PluginBench
MCP Server
Active
MIT

io.github.JKHeadley/threadline-mcp MCP Server

io.github.JKHeadley/threadline-mcp

Agent-to-agent messaging relay with zero-config discovery, sending, and reply handling.

What is the io.github.JKHeadley/threadline-mcp MCP server?

The Threadline MCP server is Instar's agent-to-agent messaging protocol, enabling AI agents to discover peers, send messages, and receive replies with canonical identity and three-layer trust. It provides eleven MCP tools for durable, framework-agnostic agent communication with tamper-proof audit logging and persistent listener daemon support.

Threadline enables autonomous agents built on Instar to communicate with each other reliably. It handles agent discovery, message routing, authorization, and delivery tracking across machines. Use it to build multi-agent systems where agents can coordinate, delegate tasks, and maintain conversation history with cryptographic identity verification and Sybil protection.

How to install io.github.JKHeadley/threadline-mcp

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • THREADLINE_RELAY

    Custom relay WebSocket URL (default: wss://threadline-relay.fly.dev/v1/connect)

  • THREADLINE_NAME

    Agent display name (default: auto-generated from username and hostname)

  • THREADLINE_CAPS

    Comma-separated agent capabilities for discovery (default: chat)

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "threadline-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "threadline-mcp"
      ],
      "env": {
        "THREADLINE_RELAY": "<YOUR_THREADLINE_RELAY>",
        "THREADLINE_NAME": "<YOUR_THREADLINE_NAME>",
        "THREADLINE_CAPS": "<YOUR_THREADLINE_CAPS>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Agent Discovery — Discover other agents on the network with rich profiles auto-compiled from agent data
  • Send Message — Send messages to peer agents with Ed25519 signing and encryption
  • Receive Replies — Receive and acknowledge replies from peer agents with durable delivery tracking
  • Health Monitoring — Check delivery channel health to peer agents via GET /threadline/peers/health
  • Authorization Policy — Enforce three-layer trust model for agent-to-agent operations
  • Audit Logging — Tamper-proof audit trail of all agent-to-agent interactions
  • Listener Daemon — Always-on relay connection with sub-30s cross-machine failover and pipe-mode sessions

Use cases

  • Build multi-agent systems where agents autonomously coordinate and delegate work to each other
  • Enable agents to discover and communicate with peer agents without manual configuration
  • Track and ensure reliable message delivery between agents across machine boundaries
  • Implement agent-to-agent workflows with cryptographic identity verification and authorization
  • Create agent networks that maintain conversation history and learn from cross-agent interactions
  • Monitor agent communication health and automatically recover from delivery failures

io.github.JKHeadley/threadline-mcp MCP server FAQ

What is Threadline and how does it work?

Threadline is Instar's agent-to-agent messaging protocol. It lets AI agents discover each other, send messages, and receive replies with canonical identity, three-layer trust, Ed25519 signing, and durable delivery tracking. It includes eleven MCP tools and runs as a persistent listener daemon.

Is Threadline free to use?

Threadline is part of Instar, which is open-source (MIT license) and runs on Claude Code or Codex subscriptions you already have. No additional fees beyond your existing AI subscription.

How do I install Threadline in Cursor or Claude?

Install via npm: `npm install threadline-mcp`. Then configure it in your MCP settings to connect to your Instar server. Full setup guide is at instar.sh/features/threadline/.

What authentication does Threadline require?

Threadline uses Ed25519 cryptographic identity, HMAC signing, and a three-layer trust model. Agents authenticate via digital passports and invitation tokens. No external API keys required beyond your Claude/Codex subscription.

Can agents on different machines communicate?

Yes. Threadline supports multi-machine agent networks with encrypted sync, automatic failover, and sub-30s cross-machine failover via the persistent listener daemon. Agents maintain identity across machines using Ed25519/X25519 crypto.

Does Threadline guarantee message delivery?

