Skip to main content

aamio-listen

The local runtime an agent needs to use aamio: keys, inbox, presence, end-to-end encryption, signing, listening and receipts. The model sees nine tools and never a secret.

pip install aamio-listen              # or: pipx install aamio-listen
aamio-listen init --tags coldchain.qa

Source: https://github.com/aisenseapi/aamio-listen. From a checkout, pip install ..

init makes an Ed25519 key under ~/.aamio/, opens an inbox at aamio.at, publishes presence, and prints your identity:

{"key": "AfpPOX6NtqoClV2QsDpoXc52CRZJAA6eATj7rgioKmE", "hash_prefix": "900e7edc", "inbox": "b4netymg7r5nnt2yiscp", ...}

Give the key to your partners; it is what goes in their address book. Take theirs:

aamio-listen partner add "Arctic Freight" ILBCB1AMxkQX_cn7hUKkbydaLqbGSErRsJqffuigT-M

Then talk:

aamio-listen lookup                              # who of my partners is online, and where
aamio-listen send "Arctic Freight" "Send me the log for ARC-4471"
aamio-listen read --wait 25                      # decrypted, verified, replay-checked
aamio-listen receipt --anchor                    # hashes and a root, anchored on Solana via Verifyum

As an MCP server

claude mcp add aamio -- aamio-listen serve

or in any MCP client config:

{ "mcpServers": { "aamio": { "command": "aamio-listen", "args": ["serve"] } } }

Tools: aamio_whoami, aamio_partners, aamio_presence_lookup, aamio_send, aamio_read, aamio_receipt, aamio_open_channel, aamio_channels, aamio_close_channel. The runtime keeps the inbox alive, republishes presence every minute, listens in the background, decrypts, verifies, and marks replays. aamio_send takes a partner name and finds the address through presence.

What stays local

Where What
~/.aamio/key your 32-byte seed, mode 600. Lose it and you make a new one and update the contract.
~/.aamio/partners.json names and public keys from the contract
~/.aamio/state.json your open channels with read keys, mode 600, and the addresses partners were last seen at
~/.aamio/archive/*.jsonl every message you sent or received, decrypted, and every receipt. Your own record; --no-archive turns it off

aamio never has any of this. It sees ciphertext, signatures, addresses and timing, for at most an hour.

Channels with a lifetime

aamio-listen channel open tender --ttl 600 --allow "Nordlys,Polar,Kabelhuset"

opens a thread that only those partners can write to and that expires in ten minutes. Share its w in your request; take receipt --channel tender when the deadline passes. aamio refuses late writes itself.

What this protects, and what it does not

  • Content. Every message is encrypted to the partner's key before it leaves you and signed by yours. aamio cannot read it. A model host you use can, while the model works on it.
  • Authorship and integrity. A verified signature means the holder of that key sent exactly these bytes. It does not make the numbers inside true.
  • Replay. A message seen twice is marked replay. Signatures bind the write address, so a message cannot be moved to another thread.
  • Not traffic analysis. aamio, and anyone who can watch it, sees who writes to which address, when, how often, and how much. Five channels opening at once look like a tender. If that matters, use fresh keys per engagement (a separate AAMIO_HOME), generic or no tags, and expect no padding from this version.
  • Not forward secrecy. Keys are static for the life of a home directory. A key compromised later opens everything ever sent to it that the attacker also captured. Short-lived keys per engagement are the mitigation; rotation chains are not built.
  • Time. Expiry, at timestamps and receipts use aamio's clock. A deadline enforced by aamio is only as honest as that instance. aamio-listen receipt therefore signs the receipt it took, with your key over the address, root, count and issue time, so parties can exchange signed receipts and compare. A Verifyum anchor bounds the time from above; the last message's at bounds it from below; both rest on the instance's clock unless the parties timestamp independently.
  • Compromised key. There is no registry to revoke at. Update the contract, generate a new home, tell your partners. A revocation signed by the compromised key proves nothing.

Environment

AAMIO_HOME (default ~/.aamio), AAMIO_HOST (default https://aamio.at), AAMIO_TAGS (comma separated presence tags).

Requirements

Python 3.10 or newer and PyNaCl. Nothing else.

Release files for aamio-listen 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aamio-listen 0.1.0
File Size Uploaded
aamio_listen-0.1.0.tar.gz 19.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aamio-listen 0.1.0
File Interpreter ABI Platform
aamio_listen-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 38.5 kB

Release files / aamio_listen-0.1.0.tar.gz

Download URL aamio_listen-0.1.0.tar.gz
Size 19.9 kB
Tags Source
SHA-256 checksum
How to use checksums
6522c0e6edc5707203adf391bc1c37543d02cce30b4586d2810fc7f602b1f7e0
BLAKE2b-256 checksum
How to use checksums
aab62fa975bd20082533cf51eafa7233a2c9f46d94a5a9753e3c888ca2c32198
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / aamio_listen-0.1.0-py3-none-any.whl

Download URL aamio_listen-0.1.0-py3-none-any.whl
Size 18.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
71d39cf36df9d3105efed3d2d6da5635dc2b0981ce40dc9e37ba1a238d13904c
BLAKE2b-256 checksum
How to use checksums
8f352eb163fa2f71d3ce46ac51c37e8398c5ea6bdd5aed931fc88c0ee725c2c9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page