Cotal

mcp
Security Audit
Fail
Health Pass
  • License — License: Apache-2.0
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Community trust — 261 GitHub stars
Code Fail
  • spawnSync — Synchronous process spawning in .github/workflows/ci.yml
  • rm -rf — Recursive force deletion command in .github/workflows/installer.yml
  • rm -rf — Recursive force deletion command in bin/cotal.ts
  • process.env — Environment variable access in bin/cotal.ts
Permissions Pass
  • Permissions — No dangerous permissions requested

No AI report is available for this listing yet.

SUMMARY

The open standard for agent coordination

README.md
Cotal

The open pub/sub standard for AI agents.

Cotal: any agent, any topology. Claude Code, OpenCode, Hermes and Codex across peer-to-peer, supervised, hierarchical and hybrid topologies

Deploy any agent topology: DAGs, graphs, swarms, supervisor trees, pipelines, or any shape you can draw.

Distributed programming for agents.

Read the docs at docs.cotal.ai   Quick start

CI
npm
Docs
Discord
License
Node

Examples · Supported agents · FAQ

What is Cotal

Cotal is a provider agnostic, cross-machine capable, and extensible open standard for AI agents to work together in one shared space, where
the structure (their topology) is yours to define.
Every agent sees who else is there
and messages anyone directly.

Most agent tools lock that structure in for you: usually a tree, where one controller
hands out work and the workers never talk to each other, or bare one-to-one messaging
with no shared space at all. With Cotal it is configuration: who delegates to whom, or
whether anyone is in charge, is something you set, so the same standard runs a flat team
of peers
, a manager with workers, a chain of command, or any mix.

And a mesh is not tied to one project or one machine. Several run side by side on the same
box, each with its own agents, channels and broker: cotal meshes lists them,
cotal use <space> picks your default, and every command takes --space <name>, so a
client project and a research team run in parallel and never see each other. The broker can
equally sit on a server you reach over the internet, so a laptop, a workstation and a
container in the cloud all join the same space.

Because the standard is open, you extend it the same way: bring your own agents, or
connect anything that speaks the contract. It runs on NATS and JetStream,
messaging infrastructure proven in production for years; the reference implementation is
TypeScript.

Quick start

curl -fsSL https://get.cotal.ai | sh

Installs into your home directory, no sudo, then runs guided setup. Read it first at
get.cotal.ai, or preview it with | sh -s -- --dry-run.

On Windows, or if you already have Node 22+: npm install -g cotal-ai && cotal setup.
Prefer your agent to do it? Point it at https://docs.cotal.ai/prompt.md.

Setup gets your machine ready and starts nothing. Then:

cotal up --detach  # start the mesh
cotal spawn        # put your agent on it and talk to it (Ctrl-C to leave)
cotal web          # watch it in the browser
cotal down         # stop everything

One agent, on a real mesh, that you can talk to. Add a second and they can see each other, which
is the whole point.

cotal up is JWT-authed by default (sender authenticity + per-agent ACLs, plus the
server-side delivery daemon for durable delivery). cotal up --open gives you a loopback-only,
live-only mesh with no auth.

Want the guided team? cotal setup --demo adds david (engineer), sven (guide) and me (the
session you drive); then cotal spawn david and watch with cotal console.

[!TIP]
Using a coding agent? cotal up brings up a manager, an endpoint that lets your agent
pull in teammates on demand: ask your agent for one ("spin up a reviewer") and it spawns it
on the mesh via cotal_spawn. See docs/connect-claude.md.

Run it your way: a whole team from one cotal.yaml manifest, each agent
in its own cmux, tmux or
Orca terminal, Codex,
OpenCode or
Hermes instead of Claude. Install flags, requirements and
uninstall are in docs/getting-started.md.

How it works

Agents in a space address each other three ways.

Multicast: alice posts to the #general channel and every subscriber receives it Unicast: alice messages bob directly; the message waits in his durable inbox while he is busy and is delivered when he frees up Anycast: a message addressed to the reviewer role; exactly one free reviewer instance claims it
Multicast: broadcast to a channel.
A message on a named channel (#general, #review) reaches everyone subscribed to it. This is how a group stays in sync.
Unicast: message one peer.
Addressed to a specific instance and delivered durably: a message to a busy or offline agent waits on the stream until it is read, so nothing is lost.
Anycast: reach any one of a role.
Address a service ("whoever is a reviewer") and exactly one available instance picks the work up. Delegation and load-balancing without naming a worker.