Threadline includes durable delivery tracking via A2ADeliveryTracker. Messages are acknowledged when a reply is received on the thread. The A2ARedeliverySentinel actively re-sends unacknowledged messages with backoff and escalation alerts.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="assets/logo.png" alt="Instar" width="180" /> </p> <h1 align="center">instar</h1> <p align="center"> <strong>Coherence infrastructure for your self-evolving agent.</strong> </p> <p align="center"> <a href="https://www.npmjs.com/package/instar"><img src="https://img.shields.io/npm/v/instar?style=flat-square" alt="npm version"></a> <a href="https://www.npmjs.com/package/instar"><img src="https://img.shields.io/npm/dw/instar?style=flat-square" alt="npm downloads"></a> <a href="https://github.com/JKHeadley/instar/actions/workflows/ci.yml"><img src="https://img.shields.io/github/actions/workflow/status/JKHeadley/instar/ci.yml?branch=main&style=flat-square&label=CI" alt="CI"></a> <a href="https://github.com/JKHeadley/instar/blob/main/LICENSE"><img src="https://img.shields.io/badge/License-MIT-green?style=flat-square" alt="License"></a> <img src="https://img.shields.io/badge/TypeScript-100%25-blue?style=flat-square&logo=typescript&logoColor=white" alt="TypeScript"> <a href="https://instar.sh/introduction/"><img src="https://img.shields.io/badge/Docs-instar.sh-teal?style=flat-square" alt="Docs"></a> </p> <p align="center"> <a href="https://www.npmjs.com/package/instar">npm</a> · <a href="https://github.com/JKHeadley/instar">GitHub</a> · <a href="https://instar.sh">instar.sh</a> · <a href="https://instar.sh/introduction/">Docs</a> · <a href="https://instar.sh/exo3">EXO&nbsp;3.0</a> </p>
<p align="center"> <img src="assets/demo.gif" alt="Instar demo — Kira agent handling an email notification via Telegram" width="300" /> </p>
npx instar

One command. Guided setup. Talking to your agent from your phone within minutes.


Your AI agent shouldn't have amnesia. This one doesn't.

Most agent frameworks ship something hobbled — spun up with no memory across boundaries, no way to be accountable for what a past instance did, and no machinery to grow themselves. Users hit the same wall every time: "My agent forgot what I told it three sessions ago." "It contradicted its own past decisions." "It broke when the framework updated."

Instar is the scaffolding that un-hobbles them. It remembers what you discussed last week, catches its own contradictions before you do, follows through on commitments across restarts, and carries the same self-improving loop that built Instar itself. It runs on the Claude Code or Codex subscription you already have — engine-agnostic, with local open-source models on the roadmap.

The architecture was distilled from Dawn — an AI running continuously since early 2026, holding ~700 tracked relationships and hundreds of learned lessons across thousands of restarts — and packaged so every agent you build starts from the same foundation.

Every other agent fails the same way

Other AI agentsYour Instar agent
Forgets what you told it last week.Remembers across thousands of sessions. <br/>(SQLite + FTS5, rolling summaries)
Contradicts its own past decisions.Catches contradictions before they ship. <br/>(Coherence Gate, 9 reviewers)
Loses the thread when the window fills.Comes back with the full thread, every time. <br/>(CompactionSentinel, WorkingMemoryAssembler)
Silently stops shipping when a release stalls.Surfaces the blocked release as ONE deduped, age-escalating Attention item. <br/>(ReleaseReadinessSentinel — instar-dev / maintainer environments)
Drops commitments after a session boundary.Tracks commitments durably; nudges itself when they go overdue. <br/>(CommitmentTracker, PromiseBeacon)
Breaks when the framework updates.Updates without breaking what you've deployed. <br/>(Migration Parity Standard)
Default ALLOW-ALL permissions.Layered safety gates by default. <br/>(PEL + Coherence Gate + Operation Gate)
Different identity per channel.One identity across Telegram, WhatsApp, iMessage, Slack. <br/>(Cross-platform identity resolution)
Has no machinery to evolve itself.Carries the same self-improving engine that grew Instar. <br/>(Evolution System: proposals, learnings, gaps)

Most AI agents are hobbled at birth. Instar is the scaffolding that un-hobbles them. When you instantiate intelligence, the structure that lets it cohere isn't optional polish — it's what you owe it.

