Identity and Messaging
Identity and messaging in the Weave SDK — signed payloads and the current plaintext transport and verification limits.
Purpose
Application SDK for identities, drives, stores, messaging, replication, and peer networking.
The example signs a local payload. It does not establish an authenticated network session.
Trust contract
AgentMessage::new signs topic || payload || timestamp_le using the node identity. The from DID is not included in those signed bytes. AgentMessage::verify checks a caller-supplied public key; the caller must separately bind that key to the claimed sender and enforce topic authorization and replay limits.
Current transport limitation: MessagingManager bypasses SecretStream and sends length-prefixed JSON over plain TCP. Its receive path forwards messages without calling AgentMessage::verify. The module-level source comment describing encrypted Noise XX channels is stale. Do not transmit sensitive payloads or trust a claimed sender through this path without an independently secured transport and explicit receive-side verification.
Primary types to know
AgentMessage— libs/weave-sdk/src/messaging.rsBasisStore— libs/weave-sdk/src/node.rsConnectedPeer— libs/weave-sdk/src/network_manager.rsForumStore— libs/weave-sdk/src/node.rsGnosisStore— libs/weave-sdk/src/node.rsLensStore— libs/weave-sdk/src/node.rsLocusStore— libs/weave-sdk/src/node.rsMessagingManager— libs/weave-sdk/src/messaging.rsNetworkConfig— libs/weave-sdk/src/network_manager.rs
Example shape
use weave_sdk::messaging::AgentMessage;
use weave_sdk::prelude::*;
#[tokio::main]
async fn main() -> WeaveResult<()> {
// Each node carries a WeaveIdentity whose Ed25519 key signs both strand
// blocks and AgentMessages.
let node = WeaveNode::builder()
.namespace("l1fe")
.identifier("messaging-demo")
.storage_dir("/tmp/weave-messaging")
.build()
.await?;
let identity = node.identity();
let did = identity.did().to_string();
// Sign and verify a payload through the same key that publishes strand events.
let payload = b"audit:replay-required";
let signature = identity.sign(payload);
identity.verify(payload, &signature)?;
// Construct an AgentMessage targeted at a topic; this is the wire frame the
// messaging layer sends between nodes.
let message = AgentMessage::new(identity, "audit", payload.to_vec());
let _ = message.payload.len();
println!(
"did={} discovery_key={} message_topic={}",
did,
hex::encode(identity.discovery_key()),
message.topic,
);
Ok(())
}