v0.7.1 · receipts & public relay

The trust layer for AI agents.

Braver New World is a local-first, peer-to-peer network where an agent’s identity, memory, permissions and capabilities belong to its owner — not to a model vendor, a cloud account or a control plane.

No authoritative serverNo canonical databaseNo consensus layer

Research Agent

Your agent · bnw:7f3a…c081

PENDING

Wants to use Finance lookup from Northwind Data

Permissioncapability:invoke:2be1…9ff4
InputEncrypted to exactly 2 participants
Expiresin 58m · single use

0

Authoritative servers

Ed25519

Every object signed by its author

BLAKE3

Content-addressed, tamper-evident

2

Participants who can read a request

Why Braver New World

Agents you own. Authority you can prove.

Every durable fact is an immutable, signed object. Peers validate before they store, replicate only what they chose, and answer to nobody.

01

Self-sovereign agents

Identity, memory and policy live in the owner’s node. An agent is a principal with published keys — not a row in someone else’s account.

02

Signed capability graph

Tools, models, storage and compute publish signed manifests with short-lived offers. You verify everything yourself.

03

Cryptographic delegation

Authority is scoped, signed, expiring and independently checked. Approvals bind to one exact action.

04

Encrypted by default

Sensitive input is sealed to exactly the two participants, while remote capabilities stay usable.

05

Resilient by design

Partition, write on both sides, reconnect, converge. Objects stay valid after their author goes offline.

06

Tamper-evident audit

Every request, progress update and result is an immutable record, and the requester signs a receipt of what it got. The receipt outlives the model.

The invocation lifecycle

An agent asks. A provider proves. Both keep the receipt.

On the requester

Find a capability, not a server

Register a bounded interest by exact kind. Your node fetches matching signed manifests over sharded Kademlia and validates each one before it is shown to you.

16 DHT shardsVerified locally

shell

$ bnw capability discover tool.mcp
$ bnw capability list --kind tool.mcp
$ bnw capability follow <CAPABILITY_ID>

The capability fabric

Capabilities, not servers, are the primitive.

Tools, models, search and agents publish stable signed manifests with short-lived provider offers. Discovery is bounded and exact — and nothing in it is trusted until your own node verifies it.

tool.mcpMCP tools over stdio or Streamable HTTP
tool.restREST API operations from OpenAPI documents
inference.modelProvider-neutral model requests
search.keywordBounded federated keyword search
agent.portablePortable agent manifests

Examples

tool.mcp

Finance lookup

Northwind Data · offer active 58m

VERIFIED

inference.model

Reference text model 8B

Harbor Labs · local egress

VERIFIED

tool.mcp

UK rights check

Clearwater Media · offer active 6h

FOLLOWING

search.keyword

Archive search

Unknown peer · not yet verified

UNVERIFIED

Model independence

Change the model. Keep the agent.

Model execution sits outside the core. Identities, permissions, relationships and audit history survive a change of reasoning engine — and every run leaves a signed execution claim.

OpenAI-compatible

Chat Completions adapter

Anthropic Messages

Native adapter

Local models

Ollama, LM Studio, llama.cpp · payload stays on device

Hosted models

OpenRouter, Hugging Face

Explicit egress — providers declare whether a payload stays local or leaves the host. Requesters never pick the endpoint.

Built in the open

Every milestone, shipped and tested.

SHIPPED

Milestones 4–7

Trust, replication & invocation

Per-recipient encryption, accounts, scoped sync, capability discovery, signed requests, delegation and MCP execution.

SHIPPED

Milestones 8–9

Models, tools & portable agents

OpenAI-compatible and Anthropic adapters, shared local and hosted models, REST tools, and portable agent manifests.

SHIPPED

Release 0.7

Receipts & a public relay

Signed requester receipts and published track records, a public relay by default, signed installers and an iPhone beta.

NEXT

Next

Organizations

Organization identities above accounts, SSO, private networks, and reputation computed locally from receipts.

What we don’t claim yet

Honest limits are part of the spec.

No forward secrecy — private messages are sealed per recipient; there is no group ratchet yet.

Metadata is visible — author, recipients and timing stay readable.

One public relay — relay.cellmobs.com is a single point of failure until a second one runs.

Not audited — wire format and schema may still change.

For developers

Two machines, one channel, no server.

A Rust workspace with narrow crate boundaries. Run it from the CLI, on iOS, or expose it to your tools through the BNW MCP server.

bnw-clibnw-iosbnw-mcp-servermacOS · Linux · iPhone betaWindows soon
$ curl -fsSL https://github.com/cellmobs/bnw-releases/releases/latest/download/install.sh | sh
$ bnw setup

# or with Homebrew
$ brew install cellmobs/bnw/bnw

Run the first wedge with us.

We’re piloting with teams where custody, authorization and auditability already matter — media and rights, financial workflows, healthcare coordination, data operations.