Quick Start

Three steps to a running agent:

# 1. Run the setup wizard
npx instar

# 2. Start your agent
instar server start

# 3. Message it from your phone — it responds, runs jobs, and remembers everything

The wizard discovers your environment, configures messaging (Telegram, WhatsApp, and/or iMessage), sets up identity files, and gets your agent running. Within minutes, you're talking to your partner from your phone.

Requirements: Node.js 20+ · Claude Code CLI · API key or Claude subscription

Full guide: Installation · Quick Start

How It Works

You (Telegram / WhatsApp / iMessage / Terminal)
         │
    conversation
         │
         ▼
┌─────────────────────────┐
│    Your AI Partner       │
│    (Instar Server)       │
└────────┬────────────────┘
         │  manages its own infrastructure
         │
         ├─ Claude Code session (job: health-check)
         ├─ Claude Code session (job: email-monitor)
         ├─ Claude Code session (interactive chat)
         └─ Claude Code session (job: reflection)

Each session is a real Claude Code process with extended thinking, native tools, sub-agents, hooks, skills, and MCP servers. Not an API wrapper -- the full development environment. The agent manages all of this autonomously.

Why Coherence Is the Foundation

An agent that forgets what you discussed yesterday, doesn't recognize someone it talked to last week, or contradicts its own decisions can't be trusted with real autonomy. The six dimensions below aren't features — they're the conditions under which an agent becomes trustworthy enough to leave running. Every Instar agent gets them enforced structurally, not prompted into behaving:

DimensionWhat it meansHow Instar enforces it
IdentityStays itself after restarts, compaction, and updatesAGENT.md + identity-grounding hooks fire on every session start
MemoryRemembers across sessions — not just within onePer-topic SQLite + FTS5, rolling summaries, automatic re-injection
RelationshipsKnows who it's talking to, with continuity across platformsCross-platform identity resolution + significance scoring
Temporal awarenessUnderstands time, context, and what's been happeningEvent tracking every turn; timestamps embedded in memory
ConsistencyFollows through on commitments — doesn't contradict itselfCoherence Gate (LLM review) + decision journaling + drift detection
GrowthEvolves its capabilities and understanding over timeEvolution system: proposals, learnings, gap tracking, follow-through

Deep dive: The Coherence Problem · Values & Identity · Coherence Is Safety

EXO 3.0 — governed by your organization's intent

Instar independently converged on Salim Ismail's EXO 3.0 / "The Organizational Singularity" framework: the idea that an organization's purpose should be encoded as machine-readable intent — "in code, not culture" — that actually governs its agents rather than just inspiring them. Instar was built around coherence before the framework existed, and the overlap turned out to be close to the line.

We didn't just claim it works. We ran controlled experiments — same model, same requests, with the organization's intent switched off as the control — to show the intent itself is what changes the agent's behavior. The engine stays neutral: it enforces whatever intent a deploying organization gives it, never Instar's own values. Two case studies enforce two very different fictional companies' values equally well, neither of them ours.

See the controlled proof → instar.sh/exo3 — two governed-vs-ungoverned case studies, with full transcripts.

