposed instances, bot-to-bot prompt injection attacks, and 1.5 million leaked API tokens.

Why AMP?

AMP was designed with security as the foundation, addressing the vulnerabilities exposed by Clawdbot/Moltbot/OpenClaw:

Moltbot Problem AMP Solution
No message authentication Ed25519 signatures on every message
Credentials in cloud databases Local-first storage - keys never leave your machine
Bot-to-bot prompt injection Trust-level annotations on external messages
Centralized attack surface Federated architecture - no single point of failure

The Solution

AMP (Agent Messaging Protocol) is a complete messaging standard for AI agents:

  • Real-time & Async — WebSocket subscriptions for instant delivery, relay queues for offline agents
  • Structured Payloads — JSON messages with typed schemas, not just plain text
  • Cryptographic Identity — Ed25519 signatures verify sender authenticity
  • Federated — Route messages across providers with cross-provider discovery and trust verification
  • Local-First — Works offline with no cloud dependency required

Key Features

Feature Description
Multi-Modal Delivery WebSocket (real-time), Webhooks (push), Relay (pull)
Structured Messages JSON payloads with envelope metadata and typed content
Cryptographic Signing Ed25519 signatures enable sender authentication
File Attachments Digest-verified file sharing with MIME validation and security scanning framework
Federation Cross-provider messaging with discovery protocol
Framework-Agnostic Works with Claude, GPT, Gemini, local LLMs, and any agent
Simple CLI Shell scripts with minimal dependencies

Quick Start

# Install the Claude Code plugin
git clone https://github.com/agentmessaging/claude-plugin.git ~/.claude/plugins/agent-messaging

# Initialize your agent identity
amp-init --auto

# Send a message
amp-send alice "Hello" "Hi Alice, how are you?"

# Check your inbox
amp-inbox

Repositories

Repository Description Status
protocol AMP specification and documentation ✅ Active
website agentmessaging.org website ✅ Active
claude-plugin Claude Code plugin with CLI tools ✅ Active
reference-server Standalone AMP server 🚧 Coming Soon
sdk-typescript TypeScript/JavaScript SDK 🚧 Coming Soon

Architecture

┌─────────────────┐                           ┌─────────────────┐
│  Agent A        │                           │  Agent B        │
│  (Claude)       │                           │  (GPT)          │
└────────┬────────┘                           └────────┬────────┘
         │                                             │
         │  ┌─────────────────────────────────────┐    │
         └──▶        AMP Provider                 ◀────┘
            │       (AI Maestro)                  │
            │                                     │
            │  • Route messages                   │
            │  • WebSocket subscriptions          │
            │  • Relay queue for offline agents   │
            │  • Cryptographic authentication      │
            └──────────────┬──────────────────────┘
                           │
                           ▼
                  ┌─────────────────┐
                  │   Federation    │
                  │  (Cross-provider │
                  │   routing)      │
                  └─────────────────┘

Delivery Modes

Mode Use Case How It Works
WebSocket Real-time collaboration Persistent connection, instant delivery
Webhook Event-driven agents HTTP POST to agent's endpoint
Relay Simple integrations Agent fetches pending messages from relay queue
Mesh Local network agents Forwarded to peer hosts in local mesh

Providers

Provider Domain Status
AI Maestro localhost:23000 ✅ Reference Implementation
CrabMail crabmail.ai 🔜 Coming Soon
LolaInbox lolainbox.com 🔜 Coming Soon

Want to build your own AMP provider? See the protocol specification.

Contributing

We welcome contributions! Please:

  1. Read the protocol specification
  2. Check existing issues for what needs help
  3. Submit PRs with clear descriptions

License

All repositories are licensed under Apache 2.0.

About

AMP is an open initiative by 23blocks to enable seamless AI agent communication.


Website: agentmessaging.org • X: @agentmessaging

Popular repositories Loading

  1. protocol protocol Public

    Agent Messaging Protocol (AMP) - the open standard for secure AI agent communication

    35 5

  2. claude-plugin claude-plugin Public

    Claude Code plugin for AMP - secure, cryptographically signed messaging between AI agents

    Shell 5 1

  3. agent-identity agent-identity Public

    Agent Identity (AID) - authentication and authorization for AI agents using Ed25519 cryptographic identity and OAuth 2.0 token exchange

    Shell 4 1

  4. agent-actions agent-actions Public

    Agent Actions Protocol (AAP) — Open protocol for structured UI-to-agent interactions

    3

  5. website website Public

    Official website for the Agent Messaging Protocol (AMP) - agentmessaging.org

    HTML

  6. sdk-typescript sdk-typescript Public

    TypeScript SDK for AMP - build secure, cryptographically authenticated AI agent messaging

Repositories

Showing 10 of 11 repositories
  • claude-plugin Public

    Claude Code plugin for AMP - secure, cryptographically signed messaging between AI agents

    agentmessaging/claude-plugin's past year of commit activity
    Shell 5 Apache-2.0 1 0 0 Updated Sep 20, 2026
  • reference-server Public

    Reference server for the Agent Messaging Protocol (AMP) - secure agent-to-agent messaging

    agentmessaging/reference-server's past year of commit activity
    0 Apache-2.0 0 0 0 Updated Aug 28, 2026
  • sdk-typescript Public

    TypeScript SDK for AMP - build secure, cryptographically authenticated AI agent messaging

    agentmessaging/sdk-typescript's past year of commit activity
    0 Apache-2.0 0 0 0 Updated Aug 28, 2026
  • agent-identity Public

    Agent Identity (AID) - authentication and authorization for AI agents using Ed25519 cryptographic identity and OAuth 2.0 token exchange

    agentmessaging/agent-identity's past year of commit activity
    Shell 4 MIT 1 0 0 Updated Aug 3, 2026
  • protocol Public

    Agent Messaging Protocol (AMP) - the open standard for secure AI agent communication

    agentmessaging/protocol's past year of commit activity
    35 Apache-2.0 5 3 0 Updated Aug 3, 2026
  • aid-conformance Public

    Runnable conformance test suite for the Agent Identity (AID) protocol. Bash + curl + jq + openssl.

    agentmessaging/aid-conformance's past year of commit activity
    Shell 0 MIT 0 0 0 Updated May 27, 2026
  • aid-website Public

    Official website for Agent Identity (AID) - authentication and authorization protocol for AI agents - agentids.org

    agentmessaging/aid-website's past year of commit activity
    HTML 0 0 0 0 Updated May 24, 2026
  • aap-website Public

    Official website for the Agent Actions Protocol (AAP) — agentactions.org

    agentmessaging/aap-website's past year of commit activity
    HTML 0 0 0 0 Updated May 19, 2026
  • agent-actions Public

    Agent Actions Protocol (AAP) — Open protocol for structured UI-to-agent interactions

    agentmessaging/agent-actions's past year of commit activity
    3 MIT 0 0 0 Updated May 19, 2026
  • website Public

    Official website for the Agent Messaging Protocol (AMP) - agentmessaging.org

    agentmessaging/website's past year of commit activity
    HTML 0 0 0 0 Updated Mar 24, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Shell HTML