ATEP: Autonomy Trust Envelope Protocol
Quantum-safe
Every signature and key exchange pairs a classical algorithm with a NIST post-quantum standard: Ed25519 with ML-DSA-65 (FIPS 204) and X25519 with ML-KEM-768 (FIPS 203). Both halves must hold.
Offline identification and verification
A robot or agent can identify and verify another with no internet connection, registry or central server, in milliseconds on a desktop CPU.
Quantum-safe here means finalized NIST standards in a hybrid construction. The reference code has not had an independent security audit. The live simulator runs real cryptography in your browser with simulated robots.
In practice Try the live simulator (opens in a new tab) Specification Quick start Test vectors Claim types Source on GitHub
- Draft
- 07
- Rust passes
- 436 of 436 vectors
- JavaScript and Python pass
- 431 of 436 vectors
- Independent audit
- none yet
New to this? ATEP in practice explains in plain language what it changes for robot fleets and AI agents, with five scenarios that illustrate how the protocol behaves.
ATEP is an open, quantum-safe trust layer for robots and AI agents. Every signature and key exchange pairs a classical algorithm with a NIST post-quantum standard (Ed25519 with ML-DSA-65 from FIPS 204, X25519 with ML-KEM-768 from FIPS 203) and both halves must hold, so protection is designed to hold against future quantum computers and against a flaw in either half. A signed and encrypted envelope lets one robot or AI agent prove to another who produced a piece of data, that it was not altered, and which third-party certifications the producer holds. It also works offline: a robot or agent can identify and verify another with no internet connection, registry or central server, because an identity is a hash of the sender's public keys and the receiver checks everything against keys, revocation lists and log checkpoints it has already cached, in milliseconds on a desktop CPU. It rides on any carrier (MCP, A2A, MQTT, ROS 2, HTTP, files) and replaces none of them. Quantum-safe here means finalized NIST standards in a hybrid construction; the reference code has not had an independent security audit.
Status. Working draft (Draft 07, the first public draft, 2 October 2026). It is not an Internet-Draft, not a standard, and its media types and some labels are provisional. Reference implementations exist: Rust passes all 436 shared test vectors, JavaScript and Python pass the 431 they can run (five need a log or a monitor); no functional package has been published to a package registry (placeholder names with no code are reserved on crates.io, npm and PyPI) and there has been no external security audit.
What it defines
- An identity model: an Agent ID is the SHA-256 of a public key bundle.
- A COSE and CBOR envelope format, signed then encrypted.
- An attestation schema for third-party claims such as
fleet-memberorsafety-certified. - Signed revocation lists and a transparency log that make certifiers accountable.
- ATEP-R, a robotics profile with required encryption and seven command classes.
What it does not define
Transport, discovery, task negotiation, or the meaning of the payload. An envelope is a byte string that verifies the same way whatever carried it.
Design commitments
Subjects are agents and organizations, never individuals. There is no global score, no mandatory root, no reputation in the core, and no surveillance feed. See governance.
Where to start
- Quick start in Rust, JavaScript and Python.
- Specification and the whole text in one file: llms-full.txt.
- Test vectors: how an implementer proves conformance.
- Claim types: the definition and schema of every claim URI under
https://atep.dev/claims/. - llms.txt, a one screen map for language models.
| Part | State | Limit |
|---|---|---|
| Rust reference core and CLI | Passes all 436 vectors | No external audit; needs a C linker to build |
| Transparency log and monitor | Implemented in Rust, acceptance tested | Plain HTTP, keys in files; not run by anyone outside the project |
JavaScript (@atep/core, WebAssembly) | Passes 431 of 436 vectors under Node (five for a log and a monitor are skipped) | Not published (the name is reserved on npm as a placeholder with no code); not tested in a real browser, Bun or Deno |
Python (atep_py) | Independent, standard library only, passes 431 of 436 vectors (five for a log and a monitor are skipped) | Slow; not published (the name is reserved on PyPI as a placeholder with no code); written by the project, not by an outside party |
| Carrier examples | MCP, A2A, HTTP, file and MQTT run and tested | ROS 2 example has not been run on ROS 2 |