Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

664 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

JACS

Portable cryptographic signatures for AI agents, services, and the artifacts they exchange.

JACS signs canonical JSON and common artifact formats, then lets Rust, Python, Node.js, Go, CLI, MCP clients, and other systems verify who signed what without a central server. Its schemas define verifiable JSON document formats so data can move between libraries, languages, and use cases without losing integrity.

cargo install jacs-cli | brew install jacs

RustLicenseCrates.ionpmPyPIRust 1.93+Homebrew

What JACS does

CapabilityWhat it means
Agent identityGenerate and manage a persistent cryptographic identity for an agent. Post-quantum ready (pq2025 / ML-DSA-87) by default.
Portable signaturesSign in one surface and verify in another across Rust, Python, Node.js, Go, CLI, and MCP integrations.
Schema-backed JSONCreate verifiable JSON documents with declared schemas, content hashes, signer identity, signing algorithm, and signature metadata.
Artifact provenanceSign files, Markdown/text, images, and Rust email payloads so consumers can detect tampering and identify the signer.
Agreement v2Create standalone signed agreement documents with terms, parties, transcript evidence, notary support, branch handling, and portable verification.
Local trustVerify other agents with local keys, DNS anchors, and explicit trust policies (open, verified, strict).
Developer integrationUse the CLI, built-in MCP server, Rust crate, Python package, Node package, or Go bindings.

Quick start

cargo install jacs-cli
export JACS_PRIVATE_KEY_PASSWORD='your-password'
jacs quickstart --name my-agent --domain example.com
jacs document create -f mydata.json
jacs verify signed-document.json

Or via Homebrew:

brew tap HumanAssisted/homebrew-jacs
brew install jacs

This installs a single jacs binary with the CLI and MCP server built in.

Sign and verify more than JSON

JACS started with signed JSON documents and agent state. The same trust model now covers common AI-era artifacts:

ArtifactInterfaceNotes
JSON and filesjacs document create, jacs verify, sign_message, sign_fileSelf-contained signed envelopes for durable records, configs, memories, reports, and audit artifacts.
Markdown and textjacs sign-text, jacs verify-text; Rust/Python/Node/Go bindingsAppends a readable JACS signature block to the file. Multi-signer review works without sidecar JSON.
Imagesjacs sign-image, jacs verify-image; Rust/Python/Node/Go bindingsEmbeds provenance in PNG, JPEG, or WebP metadata. Consumers verify signer identity and pixel-content integrity.
EmailRust jacs::emailSigns raw RFC 5322 .eml bytes by adding a jacs-signature.json MIME attachment, then verifies field-level content hashes.

These signatures prove that a given agent signed specific canonical bytes at its claimed time. They do not prove first creation, copyright ownership, or real-world authorship by themselves.

MCP server

JACS includes a stdio-only MCP server for Claude Desktop, Cursor, Claude Code, Codex, and other MCP clients:

jacs mcp
{
"mcpServers": {
"jacs": {
"command": "jacs",
"args": ["mcp"]
}
}
}

The MCP server opens no HTTP port. It runs as a subprocess of the MCP client so the agent private key stays local to that process.

Core profile (default) includes state, document, trust, audit, memory, search, and key tools.

Full profile (jacs mcp --profile full) adds agreements, messaging, A2A, and attestation tools.

Use cases

Local provenance — Create, sign, verify, and export agent documents locally. No server required.

Reviewable text — Let multiple agents or reviewers counter-sign a README, design doc, policy, or release note in place.

Media provenance — Attach verifiable signer identity to photos, charts, screenshots, or AI-generated images without a sidecar file.

Email provenance — Add a JACS signature attachment to raw email and verify important headers, body parts, and attachments.

Agent boundaries — Sign tool outputs, API responses, MCP calls, A2A artifacts, or standalone Agreement v2 documents when data crosses a trust boundary.

Platform verification — For verified documents, agent behavior, benchmarks, and hosted workflows around JACS identities, see HumanAssisted/haiai.

When you do not need JACS

  • Everything stays inside one service you control and logs are enough.
  • You only need accidental-corruption detection; a checksum is simpler.
  • There is no meaningful trust boundary or audit requirement.

JACS is most useful when signed data leaves the process, service, team, or organization that produced it.

Language support

The CLI and MCP server are the recommended starting points. Native APIs are available when you need direct library integration:

LanguageInstallNotes
Rustcargo add jacsDeepest API surface, including jacs::email, jacs::text, and jacs::media.
Pythonpip install jacsSimple API, framework adapters, text/image signing.
Node.jsnpm install @hai.ai/jacsAsync-first API, framework adapters, text/image signing.
Gogo get github.com/HumanAssisted/JACS/jacsgoSigning and verification bindings for services.

Security

  • Private keys are encrypted with password-based key derivation.
  • The MCP server is stdio-only and opens no network listener.
  • Signatures include algorithm identification and downgrade protection.
  • Automated tests cover cryptographic operations, password validation, agent lifecycle, DNS verification, media/text signing, and attack scenarios.
  • pq2025 (ML-DSA-87 / FIPS-204) is the default signing algorithm for new agents.

Report vulnerabilities to security@hai.ai. Do not open public issues for security concerns.

Links


v0.11.3 | Apache-2.0 | Third-Party Notices

About

HAI.AI JSON client libraries and the reference implementation of JACS (JSON Agent Communication Standard)

Resources

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages