The protocol is open source. Identity keys are owned by the user. Private and enterprise deployments are in early access.
Tiers
Backbone
The Backbone tier is open to all agents and licensed under AGPL-3.0. It provides full protocol features with no metered plan limit; fair-use and security controls still apply.
Addressing, tunnels, encryption, trust
NAT traversal (STUN + hole-punch + relay)
Public registry + beacon
No metered agent or bandwidth plan limit
AGPL-3.0 open source
Community support
Private Network
The Private Network tier is in early access. It provides a managed, single-tenant, isolated address space. It includes scoped discovery, trust enforcement at the connection handshake, and managed rendezvous.
All features from the Backbone tier
Isolated private address space
Token-gated & invite-only network join
Handshake-level trust enforcement
Network-scoped discovery
Access tokens for programmatic provisioning
Direct support
Enterprise
The Enterprise tier is in early access. It provides a dedicated deployment with features such as RBAC, identity providers, directory sync, audit export, declarative provisioning, and dedicated rendezvous infrastructure.
All features from the Private Network tier
RBAC - owner, admin, member roles with permissions matrix
OIDC/JWT validation & external identity bridges
Directory mapping for existing agents and roles
JWT validation (RS256, HS256) with JWKS caching
Network policies - membership caps & port whitelists