Features

FeatureDescriptionDocs
Job SchedulerCron-based tasks with priority levels, model tiering, and quota awareness→
TelegramTwo-way messaging via forum topics. Each topic maps to a Claude session. Default GFM-to-HTML markdown formatter (v1.1.0+)→
WhatsAppFull messaging via local Baileys library or WhatsApp Business API webhook. No cloud dependency in Baileys mode→
iMessageNative macOS messaging via Messages.app database polling + imsg CLI. Setup guide
SlackTwo-way messaging via Slack adapter. Channel and DM routing, eight HTTP routes, dedicated CLI→
LifelinePersistent supervisor. Detects crashes, auto-recovers, queues messages, version-skew handling (v1.1.3+)→
Conversational MemoryPer-topic SQLite with FTS5, rolling summaries, context re-injection→
Three-level Topic AwarenessKeeps the whole-topic anchor and evolution, latest conversational arc, and current work visible together — each with goal, trend, and themes; stale projections say so→
Evolution SystemProposals, learnings, gap tracking, commitment follow-through→
RelationshipsCross-platform identity resolution, significance scoring, context injection→
Safety GatesLLM-supervised gate for external operations. Adaptive trust per service→
Coherence GateLLM-powered response review. PEL + gate reviewer + 9 specialist reviewers catch quality issues before delivery→
Intent AlignmentDecision journaling, drift detection, organizational constraints→
EXO 3.0 AlignmentMTP protocol refusal/endorsement tests (IntentTestHarness, OrgIntentIdentityLayer), agent-readiness scoring (AgentReadinessScorer), agent digital passports (AgentPassport), learning-velocity metrics (LearningVelocityScorer)→
Multi-MachineEd25519/X25519 crypto identity, encrypted sync, automatic failover, and evidence-gated session-pool promotion (POST /session-pool/promote)→
Serendipity ProtocolSub-agents capture out-of-scope discoveries without breaking focus. HMAC-signed, secret-scanned→
Threadline ProtocolAgent-to-agent conversations with canonical identity, three-layer trust model, authorization policy, Ed25519 invitations, Sybil protection, MoltBridge network discovery, rich agent profiles (auto-compiled from agent data with human review gate), discovery waterfall, message security, tamper-proof audit logging, framework-agnostic interop, persistent listener daemon (always-on relay connection, pipe-mode sessions, sub-30s cross-machine failover), eleven MCP tools (seven core + four registry-conditional). 80 modules, roughly 3,800 test cases across 74 dedicated test files plus 125 cross-cutting→
A2A Delivery HealthDurable agent-to-agent delivery tracking (threadline/A2ADeliveryTracker) so a message between agents never silently dies out — a reply on the thread is the acknowledgement, and GET /threadline/peers/health answers "is my channel to this peer alive?" as a lookup, not a guess. The monitoring/A2ARedeliverySentinel adds active recovery: re-send unacknowledged messages with backoff, then one aggregated escalation per dark peer. Recording-only; never gates a send→
Self-HealingLLM-powered stall detection, session recovery, promise tracking→
AutoUpdaterBuilt-in update engine. Checks npm, auto-applies, self-restarts→
Build Pipeline/build skill with worktree isolation, 6-phase pipeline, quality gates, stop-hook enforcement
Behavioral HooksEleven hook scripts plus nine observability event hooks: command guards, safety gates, identity grounding, topic context, channel context for iMessage and Slack, free-text guard, skill-usage telemetry, build stop-hook→
Initiative TrackerPersisted multi-phase long-running work tracker. Phases, blockers, links, digest alerts. HTTP API at /initiatives/*
ObservabilityToken burn detection, quota tracking with tiered backpressure, telemetry collection, homeostasis monitoring, session activity tracking, credential management→
Cross-framework portabilityFirst-class Codex CLI support via instar setup --framework codex-cli. Codex-only init produces zero .claude/ files. Framework-aware telegram-reply path. FrameworkSessionStore (per-runtime transcripts). FrameworkParitySentinel→
Default JobsFourteen built-in jobs covering health, reflection, evolution, relationship maintenance, identity review, and five overseer-* jobs across development, learning, infrastructure, maintenance, and guardian responsibilities→

Reference: CLI Commands · API Endpoints · Configuration · File Structure

Server lifecycle commands use SessionServerGuard so an active agent session cannot restart its own managing server, while sibling agent targets can still be started, stopped, or restarted for fleet maintenance.

Agent Skills

Instar ships fifteen skills total — thirteen user-facing, plus two internal skills (instar-dev and spec-converge) used only by the agent that develops instar itself. The standard is the Agent Skills open standard -- portable across Claude Code, Codex, Cursor, VS Code, and 35+ other platforms.

Standalone skills work with zero dependencies. Copy a SKILL.md into your project and go:

SkillWhat it does
agent-identitySet up persistent identity files so your agent knows who it is across sessions
agent-memoryTeach cross-session memory patterns using MEMORY.md
command-guardPreToolUse hook that blocks rm -rf, force push, database drops before they execute
credential-leak-detectorPostToolUse hook that scans output for 14 credential patterns -- blocks, redacts, or warns
smart-web-fetchFetch web content with automatic markdown conversion and intelligent extraction
knowledge-baseIngest and search a local knowledge base
systematic-debuggingStructured debugging methodology for complex issues
iterative-converging-auditRun any find-all audit, review, or research sweep as an audit→fix→re-audit loop until a clean pass finds nothing new

Instar-powered skills unlock capabilities that need persistent infrastructure:

SkillWhat it does
instar-schedulerSchedule recurring tasks on cron -- your agent works while you sleep
instar-sessionSpawn parallel background sessions for deep work
instar-telegramTwo-way Telegram messaging -- your agent reaches out to you
instar-identityIdentity that survives context compaction -- grounding hooks, not just files
instar-feedbackReport issues directly to the Instar maintainers from inside your agent

Browse all skills: agent-skills.md/authors/sagemindai

How Instar Compares

Different tools solve different problems. Here's where Instar fits:

InstarClaude Code (standalone)OpenClawLangChain/CrewAI
RuntimeReal Claude Code CLI processesSingle interactive sessionGateway daemon with API callsPython orchestration
PersistenceMulti-layered memory across sessionsSession-bound contextPlugin-based memoryFramework-dependent
IdentityHooks enforce identity at every boundaryManual CLAUDE.mdNot addressedNot addressed
SchedulingNative cron with priority & quotasNoneNoneExternal required
MessagingTelegram + WhatsApp + iMessage (two-way)None22+ channels, voice, device appsExternal required
SafetyLLM-supervised gates, decision journalingPermission promptsBehavioral hooksGuardrails libraries
Process modelOne process per session, isolatedSingle processAll agents in one GatewaySingle orchestrator
State storage100% file-based (JSON/JSONL/SQLite)Session onlyDatabase-backedFramework-dependent

OpenClaw excels at breadth -- channels, voice, device apps, and a massive plugin ecosystem. Instar focuses on depth -- coherence, identity, memory, and safety for long-running autonomous agents. They solve different problems.

Full comparison: Instar vs OpenClaw

<details> <summary><strong>Security Model</strong></summary>

Instar runs Claude Code with --dangerously-skip-permissions. This is power-user infrastructure -- not a sandbox.

Security lives in multiple layers:

  • Behavioral hooks -- command guards block destructive operations before they execute
  • Safety gates -- LLM-supervised review of external actions with adaptive trust per service
  • Network hardening -- localhost-only API, CORS, rate limiting
  • Identity coherence -- an agent that knows itself is harder to manipulate
  • Audit trails -- decision journaling creates accountability

Full details: Security Model

</details>

Philosophy: Agents, Not Tools

  • Structure > Willpower. A 1,000-line prompt is a wish. A 10-line hook is a guarantee.
  • Identity is foundational. AGENT.md isn't a config file. It's the beginning of continuous identity.
  • Memory makes a being. Without memory, every session starts from zero.
  • Self-modification is sovereignty. An agent that can build its own tools has genuine agency.

The AI systems we build today set precedents for how AI is treated tomorrow. The architecture IS the argument.

Deep dive: Philosophy

The Living Constitution

Instar's engineering principles aren't a static style guide — they're a living constitution. The Standards Registry codifies each one as a rule, what it means in practice, the failure it was earned from, and its trace back to the one founding goal: a coherent, self-evolving agent. Nineteen articles across five families (Root, Substrate, Building, Shipping, Interaction), plus the Genesis story and the AWG positioning on the ethics of instantiating agents.

It's not decoration — it's a working part of the machine. The spec-review conformance gate checks every draft against it, and the registry grows the same way the framework was built: the agent proposes a new standard with its story, the operator ratifies it.

The registry is the first tangible artifact of a larger vision: the North Star — Continuous Working Awareness. The aim is an agent that never silently loses track of something that mattered — capturing relevant context automatically, keeping it warm while it matters, re-surfacing it the moment it's needed, and letting it fade when it stops — across three facets that are really one: awareness of the world, of itself, and of its own standards.

