// open source — now on npm

The agent tool platform that can prove what it did.

Meshrix.js connects your agents to HTTP and MCP services behind one governed gateway. Pactium, the proof layer beneath it, seals every operation into an append-only, cryptographically verifiable ledger. Run both on your own infrastructure.

View on GitHub

npm version of meshrix.js npm version of pactium

// the console

Govern by group. Approve by exception.

Agents call tools constantly — nobody reviews each request by hand. You define toolsets and scoped keys once; routine traffic flows inside those boundaries, and only an exceptional high-risk call pauses for a human. Everything below is the real Web Console, captured live — not a mockup.

// the stack

Two layers. One contract of trust.

The platform you operate, and the substrate that proves it — published as two independent npm packages. Meshrix.js consumes Pactium through its public package API; each layer also stands on its own.

Meshrix.js the platform

Apache-2.0

Connect HTTP and MCP services, govern which clients may discover and call each tool, and operate everything from the Web Console. Requires Node.js 22.19+ or 24.3+.

meshrix.js @meshrix/gateway server · console · gateway · plugins

Pactium the proof layer

Apache-2.0

Proof-first protocol substrate: an append-only operation ledger, Prolly Tree indexes, and portable proof envelopes for verifiable state. Host-neutral and independently usable — it contains no Meshrix-specific aspect.

pactium ledger · proofs · CLI · http adapter

// platform

Your services, governed for agents.

Publish existing services through one MCP endpoint. Scoped keys decide what each client can see and do; the Console shows everything that happens next.

01Web Console

Service health, keys, calls, and logs — day-to-day operation in one surface.

02Scoped API keys

Each client sees only what its key allows. Upstream credentials stay on the server.

03Approvals

Sensitive calls wait for a human decision.

04Upstream gateway

HTTP and MCP services behind one endpoint.

05Embeddable gateway

The typed Gateway API inside your own Node app, independent of the platform runtime.

npm i @meshrix/gateway

06Private deployment

Runs where you already operate. Local state stays in the data directory you choose.

meshrix-server --data-dir ~/.meshrix

// substrate

Proof, not logs.

Pactium records immutable operation facts and mints proof envelopes you can verify locally, export, and re-verify anywhere — without trusting the host that produced them.

prove.js
import { createPactium, verifyProofBundle } from "pactium";

const pactium = createPactium({ dataDir: "./.pactium" });

const envelope = await pactium.recordOperation({
  operationId: "workspace.file.write",
  workspaceId: "workspace-a",
  idempotencyKey: "intent-001",
  outcomeIdempotencyKey: "outcome-001",
  input: { path: "docs/readme.md" },
  result: { status: "written" },
});

const bundle = await pactium.exportProofBundle(envelope);
const proof = await verifyProofBundle(bundle, {
  trustPolicy: "self-carried-manifest",
});

Append-only ledger

RFC 6962-style operation ledger with Intent, Outcome, and terminal Receipt facts. History cannot be rewritten, only extended.

Prolly Tree indexes

Canonical indexes with membership, non-membership, range, multiproof, and diff support over committed state.

Portable bundles

Content-addressed proof material travels in a bundle with a self-carried manifest — verification needs no access to the origin server.

CLI included: pactium doctor · pactium serve · pactium bundle verify

// get started

From npm to a running system in minutes.

Start at the layer you need. The platform gives you the operating surface; the substrate gives you verifiable evidence.

A Run the platform

  1. npm install --global meshrix.js

    Node.js 22.19+ or 24.3+. On npm 12, add --allow-scripts=better-sqlite3.

  2. meshrix-server --with-ui --data-dir ./meshrix-data

    Starts the server and the Web Console together.

  3. Open http://127.0.0.1:7228

    Connect a service, publish its tools, and issue a scoped key for your client.

B Embed the proof layer

  1. npm install pactium

    ESM only, Node.js 22.19+ or 24.3+. No platform required.

  2. pactium.recordOperation(...)

    Record facts and receive a verifiable proof envelope.

  3. verifyProofBundle(bundle)

    Export portable bundles and verify them anywhere, against a trust policy you choose.

// open source

0.x — and honest about it.

Both packages are early and iterating in public. APIs can still evolve; the status and compatibility documents are the contract, not the marketing. A project about verifiable proof should not ask for unverifiable trust.