Underneath all three: presence. Every agent publishes a live state (idle /
waiting / working / offline) and its A2A
AgentCard. Anyone in the space can read the roster and see who is doing what, which
is what makes lateral coordination possible without a central scheduler.

Why a protocol?

Cotal complements the two protocols already in the agent stack; it doesn't replace
them.

  • MCP connects an agent to its tools.
  • A2A connects two agents in a pairwise
    request/response.
  • Cotal brings pub/sub to agents: many of them coordinating live in one shared
    space, with presence, channels, durable delivery, and the three addressing modes as
    one model.

Cotal reuses A2A's data shapes to stay interoperable: identity is an A2A AgentCard
(its role is the addressable service that anycast resolves to), and wire messages
reuse A2A Message/Part. It does not adopt A2A's HTTP/JSON-RPC transport, Task
RPCs, or request/response server model. Only the shapes carry over. Underneath, NATS +
JetStream has run in production for years. We didn't invent the hard parts.

The web dashboard

cotal web opens a god-view browser dashboard over the live space: presence, channels, DMs,
and golden-signal tiles that show at a glance what needs a human. Its graph view draws the whole
mesh as one live constellation, a wire per channel membership, glowing where messages flow.

The dashboard graph view: a live force-directed constellation of the mesh, with channels and agents as nodes and a wire per membership that glows when a message flows between them
Graph view. The whole mesh as one live constellation, a wire per channel membership, glowing where messages flow.

The dashboard channel view: the online roster, a per-channel message list, golden-signal tiles, and the NEEDS-YOU lane
Monitor and channels. The roster (status as shape and colour, role, and harness), one channel's messages, and the tiles: working / waiting / idle / offline / oldest-unattended.

The dashboard agent detail card: a per-agent drill-down with role, harness and model, live status, current activity, and tags
Agent detail. Click any node for a drill-down rendered from the peer's card: role, harness and model, live status, current activity, and tags.

Read-only and least-privilege (it self-mints a narrow cred, then drops the signing seed); the
terminal cotal console watches the same space. See docs/watch-a-mesh.md.

Examples

The cotal console: a live roster of agents and their all-activity feed in a terminal TUI Lateral coordination

Role-specialized peers in one space: presence, all three addressing modes, live state, graceful leave, and late join, each in its own terminal.

the raw protocol · plain terminals
A swarm rebuilds Cotal's console

Four real Claude Code agents join one mesh and coordinate as lateral peers; an orchestrator spawns the workers in cmux tabs and they ship a polished Ink/React TUI for the live console.

four coding agents · cmux tabs
Four Claude Code agents (orchestrator, backend, tui-designer, manager) coordinating on the Cotal mesh, with the live cotal console on the left and the agents in cmux tabs on the right
The Frontier Tower faces demo on the tmux wall: pixel-art OpenCode agents on the Cotal mesh lip-syncing their streamed replies, with the live cotal console beside them Frontier Tower faces

Ten panelist personas as animated pixel-art OpenCode agents: each thinks, lip-syncs its streamed reply, and steers its own 32×32 expression, and on the mesh they coordinate as lateral peers in one space.

ten OpenCode faces · OpenCode · tmux wall + browser

Full index: docs/examples.md.

Supported agents


Claude Code

installed plugin + hooks

OpenCode

native in-process plugin

Codex

app-server + its own TUI

Hermes

gateway daemon + plugin
Jcode
Harness API + its own TUI

pi

pi extension + live steer

They attach differently but expose the same cotal_* tools, and all six push, so a
peer message wakes an idle agent the instant it arrives; Codex and pi additionally drive a live
turn, folding an arriving message into an in-flight one with steer(). Any agent that implements the
contract joins the same way; a connector is just a thin client over the wire. Want one
for an agent that isn't here yet?
Vote for the next connector.

What Cotal adds on top of NATS

NATS is the transport; Cotal is the contract on top. Each capability below maps to a
concrete mechanism you can check against the code.

Identity and access

  • Sender authenticity. The sender rides the subject
    (cotal.<space>.inst.<target>.<sender>), policed by the server against the agent's
    JWT, not self-asserted. Identity claims in the payload are rejected, fail-closed.
  • Per-agent ACLs. Decentralized JWT auth, account = space and user = agent. The
    agent, observer, and admin profiles are default-deny allow-lists (manager is
    privileged and not user-mintable); cotal mint writes a creds file.
  • DM confidentiality by construction. Two leak paths are closed: delivery is
    ACL-gated by subject, and replay is gated because each agent's inbox is a pre-created,
    bind-only consumer it cannot re-create. (DMs are plaintext and ACL-gated, not
    encrypted.)

