ATEP

ATEP: Autonomy Trust Envelope Protocol

Quantum-safe

Every signature and key exchange pairs a classical algorithm with a NIST post-quantum standard: Ed25519 with ML-DSA-65 (FIPS 204) and X25519 with ML-KEM-768 (FIPS 203). Both halves must hold.

Offline identification and verification

A robot or agent can identify and verify another with no internet connection, registry or central server, in milliseconds on a desktop CPU.

Quantum-safe here means finalized NIST standards in a hybrid construction. The reference code has not had an independent security audit. The live simulator runs real cryptography in your browser with simulated robots.

In practice Try the live simulator (opens in a new tab) Specification Quick start Test vectors Claim types Source on GitHub

Draft
07
Rust passes
436 of 436 vectors
JavaScript and Python pass
431 of 436 vectors
Independent audit
none yet

New to this? ATEP in practice explains in plain language what it changes for robot fleets and AI agents, with five scenarios that illustrate how the protocol behaves.

ATEP is an open, quantum-safe trust layer for robots and AI agents. Every signature and key exchange pairs a classical algorithm with a NIST post-quantum standard (Ed25519 with ML-DSA-65 from FIPS 204, X25519 with ML-KEM-768 from FIPS 203) and both halves must hold, so protection is designed to hold against future quantum computers and against a flaw in either half. A signed and encrypted envelope lets one robot or AI agent prove to another who produced a piece of data, that it was not altered, and which third-party certifications the producer holds. It also works offline: a robot or agent can identify and verify another with no internet connection, registry or central server, because an identity is a hash of the sender's public keys and the receiver checks everything against keys, revocation lists and log checkpoints it has already cached, in milliseconds on a desktop CPU. It rides on any carrier (MCP, A2A, MQTT, ROS 2, HTTP, files) and replaces none of them. Quantum-safe here means finalized NIST standards in a hybrid construction; the reference code has not had an independent security audit.

Status. Working draft (Draft 07, the first public draft, 2 October 2026). It is not an Internet-Draft, not a standard, and its media types and some labels are provisional. Reference implementations exist: Rust passes all 436 shared test vectors, JavaScript and Python pass the 431 they can run (five need a log or a monitor); no functional package has been published to a package registry (placeholder names with no code are reserved on crates.io, npm and PyPI) and there has been no external security audit.

What it defines

  • An identity model: an Agent ID is the SHA-256 of a public key bundle.
  • A COSE and CBOR envelope format, signed then encrypted.
  • An attestation schema for third-party claims such as fleet-member or safety-certified.
  • Signed revocation lists and a transparency log that make certifiers accountable.
  • ATEP-R, a robotics profile with required encryption and seven command classes.

What it does not define

Transport, discovery, task negotiation, or the meaning of the payload. An envelope is a byte string that verifies the same way whatever carried it.

Design commitments

Subjects are agents and organizations, never individuals. There is no global score, no mandatory root, no reputation in the core, and no surveillance feed. See governance.

Where to start

What is built, as of 2 October 2026
PartStateLimit
Rust reference core and CLIPasses all 436 vectorsNo external audit; needs a C linker to build
Transparency log and monitorImplemented in Rust, acceptance testedPlain HTTP, keys in files; not run by anyone outside the project
JavaScript (@atep/core, WebAssembly)Passes 431 of 436 vectors under Node (five for a log and a monitor are skipped)Not published (the name is reserved on npm as a placeholder with no code); not tested in a real browser, Bun or Deno
Python (atep_py)Independent, standard library only, passes 431 of 436 vectors (five for a log and a monitor are skipped)Slow; not published (the name is reserved on PyPI as a placeholder with no code); written by the project, not by an outside party
Carrier examplesMCP, A2A, HTTP, file and MQTT run and testedROS 2 example has not been run on ROS 2