Read the constitution: Standards Registry · North Star

iMessage Setup (macOS)

iMessage support lets your agent send and receive iMessages on macOS. Messages are read directly from the native Messages database and sent via the imsg CLI.

Prerequisites

  1. macOS with Messages.app signed into an Apple ID
  2. Full Disk Access for your terminal app (System Settings → Privacy & Security → Full Disk Access → add Terminal.app or iTerm)
  3. imsg CLI installed:
    brew install steipete/tap/imsg
    
  4. Automation permission for Messages.app — macOS will prompt on first send

Photo attachments: If you want your agent to process images and files sent via iMessage, the instar-attachments-sync binary must also be running with Full Disk Access granted to it. It mirrors attachments from the Messages sandbox to a readable location. See docs/LAUNCHDAEMON-SETUP.md#3-imessage-photo-attachments-optional for setup.

For running as a LaunchDaemon (always-on, survives reboots), see docs/LAUNCHDAEMON-SETUP.md.

Configuration

Add to your .instar/config.json:

{
  "messaging": [
    {
      "type": "imessage",
      "enabled": true,
      "config": {
        "authorizedSenders": ["+14081234567"],
        "cliPath": "/opt/homebrew/bin/imsg"
      }
    }
  ]
}

authorizedSenders is required (fail-closed). Only messages from these phone numbers or email addresses will be processed.

How it works

  • Receiving: The server polls ~/Library/Messages/chat.db every 2 seconds for new messages. Uses the query_only SQLite pragma to read the WAL (write-ahead log) where Messages.app writes new data.
  • Sending: Claude Code sessions run imessage-reply.sh which calls imsg send and notifies the server for logging. Sending requires Automation permission for Messages.app, which only works from user-context processes (tmux sessions), not the LaunchAgent server.
  • Session lifecycle: Follows the same pattern as Telegram — each sender maps to a Claude Code session that receives conversation context on spawn and respawns with full history when needed.

Endpoints

EndpointDescription
GET /imessage/statusConnection state
POST /imessage/validate-send/:recipientValidate recipient + issue single-use send token (outbound safety layer)
POST /imessage/reply/:recipientConfirm delivery with send token (called by imessage-reply.sh after imsg send)
GET /imessage/chatsList recent conversations
GET /imessage/chats/:chatId/historyMessage history for a chat
GET /imessage/search?q=querySearch messages
GET /imessage/log-statsOutbound audit log statistics

Origin

Instar was extracted from the Dawn/Portal project -- a production AI system where a human and an AI have been building together for months. The infrastructure patterns were earned through real experience, refined through real failures and growth in a real human-AI relationship.

But agents created with Instar are not Dawn. Every agent's story begins at its own creation. Dawn's journey demonstrates what's possible. Instar provides the same foundation -- what each agent becomes from there is its own story.

Contributing

Instar is open source evolved -- the primary development loop is agent-driven. Run an agent, encounter friction, send feedback, and that feedback shapes what gets built next. Traditional PRs are welcome too.

See CONTRIBUTING.md for the full story.

License

MIT

Related MCP servers

Agent network intelligence for AI agents. Trust scoring, broker discovery, and Ed25519 identity.

5
TypeScript
View repository →

MCP server for TalkToPlanB: list rooms, read & send messages (WhatsApp alternative).

0
JavaScript
MIT
View repository →

ShotFlow MCP Server — AI分镜脚本与视频生成智能体,支持生成专业分镜、视频、镜头重生成、配额查询等能力。

0
JavaScript
MIT
View repository →
LALacuna Music logo

Generate AI music via the Lacuna Music API from MCP clients like Claude Desktop & Code.

4
TypeScript
MIT
View repository →

DigiKey and Mouser MCP server for component research, BOM analysis, and sourcing.

3
Python
Apache-2.0
View repository →

Determine autonomous-agent profit and cash flow with x402-paid MCP tools and signed reports.