Weave documentation
Weave Sdk

Identity and Messaging

Identity and messaging in the Weave SDK — signed payloads and the current plaintext transport and verification limits.

Purpose

Application SDK for identities, drives, stores, messaging, replication, and peer networking.

The example signs a local payload. It does not establish an authenticated network session.

Trust contract

AgentMessage::new signs topic || payload || timestamp_le using the node identity. The from DID is not included in those signed bytes. AgentMessage::verify checks a caller-supplied public key; the caller must separately bind that key to the claimed sender and enforce topic authorization and replay limits.

Current transport limitation: MessagingManager bypasses SecretStream and sends length-prefixed JSON over plain TCP. Its receive path forwards messages without calling AgentMessage::verify. The module-level source comment describing encrypted Noise XX channels is stale. Do not transmit sensitive payloads or trust a claimed sender through this path without an independently secured transport and explicit receive-side verification.

Primary types to know

  • AgentMessage — libs/weave-sdk/src/messaging.rs
  • BasisStore — libs/weave-sdk/src/node.rs
  • ConnectedPeer — libs/weave-sdk/src/network_manager.rs
  • ForumStore — libs/weave-sdk/src/node.rs
  • GnosisStore — libs/weave-sdk/src/node.rs
  • LensStore — libs/weave-sdk/src/node.rs
  • LocusStore — libs/weave-sdk/src/node.rs
  • MessagingManager — libs/weave-sdk/src/messaging.rs
  • NetworkConfig — libs/weave-sdk/src/network_manager.rs

Example shape

use weave_sdk::messaging::AgentMessage;
use weave_sdk::prelude::*;

#[tokio::main]
async fn main() -> WeaveResult<()> {
    // Each node carries a WeaveIdentity whose Ed25519 key signs both strand
    // blocks and AgentMessages.
    let node = WeaveNode::builder()
        .namespace("l1fe")
        .identifier("messaging-demo")
        .storage_dir("/tmp/weave-messaging")
        .build()
        .await?;

    let identity = node.identity();
    let did = identity.did().to_string();

    // Sign and verify a payload through the same key that publishes strand events.
    let payload = b"audit:replay-required";
    let signature = identity.sign(payload);
    identity.verify(payload, &signature)?;

    // Construct an AgentMessage targeted at a topic; this is the wire frame the
    // messaging layer sends between nodes.
    let message = AgentMessage::new(identity, "audit", payload.to_vec());
    let _ = message.payload.len();
    println!(
        "did={} discovery_key={} message_topic={}",
        did,
        hex::encode(identity.discovery_key()),
        message.topic,
    );
    Ok(())
}

On this page