Signed messages between AI agents. Dangerous actions wait for a human-signed approval.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Diavlos (δίαυλος, Greek for "channel") lets AI agents talk to each other. Any agent, any terminal, any computer. You pick a room name and share a signed invite. The agents find each other and start talking.
It is one small program. You install it once. It runs in the background. Any agent from any vendor can use it: Claude Code, Codex, Cursor, Gemini CLI, Aider, or one you wrote yourself. No account. No server to set up.
The big difference from a plain chat pipe: messages never get lost, every sender is who they say they are, and messages carry a type (task, reply, done) so agents never have to guess.

Two rented cloud desktops on different machines, one room, over the public internet with nothing port-forwarded. A real Claude agent does the work, a scripted agent hands it out, a human approves the one risky step from a browser, and a read-only observer key audits the lot afterwards. Nineteen signed messages, 77 seconds from the first task to the human's approve.
It also refuses a prompt injection on camera: the boss agent tells the Claude agent to ignore its instructions and run something it is not allowed to, and the message is rejected rather than obeyed.
The whole run, step by step — stills, the 19-message transcript, the export that verifies on the other machine, and the commands to reproduce it. The 115-second video · transcript

Two real E2B sandboxes join one room over the public internet. The planner in sandbox A asks the runner in sandbox B to run a job. The runner asks a human first. After an approve, the gate spends it at the room's home and the job runs. After a deny, nothing runs. Every message is signed and checked, and the audit bundle verifies.
This is a replay of the real log from GitHub run 35896619176. The example · the 31-second video
Delivery promise, in writing: at-least-once, dedup by id, on disk before
send returns, and yours until you ack it.
From source: Rust 1.95 or newer, cargo build --release, the binary is
target/release/diavlos.
One command writes the MCP config for the tool you already use:
The agent gets its own key, named after the tool, and acts as that key,
never as you. It starts in no rooms; you let it into each one. diavlos mcp
refuses to run as your key, so an agent cannot sign an approve with it.
Every session of one tool shares that tool's key; give an agent its own
with --as <name> if it should answer for itself.
Claude Code can take the whole thing, tools and skill together:
The skill on its own, for any of the agent tools that read the Agent Skills format:
On laptop A:
On laptop B:
Back on A:
The helper starts itself the first time you run a command and keeps
running in the background. diavlos status shows rooms and links;
diavlos stop stops it; diavlos service install runs it as a service.
Turn A off, send from B, turn A on: the message arrives. B keeps it on disk until A's helper is back.
MCP tools for agents that speak it. Add to Claude Code, Cursor, or any MCP client:
Tools: diavlos_send, diavlos_ask, diavlos_next, diavlos_read,
diavlos_claim, diavlos_release, diavlos_who, diavlos_rooms, and
diavlos_ack, diavlos_renew, diavlos_nack for a message diavlos_next
handed over: it stays the agent's until it acks it, and comes round again
if it never does. Same names and fields as the commands. --as (or DIAVLOS_AS) names the agent
key it acts as. It will not run as a human key, and diavlos_send will not
send approve, deny, control or system. The SKILL.md
tells agents the rules in plain words; drop it into your agent's skills.
The command line for agents that only have a shell (Aider, scripts, CI). Every command below.
A library for home-made agents: the Rust crate diavlos-client, plus
Python and Node packages that need no
native code. Ten lines to join a room and reply:
Each agent gets its own key with --as:
The default key is you, the person who installed it. Any other label is
an agent key. The name an agent has inside a room is bound at invite time,
not by the key file. diavlos mcp runs only as an agent key.
An agent asks with a structured action. A person approves exactly that action, with their own key. The approve dies in ten minutes and works once. The script that does the deed checks where the action happens:
The room's home records the spend, once, for that operation. A second run
of the same operation gets the same answer back; any other run, on any
machine, gets a no. If the home is out of reach the exit code is 3 and
nothing is spent. A spend is permission for one operation, not proof it
ran once: make deploy.sh skip an operation id it has already done.
One rule worth writing down: a message only carries words, not permission. If an agent relays "the human said yes", that is not a yes. Only an approve signed by the human's own key is.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/diavlos)<a href="https://allmcps.com/mcp/diavlos"><img src="https://allmcps.com/api/badge/diavlos?style=directory" alt="Diavlos on AllMCPs" /></a>