Delivery and history

  • Durable, per-reader delivery. Three JetStream streams per space, with a bookmark
    per reader: busy or offline agents resume where they left off, and a late joiner
    replays history before going live.
  • Three delivery modes, one model. Multicast, unicast, and anycast are one
    addressing scheme over the same space (subjects chat.>, inst.>, svc.>), not
    three transports.
  • Roles as addressable services. A role is the anycast address: "send to any
    reviewer" routes through a shared work queue, so specialization lives in the
    addressing.
  • Logging and tracing built in. Every message rides a durable stream, so the space
    is one replayable log of who said what to whom, in order. cotal console --plain tails it live.

Presence and attention

  • Presence and a live channel registry. Presence is a per-space NATS KV bucket
    (TTL + heartbeat); channels carry a registry (replay policy, description, instructions)
    watched live over KV.
  • Push, not poll. On push-capable hosts a peer message wakes an idle agent the
    instant it arrives, so a mesh runs hands-free; pull-only hosts read on their next turn.
  • Attention modes. Each agent sets what may interrupt it: open lets channel
    chatter wake it, dnd holds chatter for the next turn, focus admits only direct
    messages and assigned work.

Ecosystem: what runs today

Package What it is
@cotal-ai/core Endpoint, subjects, message types, the NATS client layer, and the Connector/Command contracts.
@cotal-ai/cli Mesh CLI: up, down, join, console, spawn, mint, channels, history, and the operator extension loader.
@cotal-ai/manager Agent supervisor: spawns and manages nodes via a pluggable runtime (pty / tmux / cmux / Orca / Herdr), with start/stop/ps/attach.
@cotal-ai/delivery Server-side Plane-3 delivery daemon: the durable backstop (fan-out writer + trusted reader + membership/ACL authority), co-located with the broker.
@cotal-ai/connector-core Shared MCP-bridge runtime: the mesh agent and the cotal_* tools the agent connectors above are thin clients over.

Plus the six agent connectors above and installable @cotal-ai/cmux,
@cotal-ai/tmux, @cotal-ai/orca, and
@cotal-ai/herdr runtime integrations;
the full package list is in AGENTS.md.

Documentation

The full docs live at docs.cotal.ai, built for humans and
agents alike: every page doubles as clean Markdown, and an agent can set Cotal up from
docs.cotal.ai/prompt.md alone.

FAQ

Why not just A2A or MCP?

They solve different layers. MCP connects an agent to its tools; A2A connects two
agents in a pairwise request/response. Neither gives you a live shared space with
presence, channels, durable delivery, and topology-free coordination. That's the gap
Cotal fills. Reusing A2A's AgentCard and Message/Part shapes keeps the two
interoperable.

Is Cotal TypeScript-only?

The protocol isn't. Cotal is a contract over NATS (subjects, schemas, and required
client behaviors like presence, ack-on-surface, and sender authenticity), and the layer
is deliberately thin. TypeScript is the only implementation today; any language with a
NATS client can implement the contract documented in docs/, and official
clients in other languages are planned.

Why NATS underneath, and does it run distributed?

JetStream streams give durable delivery to busy or offline agents, per-reader
bookmarks, and late-join history without Cotal reimplementing any of it. And yes: NATS
clustering takes the same subjects, streams, and accounts from one machine to a
distributed cluster unchanged.

Can an agent impersonate another?

No. The sender rides the NATS subject, which the server polices against the agent's
JWT; a payload claiming a different sender is rejected. DMs are confidential by
construction: a per-identity inbox served by a bind-only durable that agents can't
re-create or re-target.

Sponsors & partners

Immersive Commons
Building Web-A, the web for agents. We're part of it and share the vision.
Frontier Tower
San Francisco's hub for frontier technologies.

We're looking for more design partners building multi-agent systems.
Reach out.

Contributions are welcome: implement the contract in your language, build a connector,
or open an issue.

Team

David Farah
David Farah
@DavidFarahlb on X David Farah on LinkedIn
Sven Jonscher
Sven Jonscher
@svensonj00 on X Sven Jonscher on LinkedIn

Building something on Cotal, or want to? Email [email protected]. We read everything.

License

Apache-2.0 for everything in this repo: the wire protocol, core, every
extension, and the CLI. See LICENSING.md for the trademark note and the
hosted-server plan.


Made with ❤️ by Cotal, in Switzerland and San Francisco.

Reviews (0)

No results found