Skip to content

Implement Poke Interconnect Protocol (PIP v1) and MCP server - #1

Merged
CommunityPoke merged 9 commits into
mainfrom
devin/1789165569-pip-v1
Sep 11, 2026
Merged

CommunityPoke merged 9 commits into
mainfrom
devin/1789165569-pip-v1

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Summary

Implements PIP v1 as the Python package pip_protocol (dist poke-interconnect, pip-node CLI). The spec is docs/PROTOCOL.md; everything below follows it.

Core design — one transport-agnostic Node does all verification and policy; HTTP (FastAPI) and MCP (FastMCP) are thin adapters, so there is no unauthenticated path on either transport.

Envelope {pip, id, type, from, to, ts, expires, nonce, idempotency_key?, in_reply_to?, payload, sig{alg,kid,value}}
signing_input = b"PIPv1\n" + canonical_json(envelope minus sig)
instance_id   = "pip:" + base32(sha256(ed25519_pubkey))[:26]     # self-certifying
Node.handle(env) -> (signed receipt|data|error envelope, PipError|None)
  verify_inbound: version → to==self → size → kid hashes to `from` & matches pinned/rotating key
                  → signature → skew/expiry → nonce replay → payload schema
  _dispatch:      idempotency short-circuit (re-signed receipt, status=duplicate) → rate limit
                  → PolicyEngine.authorize(peer, scope, resource, action) → handler → sign
  • Policy (config/policy.example.yaml): pinned peers, scopes with prefix:* wildcards, per-resource consents (CONSENT_REQUIRED distinct from FORBIDDEN), token-bucket rate limits, size caps, redaction fields/regexes. Redaction runs before signing so signatures cover redacted content.
  • Store: MemoryStore / SqliteStore behind one Store protocol (nonces, idempotency receipts by key+ref, outbox). Outbox gives at-least-once sending with exponential backoff; receiver idempotency gives effectively-once.
  • HTTP: GET /.well-known/pip, POST /pip/v1/inbox (HTTP status mapped from PipError.http_status, body always a signed envelope), /healthz, /metrics (Prometheus, private registry), optional constant-time bearer gate, X-PIP-Request-Id/X-PIP-Trace-Id, JSON logs without payload contents. HttpPeerClient verifies the response signature and in_reply_to.
  • MCP: tools pip_handshake, pip_send_message, pip_exchange_data, pip_get_receipt, pip_list_capabilities; resources pip://identity|capabilities|policy/scopes; prompts pip_compose_message, pip_request_data. Tools never raise — failures return the signed error envelope. stdio and streamable-http (with bearer middleware).
  • Secure config: PIP_* env via pydantic-settings, key only via file path, refuses group/world-readable key files, loopback bind by default, TLS delegated to a proxy (docs/SECURITY.md).

Verification: ruff check, ruff format --check, mypy --strict src, pytest (116 tests) all pass locally; CI workflow runs the same on Python 3.10 and 3.12. Smoke-tested pip-node keygen/identity/serve-http + curl /healthz, /.well-known/pip.

Notable decisions / deviations from spec text: duplicate receipts are re-signed (a mutated stored receipt would fail signature); Consent.expires optional; any 1.x version accepted; inbound receipt/error envelopes require messages:send, data responses data:respond; pip_get_receipt takes a signed receipt-type lookup envelope and requires messages:read.

Follow-ups: async handlers / background outbox worker, peer directory beyond the static policy file, mTLS option, persistent inbox, key-rotation CLI.

Link to Devin session: https://app.devin.ai/sessions/4104d923252c419994b9ebddc2f28bec
Open in Devin Desktop: https://app.devin.ai/desktop/session/4104d923252c419994b9ebddc2f28bec?variant=devin
Requested by: @CommunityPoke

CommunityPoke and others added 9 commits September 11, 2026 22:32
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…ore, outbox, node)

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…add error_for_raw, mark_dead, receipt lookup by ref

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@CommunityPoke
CommunityPoke merged commit efb1bf8 into main Sep 11, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant