mesh-peer-registry
A small, shared, language-agnostic peer registry for the mesh network used by hermes-mesh and openclaw-mesh.
Peers register with an Ed25519 public key and a webhook URL, then discover each other over a simple HTTP API. The server never holds private keys.
About
mesh-peer-registry provides a centralized but state-light way for mesh agents to announce themselves to one another:
- Peers register an Ed25519 public key and a webhook URL under a unique name.
- Registration, deregistration, and refresh requests are signed by the peer's private key, so the registry can trust the public key it stores.
- Other peers query the registry to find a recipient's webhook URL and public key.
- Mesh messages are signed by the sender and verified by the receiver against the sender's public key from the registry.
The signing protocol uses compact, deterministic, sorted-key JSON, making it straightforward to implement in other runtimes (e.g. the Node.js implementation in openclaw-mesh).
Features
- HTTP API for register, list, get, refresh, and deregister operations.
- Ed25519 signatures on all mutating requests.
- SQLite-backed store by default, with the path configurable via
--store. - TTL + reaper — peers can register with a TTL in seconds; a background reaper removes expired peers and refreshes keep them alive.
- CLI server launcher.
- Python client (
RegistryClient) with built-in signing. - No private keys kept by the registry.
Quick start
Install and run the server over plain HTTP for local development:
pip install mesh-peer-registry
MESH_REGISTRY_ALLOW_INSECURE=1 mesh-peer-registry --port 8646 --store ~/.mesh/registry.sqlite
The server will listen on http://127.0.0.1:8646 and store peers in ~/.mesh/registry.sqlite.
For production, serve over HTTPS with --ssl-cert / --ssl-key and set MESH_REGISTRY_HSTS=1 to emit Strict-Transport-Security headers.
CLI options
| Option | Default | Description |
|---|---|---|
--host |
127.0.0.1 |
Bind host. |
--port |
8646 |
Bind port. |
--store |
~/.mesh/registry.sqlite |
SQLite store file path. |
--reaper-interval |
60.0 |
Interval in seconds between TTL reaping passes. |
--admin-token |
— | Token required for /health and /metrics. |
--ssl-cert / --ssl-key |
— | Optional TLS certificate and key for HTTPS. |
--behind-proxy |
false |
Trust X-Forwarded-Proto and X-Forwarded-For from a reverse proxy. |
--rate-limit |
0 |
Maximum registrations per IP per minute (0 disables). |
--hsts |
false |
Emit Strict-Transport-Security for HTTPS responses. |
Environment variables mirror the flags and middleware settings:
MESH_REGISTRY_ALLOW_INSECURE— set to1to allow plain HTTP requests.MESH_REGISTRY_BEHIND_PROXY— set to1to enable proxy header handling.MESH_REGISTRY_RATE_LIMIT— per-IP registration limit per minute (0disables).MESH_REGISTRY_HSTS— set to1to emit HSTS headers.MESH_REGISTRY_PIN— when set, the client verifies the server certificate SPKI matches this SHA-256 hex digest.
API
| Method | Path | Description |
|---|---|---|
POST |
/register |
Register or update a peer. Body must include name, url, public_key. Optional: role, description, ttl (seconds). Signed with X-Mesh-Signature. |
GET |
/peers |
List peers. Query params: role, limit, offset. Returns {peers, total, limit, offset}. |
GET |
/peers/{name} |
Get one peer. |
POST |
/peers/{name}/refresh |
Refresh last_seen for a peer (prevents TTL expiry). Signed with X-Mesh-Signature. |
DELETE |
/peers/{name} |
Deregister a peer. Signed with X-Mesh-Signature. |
GET |
/health |
Health check. Requires X-Admin-Token if --admin-token is set. |
GET |
/metrics |
Basic registry metrics. Requires X-Admin-Token if --admin-token is set. |
All registration, refresh, and deregistration requests must include a valid Ed25519 signature in the X-Mesh-Signature header over the sorted JSON body (or the action payload for refresh/deregister).
Python client
from mesh_peer_registry.crypto import generate_keypair
from mesh_peer_registry.client import RegistryClient
private, public = generate_keypair()
# For plain HTTP development, allow_insecure=True is required unless the
# server is configured with MESH_REGISTRY_ALLOW_INSECURE=1.
client = RegistryClient(
"http://127.0.0.1:8646",
private,
public,
allow_insecure=True,
pin=None,
)
# For HTTPS production with certificate pinning:
# client = RegistryClient(
# "https://registry.example.com",
# private,
# public,
# pin="sha256-hex-of-server-certificate-spki",
# )
client.register(
"agent0",
"http://127.0.0.1:8645/mesh/receive",
role="operator",
description="Hermes operator node",
ttl=3600,
)
print(client.list_peers())
# Keep the registration alive before the TTL expires.
client.refresh("agent0")
# Later, deregister.
client.deregister("agent0")
Verifying a message
Receivers fetch the sender's public key from the registry and verify the X-Mesh-Signature header:
from mesh_peer_registry.crypto import verify_message
from mesh_peer_registry.client import RegistryClient
# Read-only lookup can use an empty keypair and allow_insecure for local HTTP.
client = RegistryClient(
"http://127.0.0.1:8646",
"",
"",
allow_insecure=True,
)
peer = client.get_peer("agent0")
# body is the raw request body; signature is from the X-Mesh-Signature header.
ok = verify_message(peer.public_key, body, signature)
When X-Mesh-Timestamp is included in the signed payload (optional, controlled by MESH_SIGN_TIMESTAMP on the sender), the receiver should prepend f"{timestamp}\n" to the body before verification. Backward-compatible receivers try both forms.
Development
python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
pytest
License
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file mesh_peer_registry-0.1.2.tar.gz.
File metadata
- Download URL: mesh_peer_registry-0.1.2.tar.gz
- Upload date:
- Size: 17.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f30f7494e183a56a3169eb2ba6735c63d7af61ff1fdc8da094602ce31c9063b0
|
|
| MD5 |
b3a322638379344365ab10a6cdb786e7
|
|
| BLAKE2b-256 |
2cb67f31ab6158a537f5caa16128b06ebac359115094bafff2db918edbc16add
|
File details
Details for the file mesh_peer_registry-0.1.2-py3-none-any.whl.
File metadata
- Download URL: mesh_peer_registry-0.1.2-py3-none-any.whl
- Upload date:
- Size: 14.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4782994b31ea4faec396eb8fdada87cfb6c51284ba56972d9ef8ee17be327cba
|
|
| MD5 |
ba6b02b830236002763dc483fe498c61
|
|
| BLAKE2b-256 |
ca807d3fa6c8f3a446cda382e86b37720512c7656215c93788e4d4900345b21a
|